Firewall Rule Additions
This query correlates processes with Windows Firewall rule modifications they triggered, identifying which executables are creating or modifying firewall rules.
CQL · Falcon Next-Gen SIEMCopy query
#event_simpleName=ProcessRollup2
| join({#event_simpleName=FirewallSetRule}, key=ContextProcessId, field=TargetProcessId, include=[FirewallRule, FirewallRuleId])
| ImageFileName=/.*\\(?<fileName>.*\..*)/
| table([aid, UserSid, fileName, FirewallRuleId, FirewallRule, ImageFileName, CommandLine])Firewall_Rule_Additions.yml
CrowdStrike
Hunting
Endpoint
Insight
2025-08-06
2025-10-31
