Microsoft-Windows-Wininit
60 events across 3 channels
Event ID 1 —
Event ID 2 —
Event ID 3 —
Event ID 4 —
Event ID 5 —
Event ID 6 —
Event ID 7 —
Event ID 8 —
Event ID 9 —
Fields
| Name | Description |
|---|---|
Flags | — |
Event ID 10 —
Fields
| Name | Description |
|---|---|
Win32Status | — |
Event ID 11 — Custom dynamic link libraries are being loaded for every application.
Message
Fields
| Name | Description |
|---|---|
StringCount | — |
String | — |
Event ID 12 — LSASS.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-Wininit
guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
event_source_name: ''
event_id: 12
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2021-02-09T11:59:37.890339+00:00'
event_record_id: 5456
correlation: {}
execution:
process_id: 560
thread_id: 564
channel: System
computer: WIN10-client01.offsec.lan
security:
user_id: S-1-5-18
event_data:
Data:
Name: Level
Value: 4
message: 'LSASS.exe was started as a protected process with level: Level.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 13 — Credential Guard was started and will protect LSA credentials.
Message
Event ID 14 — Credential Guard configuration: 0, 0
Message
Fields
| Name | Description |
|---|---|
Config | — |
IsTestConfig | — |
IsAutoEnabled | — |
Example Event
system:
provider: Microsoft-Windows-Wininit
guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
event_source_name: ''
event_id: 14
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:27.117050+00:00'
event_record_id: 1653
correlation: {}
execution:
process_id: 636
thread_id: 640
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Config: 2
IsTestConfig: 0
IsAutoEnabled: 1
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 15 — Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.
Message
Example Event
system:
provider: Microsoft-Windows-Wininit
guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
event_source_name: ''
event_id: 15
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:27.117090+00:00'
event_record_id: 1654
correlation: {}
execution:
process_id: 636
thread_id: 640
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16 — LsaIso.
Message
Fields
| Name | Description |
|---|---|
Level | — |
Event ID 17 — Error reading Credential Guard.
Message
Fields
| Name | Description |
|---|---|
Level | — |
Event ID 18 — Key Guard was started and will protect VSM-isolated keys.
Message
Event ID 19 — Virtualization Based Security new timer creation status HRESULT: %1 New latch timer needed: %2 New latch timer waiting for system update completion...
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
NewLatchTimerNeeded | — |
NewLatchTimerWaitingSystemUpdateCompletion | — |
PreviousLatchTimerExistsButDisabled | — |
PolicyFileExists | — |
Event ID 20 — Virtualization Based Security master key timer start status Win32Error: %1 Start time: %2 Grace period: %3 Due time: %4 Policy version: %5.
Message
Fields
| Name | Description |
|---|---|
win32Error | — |
ftStartTime | — |
ullDelay | — |
ftDueTime | — |
PolicyVersion | — |
Event ID 21 — Virtualization Based Security previous timer resume status HRESULT: %1 Previous timer present: %2 Start time: %3 Grace period: %4 Policy version: %...
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
PreviousTimerPresent | — |
ftStartTime | — |
ullDelay | — |
PolicyVersion | — |
fAttemptedRecoveryIncrementCounterSucceeded | — |
fPreviousLatchTimerInvalid | — |
fPolicyFileExists | — |
Event ID 22 — Virtualization Based Security latch policy status HRESULT: %1 TPM counter value: %2 Expected TPM counter value: %3 Policy version: %4 Incremented: %5.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Counter | — |
PendingLKeyPkgId | — |
PendingPolicyVersion | — |
CounterIncremented | — |
Event ID 23 — Boot App Anti-Rollback: Initialize Completed with status: HRESULT: %1 New timer needed: %2 New timer waiting for system update completion: %3 Previ...
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
NewTimerNeeded | — |
NewTimerWaitingUpdateCompletion | — |
PreviousTimerExistsButDisabled | — |
Event ID 24 — Boot App Anti-Rollback: Timer start completed with status: Win32Error: %1 Start time: %2 Grace period: %3 Due time: %4.
Message
Fields
| Name | Description |
|---|---|
win32Error | — |
FileStartTime | — |
GracePeriod | — |
DueTime | — |
Event ID 25 — Boot App Anti-Rollback: Previous timer resumed with status: HRESULT: %1 Previous timer present: %2 Start time: %3 Grace period: %4 Attempted recove...
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
PreviousTimerExists | — |
PreviousTimerStartTime | — |
GracePeriod | — |
AttemptedRecoveryEnforcementSucceeded | — |
Event ID 26 — Boot App Anti-Rollback: Boot.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
BootStlEnforced | — |
LocalStatus | — |
Event ID 51 —
Event ID 53 —
Fields
| Name | Description |
|---|---|
SessionId | — |
Flags | — |
Event ID 55 —
Fields
| Name | Description |
|---|---|
SessionId | — |
IsRemote | — |
GracePeriod | — |
Flags | — |
Reason | — |
Message | — |
Event ID 100 — Hybrid shutdown has been overridden by a disk check request.
Message
Event ID 1001 —
Event ID 1001 —
Event ID 1015 —
Event ID 1015 —
Event ID 3002 —
Event ID 3002 —
Event ID 3003 —
Event ID 3003 —
Event ID 3004 —
Event ID 3004 —
Event ID 3005 —
Event ID 3005 —
Event ID 3006 —
Event ID 3006 —
Event ID 6001 —
Fields
| Name | Description |
|---|---|
Flags | — |
Event ID 6002 —
Fields
| Name | Description |
|---|---|
ShutdownFlags | — |
SystemShutdownDuration | — |
SkuHasLogoff | — |