Microsoft-Windows-SEC-WFP

Not an independently readable Windows event log. Microsoft-Windows-SEC-WFP is an ETW trace provider defined in mssecwfp.sys, the Microsoft Defender for Endpoint kernel sensor: its events are delivered to a realtime trace session the sensor consumes, and surface as the Defender Advanced Hunting Device* tables (see /defender/). The manifest declares an Operational channel, but Windows registers no readable Event Log channel for it, so nothing here appears in Event Viewer or forwards over WEF. The event and field names below are manifest-derived. Present only where Microsoft Defender for Endpoint is onboarded.

EventTitleSampleRule
1task_01_V1NN
2task_02_V1NN
3task_03_V1NN
4task_0NN

Event ID 1: task_01_V1

#

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 2: task_02_V1

#

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 3: task_03_V1

#

Fields #

NameDescription
ModuleTag UInt16
ProcessId HexInt32
ProcessStartKey UInt64
ProcessCreationTime Int64
IsBlocked Boolean
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsExistingConnection Boolean
FilterId UInt64
LayerId UInt16
InterfaceIndex UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Event ID 4: task_0

#

Fields #

NameDescription
ModuleTag UInt32
RuleId UInt32
LayerId UInt16
Action UInt32
FieldId UInt16
MatchType UInt32
DataType UInt32
IsBlocked Boolean

Provenance

ETW provider GUID 62834e12-795f-5ab2-b404-8d6d870dbbeb

Defined in mssecwfp.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.8821.27906.1000, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.8798.25857.1000, captured 2026-06-02 — Manifest XML pack, 2.0 MB