Microsoft-Windows-Winsock-Sockets

16 events across 1 channel

EventTitleChannelSample
1SockCreateStartOperationalN
2SockCreateStopOperationalN
3SockCloseOperationalY
4SockCloseOperationalY
5SockAcceptStartOperationalN
6SockAcceptStopOperationalN
7SockSetOptStartOperationalN
8SockSetOptStopOperationalN
9SockConnectStartOperationalN
10SockConnectStopOperationalN
11SockBindStartOperationalN
12SockBindStopOperationalN
13SockGetOptStartOperationalN
14SockGetOptStopOperationalN
15SockListenStartOperationalN
16SockListenStopOperationalN

Event ID 1: SockCreateStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockCreate
Opcode
Start

Event ID 2: SockCreateStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockCreate
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressFamily UInt32
SocketType UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ProcessId UInt32
FailurePoint HexInt32

Event ID 3: SockClose

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Level
Verbose
Task
SockClose
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsock-Sockets",
    "guid": "{BDE46AEA-2357-51FE-7367-D5296F530BD1}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 5,
    "task": 1001,
    "opcode": 1,
    "keywords": "0x0000000000001001",
    "time_created": "2026-06-02T04:01:52.944+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
    },
    "execution": {
      "process_id": 11772,
      "thread_id": 13132
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "SockClose"
}

Event ID 4: SockClose

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
SockClose
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
IsProviderSocket Boolean
FailurePoint HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsock-Sockets",
    "guid": "{BDE46AEA-2357-51FE-7367-D5296F530BD1}",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 1001,
    "opcode": 2,
    "keywords": "0x0000000000001001",
    "time_created": "2026-06-02T04:01:52.944+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
    },
    "execution": {
      "process_id": 11772,
      "thread_id": 13132
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ErrorCode": "00000000",
    "FailurePoint": "00000000",
    "IsProviderSocket": true,
    "Socket": "0x6DC"
  },
  "message": "SockClose"
}

Event ID 5: SockAcceptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockAccept
Opcode
Start

Event ID 6: SockAcceptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockAccept
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
SocketAccepted Pointer
SocketListening Pointer
ProcessId UInt32
FailurePoint HexInt32

Event ID 7: SockSetOptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockSetOpt
Opcode
Start

Event ID 8: SockSetOptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockSetOpt
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Level Int32
OptName Int32
OptLen UInt32
OptVal Binary
FailurePoint HexInt32

Event ID 9: SockConnectStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockConnect
Opcode
Start

Event ID 10: SockConnectStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockConnect
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressLength UInt32
Address Binary
FailurePoint HexInt32

Event ID 11: SockBindStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockBind
Opcode
Start

Event ID 12: SockBindStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockBind
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressLength UInt32
Address Binary
FailurePoint HexInt32

Event ID 13: SockGetOptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockGetOpt
Opcode
Start

Event ID 14: SockGetOptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockGetOpt
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Level Int32
OptName Int32
OptLen UInt32
OptVal Binary
FailurePoint HexInt32

Event ID 15: SockListenStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockListen
Opcode
Start

Event ID 16: SockListenStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockListen
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Backlog Int32
FailurePoint HexInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {BDE46AEA-2357-51FE-7367-D5296F530BD1}

Defined in ws2_32.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.2849, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads