Suspicious Firewall Modification via WMI Provider Host
Detection of unauthorized Windows Firewall rule additions performed by the WMI Provider Host process, a technique associated with defense impairment by ransomware actors.
Defenders should monitor for the addition of new firewall exceptions by the Windows Management Instrumentation (WMI) Provider Host (WmiPrvSE.exe). While legitimate administrative tasks may leverage WMI, this behavior is a known indicator of defense impairment techniques employed by threat actors, such as the Rhysida ransomware group. By utilizing WMI to programmatically modify firewall configurations, attackers can bypass interactive user interfaces to create persistence or enable inbound connectivity for command-and-control (C2) tools. This activity often involves the execution of PowerShell cmdlets or direct interaction with WMI CIM classes (e.g., MSFT_NetFirewallRule) to whitelist malicious processes or network ports. Because WmiPrvSE.exe operates as a system-level host, this activity can sometimes mask the identity of the user or script initiating the request, necessitating correlation with parent process data and audit logs.
Attack Chain
- Attacker gains initial code execution on a target Windows endpoint.
- Attacker identifies the need to enable inbound network access for a secondary tool or persistence mechanism.
- Attacker uses a PowerShell script or an administrative tool to interact with the WMI service.
- The WMI service spawns or utilizes the WmiPrvSE.exe process to handle the CIM/WMI request.
- The WmiPrvSE.exe process executes the command to add a new firewall rule (e.g., New-NetFirewallRule).
- The Windows Firewall service logs Event ID 2004 or 2071 indicating a rule addition.
- The firewall exception is active, allowing the attacker to establish C2 communication or facilitate lateral movement.
Impact
Successful exploitation allows attackers to bypass security boundaries, maintain persistence, and establish reliable communication channels for data exfiltration or secondary payload delivery. This technique has been observed in campaigns by ransomware actors like Rhysida to disable security defenses and ensure reachability of their infrastructure within a compromised environment.
Recommendation
Detection engineering teams should monitor Windows Firewall event logs specifically for rule modifications initiated by WmiPrvSE.exe.
- Enable Windows Firewall auditing to capture Event IDs 2004, 2071, and 2097.
- Deploy the provided Sigma rule to alert on firewall additions originating from WmiPrvSE.exe.
- Investigate the process lineage of WmiPrvSE.exe to determine if the originating WMI request was triggered by a known administrative script or a suspicious process like powershell.exe or cmd.exe.
Immediate actions
Deploy Sigma rule for WMI-based firewall rule additions.
Threat Hunt
Search for Event IDs 2004, 2071, or 2097 where ModifyingApplication is WmiPrvSE.exe.
Data: Windows Security Event Logs (Firewall)
Mitigations
Restrict WMI access and enforce code signing for PowerShell/administrative scripts.
Defense impairment T1686.003
Detection coverage 1
Detect New Firewall Rule Added via WmiPrvSE.EXE
mediumDetects the addition of an 'Allow' firewall rule where the modifying process is the WMI Provider Host (WmiPrvSE.EXE).
Detection queries are available on the platform. Get full rules →