BIOC Informational

Netsh.exe modifies allowed firewall port/program lists

Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Indicator:

Process action type = execution AND target process cmd = *allowedprogram* , *portopening* AND target process name = netsh.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows

Preventable: yes