Event ID: 5148

The Windows Filtering Platform has detected a DoS attack.

The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.

Network Information:
    Type:       %1


In most circumstances, this event occurs very rarely. It is designed to be generated when an ICMP DoS attack starts or was detected.

Microsoft Documentation

Event ID - 5148



Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Other Object Access Events"



LEFT/RIGHT arrow keys for navigation

Back to List