Skip to content
Security

Event ID 4946: Firewall rule added

A change has been made to Windows Firewall exception list. A rule was added.Security event 4946 records a Windows Firewall rule added locally, with its name, ID and profiles. Useful to catch attackers opening ports or allowing tools.
4946
Event ID
4946
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Needs configuration

What event 4946 means

Event 4946 is written by the Windows Firewall service (MPSSVC) when a rule is added to the local firewall policy, whether through wf.msc, netsh advfirewall, the New-NetFirewallRule cmdlet, an installer or the firewall COM API. It is not generated for rules delivered by Group Policy.

The record is thin: RuleName, RuleId and ProfileChanged. It does not say who made the change, which program or port the rule covers, or whether it allows or blocks. For those details use the Windows Firewall channel event 2004 written at the same moment, which carries ApplicationPath, LocalPorts, Action, ModifyingUser and ModifyingApplication.

Software installs and Windows updates add rules routinely, so the value is in the rule name and timing: an unfamiliar rule created minutes after a suspicious logon or process launch deserves a look.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit MPSSVC Rule-Level Policy Change (Success). Not audited in the default Windows audit policy.

The same subcategory also produces 4947 (rule modified), 4948 (rule deleted) and 4950 (setting changed). The Windows Firewall operational channel (event 2004) is on by default and gives more detail, so check it even when this subcategory is not enabled.

Key fields

FieldWhat it tells you
ProfileChangedFirewall profiles the rule applies to, e.g. All, Domain, Private, Public or a combination such as Domain,Public.
RuleIdUnique ID of the rule — a GUID-like string or a built-in rule name. The rule is stored under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules with this ID as the value name.
RuleNameDisplay name of the rule as shown in wf.msc. Attackers often pick names that look like legitimate software.

Common benign sources

  • Application installers (browsers, VPN clients, games, collaboration tools) registering their own inbound rules.
  • Windows features and roles being enabled, which add their predefined rule groups.
  • Administrators creating rules with netsh advfirewall firewall add rule or New-NetFirewallRule.

What attackers do that produces it

  • Opening inbound access for a backdoor, RAT listener or tunneling tool (for example allowing TCP 3389, 5985 or a high port) with netsh advfirewall firewall add rule.
  • Allowing an implant in a user-writable path (AppData, ProgramData, C:\Users\Public) so it can accept or make connections.
  • Enabling Remote Desktop, WinRM or SMB rules as a preparation step for lateral movement.

Investigation tips

  • Pull the matching Windows Firewall event 2004 (same second) to see the program, ports, action and the modifying process.
  • Check for netsh.exe or powershell.exe process creation (4688 or Sysmon 1) around the timestamp to identify the command line and user.
  • Look up the rule under the FirewallRules registry key using RuleId to see its full definition if the host is still live.
  • Baseline rule names across hosts; a rule that exists on one machine only is worth reviewing.

MITRE ATT&CK techniques

TechniqueTactics
T1686.003 Disable or Modify System Firewall: Windows Host FirewallDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading