Microsoft-Windows-TPM-WMI
51 events across 1 channel
Event ID 513 — TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.
Description
TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.
Message #
Event ID 514 — Failed to backup TPM Owner Authorization information to Active Directory Domain Services.
Event ID 515 — The Trusted Platform Module (TPM) hardware on this computer has failed to set its Dictionary Attack Parameters to legacy mode.
Description
The Trusted Platform Module (TPM) hardware on this computer has failed to set its Dictionary Attack Parameters to legacy mode.
Message #
Event ID 516 — Successfully sent physical presence request to clear the Trusted Platform Module(TPM).
Description
Successfully sent physical presence request to clear the Trusted Platform Module(TPM).
Message #
Event ID 517 — Failed to send physical presence request to clear the Trusted Platform Module(TPM).
Event ID 518 — Failed to get isOwned status from Trusted Platform Module(TPM), proceeding to clear TPM assuming that TPM is owned.
Event ID 519 — The TPM has been cleared.
Event ID 769 — TPM Owner Authorization configuration changed from 'OldOSManagedAuthLevel' to 'NewOSManagedAuthLevel'.
Event ID 1025 — The TPM was successfully provisioned and is now ready for use.
Description
The TPM was successfully provisioned and is now ready for use.
Message #
Event ID 1026 — The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.
Event ID 1027 — The Ownership of the Trusted Platform Module (TPM) hardware on this computer was successfully taken (TPM TakeOwnership command) by the system.
Description
The Ownership of the Trusted Platform Module (TPM) hardware on this computer was successfully taken (TPM TakeOwnership command) by the system.
Message #
Event ID 1028 — The NGC key generation task was successfully triggered.
Description
The NGC key generation task was successfully triggered.
Message #
Event ID 1029 — The triggering of the NGC key generation task failed.
Event ID 1030 — The NGC certificate enrollment task was successfully triggered.
Description
The NGC certificate enrollment task was successfully triggered.
Message #
Event ID 1031 — The triggering of the NGC certificate enrollment task failed.
Event ID 1032 — The Secure Boot update was not applied due to a known incompatibility with the current BitLocker configuration.
Event ID 1033 — Potentially revoked boot manager was detected in EFI partition.
Event ID 1034 — Secure Boot Dbx update applied successfully
#Description
Secure Boot Dbx update applied successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TPM-WMI",
"guid": "7D5387B0-CBE0-11DA-A94D-0800200C9A66",
"event_source_name": "",
"event_id": 1034,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:27:36.527418+00:00",
"event_record_id": 1724,
"correlation": {},
"execution": {
"process_id": 1092,
"thread_id": 956
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1035 — Secure Boot Dbx update applied successfully
Description
Secure Boot Dbx update applied successfully.
Message #
Event ID 1036 — Secure Boot Db update applied successfully
Description
Secure Boot Db update applied successfully.
Message #
Event ID 1037 — Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is applied successfully
Description
Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is applied successfully.
Message #
Event ID 1038 — Pre-attestation health checks confirm that the device is expected to pass attestation.
Event ID 1039 — Pre-attestation health checks confirm that the device meets most attestation criteria, but failing is still possible.
Event ID 1040 — Pre-attestation health checks confirm a critical component has failed, and the device is not expected to pass attestation.
Event ID 1041 — Pre-attestation health check detailed information: Json.
Event ID 1042 — Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfully
Description
Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfully.
Message #
Event ID 1043 — Secure Boot KEK update applied successfully
Description
Secure Boot KEK update applied successfully.
Message #
Event ID 1044 — Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate applied successfully
Description
Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate applied successfully.
Message #
Event ID 1045 — Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied successfully
Description
Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied successfully.
Message #
Event ID 1046 — Measured boot files deleted successfully.
Event ID 1047 — Measured boot file FileName was not deleted successfully due to error ErrorCode.
Event ID 1281 — This event triggers the TBS device identifier generation.
#Description
This event triggers the TBS device identifier generation.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TPM-WMI",
"guid": "7D5387B0-CBE0-11DA-A94D-0800200C9A66",
"event_source_name": "",
"event_id": 1281,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T16:48:26.716878+00:00",
"event_record_id": 346,
"correlation": {},
"execution": {
"process_id": 4332,
"thread_id": 4368
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1282 — The TBS device identifier has been generated.
Description
The TBS device identifier has been generated.
Message #
Event ID 1283 — EK Certificate tool started.
Description
EK Certificate tool started.
Message #
Event ID 1284 — EK Certificate tool succeeded in Millisecondstaken milliseconds.
Event ID 1285 — EK Certificate tool failed in Millisecondstaken milliseconds with error ErrorCode.
Event ID 1537 — The Device Health Certificate was successfully provisioned from HealthAttestationServer.
Event ID 1538 — The Device Health Certificate provisioning could not connect to HealthAttestationServer.
Event ID 1539 — The Device Health Certificate could not be provisioned from HealthAttestationServer.
Event ID 1793 — The Trusted Platform Module (TPM) hardware on this computer is scheduled to be cleared by the system.
Description
The Trusted Platform Module (TPM) hardware on this computer is scheduled to be cleared by the system.
Message #
Event ID 1794 — The Trusted Platform Module (TPM) firmware on this PC has a known security problem.
Message #
Event ID 1795 — The system firmware returned an error HResult when attempting to update a Secure Boot variable.
Description
The system firmware returned an error HResult when attempting to update a Secure Boot variable. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931.
Message #
Fields #
| Name | Description |
|---|---|
HResult Int32 | — |
UpdateType UnicodeString | — |
DeviceAttributes UnicodeString | — |
BucketId UnicodeString | — |
BucketConfidenceLevel UnicodeString | — |
Event ID 1796 — The Secure Boot update failed to update a Secure Boot variable with error UpdateType.
Event ID 1797 — The Secure Boot Dbx update failed to revoke Microsoft Windows Production PCA 2011 as the Windows UEFI CA 2023 certificate is not present in Db
Description
The Secure Boot update failed as the Windows UEFI CA 2023 certificate is not present in Db.
Message #
Event ID 1798 — The Secure Boot Dbx update failed as boot manager is not signed with the Windows UEFI CA 2023 certificate.
Description
The Secure Boot Dbx update failed as boot manager is not signed with the Windows UEFI CA 2023 certificate.
Message #
Event ID 1799 — Boot Manager signed with Windows UEFI CA 2023 was installed successfully
Description
Boot Manager signed with Windows UEFI CA 2023 was installed successfully.