Skip to content
Security

Event ID 4947: Firewall rule modified

A change has been made to Windows Firewall exception list. A rule was modified.Security event 4947 logs a local change to an existing Windows Firewall rule. Watch for rules enabled, widened or switched from block to allow.
4947
Event ID
4947
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Needs configuration

What event 4947 means

Event 4947 is written by the Windows Firewall service when an existing rule is changed locally: enabled or disabled, its program, ports, addresses, profiles or action edited. Like 4946 it is not generated for changes pushed by Group Policy.

The record only names the rule (RuleName, RuleId) and the profiles (ProfileChanged); it does not show what was changed or who changed it. The Windows Firewall channel event 2005, logged at the same time, contains the rule's new state together with ModifyingUser and ModifyingApplication.

Enabling a predefined rule group is a common and quiet way to open access — for example netsh advfirewall firewall set rule group="remote desktop" new enable=Yes flips existing rules instead of creating new ones, so it shows up here rather than in 4946.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit MPSSVC Rule-Level Policy Change (Success). Not audited in the default Windows audit policy.

Rule changes also appear in the Windows Firewall operational channel (2005), which is enabled by default. Newer Windows builds log rule modifications there under a different event ID, so a missing 2005 does not mean nothing changed.

Key fields

FieldWhat it tells you
ProfileChangedFirewall profiles the modified rule applies to (All, Domain, Private, Public or a combination).
RuleIdUnique ID of the rule; matches the value name under the FirewallRules registry key.
RuleNameDisplay name of the modified rule.

Common benign sources

  • Windows Update and application updates refreshing their own rules.
  • Administrators enabling built-in rule groups such as File and Printer Sharing or Remote Desktop.
  • Network location changes and feature configuration by management tools.

What attackers do that produces it

  • Enabling the built-in Remote Desktop, WinRM or File and Printer Sharing rules to prepare remote access.
  • Changing an existing rule from block to allow, or widening its remote address scope to Any, to avoid creating a visible new rule.

Investigation tips

  • Correlate with Windows Firewall event 2005 at the same timestamp to see the new rule state and the modifying process.
  • Search process creation (4688, Sysmon 1) for netsh advfirewall, Set-NetFirewallRule or Enable-NetFirewallRule around the event.
  • Check whether the enabled rule matches new inbound activity (4624 LogonType 3 or 10, 5156) shortly afterwards.

MITRE ATT&CK techniques

TechniqueTactics
T1686.003 Disable or Modify System Firewall: Windows Host FirewallDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading