Event ID 5444

The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.

The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.

Provider ID:    %1
Provider Name:  %2
Sub-layer ID:   %3
Sub-layer Name: %4
Sub-layer Type: %5
Weight:     %6


This event is logged for each sub-layer of each WFP provider at startup. A sub-layer is a collection of filters assigned to a layer within WFP.

Auditing:     Rarely

Enable only when building a full WFP baseline inventory at startup, investigating unexpected sub-layer registrations from third-party software, or forensically determining whether malware has registered a high-weight persistent sub-layer to gain filter evaluation priority over Windows Firewall or IPsec.


Volume:     Low

Similar to Event 5442, this activity is limited to the enumeration of persistent sub-layers during system initialization. While third-party security agents may increase the count, the event volume remains strictly bounded to the startup phase.




NameFieldInsertion StringOSExample
Provider IDProviderKey%1Any {4B153735-1049-..}
Provider NameProviderName%2Any Windows Firewall
Sub-layer IDSubLayerKey%3Any {B3CDD441-AF90-...}
Sub-layer NameSubLayerName%4Any Windows Firewall
Sub-layer TypeSubLayerType%5Any %%388
WeightWeight%6Any 3


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Filtering Platform Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List