Event ID 5446

A Windows Filtering Platform callout has been changed.

A Windows Filtering Platform callout has been changed.

Subject:
    Security ID:        %2
    Account Name:       %3

Process Information:
    Process ID: %1

Provider Information:
    ID:     %4
    Name:       %5

Change Information:
    Change Type:    %6

Callout Information:
    ID:     %7
    Name:       %8
    Type:       %9
    Run-Time ID:    %10

Layer Information:
    ID:     %11
    Name:       %12
    Run-Time ID:    %13


A WFP callout is a set of functions in a driver used for specialized filtering. Callouts can block, permit, modify, and secure network traffic.

Auditing:     Conditional

More actionable than the 5440–5444 startup events because it captures runtime changes with full subject context. Recommended for environments that need to detect: Unexpected callout registrations by unsigned kernel drivers. Malicious rootkit or implant activity using WFP for network interception. Unauthorized removal of security software callouts. Baseline deviation from expected callout inventory.


Volume:     Low

This event is logged whenever a callout is added or deleted. On a stable system this happens infrequently — primarily during service starts and stops. Expect a small burst at system startup and shutdown, and isolated events when security software services are cycled.




NameFieldInsertion StringOSExample
Process IDProcessId%1Any 1364
Security IDUserSid%2Any S-1-5-19
Account NameUserName%3Any NT AUTHORITY\...
Provider IDProviderKey%4Any {9250A3DB-5929-...}
Provider NameProviderName%5Any WFKMP
Change TypeChangeType%6Any %%385
Callout IDCalloutKey%7Any {C3DBED20-0BB6-...}
Callout NameCalloutName%8Any Windows Firewall
Callout TypeCalloutType%9Any %%390
Callout Run-Time IDCalloutId%10Any 279
Layer IDLayerKey%11Any {FA45FE2F-3CBA-...}
Layer NameLayerName%12Any Datagram Data v6


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Filtering Platform Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List