Event ID 5157: WFP connection blocked
- Event ID
- 5157
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 5157 means
Event 5157 is the failure counterpart of 5156: the Windows Filtering Platform blocked a connection, usually because of a Windows Firewall rule or the default inbound block policy. It carries the same fields — Application, ProcessID, Direction, source and destination addresses and ports, Protocol and the ID of the blocking filter (FilterRTID).
Blocked inbound traffic shows who tried to reach the host and on which ports, which exposes internal scanning and failed lateral movement attempts. Blocked outbound traffic, where outbound rules exist, shows programs trying to reach destinations they are not allowed to.
As with 5156, the Source fields hold the local endpoint and the Dest fields the remote one in practice; read them together with Direction. Broadcast and multicast discovery protocols (NetBIOS, LLMNR, SSDP, mDNS) produce a steady background of blocks on most networks.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Filtering Platform Connection (Failure). Not audited in the default Windows audit policy.
Failure auditing is far less voluminous than Success and is the setting Microsoft recommends for this subcategory. Dropped packets (as opposed to blocked connections) are logged as 5152 by the Filtering Platform Packet Drop subcategory.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| ProcessID | PID of the process whose connection was blocked; 4 (System) for kernel traffic. | ||||||
| Application | Executable path in device-path form; System for kernel-mode traffic. | ||||||
| Direction | Direction of the blocked connection.
| ||||||
| SourceAddress | Local IP address (in practice, regardless of direction). | ||||||
| SourcePort | Local port. For inbound blocks, the port the remote host tried to reach. | ||||||
| DestAddress | Remote IP address. | ||||||
| DestPort | Remote port. | ||||||
| Protocol | IANA protocol number (6 TCP, 17 UDP, 1 ICMP, 58 ICMPv6). | ||||||
| FilterRTID | Run-time ID of the blocking filter; netsh wfp show filters on the live host maps it to a rule. | ||||||
| LayerName | WFP layer, e.g. %%14610 (Receive/Accept) for inbound or %%14611 (Connect) for outbound. | ||||||
| LayerRTID | Run-time ID of the WFP layer. | ||||||
| RemoteUserID | Remote user SID when provided by IPsec, otherwise S-1-0-0. | ||||||
| RemoteMachineID | Remote machine SID when provided by IPsec, otherwise S-1-0-0. |
Common benign sources
- NetBIOS, LLMNR, SSDP and mDNS broadcast/multicast traffic hitting the default inbound block policy.
- Vulnerability scanners and inventory tools probing closed ports on schedule.
- Applications blocked by an outbound allow-list policy after an update changed their path.
What attackers do that produces it
- Internal port scanning — one source IP hitting many local ports (or many hosts) in a short time.
- Failed lateral movement attempts to SMB (445), RDP (3389), WinRM (5985/5986) or RPC (135) on hardened hosts.
- Malware or a C2 implant repeatedly trying to reach an external address blocked by outbound rules.
Investigation tips
- Group inbound blocks by remote address and count distinct local ports to spot scanning.
- For outbound blocks, identify the
Applicationand check it against process creation (4688, Sysmon 1). - Check whether the same source later succeeded (5156, 4624) after a firewall change (4946, 4947, 2004).
- Resolve
FilterRTIDon the live system to know which rule or default policy blocked the traffic.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Filtering Platform Blocked Connection From EDR Agent BinaryRule by @gott_cyber, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.