Microsoft-Windows-SEC-WFP
Not an independently readable Windows event log. Microsoft-Windows-SEC-WFP is an ETW trace provider defined in mssecwfp.sys, the Microsoft Defender for Endpoint kernel sensor: its events are delivered to a realtime trace session the sensor consumes, and surface as the Defender Advanced Hunting Device* tables (see /defender/). The manifest declares an Operational channel, but Windows registers no readable Event Log channel for it, so nothing here appears in Event Viewer or forwards over WEF. The event and field names below are manifest-derived. Present only where Microsoft Defender for Endpoint is onboarded.
| Event | Title | Sample | Rule |
|---|---|---|---|
| 1 | task_01_V1 | N | N |
| 2 | task_02_V1 | N | N |
| 3 | task_03_V1 | N | N |
| 4 | task_0 | N | N |
Event ID 1: task_01_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Event ID 2: task_02_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Event ID 3: task_03_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Provenance
ETW provider GUID 62834e12-795f-5ab2-b404-8d6d870dbbeb
Defined in mssecwfp.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.8821.27906.1000, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.8798.25857.1000, captured 2026-06-02 — Manifest XML pack, 2.0 MB