Microsoft-Windows-RPC-Audit

2 events across 1 channel

EventTitleChannelSample
1task_0OperationalN
2task_02OperationalN

Event ID 1: task_0

#
Provider
Microsoft-Windows-RPC-Audit
Channel
Operational

Fields #

NameDescription
InterfaceUuid GUID
OpNum UInt32
SubjectUserSid SIDSID of the account that performed the operation.
SubjectLogonId UInt64Logon session identifier (LUID) for the subject. Correlates with logon events (4624).
LocalIpAddressLength UInt32
LocalIpAddress Binary
RemoteIpAddressLength UInt32
RemoteIpAddress Binary
ProtocolSequence UInt32
AuthenticationService UInt32
AuthenticationLevel UInt32
Endpoint UnicodeString
RemoteHost UnicodeString
BufferSize UInt32
Buffer Binary

Event ID 2: task_02

#
Provider
Microsoft-Windows-RPC-Audit
Channel
Operational

Fields #

NameDescription
InterfaceUuid GUID
OpNum UInt32
SubjectUserSid SIDSID of the account that performed the operation.
SubjectLogonId UInt64Logon session identifier (LUID) for the subject. Correlates with logon events (4624).
LocalIpAddressLength UInt32
LocalIpAddress Binary
RemoteIpAddressLength UInt32
RemoteIpAddress Binary
ProtocolSequence UInt32
AuthenticationService UInt32
AuthenticationLevel UInt32
Endpoint UnicodeString
RemoteHost UnicodeString
ErrorCode UInt32
IsBlockedByWFP Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 3c578d57-f85a-5fc9-dea0-8c663ccff942

Defined in rpcrt4.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads