Microsoft-Windows-Kernel-Memory
14 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 1 | Analytic | |
| 2 | Analytic | |
| 3 | Analytic | |
| 4 | Analytic | |
| 5 | Analytic | |
| 6 | Analytic | |
| 7 | Analytic | |
| 8 | Analytic | |
| 9 | Analytic | |
| 10 | Analytic | |
| 11 | Analytic | |
| 12 | Analytic | |
| 13 | Analytic | |
| 14 | Analytic |
Event ID 1 —
Fields #
| Name | Description |
|---|---|
PriorityLevels UInt8 | — |
ZeroPageCount Pointer | — |
FreePageCount Pointer | — |
ModifiedPageCount Pointer | — |
ModifiedNoWritePageCount Pointer | — |
BadPageCount Pointer | — |
StandbyPageCounts Pointer | — |
RepurposedPageCounts Pointer | — |
ModifiedPageCountPageFile Pointer | — |
PagedPoolPageCount Pointer | — |
NonPagedPoolPageCount Pointer | — |
MdlPageCount Pointer | — |
CommitPageCount Pointer | — |
Event ID 2 —
Fields #
| Name | Description |
|---|---|
Count UInt32 | — |
WSCommitInfo AnsiString | — |
Event ID 3 —
Fields #
| Name | Description |
|---|---|
Count UInt32 | — |
SessionWSCommitInfo AnsiString | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Flags HexInt32 | — |
Event ID 5 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
PagesProcessed Pointer | — |
WriteCombinePagesProcessed Pointer | — |
UncachedPagesProcessed Pointer | — |
CleanPagesProcessed Pointer | — |
Event ID 6 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Flags HexInt32 | — |
Event ID 7 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8 —
Fields #
| Name | Description |
|---|---|
AcgFlag UInt32 | — |
Event ID 9 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 10 —
Fields #
| Name | Description |
|---|---|
DurationInMicroseconds UInt64 | — |
TotalBytes UInt64 | — |
LowAddress UInt64 | — |
HighAddress UInt64 | — |
SkipBytes UInt64 | — |
MemoryDescriptorList Pointer | — |
IdealNode UInt32 | — |
Flags UInt32 | — |
Event ID 11 —
Fields #
| Name | Description |
|---|---|
DurationInMicroseconds UInt64 | — |
TotalBytes UInt64 | — |
LowAddress UInt64 | — |
HighAddress UInt64 | — |
Boundary UInt64 | — |
PhysicalAddress UInt64 | — |
MappedAddress Pointer | — |
ProtectionMask UInt32 | — |
PreferredNode UInt32 | — |
PartitionId UInt32 | — |
Tag UInt32 | — |
Flags UInt32 | — |
AllocatedFromPool Boolean | — |
AllocatedFromExtension Boolean | — |
Event ID 12 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt32 | — |
Count UInt32 | — |
MemoryNodeInfo Int8 | — |
Event ID 13 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt32 | — |
Count UInt32 | — |
MemoryNodeInfo Int8 | — |
Event ID 14 —
Fields #
| Name | Description |
|---|---|
BaseAddress Pointer | — |
Size Pointer | — |