Microsoft-Windows-ZTDNS
8 events across 3 channels
Event ID 1: PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
#Description
PERMIT - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath because of PermitType PermitInfo from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
LocalPort UInt32 | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt32 | |
Protocol UInt32 | Known values
|
ProcessId UInt64 | |
ProcessPath UnicodeString | |
PermitType UInt32 | |
PermitInfo UnicodeString | |
ServiceName UnicodeString |
Event ID 2: BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
#Description
BLOCK - Connection [LocalAddress]:LocalPort -> [RemoteAddress]:RemotePort by process (ProcessId) ProcessPath from service ServiceName.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
LocalPort UInt32 | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt32 | |
Protocol UInt32 | Known values
|
ProcessId UInt64 | |
ProcessPath UnicodeString | |
ServiceName UnicodeString |
Event ID 3: UPDATE - Trusted servers by process (ProcessId) ProcessPath.
#Event ID 4: REMOVE - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
#Event ID 5: ADD - ExceptionsUpdateTypeExceptionName by process (ProcessId) ProcessPath.
#Event ID 6: UPDATE - State to ServiceState by process (ProcessId) ProcessPath.
#Event ID 7: START - ZTDNS service with status Status.
#Description
START - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 8: STOP - ZTDNS service with status Status.
#Description
STOP - ZTDNS service with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 8507cd07-f18b-54f0-b871-23c43a5bf118
Defined in ztdns.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.5074 · captured 2026-06-02