EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Policy Change (10)
Operating Systems
  • Windows 10 (10)
  • Windows 2008 (10)
  • Windows 2008 R2 (10)
  • Windows 2012 (10)
  • Windows 2012 R2 (10)
  • Windows 2016 (10)
  • Windows 2019 (10)
  • Windows 2022 (10)
  • Windows 2025 (10)
  • Windows 7 (10)
  • Windows 8 (10)
  • Windows 8.1 (10)
  • Windows Vista (10)
  • Windows 11 (9)
Tags
  • Audit Success (1)
Auditing
  • Rarely (7)
  • Conditional (2)
  • Always (1)
Volume
  • Low (9)
  • Medium (3)
  • High (1)
Audit Subcategory
  • Filtering Platform Policy Change (9)
  • Other Policy Change Events (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
5440 The following callout was present when the Windows Filtering Platform Base Filtering Engine started.
5441 The following filter was present when the Windows Filtering Platform Base Filtering Engine started.
5442 The following provider was present when the Windows Filtering Platform Base Filtering Engine started.
5443 The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.
5444 The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.
5446 A Windows Filtering Platform callout has been changed.
5447 A Windows Filtering Platform filter has been changed.
Audit Success
5448 A Windows Filtering Platform provider has been changed.
5449 A Windows Filtering Platform provider context has been changed.
5450 A Windows Filtering Platform sub-layer has been changed.



© netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy