BIOC
Informational
✕
Netsh.exe modifies allowed firewall port/program lists
Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Indicator:
Process action type = execution AND target process cmd = *allowedprogram* , *portopening* AND target process name = netsh.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows
Preventable: yes