Windows Windows Firewall
If client workstations are taking advantage of the built-in host-based Windows Firewall, then there is value in collecting events to track the firewall status. For example, if the firewall state changes from on to off, then that log should be collected. Normal users should not be modifying the firewall rules of their local machine. The below events for the listed versions of the Windows operating system are only applicable to modifications of the local firewall settings.
AIS Managed SIEM
Firewall Rule Add
Firewall Rule Change
Firewall Rules Deleted
Firewall Failed to load Group Policy
Last modified September 14, 2021