Microsoft-Windows-VerifyHardwareSecurity
13 events across 2 channels
Event ID 3001 — Hardware Security Check: CurrentCheckBit.
Event ID 3002 — SecureBoot is currently disabled.
Description
SecureBoot is currently disabled. Please enable SecureBoot through the system firmware.
Message #
Event ID 3003 — Failed to check if secureboot is enabled.
Event ID 3004 — PreRelease/Test cert found in SecureBoot database.
Event ID 3005 — Failed to check for PreRelease/Test certificates found in SecureBoot DB.
Event ID 3006 — A non-production SecureBoot Policy was detected.
Description
A non-production SecureBoot Policy was detected. Remove Debug/PreRelease policy through the system firmware.
Message #
Event ID 3007 — Failed to check for non-production SecureBoot Policy.
Event ID 3008 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Event ID 3009 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Description
Host provider HostProvider is trying to load ModulePath to invoke its Method API. ModulePath has an OriginalFilename or InternalName of InternalName. NtQuerySecurityPolicy failed with error code hr.
Message #
Fields #
| Name | Description |
|---|---|
HostProvider UnicodeString | — |
ModulePath UnicodeString | — |
Method UnicodeString | — |
InternalName UnicodeString | — |
hr Int32 | — |
Event ID 3010 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Description
Host provider HostProvider is trying to load ModulePath to invoke its Method API. ModulePath has an OriginalFilename or InternalName of InternalName. It is blocked by host lockdown security policy.
Message #
Fields #
| Name | Description |
|---|---|
HostProvider UnicodeString | — |
ModulePath UnicodeString | — |
Method UnicodeString | — |
InternalName UnicodeString | — |
Event ID 3011 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Event ID 3012 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Description
Host provider HostProvider is trying to load ModulePath to invoke its Method API. ModulePath has an OriginalFilename or InternalName of InternalName. The invoking is allowed because UMCI or host lockdown policy is not enabled.
Message #
Fields #
| Name | Description |
|---|---|
HostProvider UnicodeString | — |
ModulePath UnicodeString | — |
Method UnicodeString | — |
InternalName UnicodeString | — |
Event ID 3013 — Host provider HostProvider is trying to load ModulePath to invoke its Method API.
Description
Host provider HostProvider is trying to load ModulePath to invoke its Method API. ModulePath has an OriginalFilename or InternalName of InternalName. The invoking is allowed because of the audit mode of the host lockdown security policy.
Message #
Fields #
| Name | Description |
|---|---|
HostProvider UnicodeString | — |
ModulePath UnicodeString | — |
Method UnicodeString | — |
InternalName UnicodeString | — |