4948(S): A change has been made to Windows Firewall exception list. A rule was deleted.

Subcategory: Audit MPSSVC Rule-Level Policy Change
Event Description:
This event generates when Windows Firewall rule was deleted.
This event doesn't generate when the rule was deleted via Group Policy.
Note For recommendations, see Security Monitoring Recommendations for this event.
Event XML:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<TimeCreated SystemTime="2015-10-03T21:19:15.646187500Z" />
<Correlation />
<Execution ProcessID="500" ThreadID="528" />
<Security />
- <EventData>
<Data Name="ProfileChanged">All</Data>
<Data Name="RuleId">{F2649D59-1355-4E3C-B886-CDD08B683199}</Data>
<Data Name="RuleName">Allow All Rule</Data>
Required Server Roles: None.
Minimum OS Version: Windows Server 2008, Windows Vista.
Event Versions: 0.
Field Descriptions:
Profile Changed [Type = UnicodeString]: the list of profiles to which deleted rule was applied. Examples:
Domain, Public
Domain, Private
Private, Public
Deleted Rule:
Rule ID [Type = UnicodeString]: the unique identifier for deleted firewall rule.
To see the unique ID of the rule, you need to navigate to “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules” registry key and you'll see the list of Windows Firewall rule IDs (Name column) with parameters:

- Rule Name [Type = UnicodeString]: the name of the rule that was deleted. You can see the name of Windows Firewall rule using Windows Firewall with Advanced Security management console (wf.msc), check “Name” column:

Security Monitoring Recommendations
For 4948(S): A change has been made to Windows Firewall exception list. A rule was deleted.
- This event can be helpful in case you want to monitor all deletions of Firewall rules that were done locally.