Hide Navigation Hide TOC New Firewall Rule Added Via Netsh.EXE (cd5cfd80-aa5f-44c0-9c20-108c4ae12e3c) Detects the addition of a new rule to the Windows firewall via netsh Cluster A Galaxy A Cluster B Galaxy B Level New Firewall Rule Added Via Netsh.EXE (cd5cfd80-aa5f-44c0-9c20-108c4ae12e3c) Sigma-Rules Windows Host Firewall - T1686.003 (291ede6c-1473-454c-b614-5ac5ea63c987) Attack Pattern 1 Disable or Modify System Firewall - T1686 (eec096b8-c207-43df-b6c1-11523861e452) Attack Pattern Windows Host Firewall - T1686.003 (291ede6c-1473-454c-b614-5ac5ea63c987) Attack Pattern 2