Microsoft-Windows-SEC-WFP
4 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | task_01_V1 | Operational | N |
| 2 | task_02_V1 | Operational | N |
| 3 | task_03_V1 | Operational | N |
| 4 | task_0 | Operational | N |
Event ID 1: task_01_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Event ID 2: task_02_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Event ID 3: task_03_V1
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt16 | |
ProcessId HexInt32 | |
ProcessStartKey UInt64 | |
ProcessCreationTime Int64 | |
IsBlocked Boolean | |
Direction UInt32 | Known values
|
IsExistingConnection Boolean | |
FilterId UInt64 | |
LayerId UInt16 | |
InterfaceIndex UInt32 | |
Protocol UInt8 | Known values
|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Event ID 4: task_0
#Fields #
| Name | Description |
|---|---|
ModuleTag UInt32 | |
RuleId UInt32 | |
LayerId UInt16 | |
Action UInt32 | |
FieldId UInt16 | |
MatchType UInt32 | |
DataType UInt32 | |
IsBlocked Boolean |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 62834e12-795f-5ab2-b404-8d6d870dbbeb
Defined in mssecwfp.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.8821.27906.1000, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.8798.25857.1000, captured 2026-06-02