Microsoft-Windows-DFSN-ServerFilter
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | GetReferral Request is received by the DFSN-ServerFilter from SRV | Analytic, Operational | N | N |
| 2 | GetReferral Request has been inserted into the Upcall queue and pending … | Analytic, Operational | N | N |
| 3 | GetReferral Response is ready to be returned to SRV | Analytic, Operational | N | N |
| 4 | ProcessUpcall is started by DFSN-ServerService and ready to post response to the … | Analytic, Operational | N | N |
| 5 | ProcessUpcall has posted the response to the pending Upcall request in … | Analytic, Operational | N | N |
| 6 | ProcessUpcall has dequeued an Upcall request and ready to return to … | Analytic, Operational | N | N |
Event ID 1: GetReferral Request is received by the DFSN-ServerFilter from SRV
#Event ID 2: GetReferral Request has been inserted into the Upcall queue and pending processing by the DFSN-ServerService
#Fields #
| Name | Description |
|---|---|
Request Pointer |
Event ID 3: GetReferral Response is ready to be returned to SRV
#Description
GetReferral Response is ready to be returned to SRV.sys by the DFSN-ServerFilter.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 4: ProcessUpcall is started by DFSN-ServerService and ready to post response to the request it just processed in DFSN-ServerFilter
#Fields #
| Name | Description |
|---|---|
ResponseBuffer Pointer | |
Request Pointer | |
ResponseBufferLength UInt16 | |
RequestSize UInt16 |
Event ID 5: ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter
#Fields #
| Name | Description |
|---|---|
Response Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 6: ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request
#Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Provenance
ETW provider GUID 5407baea-a563-4e56-819f-7deaa72807ce
Defined in dfs.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB