Microsoft-Windows-Kernel-Registry
45 events across 2 channels
| Event ID | Title | Channel |
|---|---|---|
| 1 | Analytic | |
| 2 | Analytic | |
| 3 | Analytic | |
| 4 | Analytic | |
| 5 | Analytic | |
| 6 | Analytic | |
| 7 | Analytic | |
| 8 | Analytic | |
| 9 | Analytic | |
| 10 | Analytic | |
| 11 | Analytic | |
| 12 | Analytic | |
| 13 | Analytic | |
| 14 | Analytic | |
| 15 | Analytic | |
| 16 | Performance | |
| 17 | Performance | |
| 18 | Performance | |
| 19 | Performance | |
| 20 | Performance | |
| 21 | Performance | |
| 22 | Performance | |
| 23 | Performance | |
| 24 | Performance | |
| 25 | Performance | |
| 26 | Performance | |
| 27 | Performance | |
| 28 | Performance | |
| 29 | Performance | |
| 30 | Performance | |
| 31 | Performance | |
| 32 | Performance | |
| 33 | Performance | |
| 34 | Performance | |
| 35 | Performance | |
| 36 | Performance | |
| 37 | Performance | |
| 38 | Performance | |
| 39 | Performance | |
| 40 | Performance | |
| 41 | Performance | |
| 42 | Performance | |
| 43 | Performance | |
| 44 | Performance | |
| 45 | Performance |
Event ID 1 —
Fields
| Name | Description |
|---|---|
BaseObject | — |
KeyObject | — |
Status | — |
Disposition | — |
BaseName | — |
RelativeName | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
BaseObject | — |
KeyObject | — |
Status | — |
Disposition | — |
BaseName | — |
RelativeName | — |
Event ID 3 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
InfoClass | — |
DataSize | — |
KeyName | — |
CapturedDataSize | — |
CapturedData | — |
Event ID 5 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
Type | — |
DataSize | — |
KeyName | — |
ValueName | — |
CapturedDataSize | — |
CapturedData | — |
PreviousDataType | — |
PreviousDataSize | — |
PreviousDataCapturedSize | — |
PreviousData | — |
Event ID 6 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
ValueName | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
InfoClass | — |
DataSize | — |
KeyName | — |
ValueName | — |
CapturedDataSize | — |
CapturedData | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
Index | — |
InfoClass | — |
DataSize | — |
KeyName | — |
CapturedDataSize | — |
CapturedData | — |
Event ID 9 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
Index | — |
InfoClass | — |
DataSize | — |
KeyName | — |
CapturedDataSize | — |
CapturedData | — |
Event ID 10 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
EntryCount | — |
DataSize | — |
KeyName | — |
Event ID 11 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
InfoClass | — |
DataSize | — |
KeyName | — |
CapturedDataSize | — |
CapturedData | — |
Event ID 12 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
Event ID 13 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
Event ID 14 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
Event ID 15 —
Fields
| Name | Description |
|---|---|
KeyObject | — |
Status | — |
KeyName | — |
Event ID 16 —
Event ID 17 —
Fields
| Name | Description |
|---|---|
HiveFilePath | — |
FileSize | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
TotalEntrySize | — |
BytesRecovered | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
HiveFilePath | — |
HiveMountPoint | — |
Event ID 21 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 22 —
Fields
| Name | Description |
|---|---|
HiveFilePath | — |
HiveMountPoint | — |
FlushFlags | — |
Event ID 23 —
Event ID 24 —
Fields
| Name | Description |
|---|---|
BytesGathered | — |
Event ID 25 —
Fields
| Name | Description |
|---|---|
BytesGathered | — |
Event ID 26 —
Fields
| Name | Description |
|---|---|
WritesIssued | — |
BytesWritten | — |
Event ID 27 —
Fields
| Name | Description |
|---|---|
WritesIssued | — |
BytesWritten | — |
Event ID 28 —
Event ID 29 —
Event ID 30 —
Event ID 31 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 32 —
Event ID 33 —
Event ID 34 —
Event ID 35 —
Event ID 36 —
Event ID 37 —
Fields
| Name | Description |
|---|---|
SourceFile | — |
Flags | — |
Event ID 38 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 39 —
Fields
| Name | Description |
|---|---|
SourceFile | — |
Flags | — |
Event ID 40 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 41 —
Fields
| Name | Description |
|---|---|
SourceKeyPath | — |
Event ID 42 —
Event ID 43 —
Event ID 44 —
Event ID 45 —
Fields
| Name | Description |
|---|---|
StatusCode | — |