Microsoft-Windows-RPCSS
3 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | An error occurred. | EndpointMapper | N |
| 2 | Interface registered. | EndpointMapper | Y |
| 3 | Interface unregistered. | EndpointMapper | Y |
Event ID 1: An error occurred.
#Description
An error occurred.
Message #
Fields #
| Name | Description |
|---|---|
DetectionLocation UInt16 | |
Status HexInt32 | NTSTATUS reference |
AdditionalData1 HexInt32 | |
AdditionalData2 HexInt32 |
Event ID 2: Interface registered.
#Description
Interface registered.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceUUID GUID | |
ObjectUUID GUID | |
Protocol AnsiString | Known values
|
EndPoint AnsiString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-RPCSS",
"guid": "{D8975F88-7DDB-4ED0-91BF-3ADF48C48E0C}",
"event_source_name": "",
"event_id": 2,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000200",
"time_created": "2026-06-02T04:01:27.424+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 6340
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"EndPoint": "LRPC-8fd950c9bbf807c1b7",
"InterfaceUUID": "{C9AC6DB5-82B7-4E55-AE8A-E464ED7B4277}",
"ObjectUUID": "{6C637067-6569-746E-0000-000000000000}",
"Protocol": "ncalrpc"
},
"message": ""
}
Event ID 3: Interface unregistered.
#Description
Interface unregistered.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceUUID GUID | |
ObjectUUID GUID | |
Protocol AnsiString | Known values
|
EndPoint AnsiString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-RPCSS",
"guid": "{D8975F88-7DDB-4ED0-91BF-3ADF48C48E0C}",
"event_source_name": "",
"event_id": 3,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000400",
"time_created": "2026-06-02T04:01:27.324+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 6340
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"EndPoint": "LRPC-a24919522e880eb43f",
"InterfaceUUID": "{2EB08E3E-639F-4FBA-97B1-14F878961076}",
"ObjectUUID": "{24D1F7C7-76AF-4F28-9CCD-7F6CB6468601}",
"Protocol": "ncalrpc"
},
"message": ""
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {D8975F88-7DDB-4ED0-91BF-3ADF48C48E0C}
Defined in RpcEpMap.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02