Creation of a New Firewall Rule Via New-NetFirewallRule Cmdlet

Rule Info

Name
Creation of a New Firewall Rule Via New-NetFirewallRule Cmdlet
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the execution of "New-NetFirewallRule" to create a new inbound or outbound firewall rule.
Date
2024-04-29 00:00:00
Modified
None
Id
0a88ade0-d742-4bc2-92c7-5b8651ce70cb
Tags
detection.threat_hunting attack.discovery attack.t1518.001 attack.t1016
Type
Nextron Sigma feed only (private)

Rule History