A Service Filter in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of applying broadly to all traffic, the rule only affects the service named in the filter.

PowerShell exposes service filters through the NetSecurity module, particularly the Get-NetFirewallServiceFilter cmdlet. It returns objects with a Service property that names the service associated with each firewall rule.

Key cmdlets for examining firewall service filters:
- Get-NetFirewallRule — lists all firewall rules
- Get-NetFirewallServiceFilter — shows service associations for rules
- Show-NetFirewallRule — displays rules in a readable format
- Get-NetFirewallProfile — shows domain/private/public profile settings

For example, a firewall rule might allow inbound connections only for the Remote Desktop Services service. Examining these filters can reveal unexpected services with network access, misconfigured rules, or rules tied to services that should not communicate over the network.

This concept relates to Protocol (Networking) because service filters constrain how network protocols are used by tying rules to specific running services on the system.