Microsoft-Windows-ZTDNS
8 events across 3 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by … | PermittedConnections | N |
| 2 | BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by … | BlockedConnections | N |
| 3 | UPDATE - Trusted servers by process (ProcessId) ProcessPath. | Operational | N |
| 4 | REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath. | Operational | N |
| 5 | ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath. | Operational | N |
| 6 | UPDATE - State to ServiceState by process (ProcessId) ProcessPath. | Operational | N |
| 7 | START - ZTDNS service with status Status. | Operational | N |
| 8 | STOP - ZTDNS service with status Status. | Operational | N |
Event ID 1: PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
#Description
PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
LocalPort UInt32 | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt32 | |
Protocol UInt32 | Known values
|
ProcessId UInt64 | |
ProcessPath UnicodeString | |
PermitType UInt32 | |
PermitInfo UnicodeString | |
ServiceName UnicodeString |
Event ID 2: BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
#Description
BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
LocalPort UInt32 | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt32 | |
Protocol UInt32 | Known values
|
ProcessId UInt64 | |
ProcessPath UnicodeString | |
ServiceName UnicodeString |
Event ID 3: UPDATE - Trusted servers by process (ProcessId) ProcessPath.
#Event ID 4: REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
#Event ID 5: ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
#Event ID 6: UPDATE - State to ServiceState by process (ProcessId) ProcessPath.
#Event ID 7: START - ZTDNS service with status Status.
#Description
START - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 8: STOP - ZTDNS service with status Status.
#Description
STOP - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 8507cd07-f18b-54f0-b871-23c43a5bf118
Defined in ztdns.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02