Firewall Event ID 2033: All rules deleted
- Event ID
- 2033
- Channel
- Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
- Provider
- Microsoft-Windows-Windows Firewall With Advanced Security
- Log file
- Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 2033 means
Event 2033 is written to the Windows Firewall operational log when all rules are removed from a firewall configuration store at once. It records StoreType, the SID of the account in ModifyingUser and the process path in ModifyingApplication.
Wiping all rules removes every allow and block rule in that store in a single action. Depending on the default policy, this can cut off legitimate services or remove restrictions an administrator relied on, so it should be rare outside of imaging and deliberate resets.
Treat it as a significant configuration event: identify the process and account, then check what the firewall state looked like before and after (for example with 2004 events that follow as rules are restored).
When it is logged
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.
Key fields
| Field | What it tells you |
|---|---|
| StoreType | The firewall policy store whose rules were deleted. |
| ModifyingUser | SID of the account that deleted the rules. |
| ModifyingApplication | Full path of the process that deleted the rules. |
Common benign sources
- Administrators or deployment scripts resetting the firewall during imaging or troubleshooting.
- Management and security tools that rebuild the rule set from scratch.
What attackers do that produces it
- Removing all firewall rules to disrupt protections or to clear the way for remote access, for example with
netsh.exeorpowershell.exerun by an administrator account.
Investigation tips
- Identify the account from
ModifyingUserand correlateModifyingApplicationwith process creation (4688, Sysmon 1). - Review firewall events right after (2004 bursts) to see whether rules were restored, and whether new allow rules were slipped in.
- Check for other defense-impairment activity around the same time (firewall service or Defender changes).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1686.003 Disable or Modify System Firewall: Windows Host Firewall | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighAll Rules Have Been Deleted From The Windows Firewall ConfigurationRule by frack113, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.