Microsoft-Windows-ZTDNS

8 events across 3 channels

Event ID 1: PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.

#
Provider
Microsoft-Windows-ZTDNS
Channel
PermittedConnections
Task
Task_Classify
Opcode
Opcode_Classify

Description

PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.

Message #

PERMIT - Connection [%2]:%3 -> [%5]:%6 by process (%8) %9 because of %10 %11 from service %12

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
LocalPort UInt32
RemoteAddressLength UInt32
RemoteAddress Binary
RemotePort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ProcessId UInt64
ProcessPath UnicodeString
PermitType UInt32
PermitInfo UnicodeString
ServiceName UnicodeString

Event ID 2: BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.

#
Provider
Microsoft-Windows-ZTDNS
Channel
BlockedConnections
Task
Task_Classify
Opcode
Opcode_Classify

Description

BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.

Message #

BLOCK - Connection [%2]:%3 -> [%5]:%6 by process (%8) %9 from service %10

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
LocalPort UInt32
RemoteAddressLength UInt32
RemoteAddress Binary
RemotePort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ProcessId UInt64
ProcessPath UnicodeString
ServiceName UnicodeString

Event ID 3: UPDATE - Trusted servers by process (ProcessId) ProcessPath.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

UPDATE - Trusted servers by process (ProcessId) ProcessPath.

Message #

UPDATE - Trusted servers by process (%1) %2

Fields #

NameDescription
ProcessId UInt64
ProcessPath UnicodeString

Event ID 4: REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.

Message #

REMOVE - %1%2 by process (%3) %4

Fields #

NameDescription
ExceptionsUpdateType UInt32
ExceptionName UnicodeString
ProcessId UInt64
ProcessPath UnicodeString

Event ID 5: ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.

Message #

ADD - %1%2 by process (%3) %4

Fields #

NameDescription
ExceptionsUpdateType UInt32
ExceptionName UnicodeString
ProcessId UInt64
ProcessPath UnicodeString

Event ID 6: UPDATE - State to ServiceState by process (ProcessId) ProcessPath.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

UPDATE - State to ServiceState by process (ProcessId) ProcessPath.

Message #

UPDATE - State to %1 by process (%2) %3

Fields #

NameDescription
ServiceState UInt32
ProcessId UInt64
ProcessPath UnicodeString

Event ID 7: START - ZTDNS service with status Status.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

START - ZTDNS service with status Status.

Message #

START - ZTDNS service with status %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 8: STOP - ZTDNS service with status Status.

#
Provider
Microsoft-Windows-ZTDNS
Channel
Operational
Task
Task_Notify
Opcode
Opcode_Notify

Description

STOP - ZTDNS service with status Status.

Message #

STOP - ZTDNS service with status %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 8507cd07-f18b-54f0-b871-23c43a5bf118

Defined in ztdns.sys, the binary that emits these events.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads