Skip to content
Windows Firewall

Firewall Event ID 2005: Rule modified

A rule has been modified in the Windows Defender Firewall exception listFirewall event 2005 records a change to an existing Windows Firewall rule, with the rule's new settings and the user and process that changed it. On by default.
2005
Event ID
2005
Channel
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider
Microsoft-Windows-Windows Firewall With Advanced Security
Log file
Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
Category
Policy changes
Default logging
Logged by default

What event 2005 means

Event 2005 is written to the Windows Firewall operational log when an existing rule is changed — enabled, disabled, or edited. It carries the complete new definition of the rule (program, ports, addresses, Direction, Action, Active) plus ModifyingUser (SID) and ModifyingApplication (process path).

The event does not include the previous values. To see what changed, compare with an earlier 2004 or 2005 for the same RuleId, or with the rule's state on a known-good host.

Enabling a predefined rule (Remote Desktop, WinRM, File and Printer Sharing, Remote Event Log Management) is a quiet way to open a host for remote access, and it appears here with Active set to 1 rather than as a new rule.

When it is logged

Audit policy / configuration

Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.

Newer Windows 10 and Windows 11 builds log rule modifications under a different event ID in the same channel; if 2005 is absent on a recent build, look for other rule-change events there.

Key fields

FieldWhat it tells you
RuleIdUnique ID of the modified rule; use it to find the rule's earlier events.
RuleNameDisplay name of the rule.
ApplicationPathProgram the rule applies to, if any.
ServiceNameService the rule applies to, if any.
DirectionTraffic direction.
ValueMeaning
1Inbound.
2Outbound.
ProtocolIANA protocol number (6 TCP, 17 UDP).
LocalPortsLocal ports covered by the rule after the change.
RemoteAddressesRemote address scope after the change; watch for scopes widened to any.
ActionRule action after the change.
ValueMeaning
2Block.
3Allow.
ActiveWhether the rule is enabled after the change.
ValueMeaning
0Disabled.
1Enabled.
ModifyingUserSID of the account that modified the rule.
ModifyingApplicationFull path of the process that modified the rule.

Common benign sources

  • Windows servicing and application updates refreshing their rules.
  • Administrators enabling built-in rule groups for a new role or feature.
  • Network and management agents adjusting rules they own.

What attackers do that produces it

  • Enabling the built-in Remote Desktop or WinRM rules with netsh advfirewall firewall set rule group=... new enable=yes or Enable-NetFirewallRule.
  • Switching a block rule to allow, or broadening its remote address scope, to let a tool communicate.

Investigation tips

  • Compare the new state with the previous 2004/2005 for the same RuleId to identify the actual change.
  • Resolve ModifyingUser and correlate ModifyingApplication with process creation (4688, Sysmon 1) at the same time.
  • When an inbound remote-access rule was enabled, look for logons that followed (4624 LogonType 3 or 10, RDP 1149).

MITRE ATT&CK techniques

TechniqueTactics
T1686.003 Disable or Modify System Firewall: Windows Host FirewallDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading