Windows Firewall Disabled via netsh/PowerShell/Registry in Plaintext Traffic

Detects attempts to disable the Windows Firewall using the netsh command-line utility or PowerShell cmdlets, as well as registry modifications related to firewall profiles. Adversaries often perform this action to impair host-based security controls and facilitate unauthorized inbound or outbound network traffic.