Event ID 4947: Firewall rule modified
- Event ID
- 4947
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Needs configuration
What event 4947 means
Event 4947 is written by the Windows Firewall service when an existing rule is changed locally: enabled or disabled, its program, ports, addresses, profiles or action edited. Like 4946 it is not generated for changes pushed by Group Policy.
The record only names the rule (RuleName, RuleId) and the profiles (ProfileChanged); it does not show what was changed or who changed it. The Windows Firewall channel event 2005, logged at the same time, contains the rule's new state together with ModifyingUser and ModifyingApplication.
Enabling a predefined rule group is a common and quiet way to open access — for example netsh advfirewall firewall set rule group="remote desktop" new enable=Yes flips existing rules instead of creating new ones, so it shows up here rather than in 4946.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit MPSSVC Rule-Level Policy Change (Success). Not audited in the default Windows audit policy.
Rule changes also appear in the Windows Firewall operational channel (2005), which is enabled by default. Newer Windows builds log rule modifications there under a different event ID, so a missing 2005 does not mean nothing changed.
Key fields
| Field | What it tells you |
|---|---|
| ProfileChanged | Firewall profiles the modified rule applies to (All, Domain, Private, Public or a combination). |
| RuleId | Unique ID of the rule; matches the value name under the FirewallRules registry key. |
| RuleName | Display name of the modified rule. |
Common benign sources
- Windows Update and application updates refreshing their own rules.
- Administrators enabling built-in rule groups such as File and Printer Sharing or Remote Desktop.
- Network location changes and feature configuration by management tools.
What attackers do that produces it
- Enabling the built-in Remote Desktop, WinRM or File and Printer Sharing rules to prepare remote access.
- Changing an existing rule from block to allow, or widening its remote address scope to
Any, to avoid creating a visible new rule.
Investigation tips
- Correlate with Windows Firewall event 2005 at the same timestamp to see the new rule state and the modifying process.
- Search process creation (4688, Sysmon 1) for
netsh advfirewall,Set-NetFirewallRuleorEnable-NetFirewallRulearound the event. - Check whether the enabled rule matches new inbound activity (4624 LogonType 3 or 10, 5156) shortly afterwards.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1686.003 Disable or Modify System Firewall: Windows Host Firewall | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.