Microsoft-Pef-WFP-MessageProvider
Event ID 2000: The generic ETW message fragment that ORT can reassemble.
#Fields #
| Name | Description |
|---|---|
FragmentEventId UInt16 | |
GroupId UInt32 | |
ByteLength UInt32 | |
Payload Binary |
Event ID 10001: Driver Load
#Fields #
| Name | Description |
|---|---|
DriverName UnicodeString | |
MajorVersion UInt16 | |
MinorVersion UInt16 |
Event ID 10002: Driver Unload
#Fields #
| Name | Description |
|---|---|
DriverName UnicodeString | |
MajorVersion UInt16 | |
MinorVersion UInt16 |
Event ID 10005: Callout Notify Filter Add
#Fields #
| Name | Description |
|---|---|
FilterId UInt64 | |
Callout UInt32 | |
FilterWeight UInt64 |
Event ID 10006: Callout Notify Filter Delete
#Fields #
| Name | Description |
|---|---|
FilterId UInt64 | |
Callout UInt32 | |
FilterWeight UInt64 |
Event ID 20001: An error was encountered while loading the driver.
#Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
NTSTATUS UInt32 |
Event ID 20002: An error was encountered while unloading the driver.
#Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
NTSTATUS UInt32 |
Event ID 20003: An error was encountered while registering a callout.
#Fields #
| Name | Description |
|---|---|
Callout UInt32 | |
ErrorMessage UnicodeString | |
NTSTATUS UInt32 |
Event ID 20004: An error was encountered while unregistering a callout.
#Fields #
| Name | Description |
|---|---|
Callout UInt32 | |
ErrorMessage UnicodeString | |
NTSTATUS UInt32 |
Event ID 20005: An error was encountered in a classify function.
#Fields #
| Name | Description |
|---|---|
Callout UInt32 | |
ErrorMessage UnicodeString | |
NTSTATUS UInt32 |
Event ID 60011: The Transport Layer Message for IPv4.
#Description
The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
Protocol UInt8 | Known values
|
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60012: The Transport Layer Message for IPv4.
#Description
The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60021: The Transport Layer Message for IPv6.
#Description
The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
Protocol UInt8 | Known values
|
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60022: The Transport Layer Message for IPv6.
#Description
The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ByteLength UInt16 | |
MessageFrame Binary |
Event ID 60031: The ALE Layer Message for IPv4.
#Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
DestinationAddress UInt32 | |
SourcePort UInt16 | |
DestinationPort UInt16 | |
Luid UInt64 | |
Direction UInt8 | Known values
|
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ProcessId UInt64 | |
ByteLength UInt16 | |
ProcessPath Binary |
Event ID 60041: The Transport Layer Message for IPv6.
#Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
DestinationAddress Binary | |
SourcePort UInt16 | |
DestinationPort UInt16 | |
Luid UInt64 | |
Direction UInt8 | Known values
|
Protocol UInt8 | Known values
|
FlowHandle UInt64 | |
ProcessId UInt64 | |
ByteLength UInt16 | |
ProcessPath Binary |
Provenance
ETW provider GUID c22d1b14-c242-49de-9f17-1d76b8b9c458
Defined in WFPCapture.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB