Thank you!
Unfortunately we do not know for sure whether the WindowsFirewall detection is based on the same blocked events. WindowsFirewall may use an internal way to detect new applications.
We just would like to verify the entire security core operability anyhow.
Anyway thank you.
