Event ID 5443 — The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.
Description
The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.
Message #
Fields #
| Name | Description |
|---|---|
ProviderKey GUID | Provider ID |
ProviderName UnicodeString | Provider Name |
ProviderContextKey GUID | Provider Context ID |
ProviderContextName UnicodeString | Provider Context Name |
ProviderContextType UnicodeString | Provider Context Type |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Auditing",
"guid": "54849625-5478-4994-A5BA-3E3B0328C30D",
"event_source_name": "",
"event_id": 5443,
"version": 0,
"level": 0,
"task": 13572,
"opcode": 0,
"keywords": 9232379236109516800,
"time_created": "2022-04-04T13:11:16.631811+00:00",
"event_record_id": 25502,
"correlation": {
"ActivityID": "7377737E-4825-0000-C974-77732548D801"
},
"execution": {
"process_id": 612,
"thread_id": 668
},
"channel": "Security",
"computer": "WIN-TKC15D7KHUR",
"security": {
"user_id": ""
}
},
"event_data": {
"ProviderKey": "DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62",
"ProviderName": "Microsoft Corporation",
"ProviderContextKey": "93132C36-6E06-4E6F-A10B-218787CD49CF",
"ProviderContextName": "MPSSVC",
"ProviderContextType": "%%16387"
},
"message": ""
}
References #
- Microsoft Learn https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5443
- Microsoft Learn Audit Policy https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-filtering-platform-policy-change
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5443
- Example event sourced from https://github.com/NextronSystems/evtx-baseline