Skip to content

Commit 55b26b1

Browse files
frack113phantinuss
authored andcommitted
Tamper firewall by Registry
1 parent f448a13 commit 55b26b1

File tree

2 files changed

+46
-0
lines changed

2 files changed

+46
-0
lines changed
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
title: Add Exceptions to Microsoft Defender Firewall via Registry
2+
id: 6648f900-4a7d-47e3-bad6-952b313a1c0e
3+
status: experimental
4+
description: Adversaries may add system execptions to system firewalls security
5+
references:
6+
- https://www.virustotal.com/gui/file/da209017000b9812e8bc5f4e8db6499430ee2aadc72ef896964cffdfd896f143/behavior
7+
- https://app.any.run/tasks/8d4113a8-5403-4367-a79f-4ce4978d9bdb
8+
author: frack113
9+
date: 2025-01-26
10+
tags:
11+
- attack.defense-evasion
12+
- attack.t1562.004
13+
logsource:
14+
category: registry_set
15+
product: windows
16+
detection:
17+
selection:
18+
TargetObject|contains: '\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List'
19+
Details|contains: ':Enabled:'
20+
condition: selection
21+
falsepositives:
22+
- Unknown
23+
level: medium
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
title: Enable Exceptions Microsoft Defender Firewall via Registry
2+
id: c69fc6a2-607d-4530-b7d1-75823af1bde4
3+
status: experimental
4+
description: Adversaries may disable system firewalls security in order to add execptions
5+
references:
6+
- https://www.virustotal.com/gui/file/da209017000b9812e8bc5f4e8db6499430ee2aadc72ef896964cffdfd896f143/behavior
7+
- https://app.any.run/tasks/8d4113a8-5403-4367-a79f-4ce4978d9bdb
8+
author: frack113
9+
date: 2025-01-26
10+
tags:
11+
- attack.defense-evasion
12+
- attack.t1562.004
13+
logsource:
14+
category: registry_set
15+
product: windows
16+
detection:
17+
selection:
18+
TargetObject|endswith: 'System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DoNotAllowExceptions'
19+
Details: 'DWORD (0x00000000)'
20+
condition: selection
21+
falsepositives:
22+
- Unknown
23+
level: medium

0 commit comments

Comments
 (0)