Event ID 4948: Firewall rule deleted
- Event ID
- 4948
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Needs configuration
What event 4948 means
Event 4948 is logged by the Windows Firewall service when a rule is removed from the local firewall policy. As with 4946 and 4947, rules removed through Group Policy do not produce it.
Only RuleName, RuleId and ProfileChanged are recorded. The Windows Firewall channel event 2006, written at the same moment, adds the SID of the user (ModifyingUser) and the program (ModifyingApplication) that deleted the rule.
Deletions are rarer than additions, which makes them easier to review. Two patterns matter: a block rule being removed so traffic can flow, and an attacker deleting the allow rule they created earlier to cover their tracks.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit MPSSVC Rule-Level Policy Change (Success). Not audited in the default Windows audit policy.
When the whole rule set is wiped at once, the Windows Firewall channel logs 2033 (all rules deleted); review it alongside this event.
Key fields
| Field | What it tells you |
|---|---|
| ProfileChanged | Firewall profiles the deleted rule applied to. |
| RuleId | Unique ID of the deleted rule. Search older 4946 or 2004 events for the same ID to learn what the rule allowed. |
| RuleName | Display name of the deleted rule. |
Common benign sources
- Software uninstallers removing the rules they created.
- Administrators cleaning up obsolete rules.
- Updates replacing rules (delete and re-add) during upgrades.
What attackers do that produces it
- Deleting block rules that prevented a tool, port or remote host from communicating.
- Removing the allow rule created for a backdoor after use, to reduce forensic traces.
Investigation tips
- Find the matching Windows Firewall event 2006 for the modifying user SID and process.
- Look for the earlier creation of the same
RuleId(4946, 2004) to reconstruct what the rule did and how long it existed. - Check for bulk deletions (many 4948 in the same second) and for Windows Firewall event 2033 (all rules deleted).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1686.003 Disable or Modify System Firewall: Windows Host Firewall | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.