Event ID 5449

A Windows Filtering Platform provider context has been changed.

A Windows Filtering Platform provider context has been changed.

Subject:
    Security ID:        %2
    Account Name:       %3

Process Information:
    Process ID: %1

Provider Information:
    Provider ID:    %4
    Provider Name:  %5

Change Information:
    Change Type:    %6

Provider Context:
    ID: %7
    Name:   %8
    Type:   %9


Gets logged whenever a WFP provider context is added, modified, or deleted from the Base Filtering Engine. The most common trigger is system startup, when WFP-based components (Windows Firewall, IPsec, VPN clients, third-party security software) register their non-persistent contexts. It also fires when such software initializes or shuts down mid-session, or when IPsec/firewall policy changes at runtime.

Auditing:     Rarely

Generally only useful for troubleshooting WFP configuration issues, has little value for routine security monitoring or compliance.


Volume:     LowMedium

Volume usually depends on how many WFP-aware applications are installed and how actively they interact with the BFE. Volume tends to be lower on servers and potentially higher on workstations.




NameFieldInsertion StringOSExample
Process IDProcessId%1Any 858
Security IDUserSid%2Any SYSTEM
Account NameUsername%3Any NT AUTHORITY\SYSTEM
IDProviderKey%4Any {4f57a550-3b1e-4c8a-8887-35c9b1ff1b8f}
NameProviderName%5Any Microsoft Corporation
Change TypeChangeType%6Any Add
IDProviderContextKey%8Any {4f57a550-3b1e-4c8a-8887-35c9b1ff1b8f}
NameProviderContextName%9Any MPSSVC
TypeProviderContextType%10Any Not Persistent


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Filtering Platform Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List