T1686 Firewall Disabled/Flushed via netsh/PowerShell/iptables without Re-enable
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
Microsoft Sentinel (KQL)

