FirewallHardening tool

Decopi

Level 8
Verified
Oct 29, 2017
355
Look into the Windows Registry and export the content of the below key:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules

Yeah, I was also already aware that I could see the rules and commands in regedit. But both, whether importing the rules through Windows Firewall, or also through regedit, both ways are a more laborious way to view and manipulate the rules and commands (one by one, too much handy work).

I thought that perhaps you had on your hands a simple list of rules and commands, and I thought that perhaps it was simpler to ask you the favor of sharing that list with me.

But don't worry @Andy Ful , I've already taken up too much of your time, I really appreciated your contacts, so thank you.
 
  • Like
Reactions: Andy Ful

ErzCrz

Level 22
Verified
Top Poster
Well-known
Aug 19, 2019
1,152
Yeah, I was also already aware that I could see the rules and commands in regedit. But both, whether importing the rules through Windows Firewall, or also through regedit, both ways are a more laborious way to view and manipulate the rules and commands (one by one, too much handy work).

I thought that perhaps you had on your hands a simple list of rules and commands, and I thought that perhaps it was simpler to ask you the favor of sharing that list with me.

But don't worry @Andy Ful , I've already taken up too much of your time, I really appreciated your contacts, so thank you.
You can export the policy by right clicking Windows Defender>

1720893423338.png


Unfortunately being .wfw extension, not something you can import into the likes of WFC as that uses .wpw Anyway, manually adding doesn't take all that long and most AVs and FWs leave Windows Firewall running. E.g. Comodo and Windows Firewall run along side each other so you can still use the hardening rules and those files will be blocked natively by windows firewall. In the case of WFC, at long as a conflicting rule created it works fine.
 

Decopi

Level 8
Verified
Oct 29, 2017
355
You can export the policy by right clicking Windows Defender>

Unfortunately being .wfw extension, not something you can import into the likes of WFC as that uses .wpw Anyway, manually adding doesn't take all that long and most AVs and FWs leave Windows Firewall running. E.g. Comodo and Windows Firewall run along side each other so you can still use the hardening rules and those files will be blocked natively by windows firewall. In the case of WFC, at long as a conflicting rule created it works fine.

Thank you.
Import/Export through Windows Firewall is what @Kongo had already suggested in previous messages, and I was also already aware of this possibility.
It happens that import/export through WF or Regedit, both are two very laborious ways to view and manipulate (around 100) rules and commands. And I was looking for a simple list with the rules/commands.
Anyway, once again, thank you all very much for your intention to help.
 
  • Like
Reactions: oldschool

Andy Ful

From Hard_Configurator Tools
Thread author
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,458
I thought that perhaps you had on your hands a simple list of rules and commands, and I thought that perhaps it was simpler to ask you the favor of sharing that list with me.

The exact list of rules is that one exported from the Windows Registry. There is no simpler list of rules.
To manage many LOLBins, you must use a program. This can be done by using a file that contains the paths of LOLBins and the script that reads the paths one by one from that file , creates the firewall rule for each path, and writes the rules into the Windows Registry.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top