Event ID 5154 – The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
|Category||Object Access: Audit Platform Connection|
When Windows Filtering Platform allows an application or service to listen on a TCP or UDP port for incoming connections, event ID 5154 is logged. This event also logs the filter, port, or program which allowed the incoming connection.
This event log contains the following information:
- Process ID
- Application Name
- Source Address
- Source Type
- Filter Run-Time ID
- Layer Name
- Layer Run-Time
Why does event ID 5154 need to be monitored?
- To ensure only whitelisted applications are allowed to listen on specific ports
- To monitor specific port numbers, and activities regarding them
- To ensure applications listen in on only specific IP addresses
- To check the protocol that is being used by certain applications
- To monitor restricted applications
- To monitor for informational purposes
Event 5154 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10