Event ID 5443

The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.

The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.

Provider ID:    %1
Provider Name:  %2
Provider Context ID:    %3
Provider Context Name:  %4
Provider Context Type:  %5


A WFP provider context is a structured data blob that a provider stores in the Base Filtering Engine to carry policy state — most commonly IPsec negotiation parameters such as authentication methods, encryption algorithms, key lifetimes, and tunnel policies. When the BFE starts at boot, it logs one 5443 event for every persistent provider context already registered in its database.

Auditing:     Rarely

Enable only when conducting a full WFP policy baseline audit at boot, investigating IPsec policy persistence, or forensically determining whether a malicious driver has registered a persistent provider context to store covert state across reboots. This event is only useful in combination with the other 5440–5444 startup events.


Volume:     Low

This event is typically absent on workstations lacking IPsec or VPN configurations. Systems utilizing provider contexts or active IPsec policies will generate a limited number of events, strictly confined to the system initialization phase.




NameFieldInsertion StringOSExample
Provider IDProviderKey%1Any {AA6A7D87-7F8F-...}
Provider NameProviderName%2Any IPsec Policyagent
Provider Context IDProviderContextKey%3Any {4ABF47D5-0662-...}
Provider Context NameProviderContextName%4Any L2TP Main Mode Policy
Provider Context TypeProviderContextType%5Any %%388


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Filtering Platform Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List