Microsoft-Windows-Mprddm
13 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 0 | Used for debugging purposes | Operational | N |
| 1 | Connect Notification for a VPN connection | Operational | N |
| 2 | Disconnect Notification for a VPN connection | Operational | N |
| 1001 | Unable to get DHCP address | Operational | N |
| 1002 | Able to get DHCP address | Operational | N |
| 1003 | No static IP address available | Operational | N |
| 1004 | Very few static IP addresses available | Operational | N |
| 1005 | Static IP addresses available | Operational | N |
| 1006 | WAN Miniports not available | Operational | N |
| 1007 | WAN Miniports available | Operational | N |
| 1008 | All ports exhausted | Operational | N |
| 1009 | Very few ports available | Operational | N |
| 1010 | Ports available | Operational | N |
Event ID 0: Used for debugging purposes
#Event ID 1: Connect Notification for a VPN connection
#Description
Connect Notification for a VPN connection.
Message #
Fields #
| Name | Description |
|---|---|
connectionID Pointer | |
userName UnicodeString | |
remoteIPv4Address UnicodeString | |
remoteIPv6Address UnicodeString | |
ispAddress UnicodeString | |
deviceType UInt32 | |
tunnelType UnicodeString | |
portName UnicodeString | |
authenticationProtocol UInt32 | |
authenticationData UInt32 | |
eapTypeId UInt32 | |
embeddedEapTypeId UInt32 | |
quarantineState UInt32 | |
connectionStartTime FILETIME | |
isS2SConnection UInt32 | |
routingDomainId GUID |
Event ID 2: Disconnect Notification for a VPN connection
#Description
Disconnect Notification for a VPN connection.
Message #
Fields #
| Name | Description |
|---|---|
connectionID Pointer | |
userName UnicodeString | |
remoteIPv4Address UnicodeString | |
remoteIPv6Address UnicodeString | |
ispAddress UnicodeString | |
portName UnicodeString | |
bytesIn UInt64 | |
bytesOut UInt64 | |
disconnectTime FILETIME | |
isS2SConnection UInt32 |
Event ID 1004: Very few static IP addresses available
#Description
Very few static IP addresses available.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 3a5bef13-d0f7-4e7f-9ec8-5e707df711d0
Defined in mprddm.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02