Event ID 5156: WFP connection allowed
- Event ID
- 5156
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 5156 means
Event 5156 is written when the Windows Filtering Platform (WFP), the engine behind Windows Firewall, allows a connection. It ties a network flow to a local process: Application and ProcessID identify the program, while SourceAddress, SourcePort, DestAddress, DestPort and Protocol describe the flow.
Read Direction first. In practice the Source fields hold the local endpoint and the Dest fields the remote endpoint for both directions — for an inbound connection the local listening port is in SourcePort. Application uses a device path (\device\harddiskvolume3\windows\system32\svchost.exe), not a drive letter.
Success auditing records every allowed connection, including loopback and DNS traffic, which quickly fills the Security log. When enabled selectively (servers, jump hosts) it gives process-level network history without Sysmon.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Filtering Platform Connection (Success). Not audited in the default Windows audit policy.
Very high volume; Microsoft recommends Success auditing only where connection tracking is needed (e.g. high-value hosts). The same subcategory produces 5157 (blocked, Failure) and 5158 (bind permitted). The Security log size should be increased if it is enabled.
Key fields
| Field | What it tells you | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| ProcessID | PID of the process that made or received the connection; correlate with 4688 NewProcessId or Sysmon 1. | ||||||||||
| Application | Full path of the executable in device-path form (\device\harddiskvolumeN\...). System for kernel traffic such as SMB. | ||||||||||
| Direction | Direction of the connection.
| ||||||||||
| SourceAddress | Local IP address (in practice, regardless of direction). | ||||||||||
| SourcePort | Local port. For inbound connections this is the listening port (e.g. 445, 3389). | ||||||||||
| DestAddress | Remote IP address. | ||||||||||
| DestPort | Remote port. For outbound connections this is the service port contacted. | ||||||||||
| Protocol | IANA protocol number.
| ||||||||||
| FilterRTID | Run-time ID of the WFP filter that allowed the connection; resolve it with netsh wfp show filters on the live host. | ||||||||||
| LayerName | WFP layer where the decision was made.
| ||||||||||
| LayerRTID | Run-time ID of the WFP layer. | ||||||||||
| RemoteUserID | SID of the remote user when IPsec authentication provides it; otherwise S-1-0-0. | ||||||||||
| RemoteMachineID | SID of the remote computer when IPsec provides it; otherwise S-1-0-0. |
Common benign sources
- Browsers, update agents, EDR and management software connecting outbound on 443.
svchost.exeDNS, NTP and Windows Update traffic;Systemfor SMB (445) and other kernel-mode services.- Loopback connections (
127.0.0.1,::1) between local components. - Inbound connections to published services on servers (IIS on 443, SQL Server on 1433, RDP on 3389).
What attackers do that produces it
- Outbound connections from unusual binaries (
rundll32.exe,regsvr32.exe,mshta.exe, Office apps, files inAppDataorTemp) to external IPs — command and control or payload download. - Inbound RDP (3389), WinRM (5985/5986) or SMB (445) from workstations that should not administer this host.
- Beaconing patterns — the same process contacting the same remote IP and port at regular intervals.
- Connections on non-standard ports or to known tunneling and remote-access tool infrastructure.
Investigation tips
- Exclude loopback and well-known system processes first, then group by
Application,DestAddressandDestPort. - Map the device path in
Applicationto a drive letter and check the binary's hash and signature. - Correlate
ProcessIDwith process creation (4688, Sysmon 1) to get the parent and command line. - For inbound flows, match the timestamp and source IP with 4624 LogonType 3 or 10 on the same host.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighRDP over Reverse SSH Tunnel WFPRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighRemote PowerShell Sessions Network Connections (WinRM)Rule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumUncommon Outbound Kerberos Connection - SecurityRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.