Microsoft-Windows-Wininit

61 events across 4 channels

Event IDTitleChannel
1Diagnostic
2Diagnostic
3Diagnostic
4Diagnostic
5Diagnostic
6Diagnostic
7Diagnostic
8Diagnostic
9Diagnostic
10Diagnostic
11Custom dynamic link libraries are being loaded for every application.System
12LSASS.System
13Credential Guard was started and will protect LSA credentials.System
14Credential Guard configuration: 0, 0System
15Credential Guard and/or VBS Key Isolation are configured but the secure kernel …System
16LsaIso.System
17Error reading Credential Guard.System
18Key Guard was started and will protect VSM-isolated keys.System
19Virtualization Based Security new timer creation status.System
20Virtualization Based Security master key timer start status.System
21Virtualization Based Security previous timer resume status.System
22Virtualization Based Security latch policy status.System
23Boot App Anti-Rollback: Initialize Completed with status.System
24Boot App Anti-Rollback: Timer start completed with status.System
25Boot App Anti-Rollback: Previous timer resumed with status.System
26Boot App Anti-Rollback: Boot.System
51Diagnostic
53Diagnostic
55Diagnostic
100Hybrid shutdown has been overridden by a disk check request.System
1001Operational
1001System
1015Application
1015Operational
1015System
3002Operational
3002System
3003Operational
3003System
3004Operational
3004System
3005Operational
3005System
3006Operational
3006System
6001Diagnostic
6002Diagnostic
1073742825%1.Operational
1073742825System
2147486651Windows start-up process has failed to start the remote shutdown server.Operational
2147486651Windows start-up process has failed to start the remote shutdown server.System
2147486652Windows start-up process has failed to synchronize with the local security …Operational
2147486652Windows start-up process has failed to synchronize with the local security …System
3221226487A critical system process, %1, failed with status code %2.Operational
3221226487A critical system process, .System
3221228474Windows start-up process has unexpectedly terminated.Operational
3221228474Windows start-up process has unexpectedly terminated.System
3221228477Windows start-up process has failed to terminate system processes.Operational
3221228477Windows start-up process has failed to terminate system processes.System
3221228478Windows shudown failed with error code %1 in phase: %2.Operational
3221228478Windows shudown failed with error code .System

Event ID 1 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForWinstationShutdown
Opcode
Start

Event ID 2 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForWinstationShutdown
Opcode
Stop

Event ID 3 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PreShutdownNotification
Opcode
Start

Event ID 4 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PreShutdownNotification
Opcode
Stop

Event ID 5 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForSystemProcesses
Opcode
Start

Event ID 6 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForSystemProcesses
Opcode
Stop

Event ID 7 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownSystemRestore
Opcode
Start

Event ID 8 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownSystemRestore
Opcode
Stop

Event ID 9 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 10 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 11 — Custom dynamic link libraries are being loaded for every application.

Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Message #

Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Fields #

NameDescription
StringCount UInt32
String UnicodeString

Event ID 12 — LSASS.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

LSASS.exe was started as a protected process with level: .

Message #

LSASS.exe was started as a protected process with level: %1.

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2021-02-09T11:59:37.890339+00:00",
    "event_record_id": 5456,
    "correlation": {},
    "execution": {
      "process_id": 560,
      "thread_id": 564
    },
    "channel": "System",
    "computer": "WIN10-client01.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": {
      "Name": "Level",
      "Value": 4
    }
  },
  "message": "LSASS.exe was started as a protected process with level: Level."
}

References #

Event ID 13 — Credential Guard was started and will protect LSA credentials.

Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

Credential Guard was started and will protect LSA credentials.

Message #

Credential Guard was started and will protect LSA credentials.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:27:21.619522+00:00",
    "event_record_id": 2749,
    "correlation": {},
    "execution": {
      "process_id": 928,
      "thread_id": 932
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 14 — Credential Guard configuration: 0, 0

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

Credential Guard configuration.

Message #

Credential Guard configuration:

Registry Configuration: %1
Test Configuration: %2
Auto Enablement: %3

Fields #

NameDescription
Config UInt32
IsTestConfig UInt32
IsAutoEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 14,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:27.117050+00:00",
    "event_record_id": 1653,
    "correlation": {},
    "execution": {
      "process_id": 636,
      "thread_id": 640
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Config": 2,
    "IsTestConfig": 0,
    "IsAutoEnabled": 1
  },
  "message": ""
}

References #

Event ID 15 — Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Warning
Opcode
Info

Description

Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Message #

Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 15,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:27.117090+00:00",
    "event_record_id": 1654,
    "correlation": {},
    "execution": {
      "process_id": 636,
      "thread_id": 640
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 16 — LsaIso.

Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Description

LsaIso.exe, the host process for Credential Guard and VBS Key Isolation, failed to launch: Level.

Message #

LsaIso.exe, the host process for Credential Guard and VBS Key Isolation, failed to launch: %1

Fields #

NameDescription
Level UInt32

Event ID 17 — Error reading Credential Guard.

Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Description

Error reading Credential Guard (LsaIso.exe) UEFI configuration: Level.

Message #

Error reading Credential Guard (LsaIso.exe) UEFI configuration: %1

Fields #

NameDescription
Level UInt32

Event ID 18 — Key Guard was started and will protect VSM-isolated keys.

Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

VBS Key Isolation was started and will protect VSM-isolated keys.

Message #

VBS Key Isolation was started and will protect VSM-isolated keys.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 18,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:27:21.619506+00:00",
    "event_record_id": 2748,
    "correlation": {},
    "execution": {
      "process_id": 928,
      "thread_id": 932
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19 — Virtualization Based Security new timer creation status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security new timer creation status.

Message #

Virtualization Based Security new timer creation status

HRESULT: %1
New latch timer needed: %2
New latch timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4
Policy file exists: %5

Fields #

NameDescription
HRESULT Int32
NewLatchTimerNeeded Boolean
NewLatchTimerWaitingSystemUpdateCompletion Boolean
PreviousLatchTimerExistsButDisabled Boolean
PolicyFileExists Boolean

Event ID 20 — Virtualization Based Security master key timer start status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security master key timer start status.

Message #

Virtualization Based Security master key timer start status

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4
Policy version: %5

Fields #

NameDescription
win32Error UInt32
ftStartTime FILETIME
ullDelay UInt64
ftDueTime FILETIME
PolicyVersion UInt64

Event ID 21 — Virtualization Based Security previous timer resume status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security previous timer resume status.

Message #

Virtualization Based Security previous timer resume status

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Policy version: %5
Attempted recovery increment succeeded: %6
Previous timer invalid: %7
Unlatched policy file exists: %8

Fields #

NameDescription
HRESULT Int32
PreviousTimerPresent Boolean
ftStartTime FILETIME
ullDelay UInt64
PolicyVersion UInt64
fAttemptedRecoveryIncrementCounterSucceeded Boolean
fPreviousLatchTimerInvalid Boolean
fPolicyFileExists Boolean

Event ID 22 — Virtualization Based Security latch policy status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security latch policy status.

Message #

Virtualization Based Security latch policy status

HRESULT: %1
TPM counter value: %2
Expected TPM counter value: %3
Policy version: %4
Incremented: %5

Fields #

NameDescription
HRESULT Int32
Counter UInt64
PendingLKeyPkgId UInt64
PendingPolicyVersion UInt64
CounterIncremented Boolean

Event ID 23 — Boot App Anti-Rollback: Initialize Completed with status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Initialize Completed with status.

Message #

Boot App Anti-Rollback: Initialize Completed with status:
HRESULT: %1
New timer needed: %2
New timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4

Fields #

NameDescription
HRESULT Int32
NewTimerNeeded Boolean
NewTimerWaitingUpdateCompletion Boolean
PreviousTimerExistsButDisabled Boolean

Event ID 24 — Boot App Anti-Rollback: Timer start completed with status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Timer start completed with status.

Message #

Boot App Anti-Rollback: Timer start completed with status:

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4

Fields #

NameDescription
win32Error UInt32
FileStartTime FILETIME
GracePeriod UInt64
DueTime FILETIME

Event ID 25 — Boot App Anti-Rollback: Previous timer resumed with status.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Previous timer resumed with status.

Message #

Boot App Anti-Rollback: Previous timer resumed with status:

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Attempted recovery enforcement succeeded: %5

Fields #

NameDescription
HRESULT Int32
PreviousTimerExists Boolean
PreviousTimerStartTime FILETIME
GracePeriod UInt64
AttemptedRecoveryEnforcementSucceeded Boolean

Event ID 26 — Boot App Anti-Rollback: Boot.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Boot.stl Enforcement completed with status.

Message #

Boot App Anti-Rollback: Boot.stl Enforcement completed with status:

HRESULT: %1
Boot Stl Enforced Successfully: %2
WNF Published with result: %3

Fields #

NameDescription
HRESULT Int32
BootStlEnforced Boolean
LocalStatus HexInt32

Event ID 51 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
NtShutdownSystem

Event ID 53 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
SentLogoffRequest

Fields #

NameDescription
SessionId UInt32
Flags UInt32

Event ID 55 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ReceivedShutdownRequest

Fields #

NameDescription
SessionId UInt32
IsRemote UInt32
GracePeriod UInt32
Flags UInt32
Reason UInt32
Message UnicodeString

Event ID 100 — Hybrid shutdown has been overridden by a disk check request.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.

Message #

Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.

Event ID 1001 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 1001 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 1015 —

Provider
Microsoft-Windows-Wininit
Channel
Application
Level
Error

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
    "event_source_name": "Wininit",
    "event_id": 1015,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T19:07:39.959249+00:00",
    "event_record_id": 3508,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "C:\\Windows\\system32\\lsass.exe",
    "Data_1": "c0000005",
    "Binary": ""
  },
  "message": ""
}

Event ID 1015 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 1015 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3002 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3002 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3003 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3003 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3004 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3004 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3005 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3005 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3006 —

Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3006 —

Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 6001 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownDiagnostics
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 6002 —

Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PerfTrackFullShutdown

Fields #

NameDescription
ShutdownFlags UInt32
SystemShutdownDuration UInt64
SkuHasLogoff UInt32

Event ID 1073742825 — %1.

Provider
Microsoft-Windows-Wininit
Channel
Operational
Opcode
Info

Message #

%1

Event ID 1073742825 —

Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to start the remote shutdown server.

Message #

Windows start-up process has failed to start the remote shutdown server.

Event ID 2147486651 — Windows start-up process has failed to start the remote shutdown server.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to start the remote shutdown server.

Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Message #

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Event ID 2147486652 — Windows start-up process has failed to synchronize with the local security subsystem during setup.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Event ID 3221226487 — A critical system process, %1, failed with status code %2.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

A critical system process, , failed with status code . The machine must now be restarted.

Message #

A critical system process, %1, failed with status code %2.  The machine must now be restarted.

Event ID 3221226487 — A critical system process, .

Provider
Microsoft-Windows-Wininit
Channel
System

Description

A critical system process, , failed with status code . The machine must now be restarted.

Event ID 3221228474 — Windows start-up process has unexpectedly terminated.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has unexpectedly terminated.

Message #

Windows start-up process has unexpectedly terminated.

Event ID 3221228474 — Windows start-up process has unexpectedly terminated.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has unexpectedly terminated.

Event ID 3221228477 — Windows start-up process has failed to terminate system processes.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to terminate system processes.

Message #

Windows start-up process has failed to terminate system processes.

Event ID 3221228477 — Windows start-up process has failed to terminate system processes.

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to terminate system processes.

Event ID 3221228478 — Windows shudown failed with error code %1 in phase: %2.

Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows shudown failed with error code in phase: .

Message #

Windows shudown failed with error code %1 in phase: %2.

Event ID 3221228478 — Windows shudown failed with error code .

Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows shudown failed with error code in phase: .