Microsoft-Windows-ZTDNS
8 events across 3 channels
| Event ID | Title | Channel |
|---|---|---|
| 1 | PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by … | PermittedConnections |
| 2 | BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by … | BlockedConnections |
| 3 | UPDATE - Trusted servers by process (ProcessId) ProcessPath. | Operational |
| 4 | REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath. | Operational |
| 5 | ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath. | Operational |
| 6 | UPDATE - State to ServiceState by process (ProcessId) ProcessPath. | Operational |
| 7 | START - ZTDNS service with status Status. | Operational |
| 8 | STOP - ZTDNS service with status Status. | Operational |
Event ID 1 — PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
Description
PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
LocalPort UInt32 | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
RemotePort UInt32 | — |
Protocol UInt32 | — Known values
|
ProcessId UInt64 | — |
ProcessPath UnicodeString | — |
PermitType UInt32 | — |
PermitInfo UnicodeString | — |
ServiceName UnicodeString | — |
Event ID 2 — BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
Description
BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
LocalPort UInt32 | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
RemotePort UInt32 | — |
Protocol UInt32 | — Known values
|
ProcessId UInt64 | — |
ProcessPath UnicodeString | — |
ServiceName UnicodeString | — |
Event ID 3 — UPDATE - Trusted servers by process (ProcessId) ProcessPath.
Event ID 4 — REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
Event ID 5 — ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
Event ID 6 — UPDATE - State to ServiceState by process (ProcessId) ProcessPath.
Event ID 7 — START - ZTDNS service with status Status.
Description
START - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 8 — STOP - ZTDNS service with status Status.
Description
STOP - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |