[Forgot Password]
Login  Register Subscribe

24003

 
 

131573

 
 

108566

 
 

909

 
 

85401

 
 

134

Paid content will be excluded from the download.


Download | Alert*
OVAL

Ensure No Auditing for 'Audit Policy: Object Access: Filtering Platform Connection'

ID: oval:org.secpod.oval:def:35492Date: (C)2016-06-10   (M)2018-03-24
Class: COMPLIANCEFamily: windows




This subcategory reports when connections are allowed or blocked by WFP. These events can be high in volume. Events for this subcategory include: - 5031: The Windows Firewall Service blocked an application from accepting incoming connections on the network. - 5154: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. - 5155 : The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. - 5156: The Windows Filtering Platform has allowed a connection. - 5157: The Windows Filtering Platform has blocked a connection. - 5158: The Windows Filtering Platform has permitted a bind to a local port. - 5159: The Windows Filtering Platform has blocked a bind to a local port. Refer to the Microsoft Knowledgebase article "Description of security events in Windows Vista and in Windows Server 2008" for the most recent information about this setting: http://support.microsoft.com/kb/947226.

Platform:
Microsoft Windows 10
Reference:
CCE-42515-7
CCE    1
CCE-42515-7

© SecPod Technologies