[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

Ensure No Auditing for 'Audit Policy: Object Access: Filtering Platform Connection'

ID: oval:org.secpod.oval:def:35492Date: (C)2016-06-10   (M)2017-10-23
Class: COMPLIANCEFamily: windows




This subcategory reports when connections are allowed or blocked by WFP. These events can be high in volume. Events for this subcategory include: - 5031: The Windows Firewall Service blocked an application from accepting incoming connections on the network. - 5154: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. - 5155 : The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. - 5156: The Windows Filtering Platform has allowed a connection. - 5157: The Windows Filtering Platform has blocked a connection. - 5158: The Windows Filtering Platform has permitted a bind to a local port. - 5159: The Windows Filtering Platform has blocked a bind to a local port. Refer to the Microsoft Knowledgebase article "Description of security events in Windows Vista and in Windows Server 2008" for the most recent information about this setting: http://support.microsoft.com/kb/947226.

Platform:
Microsoft Windows 10
Reference:
CCE-42515-7
CCE    1
CCE-42515-7
XCCDF    4
xccdf_org.secpod_benchmark_general_Windows_10
xccdf_org.secpod_benchmark_NIST_800_53_r4_Windows_10
xccdf_org.secpod_benchmark_NIST_800_171_R1_Windows_10
xccdf_org.secpod_benchmark_PCI_3_2_Windows_10
...

© 2013 SecPod Technologies