Microsoft-Windows-Wininit

60 events across 3 channels

Event IDTitleChannel
1Diagnostic
2Diagnostic
3Diagnostic
4Diagnostic
5Diagnostic
6Diagnostic
7Diagnostic
8Diagnostic
9Diagnostic
10Diagnostic
11Custom dynamic link libraries are being loaded for every application.System
12LSASS.System
13Credential Guard was started and will protect LSA credentials.System
14Credential Guard configuration: 0, 0System
15Credential Guard and/or VBS Key Isolation are configured but the secure kernel …System
16LsaIso.System
17Error reading Credential Guard.System
18Key Guard was started and will protect VSM-isolated keys.System
19Virtualization Based Security new timer creation status HRESULT: %1 New latch …System
20Virtualization Based Security master key timer start status Win32Error: %1 Start …System
21Virtualization Based Security previous timer resume status HRESULT: %1 Previous …System
22Virtualization Based Security latch policy status HRESULT: %1 TPM counter value: …System
23Boot App Anti-Rollback: Initialize Completed with status: HRESULT: %1 New timer …System
24Boot App Anti-Rollback: Timer start completed with status: Win32Error: %1 Start …System
25Boot App Anti-Rollback: Previous timer resumed with status: HRESULT: %1 Previous …System
26Boot App Anti-Rollback: Boot.System
51Diagnostic
53Diagnostic
55Diagnostic
100Hybrid shutdown has been overridden by a disk check request.System
1001Operational
1001System
1015Operational
1015System
3002Operational
3002System
3003Operational
3003System
3004Operational
3004System
3005Operational
3005System
3006Operational
3006System
6001Diagnostic
6002Diagnostic
1073742825Operational
1073742825System
2147486651Windows start-up process has failed to start the remote shutdown server.Operational
2147486651Windows start-up process has failed to start the remote shutdown server.System
2147486652Windows start-up process has failed to synchronize with the local security …Operational
2147486652Windows start-up process has failed to synchronize with the local security …System
3221226487A critical system process, .System
3221226487A critical system process, %1, failed with status code %2.Operational
3221228474Windows start-up process has unexpectedly terminated.Operational
3221228474Windows start-up process has unexpectedly terminated.System
3221228477Windows start-up process has failed to terminate system processes.Operational
3221228477Windows start-up process has failed to terminate system processes.System
3221228478Windows shudown failed with error code .System
3221228478Windows shudown failed with error code %1 in phase: %2.Operational

Event ID 1 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 2 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 3 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 4 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 5 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 6 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 7 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 8 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 9 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
Flags

Event ID 10 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
Win32Status

Event ID 11 — Custom dynamic link libraries are being loaded for every application.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Fields

NameDescription
StringCount
String

Event ID 12 — LSASS.

Provider
Microsoft-Windows-Wininit
Channel
System
Level
4
Samples
1

Message

LSASS.exe was started as a protected process with level: %1.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-Wininit
  guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
  event_source_name: ''
  event_id: 12
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2021-02-09T11:59:37.890339+00:00'
  event_record_id: 5456
  correlation: {}
  execution:
    process_id: 560
    thread_id: 564
  channel: System
  computer: WIN10-client01.offsec.lan
  security:
    user_id: S-1-5-18
event_data:
  Data:
    Name: Level
    Value: 4
message: 'LSASS.exe was started as a protected process with level: Level.'

References

Event ID 13 — Credential Guard was started and will protect LSA credentials.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Credential Guard was started and will protect LSA credentials.

Event ID 14 — Credential Guard configuration: 0, 0

Provider
Microsoft-Windows-Wininit
Channel
System
Level
4
Samples
1

Message

Credential Guard configuration:

Registry Configuration: %1
Test Configuration: %2
Auto Enablement: %3

Fields

NameDescription
Config
IsTestConfig
IsAutoEnabled

Example Event

system:
  provider: Microsoft-Windows-Wininit
  guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
  event_source_name: ''
  event_id: 14
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:27.117050+00:00'
  event_record_id: 1653
  correlation: {}
  execution:
    process_id: 636
    thread_id: 640
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  Config: 2
  IsTestConfig: 0
  IsAutoEnabled: 1
message: ''

References

Event ID 15 — Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Provider
Microsoft-Windows-Wininit
Channel
System
Level
3
Samples
1

Message

Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Example Event

system:
  provider: Microsoft-Windows-Wininit
  guid: 206F6DEA-D3C5-4D10-BC72-989F03C8B84B
  event_source_name: ''
  event_id: 15
  version: 0
  level: 3
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:27.117090+00:00'
  event_record_id: 1654
  correlation: {}
  execution:
    process_id: 636
    thread_id: 640
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 16 — LsaIso.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

LsaIso.exe, the host process for Credential Guard and VBS Key Isolation, failed to launch: %1

Fields

NameDescription
Level

Event ID 17 — Error reading Credential Guard.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Error reading Credential Guard (LsaIso.exe) UEFI configuration: %1

Fields

NameDescription
Level

Event ID 18 — Key Guard was started and will protect VSM-isolated keys.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

VBS Key Isolation was started and will protect VSM-isolated keys.

Event ID 19 — Virtualization Based Security new timer creation status HRESULT: %1 New latch timer needed: %2 New latch timer waiting for system update completion...

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Virtualization Based Security new timer creation status

HRESULT: %1
New latch timer needed: %2
New latch timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4
Policy file exists: %5

Fields

NameDescription
HRESULT
NewLatchTimerNeeded
NewLatchTimerWaitingSystemUpdateCompletion
PreviousLatchTimerExistsButDisabled
PolicyFileExists

Event ID 20 — Virtualization Based Security master key timer start status Win32Error: %1 Start time: %2 Grace period: %3 Due time: %4 Policy version: %5.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Virtualization Based Security master key timer start status

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4
Policy version: %5

Fields

NameDescription
win32Error
ftStartTime
ullDelay
ftDueTime
PolicyVersion

Event ID 21 — Virtualization Based Security previous timer resume status HRESULT: %1 Previous timer present: %2 Start time: %3 Grace period: %4 Policy version: %...

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Virtualization Based Security previous timer resume status

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Policy version: %5
Attempted recovery increment succeeded: %6
Previous timer invalid: %7
Unlatched policy file exists: %8

Fields

NameDescription
HRESULT
PreviousTimerPresent
ftStartTime
ullDelay
PolicyVersion
fAttemptedRecoveryIncrementCounterSucceeded
fPreviousLatchTimerInvalid
fPolicyFileExists

Event ID 22 — Virtualization Based Security latch policy status HRESULT: %1 TPM counter value: %2 Expected TPM counter value: %3 Policy version: %4 Incremented: %5.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Virtualization Based Security latch policy status

HRESULT: %1
TPM counter value: %2
Expected TPM counter value: %3
Policy version: %4
Incremented: %5

Fields

NameDescription
HRESULT
Counter
PendingLKeyPkgId
PendingPolicyVersion
CounterIncremented

Event ID 23 — Boot App Anti-Rollback: Initialize Completed with status: HRESULT: %1 New timer needed: %2 New timer waiting for system update completion: %3 Previ...

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Boot App Anti-Rollback: Initialize Completed with status:
HRESULT: %1
New timer needed: %2
New timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4

Fields

NameDescription
HRESULT
NewTimerNeeded
NewTimerWaitingUpdateCompletion
PreviousTimerExistsButDisabled

Event ID 24 — Boot App Anti-Rollback: Timer start completed with status: Win32Error: %1 Start time: %2 Grace period: %3 Due time: %4.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Boot App Anti-Rollback: Timer start completed with status:

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4

Fields

NameDescription
win32Error
FileStartTime
GracePeriod
DueTime

Event ID 25 — Boot App Anti-Rollback: Previous timer resumed with status: HRESULT: %1 Previous timer present: %2 Start time: %3 Grace period: %4 Attempted recove...

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Boot App Anti-Rollback: Previous timer resumed with status:

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Attempted recovery enforcement succeeded: %5

Fields

NameDescription
HRESULT
PreviousTimerExists
PreviousTimerStartTime
GracePeriod
AttemptedRecoveryEnforcementSucceeded

Event ID 26 — Boot App Anti-Rollback: Boot.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Boot App Anti-Rollback: Boot.stl Enforcement completed with status:

HRESULT: %1
Boot Stl Enforced Successfully: %2
WNF Published with result: %3

Fields

NameDescription
HRESULT
BootStlEnforced
LocalStatus

Event ID 51 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Event ID 53 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
SessionId
Flags

Event ID 55 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
SessionId
IsRemote
GracePeriod
Flags
Reason
Message

Event ID 100 — Hybrid shutdown has been overridden by a disk check request.

Provider
Microsoft-Windows-Wininit
Channel
System

Message

Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.

Event ID 1001 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 1001 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 1015 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 1015 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3002 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3002 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3003 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3003 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3004 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3004 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3005 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3005 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3006 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3006 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 6001 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
Flags

Event ID 6002 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic

Fields

NameDescription
ShutdownFlags
SystemShutdownDuration
SkuHasLogoff

Event ID 1073742825 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

%1

Event ID 1073742825 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

Windows start-up process has failed to start the remote shutdown server.

Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3221226487 — A critical system process, .

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3221226487 — A critical system process, %1, failed with status code %2.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

A critical system process, %1, failed with status code %2.  The machine must now be restarted.

Event ID 3221228474 — Windows start-up process has unexpectedly terminated.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

Windows start-up process has unexpectedly terminated.

Event ID 3221228474 — Windows start-up process has unexpectedly terminated.

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3221228477 — Windows start-up process has failed to terminate system processes.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

Windows start-up process has failed to terminate system processes.

Event ID 3221228477 — Windows start-up process has failed to terminate system processes.

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3221228478 — Windows shudown failed with error code .

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3221228478 — Windows shudown failed with error code %1 in phase: %2.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Message

Windows shudown failed with error code %1 in phase: %2.