Netsh Firewall Command Execution
This rule detects multiple executions of 'netsh firewall' commands within a one-hour window on a single computer. This activity can indicate an adversary attempting to modify or disable system firewalls to bypass security controls, enable C2 communications, or facilitate lateral movement.
Microsoft Sentinel (KQL)

