Event ID 4946: Firewall rule added
- Event ID
- 4946
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Needs configuration
What event 4946 means
Event 4946 is written by the Windows Firewall service (MPSSVC) when a rule is added to the local firewall policy, whether through wf.msc, netsh advfirewall, the New-NetFirewallRule cmdlet, an installer or the firewall COM API. It is not generated for rules delivered by Group Policy.
The record is thin: RuleName, RuleId and ProfileChanged. It does not say who made the change, which program or port the rule covers, or whether it allows or blocks. For those details use the Windows Firewall channel event 2004 written at the same moment, which carries ApplicationPath, LocalPorts, Action, ModifyingUser and ModifyingApplication.
Software installs and Windows updates add rules routinely, so the value is in the rule name and timing: an unfamiliar rule created minutes after a suspicious logon or process launch deserves a look.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit MPSSVC Rule-Level Policy Change (Success). Not audited in the default Windows audit policy.
The same subcategory also produces 4947 (rule modified), 4948 (rule deleted) and 4950 (setting changed). The Windows Firewall operational channel (event 2004) is on by default and gives more detail, so check it even when this subcategory is not enabled.
Key fields
| Field | What it tells you |
|---|---|
| ProfileChanged | Firewall profiles the rule applies to, e.g. All, Domain, Private, Public or a combination such as Domain,Public. |
| RuleId | Unique ID of the rule — a GUID-like string or a built-in rule name. The rule is stored under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules with this ID as the value name. |
| RuleName | Display name of the rule as shown in wf.msc. Attackers often pick names that look like legitimate software. |
Common benign sources
- Application installers (browsers, VPN clients, games, collaboration tools) registering their own inbound rules.
- Windows features and roles being enabled, which add their predefined rule groups.
- Administrators creating rules with
netsh advfirewall firewall add ruleorNew-NetFirewallRule.
What attackers do that produces it
- Opening inbound access for a backdoor, RAT listener or tunneling tool (for example allowing TCP 3389, 5985 or a high port) with
netsh advfirewall firewall add rule. - Allowing an implant in a user-writable path (
AppData,ProgramData,C:\Users\Public) so it can accept or make connections. - Enabling Remote Desktop, WinRM or SMB rules as a preparation step for lateral movement.
Investigation tips
- Pull the matching Windows Firewall event 2004 (same second) to see the program, ports, action and the modifying process.
- Check for
netsh.exeorpowershell.exeprocess creation (4688 or Sysmon 1) around the timestamp to identify the command line and user. - Look up the rule under the
FirewallRulesregistry key usingRuleIdto see its full definition if the host is still live. - Baseline rule names across hosts; a rule that exists on one machine only is worth reviewing.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1686.003 Disable or Modify System Firewall: Windows Host Firewall | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.