Microsoft-Windows-SMBServer
207 events across 7 channels
Event ID 1 — Smb2 Request Negotiate
Message
Event ID 2 — Smb2 Request Session Setup
Message
Event ID 3 — Smb2 Request Logoff
Message
Event ID 4 — Smb2 Request Tree Connect
Message
Event ID 5 — Smb2 Request Tree Disconnect
Message
Event ID 6 — Smb2 Request Echo
Message
Event ID 7 — Smb2 Request Cancel
Message
Event ID 8 — Smb2 Request Create
Message
Event ID 9 — Smb2 Request Close
Message
Event ID 10 — Smb2 Request Flush
Message
Event ID 11 — Smb2 Request Read
Message
Event ID 12 — Smb2 Request Write
Message
Event ID 13 — Smb2 Request Break Oplock
Message
Event ID 14 — Smb2 Request Notify Break Lease
Message
Event ID 15 — Smb2 Request Acknowledge Break Lease
Message
Event ID 16 — Smb2 Request Lock
Message
Event ID 17 — Smb2 Request Ioctl
Message
Event ID 18 — Smb2 Request Query Directory
Message
Event ID 19 — Smb2 Request Change Notify
Message
Event ID 20 — Smb2 Request Query Info
Message
Event ID 21 — Smb2 Request Set Info
Message
Event ID 101 — Smb2 Response Negotiate
Message
Event ID 102 — Smb2 Response Session Setup
Message
Event ID 103 — Smb2 Response Logoff
Message
Event ID 104 — Smb2 Response Tree Connect
Message
Event ID 105 — Smb2 Response Tree Disconnect
Message
Event ID 106 — Smb2 Response Echo
Message
Event ID 108 — Smb2 Response Create
Message
Event ID 109 — Smb2 Response Close
Message
Event ID 110 — Smb2 Response Flush
Message
Event ID 111 — Smb2 Response Read
Message
Event ID 112 — Smb2 Response Write
Message
Event ID 113 — Smb2 Response Break Oplock
Message
Event ID 115 — Smb2 Response Acknowledge Break Lease
Message
Event ID 116 — Smb2 Response Lock
Message
Event ID 117 — Smb2 Response Ioctl
Message
Event ID 118 — Smb2 Response Query Directory
Message
Event ID 119 — Smb2 Response Change Notify
Message
Event ID 120 — Smb2 Response Query Info
Message
Event ID 121 — Smb2 Response Set Info
Message
Event ID 122 — Smb2 Response Error
Message
Event ID 200 — Smb2 Work Item Component Transition
Message
Event ID 201 — Smb2 Work Item allocated
Message
Event ID 202 — Smb2 Work Item released
Message
Event ID 203 — SMB2 Work Item activity id transfer
Message
Event ID 204 — SMB2 Work Item external activity id stop
Message
Event ID 500 — Smb2 Connection accepted
Message
Event ID 501 — Smb2 Connection Disconnected by Peer
Message
Event ID 502 — Smb2 Connection Terminated
Message
Event ID 550 — Smb2 Session Allocated
Message
Event ID 551 — Smb2 Session Authentication Failure
Message
Event ID 551 — SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) SPN: %12 SPN Validation Policy:...
Message
Fields
| Name | Description |
|---|---|
EventData.SessionGUID | — |
EventData.ConnectionGUID | — |
EventData.Status | — |
EventData.TranslatedStatus | — |
EventData.ClientAddressLength | — |
EventData.ClientAddress | — |
EventData.SessionId | — |
EventData.UserNameLength | — |
EventData.UserName | — |
EventData.ClientNameLength | — |
EventData.ClientName | — |
EventData.SPN | — |
EventData.SPNValidationPolicy | — |
EventData.ReasonCode | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 551
version: 3
level: 2
task: 551
opcode: 0
keywords: 580964351930793992
time_created: '2022-04-07T17:25:55.271679+00:00'
event_record_id: 10
correlation: {}
execution:
process_id: 4
thread_id: 4460
channel: Microsoft-Windows-SMBServer/Security
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
user_data:
EventData:
SessionGUID: E0AAB88C-4A9F-0000-B5F0-AAE09F4AD801
ConnectionGUID: E0AAB88C-4A9F-0000-A5F0-AAE09F4AD801
Status: '0xc000006d'
TranslatedStatus: '0xc000006d'
ClientAddressLength: 16
ClientAddress: 0200C33B0A0002860000000000000000
SessionId: '0x100000000061'
UserNameLength: 0
UserName: null
ClientNameLength: 12
ClientName: \\10.0.2.134
SPN: session setup failed before the SPN could be queried
SPNValidationPolicy: 0
ReasonCode: 3
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 552 — Smb2 Session Authentication Success
Message
Event ID 553 — Smb2 Session Bound to Connection
Message
Event ID 554 — Smb2 Session Terminated
Message
Event ID 555 — SMB2 Session Closed.
Message
Fields
| Name | Description |
|---|---|
SessionGUID | — |
InvalidateSession | — |
Reason | — |
Event ID 600 — Smb2 TreeConnect Allocated
Message
Event ID 601 — Smb2 TreeConnect Disconnected
Message
Event ID 602 — Smb2 TreeConnect Terminated
Message
Event ID 603 — Smb2 TreeConnect Failed due to Cluster Endpoint Initializing
Message
Event ID 604 — A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best p...
Message
Fields
| Name | Description |
|---|---|
SessionGUID | — |
TreeConnectGUID | — |
ShareNameLength | — |
ShareName | — |
Event ID 605 — A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best poss...
Message
Fields
| Name | Description |
|---|---|
SessionGUID | — |
TreeConnectGUID | — |
ShareNameLength | — |
ShareName | — |
Event ID 650 — Smb2 Open established
Message
Event ID 651 — Smb2 Open Disconnected - Preserved
Message
Event ID 652 — Smb2 Open Reconnected
Message
Event ID 653 — Smb2 Open Suspended - Preserved
Message
Event ID 654 — Smb2 Open Closed
Message
Event ID 655 — Smb2 Open Timed Out
Message
Event ID 656 — Smb2 Open Terminated
Message
Event ID 657 — Smb2 Open Clustered Client Failover Closed
Message
Event ID 658 — File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}.
Message
Fields
| Name | Description |
|---|---|
ShareName | — |
FileName | — |
UserName | — |
ComputerName | — |
Event ID 700 — Smb2 Share Added
Message
Event ID 701 — Smb2 Share Modified
Message
Event ID 702 — Smb2 Share Deleted
Message
Event ID 1000 — S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.
Message
Event ID 1001 — SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.
Message
Event ID 1002 — RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.
Message
Event ID 1003 — The server received an unencrypted message from client {ClientName}.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 1004 — The server received a incorrectly signed message from client {ClientName}.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 1005 — The server failed to validate negotiation from client {ClientName}.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 1006 — The share denied access to the client.
Message
Fields
| Name | Description |
|---|---|
ShareNameLength | — |
ShareName | — |
SharePathLength | — |
SharePath | — |
ClientAddressLength | — |
ClientAddress | — |
UserNameLength | — |
UserName | — |
ClientNameLength | — |
ClientName | — |
MappedAccess | — |
GrantedAccess | — |
ShareSecurityDescriptorLength | — |
ShareSecurityDescriptor | — |
Status | — |
TranslatedStatus | — |
SessionID | — |
Event ID 1007 — The share denied anonymous access to the client.
Message
Fields
| Name | Description |
|---|---|
ShareNameLength | — |
ShareName | — |
SharePathLength | — |
SharePath | — |
ClientAddressLength | — |
ClientAddress | — |
ClientNameLength | — |
ClientName | — |
Event ID 1009 — The server denied anonymous access to the client.
Message
Fields
| Name | Description |
|---|---|
ClientAddressLength | — |
ClientAddress | — |
ClientNameLength | — |
ClientName | — |
SessionId | — |
SessionGUID | — |
ConnectionGUID | — |
Event ID 1010 — Endpoint added.
Message
Fields
| Name | Description |
|---|---|
EventData.NameLength | — |
EventData.Name | — |
EventData.DomainNameLength | — |
EventData.DomainName | — |
EventData.TransportNameLength | — |
EventData.TransportName | — |
EventData.TransportFlags | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1010
version: 0
level: 4
task: 1010
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-06T06:25:52.476934+00:00'
event_record_id: 99
correlation: {}
execution:
process_id: 4
thread_id: 124
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
EventData:
NameLength: 16
Name: 'WINDEV2310EVAL '
DomainNameLength: 9
DomainName: WORKGROUP
TransportNameLength: 58
TransportName: \Device\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}
TransportFlags: '0x1'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1011 — Endpoint removed.
Message
Fields
| Name | Description |
|---|---|
EventData.NameLength | — |
EventData.Name | — |
EventData.DomainNameLength | — |
EventData.DomainName | — |
EventData.TransportNameLength | — |
EventData.TransportName | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1011
version: 0
level: 4
task: 1011
opcode: 0
keywords: 2305843009213693960
time_created: '2022-04-04T12:00:04.359257+00:00'
event_record_id: 18
correlation: {}
execution:
process_id: 4
thread_id: 196
channel: Microsoft-Windows-SMBServer/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
user_data:
EventData:
NameLength: 0
Name: null
DomainNameLength: 0
DomainName: null
TransportNameLength: 58
TransportName: \Device\NetBT_Tcpip_{64AAD862-869C-436D-A905-CCB55AA6A79F}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1012 — The network name information changed.
Message
Fields
| Name | Description |
|---|---|
ChangeType | — |
NetNameLength | — |
NetName | — |
Flags | — |
InterfaceIndex | — |
Capability | — |
LinkSpeed | — |
ClientAddressLength | — |
ClientAddress | — |
Event ID 1013 — Endpoint coming online.
Message
Fields
| Name | Description |
|---|---|
EndpointNameLength | — |
EndpointName | — |
TransportNameLength | — |
TransportName | — |
Event ID 1014 — Endpoint going offline.
Message
Fields
| Name | Description |
|---|---|
EndpointNameLength | — |
EndpointName | — |
TransportNameLength | — |
TransportName | — |
Event ID 1015 — Decrypt call failed.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
ClientAddressLength | — |
ClientAddress | — |
Status | — |
TranslatedStatus | — |
SessionID | — |
Event ID 1016 — Reopen failed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
TranslatedStatus | — |
RKFStatus | — |
TranslatedRKFStatus | — |
ConnectionGUID | — |
ClientNameLength | — |
ClientName | — |
ClientAddressLength | — |
ClientAddress | — |
ShareNameLength | — |
ShareName | — |
UserNameLength | — |
UserName | — |
SessionId | — |
FileNameLength | — |
FileName | — |
DurableHandle | — |
ResilientHandle | — |
PersistentHandle | — |
ResumeKey | — |
Reason | — |
Event ID 1017 — Handle scavenged.
Message
Fields
| Name | Description |
|---|---|
DurableHandle | — |
ResilientHandle | — |
PersistentFID | — |
VolatileFID | — |
ResumeKey | — |
ShareNameLength | — |
ShareName | — |
FileNameLength | — |
FileName | — |
Event ID 1018 — Backchannel invalidation of session completed.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Status | — |
TranslatedStatus | — |
TaskStatus | — |
TranslatedTaskStatus | — |
Event ID 1019 — Backchannel invalidation of file completed.
Message
Fields
| Name | Description |
|---|---|
ResumeKey | — |
Status | — |
TranslatedStatus | — |
TaskStatus | — |
TranslatedTaskStatus | — |
Event ID 1020 — File system operation has taken longer than expected.
Message
Fields
| Name | Description |
|---|---|
Command | — |
SessionGuid | — |
SessionId | — |
ConnectionGuid | — |
UserNameLength | — |
UserName | — |
ClientNameLength | — |
ClientName | — |
ClientAddressLength | — |
ClientAddress | — |
ShareNameLength | — |
ShareName | — |
FileNameLength | — |
FileName | — |
DurationInMilliseconds | — |
ThresholdInMilliseconds | — |
CtlCode | — |
SubCode | — |
TunneledControl | — |
Event ID 1021 — LmCompatibilityLevel value is different from the default.
Message
Fields
| Name | Description |
|---|---|
ConfiguredLmCompatibilityLevel | — |
DefaultLmCompatibilityLevel | — |
Event ID 1022 — File and printer sharing firewall rule enabled.
Message
Event ID 1023 — One or more shares present on this server have access based enumeration enabled.
Message
Event ID 1024 — SMB2 and SMB3 have been disabled on this server.
Message
Event ID 1025 — One or more named pipes or shares have been marked for access by anonymous users.
Message
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1025
version: 0
level: 3
task: 1025
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-06T06:25:44.207725+00:00'
event_record_id: 96
correlation: {}
execution:
process_id: 3912
thread_id: 3512
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
EventData: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1026 — File leasing has been disabled for the SMB2 and SMB3 protocols.
Message
Event ID 1027 — The file and printer sharing firewall ports are currently closed.
Message
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1027
version: 0
level: 4
task: 1027
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-05T22:32:38.630794+00:00'
event_record_id: 124
correlation: {}
execution:
process_id: 3368
thread_id: 3592
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
EventData: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1028 — The maximum cluster-supported SMB dialect has changed.
Message
Fields
| Name | Description |
|---|---|
NewDialect | — |
OldDialect | — |
Event ID 1029 — The Cipher Suite Order group policy setting is invalid.
Message
Fields
| Name | Description |
|---|---|
CipherSuiteOrder | — |
Event ID 1030 — An MDL read or write completion request failed.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ShareNameLength | — |
ShareName | — |
FileNameLength | — |
FileName | — |
IsRead | — |
Status | — |
Event ID 1031 — The server detected a problem and has captured a live kernel dump to collect debug information.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 1032 — The server detected a problem but was unable to capture a live kernel dump to collect debug information.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 1033 — Sent RDMA .
Fields
| Name | Description |
|---|---|
NotificationType | — |
InterfaceNameLength | — |
InterfaceName | — |
Event ID 1033 — Sent RDMA %1 event to LanmanServer for interface %3.
Message
Fields
| Name | Description |
|---|---|
EventData.NotificationType | — |
EventData.InterfaceNameLength | — |
EventData.InterfaceName | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1033
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213694464
time_created: '2023-10-26T04:17:52.198363+00:00'
event_record_id: 18
correlation: {}
execution:
process_id: 4
thread_id: 436
channel: Microsoft-Windows-SMBServer/Operational
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
user_data:
EventData:
NotificationType: 0
InterfaceNameLength: 34
InterfaceName: \Device\RdmaSmbIpv4_169.254.253.61
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1034 — Send RDMA Endpoint notification failure - .
Fields
| Name | Description |
|---|---|
FailureType | — |
InterfaceIndex | — |
Error | — |
DeviceNameLength | — |
DeviceName | — |
ExtraInformation | — |
Event ID 1034 — Send RDMA Endpoint notification failure - %1.
Message
Fields
| Name | Description |
|---|---|
EventData.FailureType | — |
EventData.InterfaceIndex | — |
EventData.Error | — |
EventData.DeviceNameLength | — |
EventData.DeviceName | — |
EventData.ExtraInformation | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1034
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213694464
time_created: '2023-10-26T04:17:52.198365+00:00'
event_record_id: 19
correlation: {}
execution:
process_id: 4
thread_id: 436
channel: Microsoft-Windows-SMBServer/Operational
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
user_data:
EventData:
FailureType: 6
InterfaceIndex: 0
Error: '0xc0000034'
DeviceNameLength: 34
DeviceName: \Device\RdmaSmbIpv4_169.254.253.61
ExtraInformation: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1035 — RDMA Endpoint %4 for interface %2 was %1.
Message
Fields
| Name | Description |
|---|---|
EndpointState | — |
InterfaceIndex | — |
TransportNameLength | — |
TransportName | — |
Event ID 1035 — RDMA Endpoint .
Fields
| Name | Description |
|---|---|
EndpointState | — |
InterfaceIndex | — |
TransportNameLength | — |
TransportName | — |
Event ID 1036 — RDMA Endpoint allocation failure - Endpoint allocation failed for interface .
Fields
| Name | Description |
|---|---|
InterfaceIndex | — |
Error | — |
Event ID 1036 — RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceIndex | — |
Error | — |
Event ID 1037 — RDMA listener creation failure - .
Fields
| Name | Description |
|---|---|
FailureType | — |
InterfaceIndex | — |
Error | — |
Event ID 1037 — RDMA listener creation failure - %1.
Message
Fields
| Name | Description |
|---|---|
FailureType | — |
InterfaceIndex | — |
Error | — |
Event ID 1038 — RDMA Send endpoint notification RPC failure for device .
Fields
| Name | Description |
|---|---|
FailureType | — |
DeviceNameLength | — |
DeviceName | — |
Error | — |
Event ID 1038 — RDMA Send endpoint notification RPC failure for device %3 - %1.
Message
Fields
| Name | Description |
|---|---|
EventData.FailureType | — |
EventData.DeviceNameLength | — |
EventData.DeviceName | — |
EventData.Error | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1038
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213694464
time_created: '2023-11-06T06:25:49.867686+00:00'
event_record_id: 98
correlation: {}
execution:
process_id: 4
thread_id: 428
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
EventData:
FailureType: 3
DeviceNameLength: 58
DeviceName: \Device\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}
Error: '0x102'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1039 — Received Nsi notification type .
Fields
| Name | Description |
|---|---|
NotificationType | — |
InterfaceIndex | — |
NdkOperationalState | — |
Event ID 1039 — Received Nsi notification type %1 for interface %2 with NdkOperationalState %3.
Message
Fields
| Name | Description |
|---|---|
NotificationType | — |
InterfaceIndex | — |
NdkOperationalState | — |
Event ID 1040 — Received Mib notification type .
Fields
| Name | Description |
|---|---|
NotificationType | — |
InterfaceIndex | — |
Event ID 1040 — Received Mib notification type %1 for interface %2.
Message
Fields
| Name | Description |
|---|---|
EventData.NotificationType | — |
EventData.InterfaceIndex | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1040
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213694464
time_created: '2023-11-05T22:32:37.991590+00:00'
event_record_id: 123
correlation: {}
execution:
process_id: 4
thread_id: 136
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
EventData:
NotificationType: 3
InterfaceIndex: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1041 — Error reading FSCTL properties information from the registry.
Message
Fields
| Name | Description |
|---|---|
FailureType | — |
RegistryValueNameLength | — |
RegistryValueName | — |
Event ID 1042 — The certificate for the server is about to expire.
Message
Fields
| Name | Description |
|---|---|
CertSubjectNameLength | — |
CertSubjectName | — |
CertThumbprintLength | — |
CertThumbprint | — |
Expiring | — |
Event ID 1043 — RDMA connection disconnected.
Message
Fields
| Name | Description |
|---|---|
CloseOperationDurationInMillieconds | — |
TransportNameLength | — |
TransportName | — |
EndpointShutdown | — |
EndpointRemoved | — |
Event ID 1044 — Quic connection shutdown.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Reason | — |
EndpointNameLength | — |
EndpointName | — |
TransportNameLength | — |
TransportName | — |
Event ID 1045 — The server failed to update server certificate mapping.
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
SubjectLength | — |
Subject | — |
ThumbPrintLength | — |
ThumbPrint | — |
Status | — |
RemovedLength | — |
Removed | — |
Event ID 1045 — The server failed to update server certificate mapping.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
SubjectLength | — |
Subject | — |
ThumbPrintLength | — |
ThumbPrint | — |
Status | — |
RemovedLength | — |
Removed | — |
Event ID 1046 — The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server...
Message
Fields
| Name | Description |
|---|---|
ShareNameLength | — |
ShareName | — |
ClientNameLength | — |
ClientName | — |
UserNameLength | — |
UserName | — |
ClientAddressLength | — |
ClientAddress | — |
SessionID | — |
Smb2Command | — |
Event ID 1047 — The server received a %2 request but is taking an abnormal amount of time to process it.
Message
Fields
| Name | Description |
|---|---|
InstanceId | — |
Smb2Command | — |
Smb2PerfBlock | — |
Duration | — |
Threshold | — |
Event ID 1048 — The server processed a %1 request.
Message
Fields
| Name | Description |
|---|---|
Smb2Command | — |
AcquireLockTime | — |
IoTime | — |
TotalTime | — |
Threshold | — |
Event ID 1049 — The certificate for the server has expired.
Message
Fields
| Name | Description |
|---|---|
CertSubjectNameLength | — |
CertSubjectName | — |
CertThumbprintLength | — |
CertThumbprint | — |
Expiring | — |
Event ID 1050 — Found %1 endpoint(s) related to interface ID %2, closed %3 of which.
Message
Fields
| Name | Description |
|---|---|
InterfaceID | — |
NumberOfEndpointsFound | — |
NumberOfEndpointsClosed | — |
Event ID 1051 — The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server.
Message
Fields
| Name | Description |
|---|---|
ClientCipherSuiteOrderLength | — |
ClientCipherSuiteOrder | — |
ServerCipherSuiteOrderLength | — |
ServerCipherSuiteOrder | — |
ClientCipherCount | — |
LoggedClientCipherCount | — |
ClientCipherOrder | — |
Event ID 1052 — Failed to restore a server certificate mapping from persistent storage.
Message
Fields
| Name | Description |
|---|---|
SubjectLength | — |
Subject | — |
ThumbprintLength | — |
Thumbprint | — |
Status | — |
Event ID 1053 — Restored %2 of %1 server certificate mappings from persistent storage.
Message
Fields
| Name | Description |
|---|---|
CountOfCertsTotal | — |
CountOfCertsRestored | — |
Status | — |
Event ID 1054 — Network operation has taken longer than expected.
Message
Fields
| Name | Description |
|---|---|
Command | — |
SessionGuid | — |
SessionId | — |
ConnectionGuid | — |
UserNameLength | — |
UserName | — |
ClientNameLength | — |
ClientName | — |
ClientAddressLength | — |
ClientAddress | — |
ShareNameLength | — |
ShareName | — |
FileNameLength | — |
FileName | — |
DurationInMilliseconds | — |
ThresholdInMilliseconds | — |
CtlCode | — |
SubCode | — |
TunneledControl | — |
Event ID 1055 — RDMA rundown is active.
Message
Fields
| Name | Description |
|---|---|
ActiveRdmaResourceCount | — |
Event ID 1056 — RDMA rundown is complete.
Message
Fields
| Name | Description |
|---|---|
NoOp | — |
Event ID 1057 — Reactivation of RDMA support has commenced.
Message
Event ID 1058 — RDMA is no longer disabled.
Message
Fields
| Name | Description |
|---|---|
NoOp | — |
Event ID 1059 — SMBDirect load attempt complete.
Message
Fields
| Name | Description |
|---|---|
IsSuccess | — |
LoadStatus | — |
ServicePathLength | — |
ServicePath | — |
DeviceNameLength | — |
DeviceName | — |
Event ID 1060 — SMB DDP security changed from %1 to %2.
Message
Fields
| Name | Description |
|---|---|
OldValue | — |
NewValue | — |
Event ID 1061 — SMB2 Request Negotiate Dialect Failure Session ID: %1 Client Address: %18 Client Name:%20 Client Dialects: %12 Minimum dialect required by server: ...
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
ProcessId | — |
TreeId | — |
MessageId | — |
MasterMessageId | — |
Command | — |
CreditsRequested | — |
Flags | — |
SecurityMode | — |
Capabilities | — |
DialectCount | — |
Dialects | — |
ClientGuid | — |
ConnectionGUID | — |
MinSmb2Dialect | — |
MaxSmb2Dialect | — |
ClientAddressLength | — |
ClientAddress | — |
ClientNameLength | — |
ClientName | — |
Event ID 1062 — SMB Dialect Change %1 was changed from %2 to %3.
Message
Fields
| Name | Description |
|---|---|
SmbDialect | — |
OldDialect | — |
NewDialect | — |
Event ID 1080 — Component capabilities: %1 Internal patch number: %2.
Message
Fields
| Name | Description |
|---|---|
SrvNetComponentCapabilities | — |
PatchNumber | — |
Event ID 1800 — CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.
Message
Event ID 1801 — CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.
Message
Event ID 1802 — The server failed to reserve the next ID region in the cluster registry.
Message
Event ID 1803 — The security descriptor differs from the default value.
Message
Fields
| Name | Description |
|---|---|
DescriptorName | — |
Event ID 1804 — No SMB1 usage detected in the last 20 minutes.
Message
Fields
| Name | Description |
|---|---|
Days | — |
Event ID 1900 — TDI mode enabled: .
Fields
| Name | Description |
|---|---|
IsTdiEnabled | — |
Event ID 1900 — TDI mode enabled.
Message
Fields
| Name | Description |
|---|---|
IsTdiEnabled | — |
Example Event
system:
provider: Microsoft-Windows-SMBServer
guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
event_source_name: ''
event_id: 1900
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213694464
time_created: '2023-11-06T06:25:43.357313+00:00'
event_record_id: 95
correlation: {}
execution:
process_id: 4
thread_id: 224
channel: Microsoft-Windows-SMBServer/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsTdiEnabled: true
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1901 — Failed to allocate an NSI table for network interface enumeration: .
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1901 — Failed to allocate an NSI table for network interface enumeration.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1902 — Received notification of a newly-started network interface with Luid .
Fields
| Name | Description |
|---|---|
AddressFamily | — |
NetLuid | — |
Event ID 1902 — Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23).
Message
Fields
| Name | Description |
|---|---|
AddressFamily | — |
NetLuid | — |
Event ID 1903 — Received notification of a stopped network interface with Luid .
Fields
| Name | Description |
|---|---|
AddressFamily | — |
NetLuid | — |
Event ID 1903 — Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23).
Message
Fields
| Name | Description |
|---|---|
AddressFamily | — |
NetLuid | — |
Event ID 1904 — Failed to open network interface with Luid .
Fields
| Name | Description |
|---|---|
NetLuid | — |
Status | — |
Event ID 1904 — Failed to open network interface with Luid %1: error %2.
Message
Fields
| Name | Description |
|---|---|
NetLuid | — |
Status | — |
Event ID 1905 — The server closed the session as part of periodic system cleanup.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
InstanceId | — |
Reason | — |
Event ID 1906 — Session key for connection is weaker than required.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
SessionKeyLength | — |
RequiredSessionKeyLength | — |
SessionId | — |
UserName | — |
AuthProtocol | — |
Event ID 1907 — Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.
Message
Event ID 1908 — Custom FSCTL allow list was not successfully loaded after several retries.
Message
Event ID 1909 — Send QUIC Endpoint notification failure - .
Fields
| Name | Description |
|---|---|
FailureType | — |
InterfaceIndex | — |
Error | — |
DeviceNameLength | — |
DeviceName | — |
ExtraInformation | — |
Event ID 1909 — Send QUIC Endpoint notification failure - %1.
Message
Fields
| Name | Description |
|---|---|
FailureType | — |
InterfaceIndex | — |
Error | — |
DeviceNameLength | — |
DeviceName | — |
ExtraInformation | — |
Event ID 1910 — RDMA listen socket disable override is %1.
Message
Fields
| Name | Description |
|---|---|
CurrentDisableOverrideState | — |
NewState | — |
SrvNetEnableRdmaSupport | — |
SrvNetEvaluateRdmaEnabledPolicy | — |
SrvNetIsSMBDirectSupported | — |
ActionTaken | — |
Event ID 1911 — Server Certificate failure - %1.
Message
Fields
| Name | Description |
|---|---|
FailureType | — |
Error | — |
MappingNameLength | — |
MappingName | — |
ThumprintLength | — |
Thumbprint | — |
Event ID 1912 — Warning to set the QoS policy on file %6.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ServerNameLength | — |
ServerName | — |
ShareNameLength | — |
ShareName | — |
FileNameLength | — |
FileName | — |
Event ID 1913 — The SMB connection was successfully established.
Message
Fields
| Name | Description |
|---|---|
EndpointNameLength | — |
EndpointName | — |
ConnectionType | — |
ServerSocketAddressLength | — |
ServerSocketAddress | — |
ClientSocketAddressLength | — |
ClientSocketAddress | — |
ConnectionIdSize | — |
ConnectionId | — |
MutualAuthentication | — |
AccessControlCheck | — |
Event ID 1914 — The server was unable to perform revocation checks on the client certificate chain.
Message
Fields
| Name | Description |
|---|---|
Status | — |
EndpointNameLength | — |
EndpointName | — |
ConnectionType | — |
TransportNameLength | — |
TransportName | — |
ClientSocketAddressLength | — |
ClientSocketAddress | — |
Event ID 2000 — Packet Fragment ({FragmentSize} bytes).
Message
Fields
| Name | Description |
|---|---|
FragmentSize | — |
Event ID 3000 — SMB1 access Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 3002 — A remote device attempted SMB1 connection to this computer.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 3003 — SMB1 server service has been automatically uninstalled.
Message
Fields
| Name | Description |
|---|---|
Days | — |
Event ID 3004 — SMB server admin file rundown
Message
Fields
| Name | Description |
|---|---|
FileId | — |
FileNameLength | — |
FileName | — |
SessionId | — |
ShareId | — |
Event ID 3005 — SMB server admin session rundown
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
ComputerNameLength | — |
ComputerName | — |
UserNameLength | — |
UserName | — |
DomainNameLength | — |
DomainName | — |
DomainAndUserNameLength | — |
DomainAndUserName | — |
ClientOsLength | — |
ClientOs | — |
TransportNameLength | — |
TransportName | — |
ServerNameLength | — |
ServerName | — |
StartTime | — |
LastActiveTime | — |
Event ID 3006 — SMB server admin share rundown
Message
Fields
| Name | Description |
|---|---|
ShareId | — |
ShareNameLength | — |
ShareName | — |
Event ID 3007 — Access Denied Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny en...
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ClientSocketAddressLength | — |
ClientSocketAddress | — |
SupportedHashAlgsStrLength | — |
SupportedHashAlgsStr | — |
CertChainPropertiesStrLength | — |
CertChainPropertiesStr | — |
DenySidsStrLength | — |
DenySidsStr | — |
AllowSidsStrLength | — |
AllowSidsStr | — |
ConnectionIdSize | — |
ConnectionId | — |
Event ID 3008 — Access Allowed Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny e...
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ClientSocketAddressLength | — |
ClientSocketAddress | — |
SupportedHashAlgsStrLength | — |
SupportedHashAlgsStr | — |
CertChainPropertiesStrLength | — |
CertChainPropertiesStr | — |
DenySidsStrLength | — |
DenySidsStr | — |
AllowSidsStrLength | — |
AllowSidsStr | — |
ConnectionIdSize | — |
ConnectionId | — |
Event ID 3009 — An error occurred while checking client certificate chain access during mutual authentication.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ServerNameLength | — |
ServerName | — |
ClientSocketAddressLength | — |
ClientSocketAddress | — |
ConnectionIdSize | — |
ConnectionId | — |
Event ID 3010 — An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0?
Message
Fields
| Name | Description |
|---|---|
Port | — |
Event ID 3011 — The SMB server service created an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: ...
Message
Fields
| Name | Description |
|---|---|
TransportNameLength | — |
TransportName | — |
Port | — |
TransportType | — |
SrvInstances | — |
Status | — |
Event ID 3012 — The SMB server service failed to create an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvIn...
Message
Fields
| Name | Description |
|---|---|
TransportNameLength | — |
TransportName | — |
Port | — |
TransportType | — |
SrvInstances | — |
Status | — |
Event ID 3013 — An administrator created an alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can ...
Message
Fields
| Name | Description |
|---|---|
Port | — |
TransportType | — |
SrvInstances | — |
Event ID 3014 — An administrator updated an existing alterative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clie...
Message
Fields
| Name | Description |
|---|---|
Port | — |
TransportType | — |
SrvInstances | — |
Event ID 3015 — An administrator removed an existing alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: This wi...
Message
Fields
| Name | Description |
|---|---|
Port | — |
TransportType | — |
SrvInstances | — |
Event ID 3016 — The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.
Message
Fields
| Name | Description |
|---|---|
Interface | — |
Status | — |
Event ID 3017 — The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.
Message
Fields
| Name | Description |
|---|---|
Interface | — |
Status | — |
Event ID 3018 — The inbound %2 firewall rule already exists for port %1.
Message
Fields
| Name | Description |
|---|---|
Port | — |
ProtocolType | — |
Event ID 3019 — The inbound %2 firewall rule failed to be created for port %1.
Message
Fields
| Name | Description |
|---|---|
Port | — |
ProtocolType | — |
Event ID 3020 — The inbound %2 firewall rule was successfully created for port %1.
Message
Fields
| Name | Description |
|---|---|
Port | — |
ProtocolType | — |
Event ID 3021 — The SMB server observed that the client doesn't support signing.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
UserNameLength | — |
UserName | — |
ServerRequiresSigning | — |
Event ID 3022 — The SMB server observed that the client doesn't support encryption.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
ServerRequiresEncryption | — |
SmbClientDoesNotSupportEncryptionType | — |
Event ID 3023 — The SMB client was logged on as Guest account.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
Event ID 3024 —
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
Status | — |
SPNValidationPolicy | — |
Event ID 3024 — The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection ...
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
Status | — |
SPNValidationPolicy | — |
Event ID 3025 —
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
SPN | — |
ServiceClassIsValid | — |
PrincipalNameIsValid | — |
SPNValidationPolicy | — |
Event ID 3025 — The SMB server observed that the client sent an unrecognized SPN during authentication.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
SPN | — |
ServiceClassIsValid | — |
PrincipalNameIsValid | — |
SPNValidationPolicy | — |
Event ID 3026 —
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
SPNValidationPolicy | — |
Event ID 3026 — The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but electe...
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
SPNValidationPolicy | — |
Event ID 3027 —
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
ServerRequiresSigning | — |
Event ID 3027 — The SMBv1 server observed that the SMBv1 client does not have signing enabled.
Message
Fields
| Name | Description |
|---|---|
ClientNameLength | — |
ClientName | — |
ServerRequiresSigning | — |
Event ID 4000 —
Fields
| Name | Description |
|---|---|
ShareNameLength | — |
ShareName | — |
ClientAddressLength | — |
ClientAddress | — |
ClientNameLength | — |
ClientName | — |
SessionId | — |
TreeId | — |
ConnectionType | — |
SigningUsed | — |
EncyptionUsed | — |
CompressionUsed | — |
Sigma Rules
- Unsigned or Unencrypted SMB Connection to Share Established
Detects SMB server connections to shares without signing or encryption enabled. This could indicate potential lateral movement activity using unsecured SMB shares.
Event ID 4000 — The SMB client connection to the share was established.
Message
Fields
| Name | Description |
|---|---|
ShareNameLength | — |
ShareName | — |
ClientAddressLength | — |
ClientAddress | — |
ClientNameLength | — |
ClientName | — |
SessionId | — |
TreeId | — |
ConnectionType | — |
SigningUsed | — |
EncyptionUsed | — |
CompressionUsed | — |
Event ID 40000 — Packet ({PacketSize} bytes).
Message
Fields
| Name | Description |
|---|---|
PacketSize | — |