Microsoft-Pef-WFP-MessageProvider
19 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 2000 | The generic ETW message fragment that ORT can reassemble. | Diagnostic | N |
| 10001 | Driver Load | Diagnostic | N |
| 10002 | Driver Unload | Diagnostic | N |
| 10003 | Callout Register | Diagnostic | N |
| 10004 | Callout Unregister | Diagnostic | N |
| 10005 | Callout Notify Filter Add | Diagnostic | N |
| 10006 | Callout Notify Filter Delete | Diagnostic | N |
| 20001 | An error was encountered while loading the driver. | Diagnostic | N |
| 20002 | An error was encountered while unloading the driver. | Diagnostic | N |
| 20003 | An error was encountered while registering a callout. | Diagnostic | N |
| 20004 | An error was encountered while unregistering a callout. | Diagnostic | N |
| 20005 | An error was encountered in a classify function. | Diagnostic | N |
| 60011 | The Transport Layer Message for IPv4. | Diagnostic | N |
| 60012 | The Transport Layer Message for IPv4. | Diagnostic | N |
| 60021 | The Transport Layer Message for IPv6. | Diagnostic | N |
| 60022 | The Transport Layer Message for IPv6. | Diagnostic | N |
| 60031 | The ALE Layer Message for IPv4. | Diagnostic | N |
| 60041 | The Transport Layer Message for IPv6. | Diagnostic | N |
| 60050 | A packet has been discarded. | Diagnostic | N |
Event ID 2000: The generic ETW message fragment that ORT can reassemble.
#Event ID 10001: Driver Load
#Event ID 10002: Driver Unload
#Event ID 10003: Callout Register
#Event ID 10004: Callout Unregister
#Event ID 10005: Callout Notify Filter Add
#Event ID 10006: Callout Notify Filter Delete
#Event ID 20001: An error was encountered while loading the driver.
#Event ID 20002: An error was encountered while unloading the driver.
#Event ID 20003: An error was encountered while registering a callout.
#Event ID 20004: An error was encountered while unregistering a callout.
#Event ID 20005: An error was encountered in a classify function.
#Event ID 60011: The Transport Layer Message for IPv4.
#Description
The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
Protocol UInt8 | Known values
|
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60012: The Transport Layer Message for IPv4.
#Description
The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60021: The Transport Layer Message for IPv6.
#Description
The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
Protocol UInt8 | Known values
|
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60022: The Transport Layer Message for IPv6.
#Description
The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60031: The ALE Layer Message for IPv4.
#Description
The ALE Layer Message for IPv4.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
SourcePort UInt16 | |
DestinationPort UInt16 | |
Luid UInt64 | |
Direction UInt8 | Known values
|
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ProcessId UInt64 | |
ByteLength UInt16 | |
ProcessPath Binary |
Event ID 60041: The Transport Layer Message for IPv6.
#Description
The Transport Layer Message for IPv6.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
SourcePort UInt16 | |
DestinationPort UInt16 | |
Luid UInt64 | |
Direction UInt8 | Known values
|
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ProcessId UInt64 | |
ByteLength UInt16 | |
ProcessPath Binary |
Event ID 60050: A packet has been discarded.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID c22d1b14-c242-49de-9f17-1d76b8b9c458
Defined in WFPCapture.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02