> For the complete documentation index, see [llms.txt](https://psmths.gitbook.io/windows-forensics/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://psmths.gitbook.io/windows-forensics/artifacts-by-type/event-log-artifacts/microsoft-windows-windows-firewall-with-advanced-security/evtx-2073-firewall-windows-11.md).

# EventID 2073: Firewall Rule Modified

This event indicates that a Windows Defender Firewall rule has been modified. While currently unique to newer versions of Windows 11, it is functionally similar to:

{% content-ref url="/pages/HN15mTucjsXzNq73zQ8A" %}
[EventID 2005: Firewall Rule Modified](/windows-forensics/artifacts-by-type/event-log-artifacts/microsoft-windows-windows-firewall-with-advanced-security/evtx-2005-firewall.md)
{% endcontent-ref %}
