Microsoft-Antimalware-Engine

109 events across 1 channel

Event IDTitleChannel
1Start of engine scan requestApplication
2End of engine scan requestApplication
3Application
4Application
5Start of stream scan requestApplication
6End of stream scan requestApplication
7Skipped fileApplication
8Application
9Application
10Application
11Application
12Application
13Application
14Application
15Application
16Application
17Application
18Application
19Application
20Application
21Application
22Application
23Application
24Application
25Application
26Application
27Application
28Application
29Application
30Application
31Application
32Application
33Application
35Application
36Application
37Application
38Application
39Application
40Application
41Application
42Application
43Application
44Application
45Application
46Application
47Application
48Application
49Application
50Application
51Application
52Application
53Application
58Application
59Application
60Application
61Application
62Application
63Application
64Application
65Application
66Application
67Application
68Application
69Application
70Application
71Application
72Application
73Application
74Application
75Application
76Application
77Application
78Application
79Application
80Application
81Application
82Application
83Application
84Application
85Application
86Application
87Application
88Application
89Application
90Application
91Application
92Application
93Application
94Application
95Application
96Application
97Application
98Application
99Application
100Application
101Application
102Application
103Application
104Application
105Application
106Application
107Application
108Application
109Application
110Application
111Application
112Application
113Application
114Application

Event ID 1 — Start of engine scan request

Provider
Microsoft-Antimalware-Engine
Channel
Application

Message

Start of engine scan request

Fields

NameDescription
EngineId
Id
Type
Flags
ScanSource
ResourceCount
FirstResourceType
FirstResourcePath
ThreadTime

Event ID 2 — End of engine scan request

Provider
Microsoft-Antimalware-Engine
Channel
Application

Message

End of engine scan request

Fields

NameDescription
EngineId
Id
Type
Flags
ScanSource
ResourceCount
FirstResourceType
FirstResourcePath
ThreadTime
StartQPC

Event ID 3 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Message

Event ID 4 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineVersion
AVVersion
ASVersion

Event ID 5 — Start of stream scan request

Provider
Microsoft-Antimalware-Engine
Channel
Application

Message

Start of stream scan request

Fields

NameDescription
Id
Path
Process
Reason
ThreadTime
PID

Event ID 6 — End of stream scan request

Provider
Microsoft-Antimalware-Engine
Channel
Application

Message

End of stream scan request

Fields

NameDescription
Id
Path
Process
Reason
ThreadTime
PID

Event ID 7 — Skipped file

Provider
Microsoft-Antimalware-Engine
Channel
Application

Message

Skipped file

Fields

NameDescription
Path
Reason

Event ID 8 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
GUID
Type
Name
SignatureId
ImagePath

Event ID 9 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
PPID
ImagePath
Flags

Event ID 10 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
ImagePath

Event ID 11 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
ImagePath

Event ID 12 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
ImageName
FileName

Event ID 13 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 14 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 15 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 16 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName
OldFileName

Event ID 17 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 18 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 19 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 20 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath
ValueName

Event ID 21 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath
ValueName

Event ID 22 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID

Event ID 23 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID

Event ID 24 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID

Event ID 25 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID

Event ID 26 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID

Event ID 27 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
DetectionId

Event ID 28 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
RecordType
ImagePath
Path

Event ID 29 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
TPID
TTID
ImageName

Event ID 30 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
ThreadTime

Event ID 31 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
ThreadTime
StartQPC

Event ID 32 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
PID
ThreadTime

Event ID 33 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
PID
ThreadTime
StartQPC

Event ID 35 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ScanSource
EventType
Classification
Info
FileName
FileID
FileUSN
Result

Event ID 36 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ScanSource
EventType
Classification
Info
FileName
FileID
FileUSN
Result

Event ID 37 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ScanSource
EventType
Classification
Info
FileName
FileID
FileUSN
Result

Event ID 38 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
FileName
CacheName
Result

Event ID 39 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
FileName
CacheName
Result

Event ID 40 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
action
key
filename
result

Event ID 41 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
utilization
result

Event ID 42 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
key
filename
parentKey
result

Event ID 43 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Message
Name
Data
StartStop
ThreadTime

Event ID 44 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
action
vault
key
result

Event ID 45 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
vault
records
result

Event ID 46 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 47 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 48 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 49 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 50 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 51 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 52 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 53 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
TargetPID
AccessMask
WasHardened

Event ID 58 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
KeyPath

Event ID 59 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
VName
SigSeq
SigSha
Result

Event ID 60 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
Channel
EventId

Event ID 61 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FolderName

Event ID 62 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Count

Event ID 63 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
TaintReason
ReasonImagePath
ProcessImagePath

Event ID 64 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName
OldFileName

Event ID 65 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FolderName

Event ID 66 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName
FileHardLinkName

Event ID 67 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Message
Name
Data
StartStop
ThreadTime
DeltaCPU
DeltaWall

Event ID 68 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
SigName
SigSeq
SigSha
SigTypeName
Dimension
Value
Limit
FileName
VPath
FileSha1
PartialCRC1
PartialCRC2
PartialCRC3
FileSize

Event ID 69 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Guid
VolumeSize
Attributes
FilesCount
FileGuidsArray
FileSizeArray
CompressedFileSizeArray
FileNameArray
FileAttributesArray
EfiFileTypeArray
FileSha1Array
SmbiosAttributes
FileCRCsArray

Event ID 70 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
BasePath
CommandLine
PID
ParentPID
Flags
IntegrityLevel

Event ID 71 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 72 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 73 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
CreationTime
PID
filepath
flags
flags2low
flags2high
oldFlags
oldFlags2low
oldFlags2high
Source

Event ID 74 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Sha1
Sha256
SigSeq
SigSha
AllSigSeqs
AllSigShas
RealPath
VPath
EtwDataReportType
ReportType
EngineReportGuid
ResourceData
ResourceSchema
Determination
ActionStatus
ProcessID
ProcessCreationTime
ProcessPath
ThreatName
Classification
IsLatent
IsPassiveMode
ScanSource
ScanType
RtpProcessID
RtpProcessCreationTime
ProcessCommandLine
ExtraDataJson

Event ID 75 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
DeviceInfo
TCGEventsArray
PCRsArray

Event ID 76 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
JsonData

Event ID 77 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
Level
EffectiveLevel
TriggerSigSeq
Origin

Event ID 78 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ImageFilePath
Level
EffectiveLevel
TriggerSigSeq
Origin

Event ID 79 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
Level
TriggerSigSeq

Event ID 80 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
Level
TriggerSigSeq
StopReason

Event ID 81 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
ScanReason

Event ID 82 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
ScanReason
ScanResult

Event ID 83 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId

Event ID 84 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId

Event ID 85 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId

Event ID 86 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId

Event ID 87 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 88 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 89 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 90 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 91 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
ThreadId
StartQPC

Event ID 92 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
ThreadId
StartQPC

Event ID 93 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
PID
ThreadId
StartQPC

Event ID 94 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
FilePath
PID
ThreadId
StartQPC

Event ID 95 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
ProcessId
CreationTime
FileName
FirstOffsetWritten
LastOffsetWritten
SmallestOffsetWritten
BiggestOffsetWritten
TotalSizeOfWrites
TotalSizeOfAppends
NumberOfWrites

Event ID 96 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
OnboardedInfo

Event ID 97 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
Id
Type
Flags
ScanSource
ResourceCount
FirstResourceType
FirstResourcePath
ThreadId
StartQPC

Event ID 98 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
Id
Type
Flags
ScanSource
ResourceCount
FirstResourceType
FirstResourcePath
ThreadId
StartQPC

Event ID 99 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
CreationTime
PID
flags
flags2low
flags2high

Event ID 100 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
CreationTime
PID
flags
flags2low
flags2high

Event ID 101 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 102 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
EngineVersion
AVVersion
ASVersion

Event ID 103 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FileName

Event ID 104 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
FeatureId
FirstParam
SecondParam

Event ID 105 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
EventId
KeyPath
ValueName
OldValue
NewValue
UserMode
FeatureType

Event ID 106 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
LiveContextCount
TotalContextCount

Event ID 107 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
EngineId
LiveContextCount
TotalContextCount

Event ID 108 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
Type
Scope
ResourceType
TargetResource
ParentResource
DetectionName
UserName

Event ID 109 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
ProcessContextId
ImagePath

Event ID 110 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
ProcessContextId
TerminationTime

Event ID 111 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
AttrId
AttrSeq
AttrSubset

Event ID 112 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
AttrId
AttrSeq
AttrSubset
MatchedThreatsNumber
IsMultiProcMatch
IsMultiProcDetection

Event ID 113 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
DetectionName
SigSeq

Event ID 114 —

Provider
Microsoft-Antimalware-Engine
Channel
Application

Fields

NameDescription
PID
DetectionName
SigSeq
CloudResponse