Microsoft-Windows-Winsock-Sockets

16 events across 1 channel

EventTitleChannel
1SockCreateStartOperational
2SockCreateStopOperational
3SockCloseOperational
4SockCloseOperational
5SockAcceptStartOperational
6SockAcceptStopOperational
7SockSetOptStartOperational
8SockSetOptStopOperational
9SockConnectStartOperational
10SockConnectStopOperational
11SockBindStartOperational
12SockBindStopOperational
13SockGetOptStartOperational
14SockGetOptStopOperational
15SockListenStartOperational
16SockListenStopOperational

Event ID 1: SockCreateStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockCreate
Opcode
Start

Event ID 2: SockCreateStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockCreate
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressFamily UInt32
SocketType UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ProcessId UInt32
FailurePoint HexInt32

Event ID 3: SockClose

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Level
Verbose
Task
SockClose
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsock-Sockets",
    "guid": "{BDE46AEA-2357-51FE-7367-D5296F530BD1}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 5,
    "task": 1001,
    "opcode": 1,
    "keywords": "0x0000000000001001",
    "time_created": "2026-06-02T04:01:52.944+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
    },
    "execution": {
      "process_id": 11772,
      "thread_id": 13132
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "SockClose"
}

Event ID 4: SockClose

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
SockClose
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
IsProviderSocket Boolean
FailurePoint HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsock-Sockets",
    "guid": "{BDE46AEA-2357-51FE-7367-D5296F530BD1}",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 1001,
    "opcode": 2,
    "keywords": "0x0000000000001001",
    "time_created": "2026-06-02T04:01:52.944+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
    },
    "execution": {
      "process_id": 11772,
      "thread_id": 13132
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ErrorCode": "00000000",
    "FailurePoint": "00000000",
    "IsProviderSocket": true,
    "Socket": "0x6DC"
  },
  "message": "SockClose"
}

Event ID 5: SockAcceptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockAccept
Opcode
Start

Event ID 6: SockAcceptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockAccept
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
SocketAccepted Pointer
SocketListening Pointer
ProcessId UInt32
FailurePoint HexInt32

Event ID 7: SockSetOptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockSetOpt
Opcode
Start

Event ID 8: SockSetOptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockSetOpt
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Level Int32
OptName Int32
OptLen UInt32
OptVal Binary
FailurePoint HexInt32

Event ID 9: SockConnectStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockConnect
Opcode
Start

Event ID 10: SockConnectStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockConnect
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressLength UInt32
Address Binary
FailurePoint HexInt32

Event ID 11: SockBindStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockBind
Opcode
Start

Event ID 12: SockBindStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockBind
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
AddressLength UInt32
Address Binary
FailurePoint HexInt32

Event ID 13: SockGetOptStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockGetOpt
Opcode
Start

Event ID 14: SockGetOptStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockGetOpt
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Level Int32
OptName Int32
OptLen UInt32
OptVal Binary
FailurePoint HexInt32

Event ID 15: SockListenStart

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockListen
Opcode
Start

Event ID 16: SockListenStop

#
Provider
Microsoft-Windows-Winsock-Sockets
Channel
Operational
Task
SockListen
Opcode
Stop

Fields #

NameDescription
ErrorCode HexInt32
Socket Pointer
Backlog Int32
FailurePoint HexInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {BDE46AEA-2357-51FE-7367-D5296F530BD1}

Defined in ws2_32.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893 · sample captured from a live trace · binary version 10.0.20348.2849 · captured 2026-06-02
  • WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.2849 · captured 2026-06-02
  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.1 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests