Microsoft-Windows-Wininit
61 events across 4 channels
Event ID 1 —
Event ID 2 —
Event ID 3 —
Event ID 4 —
Event ID 5 —
Event ID 6 —
Event ID 7 —
Event ID 8 —
Event ID 9 —
Fields #
| Name | Description |
|---|---|
Flags UInt32 | — |
Event ID 10 —
Fields #
| Name | Description |
|---|---|
Win32Status UInt32 | — |
Event ID 11 — Custom dynamic link libraries are being loaded for every application.
Event ID 12 — LSASS.
#Description
LSASS.exe was started as a protected process with level: .
Message #
Fields #
| Name | Description |
|---|---|
Data | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
"event_source_name": "",
"event_id": 12,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2021-02-09T11:59:37.890339+00:00",
"event_record_id": 5456,
"correlation": {},
"execution": {
"process_id": 560,
"thread_id": 564
},
"channel": "System",
"computer": "WIN10-client01.offsec.lan",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Data": {
"Name": "Level",
"Value": 4
}
},
"message": "LSASS.exe was started as a protected process with level: Level."
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 13 — Credential Guard was started and will protect LSA credentials.
Description
Credential Guard was started and will protect LSA credentials.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
"event_source_name": "",
"event_id": 13,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:21.619522+00:00",
"event_record_id": 2749,
"correlation": {},
"execution": {
"process_id": 928,
"thread_id": 932
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 14 — Credential Guard configuration: 0, 0
#Description
Credential Guard configuration.
Message #
Fields #
| Name | Description |
|---|---|
Config UInt32 | — |
IsTestConfig UInt32 | — |
IsAutoEnabled UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
"event_source_name": "",
"event_id": 14,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:27.117050+00:00",
"event_record_id": 1653,
"correlation": {},
"execution": {
"process_id": 636,
"thread_id": 640
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Config": 2,
"IsTestConfig": 0,
"IsAutoEnabled": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 15 — Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.
#Description
Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:27.117090+00:00",
"event_record_id": 1654,
"correlation": {},
"execution": {
"process_id": 636,
"thread_id": 640
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16 — LsaIso.
Event ID 17 — Error reading Credential Guard.
Event ID 18 — Key Guard was started and will protect VSM-isolated keys.
Description
VBS Key Isolation was started and will protect VSM-isolated keys.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
"event_source_name": "",
"event_id": 18,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:21.619506+00:00",
"event_record_id": 2748,
"correlation": {},
"execution": {
"process_id": 928,
"thread_id": 932
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 19 — Virtualization Based Security new timer creation status.
Event ID 20 — Virtualization Based Security master key timer start status.
Event ID 21 — Virtualization Based Security previous timer resume status.
Description
Virtualization Based Security previous timer resume status.
Message #
Fields #
| Name | Description |
|---|---|
HRESULT Int32 | — |
PreviousTimerPresent Boolean | — |
ftStartTime FILETIME | — |
ullDelay UInt64 | — |
PolicyVersion UInt64 | — |
fAttemptedRecoveryIncrementCounterSucceeded Boolean | — |
fPreviousLatchTimerInvalid Boolean | — |
fPolicyFileExists Boolean | — |
Event ID 22 — Virtualization Based Security latch policy status.
Event ID 23 — Boot App Anti-Rollback: Initialize Completed with status.
Event ID 24 — Boot App Anti-Rollback: Timer start completed with status.
Event ID 25 — Boot App Anti-Rollback: Previous timer resumed with status.
Event ID 26 — Boot App Anti-Rollback: Boot.
Event ID 51 —
Event ID 53 —
Fields #
| Name | Description |
|---|---|
SessionId UInt32 | — |
Flags UInt32 | — |
Event ID 55 —
Fields #
| Name | Description |
|---|---|
SessionId UInt32 | — |
IsRemote UInt32 | — |
GracePeriod UInt32 | — |
Flags UInt32 | — |
Reason UInt32 | — |
Message UnicodeString | — |
Event ID 100 — Hybrid shutdown has been overridden by a disk check request.
Description
Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.
Message #
Event ID 1001 —
Event ID 1001 —
Event ID 1015 —
Fields #
| Name | Description |
|---|---|
Data_0 | — |
Data_1 | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wininit",
"guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
"event_source_name": "Wininit",
"event_id": 1015,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T19:07:39.959249+00:00",
"event_record_id": 3508,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "C:\\Windows\\system32\\lsass.exe",
"Data_1": "c0000005",
"Binary": ""
},
"message": ""
}
Event ID 1015 —
Event ID 1015 —
Event ID 3002 —
Event ID 3002 —
Event ID 3003 —
Event ID 3003 —
Event ID 3004 —
Event ID 3004 —
Event ID 3005 —
Event ID 3005 —
Event ID 3006 —
Event ID 3006 —
Event ID 6001 —
Fields #
| Name | Description |
|---|---|
Flags UInt32 | — |
Event ID 6002 —
Fields #
| Name | Description |
|---|---|
ShutdownFlags UInt32 | — |
SystemShutdownDuration UInt64 | — |
SkuHasLogoff UInt32 | — |
Event ID 1073742825 — %1.
Message #
Event ID 1073742825 —
Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.
Description
Windows start-up process has failed to start the remote shutdown server.
Message #
Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.
Description
Windows start-up process has failed to start the remote shutdown server.
Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.
Description
Windows start-up process has failed to synchronize with the local security subsystem during setup.
Message #
Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.
Description
Windows start-up process has failed to synchronize with the local security subsystem during setup.
Event ID 3221226487 — A critical system process, %1, failed with status code %2.
Description
A critical system process, , failed with status code . The machine must now be restarted.
Message #
Event ID 3221226487 — A critical system process, .
Description
A critical system process, , failed with status code . The machine must now be restarted.
Event ID 3221228474 — Windows start-up process has unexpectedly terminated.
Description
Windows start-up process has unexpectedly terminated.
Message #
Event ID 3221228474 — Windows start-up process has unexpectedly terminated.
Description
Windows start-up process has unexpectedly terminated.
Event ID 3221228477 — Windows start-up process has failed to terminate system processes.
Description
Windows start-up process has failed to terminate system processes.
Message #
Event ID 3221228477 — Windows start-up process has failed to terminate system processes.
Description
Windows start-up process has failed to terminate system processes.
Event ID 3221228478 — Windows shudown failed with error code %1 in phase: %2.
Description
Windows shudown failed with error code in phase: .
Message #
Event ID 3221228478 — Windows shudown failed with error code .
Description
Windows shudown failed with error code in phase: .