Microsoft-Windows-Firewall
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 6400 | An attempt to programmatically disable the Windows Defender Firewall using a … | System | N | N |
Event ID 6400: An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.
#Description
An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected because this API is not supported on Windows Vista. This has most likely occurred due to an application which is incompatible with Windows Vista. Please contact the application's vendor to make sure you have a Windows Vista compatible application version. Error Code: E_NOTIMPL Caller Process Name: CallerProcessName Process Id: ProcessId Publisher: Publisher
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessName UnicodeString | |
ProcessId UInt32 | |
Publisher UnicodeString |
References #
Provenance
ETW provider GUID e595f735-b42a-494b-afcd-b68666945cd3
Defined in mpssvc.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3328, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02 — Manifest XML pack, 2.0 MB