WinSecWiki > Security Settings > Advanced Audit Policies > Policy Change > Other Policy Change Events

Audit Other Policy Change Events

So far I've only found one event in this category and it should clearly be in the Filtering Platform Policy Change subcategory instead. As with all subcategories you must use auditpol to enable to disable these events.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
5447 A Windows Filtering Platform filter has been changed.

Back to top

 

Upcoming Webinars
  • AD Certificate Services: A Massive Chunk of Windows Security Functionality Finally Gets the Security Research It Deserves
  • Linux Security: Locking Down Admin Access with SSH and Sudo
  • Understanding Broken Object Level Authorization: The Quiet Access Control Failure Undermining Today’s Apps
  • Patching 3rd Party Apps on PCs Managed by Intune
Additional Resources
    Policy Change
    •Audit Policy Change
    •Authentication Policy Change
    •Authorization Policy Change
    •Filtering Platform Policy Change
    •MPSSVC Rule-Level Policy Change
    •Other Policy Change Events

     
     
    User name:
    Password:
      / Forgot?
      Register
    January 2026
    Patch Tuesday
    "Patch Tuesday - Starting 2026 with a Bang; 3 Zero Days " - sponsored by LOGbinder and Supercharger
    .
    Tweet
    Follow @randyfsmith
    About | Newsletter | Contact Ultimate IT Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, Inc. All rights reserved.
    Disclaimer: We do our best to provide quality information and expert commentary but use all information at your own risk. For complaints, please contact abuse@ultimatewindowssecurity.com.
    Terms of Use | Privacy |
    Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.