EventID 2006: Firewall Rule Deleted
This event indicates that a firewall rule has been deleted.
In recent builds of Windows 11, this event has been replaced by a new Event ID:
Analysis Value
pageSecurity IdentifierpageFile PathpageExecution AccountpageParent and Child InformationpageEvidence of ExecutionpageFirewall ActivityOperating System Availability
Major Version | Support | Major Version | Support |
---|---|---|---|
Windows 11 | ⚠️ | Server 2019 | ✅ |
Windows 10 | ✅ | Server 2016 | ✅ |
Windows 8 | ✅ | Server 2012 | ✅ |
Windows 7 | ✅ | Server 2008 | ✅ |
Windows Vista | ✅ | Server 2003 | ❌ |
Windows XP | ❌ |
Artifact Location(s)
%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
Artifact Interpretation
Field | Interpretation | Reference |
---|---|---|
| Provides the Security Identifier (SID) of the account that deleted the firewall rule. | |
| Provides the Security Identifier (SID) of the account that deleted the firewall rule. | |
| Provides the full image path of the process that deleted the firewall rule. | |
| Provides the Process ID of the application that deleted the firewall rule. | |
| Provides the Thread ID of the application that deleted the firewall rule. |
The presence of this event indicates that the system's firewall was modified by deleting a rule. This may be indicative of attacker activity. There are many legitimate processes such as svchost.exe
that will be observed modifying the Windows Firewall, so this event should be correlated with others to determine if the activity is legitimate or not.
The following additional fields are available in this event:
XML Path | Interpretation |
---|---|
| The GUID of the deleted firewall rule |
| The name for the deleted firewall rule as it appeared in the Windows Firewall |
Example - Windows 10
On an example system, an existing Windows Firewall rule was deleted from within the Windows Defender Firewall with Advanced Security control panel, causing the following event to be logged:
This example was produced on Windows 10, Version 10.0.19044 Build 19044
Example - Windows 11
The same activity, when reproduced on a Windows 11 system, results in the following event being logged:
This example was produced on Windows 11, Version 10.0.22621 Build 22621
Last updated