Microsoft-Windows-SEC-WFP
4 events across 1 channel
Event ID 1 —
Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | — |
ProcessId HexInt32 | — |
ProcessStartKey UInt64 | — |
ProcessCreationTime Int64 | — |
IsBlocked Boolean | — |
Direction UInt32 | — Known values
|
IsExistingConnection Boolean | — |
FilterId UInt64 | — |
LayerId UInt16 | — |
InterfaceIndex UInt32 | — |
Protocol UInt8 | — Known values
|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Event ID 2 —
Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | — |
ProcessId HexInt32 | — |
ProcessStartKey UInt64 | — |
ProcessCreationTime Int64 | — |
IsBlocked Boolean | — |
Direction UInt32 | — Known values
|
IsExistingConnection Boolean | — |
FilterId UInt64 | — |
LayerId UInt16 | — |
InterfaceIndex UInt32 | — |
Protocol UInt8 | — Known values
|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Event ID 3 —
Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | — |
ProcessId HexInt32 | — |
ProcessStartKey UInt64 | — |
ProcessCreationTime Int64 | — |
IsBlocked Boolean | — |
Direction UInt32 | — Known values
|
IsExistingConnection Boolean | — |
FilterId UInt64 | — |
LayerId UInt16 | — |
InterfaceIndex UInt32 | — |
Protocol UInt8 | — Known values
|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
ModuleTag UInt32 | — |
RuleId UInt32 | — |
LayerId UInt16 | — |
Action UInt32 | — |
FieldId UInt16 | — |
MatchType UInt32 | — |
DataType UInt32 | — |
IsBlocked Boolean | — |