Microsoft-Windows-Iphlpsvc
18 events across 2 channels
Event ID 4000 — Teredo server has successfully started.
Message
Event ID 4001 — Teredo server has failed to start with the following error.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
TeredoReasonCode | — |
Event ID 4002 — Teredo server primary or secondary IPv4 address is invalid.
Message
Fields
| Name | Description |
|---|---|
Interface | — |
ErrorCode | — |
Event ID 4003 — Configured Teredo server name %1 is invalid.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
ErrorCode | — |
Event ID 4004 — Teredo server initialization has failed with the following error code %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 4005 — Teredo server has stopped.
Message
Event ID 4100 — ISATAP router address %1 was set with status %2.
Message
Fields
| Name | Description |
|---|---|
IsatapRouter | — |
ErrorCode | — |
Sigma Rules
- ISATAP Router Address Was Set
Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.
Event ID 4200 — %1 interface %2 with address %3 has been brought up.
Message
Fields
| Name | Description |
|---|---|
ProtocolType | — |
Interface | — |
Address | — |
Event ID 4201 — %1 interface %2 is no longer active.
Message
Fields
| Name | Description |
|---|---|
ProtocolType | — |
Interface | — |
Event ID 4202 — Unable to update the IP address on %1 interface %2.
Message
Fields
| Name | Description |
|---|---|
Error_Code | — |
ProtocolType | — |
Interface | — |
UpdateType | — |
ErrorCode | — |
Event ID 4300 — IP-HTTPS server has successfully started using the server URL %1.
Message
Fields
| Name | Description |
|---|---|
ServerUrl | — |
Event ID 4301 — IP-HTTPS server has stopped.
Message
Event ID 4302 — IP-HTTPS server has failed to start with the following error.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
IpHTTPSReasonCode | — |
Event ID 4303 — IP-HTTPS client %1 (%2) is associated with IP address %3.
Message
Fields
| Name | Description |
|---|---|
ClientMachineName | — |
TunnelSourceIP | — |
RemoteIP | — |
Event ID 4304 — IP-HTTPS client %1 (%2) is disassociated from IP address %3.
Message
Fields
| Name | Description |
|---|---|
ClientMachineName | — |
TunnelSourceIP | — |
RemoteIP | — |
Event ID 4400 — DNS64: No matching IPv6 prefix found for IPv4 address %4, received for name %3 queried by client %2.
Message
Fields
| Name | Description |
|---|---|
AddrLength | — |
ClientIP | — |
QuestionName | — |
Translated IPv4 Address | — |
TranslatedIPv4Address | — |
Event ID 4500 — DA MULTISITE: Configured DA site %1.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |
Event ID 4501 — DA MULTISITE: Unconfigured DA site %1.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |