Microsoft-Windows-SEC-WFP

4 events across 1 channel

EventTitleChannelSample
1task_01_V1OperationalN
2task_02_V1OperationalN
3task_03_V1OperationalN
4task_0OperationalN

Event ID 1: task_01_V1

#
Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 2: task_02_V1

#
Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 3: task_03_V1

#
Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 4: task_0

#
Provider
Microsoft-Windows-SEC-WFP
Channel
Operational

Fields #

NameDescription
ModuleTag UInt32
RuleId UInt32
LayerId UInt16
Action UInt32
FieldId UInt16
MatchType UInt32
DataType UInt32
IsBlocked Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 62834e12-795f-5ab2-b404-8d6d870dbbeb

Defined in mssecwfp.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.8821.27906.1000, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.8798.25857.1000, captured 2026-06-02

Downloads