Microsoft-Windows-Iphlpsvc

18 events across 2 channels

Event ID 4000 — Teredo server has successfully started.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Teredo server has successfully started.

Message #

Teredo server has successfully started.

Event ID 4001 — Teredo server has failed to start with the following error: ErrorCode.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Teredo server has failed to start with the following error: ErrorCode.

Message #

Teredo server has failed to start with the following error: %1.
Teredo Reason Code: %2.

Fields #

NameDescription
ErrorCode UInt32
TeredoReasonCode UInt32

Event ID 4002 — Teredo server primary or secondary IPv4 address is invalid.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Teredo server primary or secondary IPv4 address is invalid. Primary IPv4 address: Interface. Error Code: ErrorCode.

Message #

Teredo server primary or secondary IPv4 address is invalid. Primary IPv4 address: %1. Error Code: %2.

Fields #

NameDescription
Interface UnicodeString
ErrorCode UInt32

Event ID 4003 — Configured Teredo server name ServerName is invalid.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Configured Teredo server name ServerName is invalid. Error Code: ErrorCode.

Message #

Configured Teredo server name %1 is invalid. Error Code: %2.

Fields #

NameDescription
ServerName UnicodeString
ErrorCode UInt32

Event ID 4004 — Teredo server initialization has failed with the following error code ErrorCode.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Teredo server initialization has failed with the following error code ErrorCode.

Message #

Teredo server initialization has failed with the following error code %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 4005 — Teredo server has stopped.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Teredo server has stopped.

Message #

Teredo server has stopped.

Event ID 4100 — ISATAP router address IsatapRouter was set with status ErrorCode.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

ISATAP router address IsatapRouter was set with status ErrorCode.

Message #

ISATAP router address %1 was set with status %2.

Fields #

NameDescription
IsatapRouter UnicodeString
ErrorCode UInt32

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

  • ISATAP Router Address Was Set source medium: Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.

Event ID 4200 — ProtocolType interface Interface with address Address has been brought up.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

ProtocolType interface Interface with address Address has been brought up.

Message #

%1 interface %2 with address %3 has been brought up.

Fields #

NameDescription
ProtocolType UInt32
Interface UnicodeString
Address UnicodeString

Event ID 4201 — ProtocolType interface Interface is no longer active.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

ProtocolType interface Interface is no longer active.

Message #

%1 interface %2 is no longer active.

Fields #

NameDescription
ProtocolType UInt32
Interface UnicodeString

Event ID 4202 — Unable to update the IP address on Error_Code interface ProtocolType.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

Unable to update the IP address on Error_Code interface ProtocolType. Update Type: Interface. Error Code: UpdateType.

Message #

Unable to update the IP address on %1 interface %2. Update Type: %3. Error Code: %4.

Fields #

NameDescription
Error_Code
ProtocolType UInt32
Interface UnicodeString
UpdateType UInt32
ErrorCode UInt32

Event ID 4300 — IP-HTTPS server has successfully started using the server URL ServerUrl.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

IP-HTTPS server has successfully started using the server URL ServerUrl.

Message #

IP-HTTPS server has successfully started using the server URL %1.

Fields #

NameDescription
ServerUrl UnicodeString

Event ID 4301 — IP-HTTPS server has stopped.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

IP-HTTPS server has stopped.

Message #

IP-HTTPS server has stopped.

Event ID 4302 — IP-HTTPS server has failed to start with the following error: ErrorCode.

Provider
Microsoft-Windows-Iphlpsvc
Channel
System

Description

IP-HTTPS server has failed to start with the following error: ErrorCode.

Message #

IP-HTTPS server has failed to start with the following error: %1. 
 IP HTTPS reason code %2.

Fields #

NameDescription
ErrorCode UInt32
IpHTTPSReasonCode UInt32

Event ID 4303 — IP-HTTPS client ClientMachineName (TunnelSourceIP) is associated with IP address RemoteIP.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Description

IP-HTTPS client ClientMachineName (TunnelSourceIP) is associated with IP address RemoteIP.

Message #

IP-HTTPS client %1 (%2) is associated with IP address %3.

Fields #

NameDescription
ClientMachineName UnicodeString
TunnelSourceIP UnicodeString
RemoteIP UnicodeString

Event ID 4304 — IP-HTTPS client ClientMachineName (TunnelSourceIP) is disassociated from IP address RemoteIP.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Description

IP-HTTPS client ClientMachineName (TunnelSourceIP) is disassociated from IP address RemoteIP.

Message #

IP-HTTPS client %1 (%2) is disassociated from IP address %3.

Fields #

NameDescription
ClientMachineName UnicodeString
TunnelSourceIP UnicodeString
RemoteIP UnicodeString

Event ID 4400 — DNS64: No matching IPv6 prefix found for IPv4 address Translated IPv4 Address, received for name QuestionName queried by client ClientIP.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Description

DNS64: No matching IPv6 prefix found for IPv4 address Translated IPv4 Address, received for name QuestionName queried by client ClientIP.

Message #

DNS64: No matching IPv6 prefix found for IPv4 address %4, received for name %3 queried by client %2.

Fields #

NameDescription
AddrLength UInt32
ClientIP Binary
QuestionName UnicodeString
Translated IPv4 Address UInt32
TranslatedIPv4Address UInt32

Event ID 4500 — DA MULTISITE: Configured DA site SiteName.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Description

DA MULTISITE: Configured DA site SiteName.

Message #

DA MULTISITE: Configured DA site %1.

Fields #

NameDescription
SiteName UnicodeString

Event ID 4501 — DA MULTISITE: Unconfigured DA site SiteName.

Provider
Microsoft-Windows-Iphlpsvc
Channel
Operational

Description

DA MULTISITE: Unconfigured DA site SiteName.

Message #

DA MULTISITE: Unconfigured DA site %1.

Fields #

NameDescription
SiteName UnicodeString