Microsoft-Windows-Deplorch
5 events across 1 channel
| Event | Title | Channel |
|---|---|---|
| 1001 | Starting system services. | Analytic |
| 1002 | Finished starting system services with status ErrorCode. | Analytic |
| 2001 | Running user-provided script: '{CommandLine}'. | Analytic |
| 2002 | Successfully executed script: '{Command}'. | Analytic |
| 2003 | Failed to execute script: '{Command}'. | Analytic |
Event ID 1002: Finished starting system services with status ErrorCode.
#Event ID 2001: Running user-provided script: '{CommandLine}'.
#Event ID 2002: Successfully executed script: '{Command}'.
#Event ID 2003: Failed to execute script: '{Command}'.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID b9da9fe6-ae5f-4f3e-b2fa-8e623c11dc75
Defined in setupetw.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02
- Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.4202 · captured 2026-06-02
Downloads
- Microsoft-Windows-Deplorch registered manifest XML (WS2022-20348.4893) manifest-xml
- Microsoft-Windows-Deplorch registered manifest XML (Win11-26200.6584) manifest-xml