Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/smtimesiwndr/gdid-reversal
Reverse EngineeringForensicsPrivacyLearning & Education
GitHubsmtimesiwndr/gdid-reversal

gdid-reversal

Reverse-engineered analysis of Microsoft's Global Device Identifier (GDID) revealing its generation as a server-assigned MSA Device PUID, storage in registry, and transmission via Connected Devices Platform, with reproducible forensic methodology.

View Repository
70642192 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Full writeup of the Windows GDID

Global Device Identifier fully reverse engineered

Primary source Platform Symbols Method Claims

How Microsoft's "Global Device Identifier", the persistent Windows fingerprint named in the July 2026 Scattered Spider complaint, is actually generated, stored, and transmitted.


TL;DR

[!NOTE] Listed below is true, but missing some information. Regardless of being logged in with a MSA you WILL have a GDID. I didn't realize this at the time of posting but I looked into it. CDP has an anonymous device path that is used if no MSA has been connected. The underlying system is still factually correct just missing a few things.

  • GDID is a real telemetry item. It shows up in the U.S. federal criminal complaint (United States v. Peter Stokes, N.D. Ill., July 2026) as Global Device Identifier g:6755467234350028.
  • It is a Microsoft Account "Device PUID". A 64 bit Passport Unique ID assigned to a Windows installation when it registers with a Microsoft Account, written in the device graph as g:<decimal>.
  • The claims are wrong. It is not "128 bit" and not "generated from serial numbers." The court record itself says a reinstall produces a new GDID, which rules out it being derived from hardware serials like your GPU.
  • The stack, bottom to top: wlidsvc (Microsoft Account service) provisions the device with login.live.com and gets back a device PUID -> stores it in the registry -> the Connected Devices Platform (cdp.dll / CDPSvc) reads it and registers it into the Device Directory Service (DDS) graph -> Delivery Optimization reports it as the documented UCDOStatus.GlobalDeviceId.
  • All of it was reproduced on a live Windows 11 (26200) machine with public symbols. You can find your own GDID in one registry read (§7).

[!NOTE] Confidence labelling. Every claim is tagged so you can weigh each one yourself: [COURT] primary source fact, [OBSERVED] reproduced live on my test machine, [STATIC] proven from binaries and public Windows PDBs, [ASSESSED] strong inference from the evidence.


Contents

  1. Background: what the court actually said
  2. Debunking the viral myths
  3. Where GDID surfaces: Delivery Optimization
  4. Who owns it: Connected Devices Platform to DDS
  5. How CDP gets it: it consumes, it does not compute
  6. The mint: MSA Device PUID (wlidsvc)
  7. Find your own GDID
  8. Reducing the exposure
  9. Methodology (reproducible)
  10. Limitations and honest caveats

1. Background: what the court actually said

On July 1, 2026 the DOJ unsealed a criminal complaint against Peter Stokes, an alleged member of Scattered Spider (a.k.a. Octo Tempest / UNC3944 / 0ktapus). The affidavit describes how Microsoft helped the FBI attribute activity to a device.

[!IMPORTANT] [COURT] From the superseding complaint (¶25, p.34), verbatim:

"the ngrok account was set up through Global Device Identifier g:6755467234350028 ('the GDID'). According to a Microsoft representative, a Global Device Identifier in the Windows ecosystem is a persistent, device level identifier designed to uniquely identify an installation of a Windows operating system on a device... A GDID is a globally unique identifier tied to the installation of Windows on a device. A GDID remains consistent across Windows operating system updates on a device, but a reinstall of Windows... will be tied to a new unique GDID."

A footnote adds that one Microsoft user can have multiple GDIDs. The affidavit then correlates the GDID's IP history and browsing (e.g. empirehotelnyc.com, a Growtopia/Ubisoft login URL) with the accounts the suspect was logged into.

Two things here carry the rest of this writeup:

  1. The value is g: plus a decimal integer (g:6755467234350028). In hex that is 0x0018000FC8CB93CC, so a 64 bit number.
  2. A reinstall gives a new GDID. So it can't just be a function of unchanging hardware.

2. Debunking the viral narrative

The social media summary claimed the GDID is "a 128 bit identifier generated from serial numbers on install." Both halves are false:

Claim (social media)Reality (primary source)
"128 bit"The value in the complaint is g:6755467234350028, a decimal that fits in 64 bits (0x0018000FC8CB93CC).
"generated from serial numbers on install"The complaint says a reinstall produces a new GDID. A value derived from fixed serials would come back the same after a reinstall, not change.

[!NOTE] After some more reversing of CDP. I provided some misinfo. Using a local account does not prevent a GDID. CDP has an anonymous device path that is taken if no microsoft account. Keep this in mind when reading.


3. Where GDID surfaces: Delivery Optimization

[STATIC] Microsoft's public Azure Monitor docs define a GlobalDeviceId column in the UCDOStatus (Update Compliance / Delivery Optimization) table:

GlobalDeviceId (string): "Microsoft global device identifier. This is an identifier used by Microsoft internally."

It sits right next to LastCensusSeenTime, ISP, City, Country, so a device id lined up with geo and IP. This is the one place Microsoft names the value in public docs. But Delivery Optimization only reports it. Importantly it does NOT own it. Follow it upstream and you land on the Connected Devices Platform.


4. Who owns it: the Connected Devices Platform to DDS

[STATIC] C:\Windows\System32\cdp.dll (the Connected Devices Platform, services CDPSvc + CDPUserSvc) contains the GlobalDeviceId symbol and an entire Device Directory Service registration subsystem:

ddsregistrationclient.cpp   ddsregistrationmanager.cpp   ddsregistrationinfo.cpp
DdsRegistrationClient   RegisterUserDevicesObserver   DdsRegistrationInfoProviderForCDP
endpoints: dds.microsoft.com  fd.dds.microsoft.com  aad.cs.dds.microsoft.com  cdpcs.access.microsoft.com
device-id format string: "g:%s"

DDS = Device Directory Service, Microsoft's cross device identity graph (the backend behind Phone Link, cloud clipboard, "Continue on PC", Nearby Share). CDP is the Windows client that registers the installation into that graph, where it gets keyed as g:<decimal>.

4.1 Captured live

[OBSERVED] Forcing a fresh registration (restart CDPSvc with its local state cleared) and capturing CDP's own ETW providers produced the whole handshake:

DdsClient::RegisterUserDeviceAsync()   RegistrationReason: Startup   Account Type: MSA
DDSClient: Registration response received. HTTP status code: 200
OnRegisterUserDeviceComplete
GetDeviceIdAndTicketActivity -> deviceid: 0018XXXXXXXXXXXX

That deviceid, written as g:<decimal>, matches the complaint's value structurally:

valuehex (64 bit)class prefix
My machine (redacted)g:XXXXXXXXXXXXXXXX0x0018XXXXXXXXXXXX0018
Court exhibitg:67554672343500280x0018000FC8CB93CC0018
Download Tool