Skip to content
Windows Firewall

Firewall Event ID 2006: Rule deleted

A rule has been deleted in the Windows Defender Firewall exception listFirewall event 2006 records the deletion of a Windows Firewall rule, with the rule ID, name, and the user SID and process that removed it. On by default.
2006
Event ID
2006
Channel
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider
Microsoft-Windows-Windows Firewall With Advanced Security
Log file
Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
Category
Policy changes
Default logging
Logged by default

What event 2006 means

Event 2006 is written to the Windows Firewall operational log when a rule is deleted. It is short: RuleId, RuleName, ModifyingUser (SID) and ModifyingApplication (process path). The rule's former settings are not included.

To know what the rule did, search earlier 2004 or 2005 events for the same RuleId, or the Security log (4946, 4947) if MPSSVC auditing was on.

Uninstallers and updates delete rules routinely. The interesting cases are block rules removed by a scripting tool, and rules deleted shortly after being created — a sign of an attacker cleaning up.

When it is logged

Audit policy / configuration

Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.

Recent Windows 11 builds log rule deletions under event 2052 in the same channel (as used by public Sigma rules); include both IDs in hunts.

Key fields

FieldWhat it tells you
RuleIdUnique ID of the deleted rule; search earlier 2004/2005 events for it.
RuleNameDisplay name of the deleted rule.
ModifyingUserSID of the account that deleted the rule.
ModifyingApplicationFull path of the process that deleted the rule (netsh.exe, powershell.exe, an uninstaller).

Common benign sources

  • Application uninstallers removing their own rules.
  • Updates that delete and recreate rules during upgrades.
  • Administrators removing obsolete rules.

What attackers do that produces it

  • Deleting block rules to let malware or a C2 channel communicate.
  • Removing the allow rule created earlier for a backdoor, to reduce traces.

Investigation tips

  • Rebuild the deleted rule from earlier 2004/2005 events with the same RuleId.
  • Check ModifyingApplication and correlate with process creation (4688, Sysmon 1) to get the command line and parent.
  • Measure the rule's lifetime; a rule created and deleted within the same intrusion window is suspicious.

MITRE ATT&CK techniques

TechniqueTactics
T1686.003 Disable or Modify System Firewall: Windows Host FirewallDefense Impairment
T1070 Indicator RemovalStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading