DFIR Reference v0.1

Windows Firewall Event Reference

Cross-channel reference for Windows Firewall and Windows Filtering Platform (WFP) forensic analysis. Covers Security.evtx rule-change events, WFP connection/packet events, and the dedicated Windows Firewall With Advanced Security operational log.

15Event IDs
4Log Channels
6Sigma Rules
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallSecuritySecurity (WFP)Security / System
Showing 15 of 15 events

⚡ Sigma Detection Rules — Windows Firewall Event Reference

Curated highest-signal Sigma-style detection rules for Windows Firewall Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.

Convert to your SIEM: sigconverter.io

6 detection rules 6 event IDs covered
Copied!