Windows Firewall Disabled via netsh, PowerShell, or Registry (T1562.004)

Detects attempts to disable or modify Windows Firewall settings using netsh, PowerShell, or direct registry modifications. Adversaries often perform these actions to evade detection and maintain uninhibited network communication for C2 or data exfiltration.