Microsoft-Windows-TPM-WMI
51 events across 1 channel
Event ID 513 — TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.
Message
Event ID 514 — Failed to backup TPM Owner Authorization information to Active Directory Domain Services.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 515 — The Trusted Platform Module (TPM) hardware on this computer has failed to set its Dictionary Attack Parameters to legacy mode.
Message
Event ID 516 — Successfully sent physical presence request to clear the Trusted Platform Module(TPM).
Message
Event ID 517 — Failed to send physical presence request to clear the Trusted Platform Module(TPM).
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 518 — Failed to get isOwned status from Trusted Platform Module(TPM), proceeding to clear TPM assuming that TPM is owned.
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 519 — The TPM has been cleared.
Message
Fields
| Name | Description |
|---|---|
ClearReason | — |
Event ID 769 — TPM Owner Authorization configuration changed from '.
Message
Fields
| Name | Description |
|---|---|
OldOSManagedAuthLevel | — |
NewOSManagedAuthLevel | — |
Event ID 1025 — The TPM was successfully provisioned and is now ready for use.
Message
Event ID 1026 — The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
StatusInformation | — |
Event ID 1027 — The Ownership of the Trusted Platform Module (TPM) hardware on this computer was successfully taken (TPM TakeOwnership command) by the system.
Message
Event ID 1028 — The NGC key generation task was successfully triggered.
Message
Event ID 1029 — The triggering of the NGC key generation task failed.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1030 — The NGC certificate enrollment task was successfully triggered.
Message
Event ID 1031 — The triggering of the NGC certificate enrollment task failed.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1032 — The Secure Boot update was not applied due to a known incompatibility with the current BitLocker configuration.
Message
Fields
| Name | Description |
|---|---|
UpdateType | — |
Event ID 1033 — Potentially revoked boot manager was detected in EFI partition.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 1034 — Secure Boot Dbx update applied successfully
Message
Example Event
system:
provider: Microsoft-Windows-TPM-WMI
guid: 7D5387B0-CBE0-11DA-A94D-0800200C9A66
event_source_name: ''
event_id: 1034
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:27:36.527418+00:00'
event_record_id: 1724
correlation: {}
execution:
process_id: 1092
thread_id: 956
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1035 — Secure Boot Dbx update applied successfully
Message
Event ID 1036 — Secure Boot Db update applied successfully
Message
Event ID 1037 — Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is applied successfully
Message
Event ID 1038 — Pre-attestation health checks confirm that the device is expected to pass attestation.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 1039 — Pre-attestation health checks confirm that the device meets most attestation criteria, but failing is still possible.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 1040 — Pre-attestation health checks confirm a critical component has failed, and the device is not expected to pass attestation.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 1041 — Pre-attestation health check detailed information.
Message
Fields
| Name | Description |
|---|---|
Json | — |
Event ID 1042 — Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfully
Message
Event ID 1043 — Secure Boot KEK update applied successfully
Message
Event ID 1044 — Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate applied successfully
Message
Event ID 1045 — Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied successfully
Message
Event ID 1046 — Measured boot files deleted successfully.
Message
Fields
| Name | Description |
|---|---|
FilesCount | — |
Files | — |
Event ID 1047 — Measured boot file %1 was not deleted successfully due to error %2.
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Event ID 1281 — This event triggers the TBS device identifier generation.
Message
Example Event
system:
provider: Microsoft-Windows-TPM-WMI
guid: 7D5387B0-CBE0-11DA-A94D-0800200C9A66
event_source_name: ''
event_id: 1281
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T16:48:26.716878+00:00'
event_record_id: 346
correlation: {}
execution:
process_id: 4332
thread_id: 4368
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1282 — The TBS device identifier has been generated.
Message
Event ID 1283 — EK Certificate tool started.
Message
Event ID 1284 — EK Certificate tool succeeded in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
Millisecondstaken | — |
Event ID 1285 — EK Certificate tool failed in %1 milliseconds with error %2.
Message
Fields
| Name | Description |
|---|---|
Millisecondstaken | — |
ErrorCode | — |
Event ID 1537 — The Device Health Certificate was successfully provisioned from %1.
Message
Fields
| Name | Description |
|---|---|
HealthAttestationServer | — |
Event ID 1538 — The Device Health Certificate provisioning could not connect to %1.
Message
Fields
| Name | Description |
|---|---|
HealthAttestationServer | — |
HResult | — |
Event ID 1539 — The Device Health Certificate could not be provisioned from %1.
Message
Fields
| Name | Description |
|---|---|
HealthAttestationServer | — |
HTTPStatus | — |
ServerResponse | — |
Event ID 1793 — The Trusted Platform Module (TPM) hardware on this computer is scheduled to be cleared by the system.
Message
Event ID 1794 — The Trusted Platform Module (TPM) firmware on this PC has a known security problem.
Message
Event ID 1795 — The system firmware returned an error %1 when attempting to update a Secure Boot variable.
Message
Fields
| Name | Description |
|---|---|
HResult | — |
UpdateType | — |
DeviceAttributes | — |
BucketId | — |
BucketConfidenceLevel | — |
Event ID 1796 — The Secure Boot update failed to update a Secure Boot variable with error %1.
Message
Fields
| Name | Description |
|---|---|
UpdateType | — |
HResult | — |
Event ID 1797 — The Secure Boot Dbx update failed to revoke Microsoft Windows Production PCA 2011 as the Windows UEFI CA 2023 certificate is not present in Db
Message
Event ID 1798 — The Secure Boot Dbx update failed as boot manager is not signed with the Windows UEFI CA 2023 certificate.
Message
Event ID 1799 — Boot Manager signed with Windows UEFI CA 2023 was installed successfully
Message
Event ID 1800 — A reboot is required before installing the update.
Message
Fields
| Name | Description |
|---|---|
UpdateType | — |
Event ID 1801 — Secure Boot certificates have been updated but are not yet applied to the device firmware.
Message
Fields
| Name | Description |
|---|---|
DeviceAttributes | — |
BucketId | — |
BucketConfidenceLevel | — |
UpdateType | — |
Event ID 1802 — The Secure Boot update %1 was blocked due to a known firmware issue on the device.
Message
Fields
| Name | Description |
|---|---|
UpdateType | — |
DeviceAttributes | — |
BucketId | — |
BucketConfidenceLevel | — |
SkipReason | — |
Event ID 1803 — A PK-signed Key Exchange Key (KEK) cannot be found for this device.
Message
Fields
| Name | Description |
|---|---|
DeviceAttributes | — |
BucketId | — |
BucketConfidenceLevel | — |
Event ID 1808 — This device has updated Secure Boot CA/keys.
Message
Fields
| Name | Description |
|---|---|
DeviceAttributes | — |
BucketId | — |
BucketConfidenceLevel | — |
UpdateType | — |