Firewall Event ID 2006: Rule deleted
- Event ID
- 2006
- Channel
- Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
- Provider
- Microsoft-Windows-Windows Firewall With Advanced Security
- Log file
- Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 2006 means
Event 2006 is written to the Windows Firewall operational log when a rule is deleted. It is short: RuleId, RuleName, ModifyingUser (SID) and ModifyingApplication (process path). The rule's former settings are not included.
To know what the rule did, search earlier 2004 or 2005 events for the same RuleId, or the Security log (4946, 4947) if MPSSVC auditing was on.
Uninstallers and updates delete rules routinely. The interesting cases are block rules removed by a scripting tool, and rules deleted shortly after being created — a sign of an attacker cleaning up.
When it is logged
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.
Recent Windows 11 builds log rule deletions under event 2052 in the same channel (as used by public Sigma rules); include both IDs in hunts.
Key fields
| Field | What it tells you |
|---|---|
| RuleId | Unique ID of the deleted rule; search earlier 2004/2005 events for it. |
| RuleName | Display name of the deleted rule. |
| ModifyingUser | SID of the account that deleted the rule. |
| ModifyingApplication | Full path of the process that deleted the rule (netsh.exe, powershell.exe, an uninstaller). |
Common benign sources
- Application uninstallers removing their own rules.
- Updates that delete and recreate rules during upgrades.
- Administrators removing obsolete rules.
What attackers do that produces it
- Deleting block rules to let malware or a C2 channel communicate.
- Removing the allow rule created earlier for a backdoor, to reduce traces.
Investigation tips
- Rebuild the deleted rule from earlier 2004/2005 events with the same
RuleId. - Check
ModifyingApplicationand correlate with process creation (4688, Sysmon 1) to get the command line and parent. - Measure the rule's lifetime; a rule created and deleted within the same intrusion window is suspicious.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumA Rule Has Been Deleted From The Windows Firewall Exception ListRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.