Jump to content

[Microsoft Windows Security Auditing] Event ID 5159


Recommended Posts

Posted

Source: Microsoft Windows Security Auditing

Event ID: 5159

The Windows Filtering Platform has blocked a bind to a local port

- Process ID: 468

- Application Name: svchost

- Source Address: 0.0.0.0

- Source Port: 50640

- Protocol: 17

- Filter Run-Time ID: 0

- Layer Name: Resource Assignment

- Layer Run-Time ID: 36

- - Process ID: 4

- - Thread ID: 92

I am getting hundreds of these. The Windows Firewall is turned off. Even though, the Windows Firewall service was active. I disabled the service but these still appear.

I attempted to use Process Monitor to view Process 4, but it could not read any of the Threads. Is there a newer version of Process Monitor that works properly in 64bit?


Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...