{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/sysadmin-tooling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["defense-impairment","windows","sysadmin-tooling"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries and malicious software frequently leverage the legitimate Windows command-line utility 'netsh.exe' to modify network security configurations. By executing specific commands, actors can delete firewall port or application rules, thereby disabling critical defense mechanisms. This activity is typically observed during the post-exploitation phase, where an attacker seeks to bypass restrictive network segmentation or security policies to establish persistence or enable C2 traffic. Defenders should distinguish between legitimate administrative maintenance, software updates, and unauthorized modifications initiated by non-standard parent processes.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access or code execution on the target Windows system.\u003c/li\u003e\n\u003cli\u003eAttacker performs internal reconnaissance to identify existing firewall rules.\u003c/li\u003e\n\u003cli\u003eAttacker determines a need to disable security filters for a specific port or service.\u003c/li\u003e\n\u003cli\u003eAttacker executes 'netsh.exe' with elevated privileges to modify the Windows Firewall configuration.\u003c/li\u003e\n\u003cli\u003eThe command 'netsh firewall delete' or 'netsh advfirewall firewall delete' is issued against specific rules.\u003c/li\u003e\n\u003cli\u003eThe Windows Firewall removes the specified rule, creating an open hole in network ingress/egress filtering.\u003c/li\u003e\n\u003cli\u003eAttacker proceeds with malicious objectives, such as lateral movement or exfiltration, unimpeded by previous security rules.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deletion of firewall rules impairs host-based security, increasing the probability of successful exploitation, lateral movement, or data exfiltration. If left unmonitored, this activity allows adversaries to maintain long-term access and control within the target network segment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor process creation events for 'netsh.exe' command-line arguments related to firewall rule deletion.\u003c/li\u003e\n\u003cli\u003eBaseline common administrative scripts or software installation processes that frequently modify firewall rules to reduce false positives in the detection logic.\u003c/li\u003e\n\u003cli\u003eEnable PowerShell script block logging and process creation (Event ID 1) for visibility into administrative tool execution.\u003c/li\u003e\n\u003cli\u003eAudit and restrict administrative access to systems where modification of firewall settings is not required by standard business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:22:28Z","date_published":"2026-09-01T12:22:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netsh-firewall-deletion/","summary":"Adversaries utilize the netsh.exe utility to impair host-based security by removing active firewall rules, potentially facilitating unauthorized lateral movement or command-and-control communication.","title":"Windows Firewall Rule Deletion via Netsh.exe","url":"https://feed.craftedsignal.io/briefs/2026-09-netsh-firewall-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Sysadmin-Tooling","version":"https://jsonfeed.org/version/1.1"}