Microsoft-Windows-SecurityMitigationsBroker
30 events across 3 channels
Event ID 1001 —
Event ID 1002 —
Event ID 1003 — Failed to get the COM call context.
Event ID 1004 — Failed to get the calling process information.
Event ID 1005 — Failed to get the DX adapter driver capabilities.
Event ID 1006 — ACG status of the DX adapter driver, AdapterId=DriverId, capability=ACGState.
Event ID 1007 — Failed to get the mitigation status of the calling proces.
Event ID 1008 — Failed to set the mitigation status of the calling proces.
Event ID 1009 — Calling process ACG status, AdapterId=DriverId, ProcessId=ProcessId, ACG status=ACGState.
Event ID 1010 — Calling process is in ACG telemetry mode.
Event ID 1011 — Calling process is not in an AppContainer.
Event ID 1012 — Failed to adjust the calling process ACG status for the reported DX adapter change event.
Event ID 1013 — Finished applying the security protection policies for the reported DX adapter change event.
Event ID 1014 — Calling process does not have ACG turned on.
Event ID 1015 — ACG will be turned off for the calling process due to unsupportive DX adapter driver.
Event ID 1016 — Failed to create the DX object factory.
Event ID 1017 — Failed to enumerate the DX adapters.
Event ID 1018 — Failed to query the descriptor for the adapter id.
Event ID 1019 — Enumerated a DX adapter.
Event ID 1020 — Calling process uses the software rendering adapter.
Event ID 1021 — Failed to query the IDXGIAdapter2 interface from the enumerated adapter.
Event ID 1022 — Encountered a DX adapter that does not support ACG.
Event ID 1023 — Forced ACG on the DX Adapter which uses a WDDM 2.
Description
Forced ACG on the DX Adapter which uses a WDDM 2.0 and above driver from a supported vendor. Description:Description, VendorId:VendorId, DeviceId:DeviceId, AdapterId=DriverId, ProcessId=ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
Description UnicodeString | — |
VendorId UInt32 | — |
DeviceId UInt32 | — |
DriverId UInt64 | — |
ProcessId UInt32 | — |