Microsoft-Windows-DFSN-ServerFilter
12 events across 2 channels
Event ID 1: GetReferral Request is received by the DFSN-ServerFilter from SRV.
#Event ID 1: GetReferral Request is received by the DFSN-ServerFilter from SRV
#Description
GetReferral Request is received by the DFSN-ServerFilter from SRV.sys.
Fields #
| Name | Description |
|---|---|
InputBuffer Pointer | |
Request Pointer | |
InputBufferLength UInt16 | |
RequestSize UInt16 |
Event ID 2: GetReferral Request has been inserted into the Upcall queue and pending processing by the DFSN-ServerService
#Event ID 2: GetReferral Request has been inserted into the Upcall queue and pending processing by the DFSN-ServerService
#Description
GetReferral Request has been inserted into the Upcall queue and pending processing by the DFSN-ServerService.
Fields #
| Name | Description |
|---|---|
Request Pointer |
Event ID 3: GetReferral Response is ready to be returned to SRV.
#Description
GetReferral Response is ready to be returned to SRV.sys by the DFSN-ServerFilter.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 3: GetReferral Response is ready to be returned to SRV
#Description
GetReferral Response is ready to be returned to SRV.sys by the DFSN-ServerFilter.
Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 4: ProcessUpcall is started by DFSN-ServerService and ready to post response to the request it just processed in DFSN-ServerFilter
#Event ID 4: ProcessUpcall is started by DFSN-ServerService and ready to post response to the request it just processed in DFSN-ServerFilter
#Description
ProcessUpcall is started by DFSN-ServerService and ready to post response to the request it just processed in DFSN-ServerFilter.
Fields #
| Name | Description |
|---|---|
ResponseBuffer Pointer | |
Request Pointer | |
ResponseBufferLength UInt16 | |
RequestSize UInt16 |
Event ID 5: ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter
#Description
ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter.
Message #
Fields #
| Name | Description |
|---|---|
Response Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 5: ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter
#Description
ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter.
Fields #
| Name | Description |
|---|---|
Response Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 6: ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request
#Description
ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 6: ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request
#Description
ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request.
Fields #
| Name | Description |
|---|---|
Request Pointer | |
OutputBuffer Pointer | |
RequestSize UInt16 | |
OutputBufferLength UInt16 | |
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 5407baea-a563-4e56-819f-7deaa72807ce
Defined in dfs.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02