Microsoft-Windows-Iphlpsvc

18 events across 2 channels

Event ID 4000 — Teredo server has successfully started.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Teredo server has successfully started.

Event ID 4001 — Teredo server has failed to start with the following error.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Teredo server has failed to start with the following error: %1.
Teredo Reason Code: %2.

Fields

NameDescription
ErrorCode
TeredoReasonCode

Event ID 4002 — Teredo server primary or secondary IPv4 address is invalid.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Teredo server primary or secondary IPv4 address is invalid. Primary IPv4 address: %1. Error Code: %2.

Fields

NameDescription
Interface
ErrorCode

Event ID 4003 — Configured Teredo server name %1 is invalid.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Configured Teredo server name %1 is invalid. Error Code: %2.

Fields

NameDescription
ServerName
ErrorCode

Event ID 4004 — Teredo server initialization has failed with the following error code %1.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Teredo server initialization has failed with the following error code %1.

Fields

NameDescription
ErrorCode

Event ID 4005 — Teredo server has stopped.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Teredo server has stopped.

Event ID 4100 — ISATAP router address %1 was set with status %2.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

ISATAP router address %1 was set with status %2.

Fields

NameDescription
IsatapRouter
ErrorCode

Sigma Rules

  • ISATAP Router Address Was Set
    Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.

Event ID 4200 — %1 interface %2 with address %3 has been brought up.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

%1 interface %2 with address %3 has been brought up.

Fields

NameDescription
ProtocolType
Interface
Address

Event ID 4201 — %1 interface %2 is no longer active.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

%1 interface %2 is no longer active.

Fields

NameDescription
ProtocolType
Interface

Event ID 4202 — Unable to update the IP address on %1 interface %2.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

Unable to update the IP address on %1 interface %2. Update Type: %3. Error Code: %4.

Fields

NameDescription
Error_Code
ProtocolType
Interface
UpdateType
ErrorCode

Event ID 4300 — IP-HTTPS server has successfully started using the server URL %1.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

IP-HTTPS server has successfully started using the server URL %1.

Fields

NameDescription
ServerUrl

Event ID 4301 — IP-HTTPS server has stopped.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

IP-HTTPS server has stopped.

Event ID 4302 — IP-HTTPS server has failed to start with the following error.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Message

IP-HTTPS server has failed to start with the following error: %1. 
 IP HTTPS reason code %2.

Fields

NameDescription
ErrorCode
IpHTTPSReasonCode

Event ID 4303 — IP-HTTPS client %1 (%2) is associated with IP address %3.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Message

IP-HTTPS client %1 (%2) is associated with IP address %3.

Fields

NameDescription
ClientMachineName
TunnelSourceIP
RemoteIP

Event ID 4304 — IP-HTTPS client %1 (%2) is disassociated from IP address %3.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Message

IP-HTTPS client %1 (%2) is disassociated from IP address %3.

Fields

NameDescription
ClientMachineName
TunnelSourceIP
RemoteIP

Event ID 4400 — DNS64: No matching IPv6 prefix found for IPv4 address %4, received for name %3 queried by client %2.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Message

DNS64: No matching IPv6 prefix found for IPv4 address %4, received for name %3 queried by client %2.

Fields

NameDescription
AddrLength
ClientIP
QuestionName
Translated IPv4 Address
TranslatedIPv4Address

Event ID 4500 — DA MULTISITE: Configured DA site %1.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Message

DA MULTISITE: Configured DA site %1.

Fields

NameDescription
SiteName

Event ID 4501 — DA MULTISITE: Unconfigured DA site %1.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Message

DA MULTISITE: Unconfigured DA site %1.

Fields

NameDescription
SiteName