Microsoft-Windows-Firewall
1 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 6400 | An attempt to programmatically disable the Windows Defender Firewall using a … | System | N |
Event ID 6400: An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.
#Description
An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected because this API is not supported on Windows Vista. This has most likely occurred due to an application which is incompatible with Windows Vista. Please contact the application's vendor to make sure you have a Windows Vista compatible application version. Error Code: E_NOTIMPL Caller Process Name: CallerProcessName Process Id: ProcessId Publisher: Publisher
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessName UnicodeString | |
ProcessId UInt32 | |
Publisher UnicodeString |
References #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID e595f735-b42a-494b-afcd-b68666945cd3
Defined in mpssvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3328, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02