Microsoft-Windows-Sysprep
14 events across 1 channel
Event ID 1001: Executing sysprep providers from registry location "BasePath" during Phase.
#Event ID 1002: Finished executing sysprep providers with status ErrorCode.
#Event ID 2001: Calling external function "FunctionName" from "DllName".
#Event ID 2002: External function returned with status DllName.
#Event ID 3001: Loading meta-data file "ActionFilePath".
#Event ID 3002: Loading of meta-data file "ActionFilePath" completed.
#Event ID 4001: Creating action list for component "ComponentName".
#Event ID 4002: Action list for component "ComponentName" created.
#Event ID 5001: Deleting file(s) "FilePattern" from directory "DirectoryPath".
#Event ID 5002: File deletion of "FilePattern" from directory "DirectoryPath" returned with status ErrorCode.
#Event ID 6001: Deleting directory "DirectoryPath".
#Event ID 6002: Directory deletion for "DirectoryPath" returned with status ErrorCode.
#Event ID 7001: Starting execution of phase "Phase".
#Event ID 7002: Execution of phase returned status ErrorCode.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 75ebc33e-77b8-4ba8-9474-4f4a9db2f5c6
Defined in sysprep.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02
- Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.1 · captured 2026-06-02
Downloads
- Microsoft-Windows-Sysprep registered manifest XML (WS2022-20348.4893) manifest-xml
- Microsoft-Windows-Sysprep registered manifest XML (Win11-26200.6584) manifest-xml