Windows firewall disabled

Goal

Detect when the Windows firewall is disabled.

Strategy

Monitor the Windows event logs where @evt.id is 4950 and the @Event.EventData.Data.SettingValue:No.

Triage and response

Verify if {{@Event.System.Computer}} has a legitimate reason for having the Windows firewall disabled.