Microsoft-Windows-Security-IdentityStore
27 events across 1 channel
| Event | Title | Channel |
|---|---|---|
| 1 | CreateConnectedUserStart | Performance |
| 2 | CreateConnectedUserStart2 | Performance |
| 3 | CreateConnectedUserStop | Performance |
| 4 | ConnectDisconnectUserStart | Performance |
| 5 | ConnectDisconnectUserStop | Performance |
| 6 | ConnectDisconnectUserStart6 | Performance |
| 7 | ConnectDisconnectUserStop7 | Performance |
| 8 | ConnectDisconnectUserStart8 | Performance |
| 9 | ConnectDisconnectUserStop9 | Performance |
| 10 | ConnectDisconnectUserStart10 | Performance |
| 11 | ConnectDisconnectUserStop11 | Performance |
| 12 | IdentityQueryStart | Performance |
| 13 | IdentityQueryStop | Performance |
| 14 | IdentityQuery | Performance |
| 15 | IdentityQuery | Performance |
| 16 | IdentityQuery | Performance |
| 17 | IdentityQuery | Performance |
| 18 | IdentityQueryStart18 | Performance |
| 19 | IdentityQueryStop19 | Performance |
| 20 | IdentityQueryStart20 | Performance |
| 21 | IdentityQueryStop21 | Performance |
| 22 | CreateConnectedUserStart22 | Performance |
| 23 | CreateConnectedUserStop23 | Performance |
| 24 | CreateConnectedUserStart24 | Performance |
| 25 | CreateConnectedUserStop25 | Performance |
| 26 | ConnectDisconnectUserStart26 | Performance |
| 27 | ConnectDisconnectUserStop27 | Performance |
Event ID 1: CreateConnectedUserStart
#Event ID 2: CreateConnectedUserStart2
#Event ID 3: CreateConnectedUserStop
#Event ID 4: ConnectDisconnectUserStart
#Event ID 5: ConnectDisconnectUserStop
#Event ID 6: ConnectDisconnectUserStart6
#Event ID 7: ConnectDisconnectUserStop7
#Event ID 8: ConnectDisconnectUserStart8
#Event ID 9: ConnectDisconnectUserStop9
#Event ID 10: ConnectDisconnectUserStart10
#Event ID 11: ConnectDisconnectUserStop11
#Event ID 12: IdentityQueryStart
#Event ID 13: IdentityQueryStop
#Event ID 14: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 14,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.425+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 15: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.519+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 16: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.515+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 17: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 17,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.516+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 18: IdentityQueryStart18
#Event ID 19: IdentityQueryStop19
#Event ID 20: IdentityQueryStart20
#Event ID 21: IdentityQueryStop21
#Event ID 22: CreateConnectedUserStart22
#Event ID 23: CreateConnectedUserStop23
#Event ID 24: CreateConnectedUserStart24
#Event ID 25: CreateConnectedUserStop25
#Event ID 26: ConnectDisconnectUserStart26
#Event ID 27: ConnectDisconnectUserStop27
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {00B7E1DF-B469-4C69-9C41-53A6576E3DAD}
Defined in idstore.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584 · sample captured from a live trace · binary version 10.0.26100.5074 · captured 2026-06-02
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.2849 · captured 2026-06-02
- Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.5074 · captured 2026-06-02
Downloads
- Microsoft-Windows-Security-IdentityStore registered manifest XML (WS2022-20348.4893) manifest-xml
- Microsoft-Windows-Security-IdentityStore registered manifest XML (Win11-26200.6584) manifest-xml