Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|
1004667 | EVID 5031 & 5152 - 5159 : Windows Firewall Events | Base Rule | Network Traffic | Network Traffic |
EVID 5031 : Firewall Service Blocked Incoming App | Sub Rule | Traffic Denied by Host Firewall | Network Deny |
EVID 5152 : Permitted Bind To Local Port | Sub Rule | Permitted Bind To Local Port | Information |
EVID 5153 : Restricted Filtering Blocked Packet | Sub Rule | Traffic Denied by Host Firewall | Network Deny |
EVID 5154 : App Allowed To Listen For Conn | Sub Rule | Application Allowed To Listen For Connections | Information |
EVID 5155 : App Not Allowed To Listen For Conn | Sub Rule | Traffic Denied by Host Firewall | Network Deny |
EVID 5156 : Filtering Platform Allowed Connection | Sub Rule | Traffic Allowed by Host Firewall | Network Allow |
EVID 5157 : Filtering Platform Blocked Connection | Sub Rule | Traffic Denied by Host Firewall | Network Deny |
EVID 5158 : Permitted Bind To Local Port | Sub Rule | Permitted Bind To Local Port | Information |
EVID 5159 : Denied Bind To Local Port | Sub Rule | Traffic Denied by Host Firewall | Network Deny |