kevmap

TechniquesT1686.003 › AN2043

AN2043 Analytic 2043

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.</p>
Detects
T1686.003 Windows Host Firewall
Part of
DET0901 Detect Windows Firewall

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AuthorizedAdminAccountsKnown administrators allowed to manage host firewall settings
MaintenanceWindowApproved change windows where firewall modifications are expected
ExposureCorrelationWindowTime window to correlate firewall change with new connections/listeners
SensitivePortsPorts of concern such as RDP, SMB, WinRM, SSH, custom admin ports
AllowedManagementParentsExpected parent processes such as SCCM, Intune agent, GPO client
RuleScopeThresholdDetect widening from subnet/local scope to Any/0.0.0.0/0