Skip to content
Security

Event ID 5157: WFP connection blocked

The Windows Filtering Platform has blocked a connectionSecurity event 5157 logs each connection blocked by the Windows Filtering Platform, with process, direction, addresses and ports. Reveals scans and blocked C2.
5157
Event ID
5157
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Network
Default logging
Needs configuration

What event 5157 means

Event 5157 is the failure counterpart of 5156: the Windows Filtering Platform blocked a connection, usually because of a Windows Firewall rule or the default inbound block policy. It carries the same fields — Application, ProcessID, Direction, source and destination addresses and ports, Protocol and the ID of the blocking filter (FilterRTID).

Blocked inbound traffic shows who tried to reach the host and on which ports, which exposes internal scanning and failed lateral movement attempts. Blocked outbound traffic, where outbound rules exist, shows programs trying to reach destinations they are not allowed to.

As with 5156, the Source fields hold the local endpoint and the Dest fields the remote one in practice; read them together with Direction. Broadcast and multicast discovery protocols (NetBIOS, LLMNR, SSDP, mDNS) produce a steady background of blocks on most networks.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Filtering Platform Connection (Failure). Not audited in the default Windows audit policy.

Failure auditing is far less voluminous than Success and is the setting Microsoft recommends for this subcategory. Dropped packets (as opposed to blocked connections) are logged as 5152 by the Filtering Platform Packet Drop subcategory.

Key fields

FieldWhat it tells you
ProcessIDPID of the process whose connection was blocked; 4 (System) for kernel traffic.
ApplicationExecutable path in device-path form; System for kernel-mode traffic.
DirectionDirection of the blocked connection.
ValueMeaning
%%14592Inbound.
%%14593Outbound.
SourceAddressLocal IP address (in practice, regardless of direction).
SourcePortLocal port. For inbound blocks, the port the remote host tried to reach.
DestAddressRemote IP address.
DestPortRemote port.
ProtocolIANA protocol number (6 TCP, 17 UDP, 1 ICMP, 58 ICMPv6).
FilterRTIDRun-time ID of the blocking filter; netsh wfp show filters on the live host maps it to a rule.
LayerNameWFP layer, e.g. %%14610 (Receive/Accept) for inbound or %%14611 (Connect) for outbound.
LayerRTIDRun-time ID of the WFP layer.
RemoteUserIDRemote user SID when provided by IPsec, otherwise S-1-0-0.
RemoteMachineIDRemote machine SID when provided by IPsec, otherwise S-1-0-0.

Common benign sources

  • NetBIOS, LLMNR, SSDP and mDNS broadcast/multicast traffic hitting the default inbound block policy.
  • Vulnerability scanners and inventory tools probing closed ports on schedule.
  • Applications blocked by an outbound allow-list policy after an update changed their path.

What attackers do that produces it

  • Internal port scanning — one source IP hitting many local ports (or many hosts) in a short time.
  • Failed lateral movement attempts to SMB (445), RDP (3389), WinRM (5985/5986) or RPC (135) on hardened hosts.
  • Malware or a C2 implant repeatedly trying to reach an external address blocked by outbound rules.

Investigation tips

  • Group inbound blocks by remote address and count distinct local ports to spot scanning.
  • For outbound blocks, identify the Application and check it against process creation (4688, Sysmon 1).
  • Check whether the same source later succeeded (5156, 4624) after a firewall change (4946, 4947, 2004).
  • Resolve FilterRTID on the live system to know which rule or default policy blocked the traffic.

MITRE ATT&CK techniques

TechniqueTactics
T1046 Network Service DiscoveryDiscovery
T1071 Application Layer ProtocolCommand and Control
T1021 Remote ServicesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading