Hi,
Microflow policing is implemented via netflow on the 6500, so it is processed in hardware. Incidentally, microflow policing is specifically not supported in software for this reason. ;)
If the packets are destined to the MSFC, it is likely due to something else you have configured. Also keep in mind that we need to leak some packets to the CPU to build the netflow entries - this may be what you are seeing as well.