Microsoft-Windows-Iphlpsvc

Event ID 4000: Teredo server has successfully started.

#
Channel
System

Event ID 4001: Teredo server has failed to start with the following error: ErrorCode.

#
Channel
System

Message #

Teredo server has failed to start with the following error: %1.
Teredo Reason Code: %2.

Fields #

NameDescription
ErrorCode UInt32
TeredoReasonCode UInt32

Event ID 4002: Teredo server primary or secondary IPv4 address is invalid.

#
Channel
System

Description

Teredo server primary or secondary IPv4 address is invalid. Primary IPv4 address: Interface. Error Code: ErrorCode.

Message #

Teredo server primary or secondary IPv4 address is invalid. Primary IPv4 address: %1. Error Code: %2.

Fields #

NameDescription
Interface UnicodeString
ErrorCode UInt32

Event ID 4003: Configured Teredo server name ServerName is invalid.

#
Channel
System

Description

Configured Teredo server name ServerName is invalid. Error Code: ErrorCode.

Message #

Configured Teredo server name %1 is invalid. Error Code: %2.

Fields #

NameDescription
ServerName UnicodeString
ErrorCode UInt32

Event ID 4004: Teredo server initialization has failed with the following error code ErrorCode.

#
Channel
System

Message #

Teredo server initialization has failed with the following error code %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 4005: Teredo server has stopped.

#
Channel
System

Event ID 4100: ISATAP router address IsatapRouter was set with status ErrorCode.

#
Channel
System

Message #

ISATAP router address %1 was set with status %2.

Fields #

NameDescriptionRules
IsatapRouter UnicodeString2 detection rules
ErrorCode UInt32

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • ISATAP Router Address Was Set source medium: Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.T1557, T1565, T1565.002

Event ID 4200: ProtocolType interface Interface with address Address has been brought up.

#
Channel
System

Message #

%1 interface %2 with address %3 has been brought up.

Fields #

NameDescription
ProtocolType UInt32
Interface UnicodeString
Address UnicodeString

Event ID 4201: ProtocolType interface Interface is no longer active.

#
Channel
System

Message #

%1 interface %2 is no longer active.

Fields #

NameDescription
ProtocolType UInt32
Interface UnicodeString

Event ID 4202: Unable to update the IP address on Error_Code interface ProtocolType.

#
Channel
System

Description

Unable to update the IP address on Error_Code interface ProtocolType. Update Type: Interface. Error Code: UpdateType.

Message #

Unable to update the IP address on %1 interface %2. Update Type: %3. Error Code: %4.

Fields #

NameDescription
ProtocolType UInt32
Interface UnicodeString
UpdateType UInt32
ErrorCode UInt32

Event ID 4300: IP-HTTPS server has successfully started using the server URL ServerUrl.

#
Channel
System

Message #

IP-HTTPS server has successfully started using the server URL %1.

Fields #

NameDescription
ServerUrl UnicodeString

Event ID 4301: IP-HTTPS server has stopped.

#
Channel
System

Event ID 4302: IP-HTTPS server has failed to start with the following error: ErrorCode.

#
Channel
System

Message #

IP-HTTPS server has failed to start with the following error: %1. 
 IP HTTPS reason code %2.

Fields #

NameDescription
ErrorCode UInt32
IpHTTPSReasonCode UInt32

Event ID 4303: IP-HTTPS client ClientMachineName (TunnelSourceIP) is associated with IP address RemoteIP.

#
Channel
Operational

Message #

IP-HTTPS client %1 (%2) is associated with IP address %3.

Fields #

NameDescription
ClientMachineName UnicodeString
TunnelSourceIP UnicodeString
RemoteIP UnicodeString

Event ID 4304: IP-HTTPS client ClientMachineName (TunnelSourceIP) is disassociated from IP address RemoteIP.

#
Channel
Operational

Message #

IP-HTTPS client %1 (%2) is disassociated from IP address %3.

Fields #

NameDescription
ClientMachineName UnicodeString
TunnelSourceIP UnicodeString
RemoteIP UnicodeString

Event ID 4400: DNS64: No matching IPv6 prefix found for IPv4 address Translated IPv4 Address, received for name QuestionName queried by client ClientIP.

#
Channel
Operational

Message #

DNS64: No matching IPv6 prefix found for IPv4 address %4, received for name %3 queried by client %2.

Fields #

NameDescription
AddrLength UInt32
ClientIP Binary
QuestionName UnicodeString
TranslatedIPv4Address UInt32

Event ID 4500: DA MULTISITE: Configured DA site SiteName.

#
Channel
Operational

Message #

DA MULTISITE: Configured DA site %1.

Fields #

NameDescription
SiteName UnicodeString

Event ID 4501: DA MULTISITE: Unconfigured DA site SiteName.

#
Channel
Operational

Message #

DA MULTISITE: Unconfigured DA site %1.

Fields #

NameDescription
SiteName UnicodeString

Provenance

ETW provider GUID 66a5c15c-4f8e-4044-bf6e-71d896038977

Defined in iphlpsvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02 — Manifest XML pack, 2.0 MB