-
Open
wf.msc
> Advanced Settings > Properties -
Under each profile (Domain, Private, Public), click Customize under Logging
-
Set "Log dropped packets" and "Log successful connections" to Yes
-
Review logs located at
%systemroot%\system32\LogFiles\Firewall\pfirewall.log
Regularly reviewing logs helps detect suspicious activity early.