Skip to content
Windows Firewall

Firewall Event ID 2033: All rules deleted

All rules have been deleted from the Windows Defender Firewall configuration on this computerFirewall event 2033 records that every rule was deleted from a Windows Firewall rule store, with the user SID and process responsible. Rare and worth reviewing.
2033
Event ID
2033
Channel
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider
Microsoft-Windows-Windows Firewall With Advanced Security
Log file
Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
Category
Policy changes
Default logging
Logged by default

What event 2033 means

Event 2033 is written to the Windows Firewall operational log when all rules are removed from a firewall configuration store at once. It records StoreType, the SID of the account in ModifyingUser and the process path in ModifyingApplication.

Wiping all rules removes every allow and block rule in that store in a single action. Depending on the default policy, this can cut off legitimate services or remove restrictions an administrator relied on, so it should be rare outside of imaging and deliberate resets.

Treat it as a significant configuration event: identify the process and account, then check what the firewall state looked like before and after (for example with 2004 events that follow as rules are restored).

When it is logged

Audit policy / configuration

Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.

Key fields

FieldWhat it tells you
StoreTypeThe firewall policy store whose rules were deleted.
ModifyingUserSID of the account that deleted the rules.
ModifyingApplicationFull path of the process that deleted the rules.

Common benign sources

  • Administrators or deployment scripts resetting the firewall during imaging or troubleshooting.
  • Management and security tools that rebuild the rule set from scratch.

What attackers do that produces it

  • Removing all firewall rules to disrupt protections or to clear the way for remote access, for example with netsh.exe or powershell.exe run by an administrator account.

Investigation tips

  • Identify the account from ModifyingUser and correlate ModifyingApplication with process creation (4688, Sysmon 1).
  • Review firewall events right after (2004 bursts) to see whether rules were restored, and whether new allow rules were slipped in.
  • Check for other defense-impairment activity around the same time (firewall service or Defender changes).

MITRE ATT&CK techniques

TechniqueTactics
T1686.003 Disable or Modify System Firewall: Windows Host FirewallDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading