Microsoft-Windows-DesktopActivityModerator

21 events across 1 channel

EventTitleChannel
1StartDriverStartDiagnostic
4StartDriverDiagnostic
9StartDriverStopDiagnostic
11StopDriverStartDiagnostic
19StopDriverStopDiagnostic
21SuspendResumeStartDiagnostic
22SuspendResumeStopDiagnostic
23ThrottleStartDiagnostic
24ThrottleStopDiagnostic
25ResiliencyEngageStartDiagnostic
26ResiliencyEngageStopDiagnostic
31ProcessActivityStartDiagnostic
32ProcessActivityStopDiagnostic
41ProcessExemptDiagnostic
42PolicyReloadDiagnostic
51PdcCallbackDiagnostic
52PdcCallback52Diagnostic
53PdcCallback53Diagnostic
54PdcAcknowledgeDiagnostic
60IoTrackingPerfTrackDiagnostic
61IoTrackingCallbackDiagnostic

Event ID 1: StartDriverStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver
Opcode
Start

Event ID 4: StartDriver

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver

Event ID 9: StartDriverStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver
Opcode
Stop

Fields #

NameDescription
NTSTATUS UInt32

Event ID 11: StopDriverStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StopDriver
Opcode
Start

Event ID 19: StopDriverStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StopDriver
Opcode
Stop

Event ID 21: SuspendResumeStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
SuspendResume
Opcode
Start

Fields #

NameDescription
SuspendFlag Boolean

Event ID 22: SuspendResumeStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
SuspendResume
Opcode
Stop

Fields #

NameDescription
SuspendFlag Boolean

Event ID 23: ThrottleStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
Throttle
Opcode
Start

Fields #

NameDescription
SuspendFlag Boolean

Event ID 24: ThrottleStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
Throttle
Opcode
Stop

Fields #

NameDescription
SuspendFlag Boolean

Event ID 25: ResiliencyEngageStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ResiliencyEngage
Opcode
Start

Fields #

NameDescription
ActiveFlag Boolean

Event ID 26: ResiliencyEngageStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ResiliencyEngage
Opcode
Stop

Fields #

NameDescription
ActiveFlag Boolean

Event ID 31: ProcessActivityStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessActivity
Opcode
Start

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32
ImageFileNameLength UInt16
ImageFileName UnicodeString
CommandLineLength UInt16
CommandLine UnicodeString

Event ID 32: ProcessActivityStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessActivity
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32

Event ID 41: ProcessExempt

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessExempt

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32
ExemptGroup UInt32
RegisterAtLaunch Boolean

Event ID 42: PolicyReload

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PolicyReload

Fields #

NameDescription
PolicyRecords UInt32

Event ID 51: PdcCallback

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
State UInt32
NTSTATUS UInt32
WorkItemQueued Boolean

Event ID 52: PdcCallback52

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
ClientState UInt32

Event ID 53: PdcCallback53

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
Flags UInt32

Event ID 54: PdcAcknowledge

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcAcknowledge

Event ID 60: IoTrackingPerfTrack

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
IoTrackingPerfTrack
Opcode
Info

Fields #

NameDescription
DeviceBucket UInt32
ElapsedTimeMs UInt32
FastIoCount UInt32
SlowIoCount UInt32

Event ID 61: IoTrackingCallback

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
IoTrackingCallback
Opcode
Info

Fields #

NameDescription
DeviceType UInt16
DeviceBucket UInt32
ElapsedTime UInt64
SlowIo Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 32dd13df-9c0b-4c3b-b854-ee76c050f5f4

Defined in dam.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02
  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.5074 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests