Microsoft-Windows-RPC-Audit
2 events across 1 channel
Event ID 1: task_0
#Fields #
| Name | Description |
|---|---|
InterfaceUuid GUID | |
OpNum UInt32 | |
SubjectUserSid SID | SID of the account that performed the operation. |
SubjectLogonId UInt64 | Logon session identifier (LUID) for the subject. Correlates with logon events (4624). |
LocalIpAddressLength UInt32 | |
LocalIpAddress Binary | |
RemoteIpAddressLength UInt32 | |
RemoteIpAddress Binary | |
ProtocolSequence UInt32 | |
AuthenticationService UInt32 | |
AuthenticationLevel UInt32 | |
Endpoint UnicodeString | |
RemoteHost UnicodeString | |
BufferSize UInt32 | |
Buffer Binary |
Event ID 2: task_02
#Fields #
| Name | Description |
|---|---|
InterfaceUuid GUID | |
OpNum UInt32 | |
SubjectUserSid SID | SID of the account that performed the operation. |
SubjectLogonId UInt64 | Logon session identifier (LUID) for the subject. Correlates with logon events (4624). |
LocalIpAddressLength UInt32 | |
LocalIpAddress Binary | |
RemoteIpAddressLength UInt32 | |
RemoteIpAddress Binary | |
ProtocolSequence UInt32 | |
AuthenticationService UInt32 | |
AuthenticationLevel UInt32 | |
Endpoint UnicodeString | |
RemoteHost UnicodeString | |
ErrorCode UInt32 | |
IsBlockedByWFP Boolean |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 3c578d57-f85a-5fc9-dea0-8c663ccff942
Defined in rpcrt4.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02