5031 Security log · Windows Firewall medium severity medium volume

Windows Event ID 5031 — Windows Firewall blocked an application from accepting incoming connections

Firewall blocked an application from accepting connections. Application and Protocol are key.

Why event 5031 matters

Backdoor or reverse shell listener being blocked by firewall. Attacker may subsequently disable firewall (5025) to resolve this.

How to detect it

Alert: unexpected applications being blocked. Correlate with 5025 (firewall stop) that may follow.

Log source
Security
Advanced Audit Policy — enable the 'Windows Firewall' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 5031   // Windows Firewall blocked an application from accepting incoming connections
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=5031
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# Windows Firewall blocked an application from accepting incoming connections — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 5031 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Windows Firewall events

4944 The following policy was active when the Windows Firewall started 4946 A change has been made to Windows Firewall exception list — a rule was added 4947 A change has been made to Windows Firewall exception list — a rule was modified 4948 A change has been made to Windows Firewall exception list — a rule was deleted 4950 A Windows Firewall setting has changed 4957 Windows Firewall did not apply the following rule 5024 The Windows Firewall Service has started successfully 5025 The Windows Firewall Service has been stopped

Frequently asked questions

What is Windows Event ID 5031?

Windows Firewall blocked an application from accepting incoming connections. Firewall blocked an application from accepting connections. Application and Protocol are key.

Which log records event 5031?

Event 5031 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Windows Firewall' subcategory (Success and/or Failure).

How do you detect activity around event 5031?

Alert: unexpected applications being blocked. Correlate with 5025 (firewall stop) that may follow.