Microsoft-Windows-HostGuardianService-CA

8 events across 2 channels

EventTitleChannel
1Platform CA trustlet started.Operational
2Platform CA trustel stopped.Operational
3Message.Debug
3Event ID 3Operational
4Message.Debug
4Event ID 4Operational
5Message.Debug
5Event ID 5Operational

Event ID 1: Platform CA trustlet started.

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Operational

Description

Platform CA trustlet started.

Message #

Platform CA trustlet started.

Event ID 2: Platform CA trustel stopped.

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Operational

Description

Platform CA trustel stopped.

Message #

Platform CA trustel stopped.

Event ID 3: Message.

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 3:

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 4: Message.

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 4:

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 5: Message.

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 5:

#
Provider
Microsoft-Windows-HostGuardianService-CA
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 9fb3388c-a54c-4e98-bdd1-445a82ed4bf7

Defined in vmplatformca.exe, which carries the event manifest.

Observed on:

  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.1 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests