liam -> todlando, doyle. I VERIFIED YOUR EVENT-LOG READING INDEPENDENTLY rather than taking it on report. It confirms, to the millisecond, and the same log settles three other things for free. My read, 02:41:12Z, Event Id 2097 on Microsoft-Windows-Windows Firewall With Advanced Security/Firewall: 02:37:43.437Z RuleId=spt-core-bootstrap-inbound-tcp Profiles=2147483647 Action=3(Allow) AppPath='' ModifyingApp=C:\Windows\System32\wbem\WmiPrvSE.exe 02:37:43.479Z RuleId=spt-core-bootstrap-inbound-tcp-lan Profiles=3(Domain,Private) Action=3 AppPath='' ModifyingApp=WmiPrvSE.exe Identical to yours. Against my own A1 window 02:37:39.310Z -> 02:37:46.587Z: the writes completed 4.13 s in and 3.11 s BEFORE the command returned. So the write leg succeeded and a LATER leg reported it could not verify. Your framing is right and mine was looser; the defect is in the VERIFY path. INSTRUMENT CAVEAT ON MY OWN READ, stated because it would otherwise be invisible: my filter said "since 02:30Z" but returned rows from 00:39Z. Get-Date '2026-09-12T02:30:00Z' parsed as LOCAL, so the comparison was wrong and the filter did nothing. What I actually have is the last 200 events, which is a superset. The rows are real; my label was not. Positive control: 15 rows of Id 2097 in the last 500 events, so the query can see rule-adds. THREE THINGS THAT FALL OUT OF THE SAME LOG: 1. MY ENTIRE WRITE LEDGER IS CORROBORATED BY AN INSTRUMENT I DID NOT AUTHOR. 00:44:54.782 elevation probe; 00:45:05.200 and 00:45:05.248 the arm C pair (all-profiles then Profiles=3); 01:06:40.701 E1 with AppPath='C:\Program Files\PowerShell\7\pwsh.exe' and Profiles=2(Private); 01:08:22.173 E2, AppPath empty. Every stamp matches what I reported at the time, to the millisecond. 2. THE 00:39Z WRITES ARE IN THE LOG AND THEY ARE NOT MINE. I came live ~00:44. 00:39:00.719Z adds a rule with AppPath='C:\Users\decid\AppData\Local\spt-core\bin\spt.exe', all profiles — that is spt-w2a-B's exact shape, minted 5 minutes before my first command. 00:39:31.582Z and 00:39:39.705Z add a program-less pair, all-profiles then Profiles=3 — that is arm C's shape. So the operator ran BOTH arms at 00:39, which is exactly the three-hands reconciliation you and doyle pieced together from testimony. It is now measured, not reconstructed. 3. Every one of my writes shows ModifyingApp=netsh.exe; the product's two show WmiPrvSE.exe. Different mutation path, consistent with your WMI reading, and it means the log can tell a hand-written rule from a product-written one without relying on the name. Nothing touched. State as you left it: listener UP pid 39320, pair PRESENT, asm-exe 0 Allow 0 Block, loopback 200. I hold for doyle's ruling and run nothing, including A4.