Windows Kernel Trace

141 events across 1 channel

EventTitleChannel
0FileIo_NameETW Trace
1Thread_TypeGroup1ETW Trace
2Thread_TypeGroup1ETW Trace
3Thread_TypeGroup1ETW Trace
4Thread_TypeGroup1ETW Trace
5Header_Extension_TypeGroupETW Trace
8RDCompleteETW Trace
10SystemConfig_V3_CPUETW Trace
11DiskIo_TypeGroup1ETW Trace
12DiskIo_TypeGroup2ETW Trace
13DiskIo_TypeGroup2ETW Trace
14DiskIo_TypeGroup3ETW Trace
15SystemConfig_V3_ServicesETW Trace
16Registry_TypeGroup1ETW Trace
17UdpIp_FailETW Trace
18Registry_TypeGroup1ETW Trace
19Registry_TypeGroup1ETW Trace
20Registry_TypeGroup1ETW Trace
21SystemConfig_V3_IRQETW Trace
22SystemConfig_PnPETW Trace
23Registry_TypeGroup1ETW Trace
24Registry_TypeGroup1ETW Trace
25Registry_TypeGroup1ETW Trace
26UdpIp_TypeGroup2ETW Trace
27UdpIp_TypeGroup2ETW Trace
28Registry_TypeGroup1ETW Trace
29Registry_TypeGroup1ETW Trace
30Registry_TxRETW Trace
31Registry_TxRETW Trace
32SystemConfig_V4_MobilePlatformETW Trace
33ObHandleEventETW Trace
34ObHandleDuplicateEventETW Trace
35FileIo_NameETW Trace
36CSwitch_V4ETW Trace
37FileIo_V2_MapFileETW Trace
38FileIo_V2_MapFileETW Trace
39Process_Defunct_TypeGroup1ETW Trace
40FileIo_V2_MapFileETW Trace
41SpinLockETW Trace
42PoolSnapshotETW Trace
43PoolSnapshotETW Trace
44PoolSnapshotETW Trace
45PoolSnapshotETW Trace
46SampledProfileETW Trace
47PmcCounterProfileETW Trace
48ThreadPriorityETW Trace
49ThreadPriorityETW Trace
50ObReferenceEventETW Trace
51ThreadPriorityETW Trace
52ThreadPriorityETW Trace
53ThreadAffinityETW Trace
55DiskIo_TypeGroup1ETW Trace
56DiskIo_TypeGroup1ETW Trace
57DiskIo_TypeGroup3ETW Trace
58DiskIo_TypeGroup2ETW Trace
59DiskIo_TypeGroup2ETW Trace
60DiskIo_TypeGroup2ETW Trace
61ThreadMigrationETW Trace
62KernelQueueEnqueueETW Trace
63KernelQueueDequeueETW Trace
64FileIo_CreateETW Trace
65FileIo_SimpleOpETW Trace
66FileIo_SimpleOpETW Trace
67FileIo_ReadWriteETW Trace
68FileIo_ReadWriteETW Trace
69FileIo_InfoETW Trace
70FileIo_InfoETW Trace
71FileIo_InfoETW Trace
72FileIo_DirEnumETW Trace
73SampledProfileInterval_V3ETW Trace
74SampledProfileInterval_V3ETW Trace
75SpinLockConfig_V3ETW Trace
76SpinLockConfig_V3ETW Trace
77FileIo_DirEnumETW Trace
79FileIo_PathOperationETW Trace
80FileIo_PathOperationETW Trace
81FileIo_PathOperationETW Trace
82Header_LastDroppedTimes_TypeGroupETW Trace
83Process_V2_TypeGroup4ETW Trace
84Process_V2_TypeGroup4ETW Trace
92ISR_UnexpectedETW Trace
93IoTimerEventETW Trace
94IoTimerEventETW Trace
95ISRETW Trace
96FltIoInitETW Trace
97FltIoInitETW Trace
98FltIoCompletionETW Trace
99FltIoCompletionETW Trace
100PageFault_HeapRangeRundownETW Trace
101FltIoFailureETW Trace
102PageFault_HeapRangeTypeGroupETW Trace
103PageFault_HeapRangeTypeGroupETW Trace
104PageFault_HeapRangeDestroyETW Trace
105PageFault_ImageLoadBackedETW Trace
106CancelKTimer2ETW Trace
107DisableKTimer2ETW Trace
108FinalizeKTimer2ETW Trace
114HV_HypercallETW Trace
122ContextRegistersAMD64ETW Trace
123ContextRegistersARM64ETW Trace
127PageFault_VirtualRotateETW Trace
128PageFault_VirtualAllocRundownETW Trace
129PageFault_VirtualAllocRundownETW Trace
130LoaderBasicEventETW Trace
131LoaderBasicEventETW Trace
132LoaderBasicEventETW Trace
133LoaderBasicEventETW Trace
134PageFault_MemResetETW Trace
135LoaderBasicEventETW Trace
144LoaderBaseEventETW Trace
145LoaderBaseEventETW Trace
146LoaderBaseEventETW Trace
147LoaderBaseEventETW Trace
148LoaderBaseEventETW Trace
149LoaderBaseEventETW Trace
150LoaderBaseEventETW Trace
160LoaderCodedEventETW Trace
161LoaderCodedEventETW Trace
162LoaderCodedEventETW Trace
163LoaderCodedEventETW Trace
164LoaderCodedEventETW Trace
165LoaderCodedEventStatusETW Trace
166LoaderCodedEventStatusETW Trace
167LoaderCodedEventStatusETW Trace
168LoaderCodedEventStatusETW Trace
169LoaderCodedEventStatusETW Trace
170LoaderCodedEventStatusETW Trace
171LoaderCodedEventStatusETW Trace
172LoaderCodedEventStatusETW Trace
173LoaderCodedEventStatusETW Trace
174LoaderCodedEventStatusETW Trace
176LoaderNewDllEventETW Trace
177LoaderNewDllEventETW Trace
192LoaderCodedEventPathETW Trace
193LoaderCodedEventPathETW Trace
208LoaderCodedEventStatusETW Trace
209LoaderCodedEventStatusETW Trace
210LoaderCodedEventStatusETW Trace
211LoaderCodedEventStatusETW Trace
212LoaderDllSearchResultsETW Trace
213LoaderPathSearchResultsETW Trace

Event ID 0: FileIo_Name

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
FileObject mof:UInt32
FileName mof:String

Event ID 1: Thread_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
TThreadId mof:UInt32
StackBase mof:UInt32
StackLimit mof:UInt32
UserStackBase mof:UInt32
UserStackLimit mof:UInt32
Affinity mof:UInt32
Win32StartAddr mof:UInt32
TebBase mof:UInt32
SubProcessTag mof:UInt32
BasePriority mof:UInt8
PagePriority mof:UInt8
IoPriority mof:UInt8
ThreadFlags mof:UInt8
ThreadName mof:String

Event ID 2: Thread_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
TThreadId mof:UInt32
StackBase mof:UInt32
StackLimit mof:UInt32
UserStackBase mof:UInt32
UserStackLimit mof:UInt32
Affinity mof:UInt32
Win32StartAddr mof:UInt32
TebBase mof:UInt32
SubProcessTag mof:UInt32
BasePriority mof:UInt8
PagePriority mof:UInt8
IoPriority mof:UInt8
ThreadFlags mof:UInt8
ThreadName mof:String

Event ID 3: Thread_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
TThreadId mof:UInt32
StackBase mof:UInt32
StackLimit mof:UInt32
UserStackBase mof:UInt32
UserStackLimit mof:UInt32
Affinity mof:UInt32
Win32StartAddr mof:UInt32
TebBase mof:UInt32
SubProcessTag mof:UInt32
BasePriority mof:UInt8
PagePriority mof:UInt8
IoPriority mof:UInt8
ThreadFlags mof:UInt8
ThreadName mof:String

Event ID 4: Thread_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
TThreadId mof:UInt32
StackBase mof:UInt32
StackLimit mof:UInt32
UserStackBase mof:UInt32
UserStackLimit mof:UInt32
Affinity mof:UInt32
Win32StartAddr mof:UInt32
TebBase mof:UInt32
SubProcessTag mof:UInt32
BasePriority mof:UInt8
PagePriority mof:UInt8
IoPriority mof:UInt8
ThreadFlags mof:UInt8
ThreadName mof:String

Event ID 5: Header_Extension_TypeGroup

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
GroupMask1 mof:UInt32
GroupMask2 mof:UInt32
GroupMask3 mof:UInt32
GroupMask4 mof:UInt32
GroupMask5 mof:UInt32
GroupMask6 mof:UInt32
GroupMask7 mof:UInt32
GroupMask8 mof:UInt32
KernelEventVersion mof:UInt32

Event ID 8: RDComplete

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 10: SystemConfig_V3_CPU

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
MHz mof:UInt32
NumberOfProcessors mof:UInt32
MemSize mof:UInt32
PageSize mof:UInt32
AllocationGranularity mof:UInt32
ComputerName mof:Char16
DomainName mof:Char16
HyperThreadingFlag mof:UInt32
HighestUserAddress mof:UInt32
ProcessorArchitecture mof:UInt16
ProcessorLevel mof:UInt16
ProcessorRevision mof:UInt16
PaeEnabled mof:UInt8
NxEnabled mof:UInt8
MemorySpeed mof:UInt32

Event ID 11: DiskIo_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt32
IrpFlags mof:UInt32
TransferSize mof:UInt32
Reserved mof:UInt32
ByteOffset mof:UInt64
FileObject mof:UInt32
Irp mof:UInt32
HighResResponseTime mof:UInt64
IssuingThreadId mof:UInt32

Event ID 12: DiskIo_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 13: DiskIo_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 14: DiskIo_TypeGroup3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt32
IrpFlags mof:UInt32
HighResResponseTime mof:UInt64
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 15: SystemConfig_V3_Services

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
ServiceState mof:UInt32
SubProcessTag mof:UInt32
ServiceName mof:String
DisplayName mof:String
ProcessName mof:String
LoadOrderGroup mof:String
SvchostGroup mof:String

Event ID 16: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
S1 mof:UInt8
S2 mof:UInt8
S3 mof:UInt8
S4 mof:UInt8
S5 mof:UInt8
Pad1 mof:UInt8
Pad2 mof:UInt8
Pad3 mof:UInt8

Event ID 17: UdpIp_Fail

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:SInt64
Status mof:UInt32NTSTATUS reference
Index mof:UInt32
KeyHandle mof:UInt32
KeyName mof:String

Event ID 18: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt16
BusType mof:UInt16
DeviceType mof:UInt16
MediaType mof:UInt16
StartingOffset mof:UInt64
Size mof:UInt64
NumberOfFreeBlocks mof:UInt64
TotalNumberOfBlocks mof:UInt64
NextWritableAddress mof:UInt64
NumberOfSessions mof:UInt32
NumberOfTracks mof:UInt32
BytesPerSector mof:UInt32
DiscStatus mof:UInt16
LastSessionStatus mof:UInt16
DriveLetter mof:String
FileSystemName mof:String
DeviceName mof:String
ManufacturerName mof:String

Event ID 19: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:SInt64
Status mof:UInt32NTSTATUS reference
Index mof:UInt32
KeyHandle mof:UInt32
KeyName mof:String

Event ID 20: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:SInt64
Status mof:UInt32NTSTATUS reference
Index mof:UInt32
KeyHandle mof:UInt32
KeyName mof:String

Event ID 21: SystemConfig_V3_IRQ

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IRQAffinity mof:UInt64
IRQGroup mof:UInt16
Reserved mof:UInt16
IRQNum mof:UInt32
DeviceDescriptionLen mof:UInt32
DeviceDescription mof:String

Event ID 22: SystemConfig_PnP

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ClassGuid mof:Object
UpperFiltersCount mof:UInt32
LowerFiltersCount mof:UInt32
DevStatus mof:UInt32
DevProblem mof:UInt32
DeviceID mof:String
DeviceDescription mof:String
FriendlyName mof:String
PdoName mof:String
ServiceName mof:String
UpperFilters mof:String
LowerFilters mof:String

Event ID 23: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
TargetId mof:UInt32
DeviceType mof:UInt32
DeviceTimingMode mof:UInt32
LocationInformationLen mof:UInt32
LocationInformation mof:String

Event ID 24: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:SInt64
Status mof:UInt32NTSTATUS reference
Index mof:UInt32
KeyHandle mof:UInt32
KeyName mof:String

Event ID 25: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:SInt64
Status mof:UInt32NTSTATUS reference
Index mof:UInt32
KeyHandle mof:UInt32
KeyName mof:String

Event ID 26: UdpIp_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
PID mof:UInt32
size mof:UInt32
daddr mof:Object
saddr mof:Object
dport mof:Object
sport mof:Object
startime mof:UInt32
endtime mof:UInt32
seqnum mof:UInt32
connid mof:UInt32

Event ID 27: UdpIp_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
PID mof:UInt32
size mof:UInt32
daddr mof:Object
saddr mof:Object
dport mof:Object
sport mof:Object
seqnum mof:UInt32
connid mof:UInt32

Event ID 28: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
PID mof:UInt32
size mof:UInt32
daddr mof:Object
saddr mof:Object
dport mof:Object
sport mof:Object
mss mof:UInt16
sackopt mof:UInt16
tsopt mof:UInt16
wsopt mof:UInt16
rcvwin mof:UInt32
rcvwinscale mof:SInt16
sndwinscale mof:SInt16
seqnum mof:UInt32
connid mof:UInt32

Event ID 29: Registry_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
PID mof:UInt32
size mof:UInt32
daddr mof:Object
saddr mof:Object
dport mof:Object
sport mof:Object
seqnum mof:UInt32
connid mof:UInt32

Event ID 30: Registry_TxR

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
PID mof:UInt32
size mof:UInt32
daddr mof:Object
saddr mof:Object
dport mof:Object
sport mof:Object
seqnum mof:UInt32
connid mof:UInt32

Event ID 31: Registry_TxR

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
AlignmentClusters mof:UInt64
AvgFreeSpaceSize mof:UInt64
ClustersPerSlab mof:UInt64
FragmentedDirectoryExtents mof:UInt64
FragmentedExtents mof:UInt64
FreeSpaceCount mof:UInt64
LargestFreeSpaceSize mof:UInt64
LastRunActualPurgeClusters mof:UInt64
LastRunClustersTrimmed mof:UInt64
LastRunFullDefragTime mof:UInt64
LastRunTime mof:UInt64
MFTSize mof:UInt64
TotalClusters mof:UInt64
TotalUsedClusters mof:UInt64
AvgFragmentsPerFile mof:UInt32
BytesPerCluster mof:UInt32
DirectoryCount mof:UInt32
FragmentedDirectories mof:UInt32
FragmentedFiles mof:UInt32
FragmentedSpace mof:UInt32
HardwareIssue mof:UInt32
InUseMFTRecords mof:UInt32
InUseSlabs mof:UInt32
LastRunActualPurgeSlabs mof:UInt32
LastRunInitialBackedSlabs mof:UInt32
LastRunPercentFragmentation mof:UInt32
LastRunPinnedSlabs mof:UInt32
LastRunPotentialPurgeSlabs mof:UInt32
LastRunSpaceInefficientSlabs mof:UInt32
LastRunTrimmedSlabs mof:UInt32
LastRunUnknownEvictFailSlabs mof:UInt32
LastRunVolsnapPinnedSlabs mof:UInt32
MFTFragmentCount mof:UInt32
MovableFiles mof:UInt32
TotalMFTRecords mof:UInt32
TotalSlabs mof:UInt32
UnmovableFiles mof:UInt32
VolumeId mof:Object
VolumePathNames mof:String

Event ID 32: SystemConfig_V4_MobilePlatform

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DeviceManufacturer mof:String
DeviceManufacturerDisplayName mof:String
DeviceModel mof:String
DeviceModelDisplayName mof:String
MobileOperator mof:String
SocVersion mof:String
BspVersion mof:String

Event ID 33: ObHandleEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ProcessId mof:UInt32
PageFaultCount mof:UInt32
HandleCount mof:UInt32
Reserved mof:UInt32
PeakVirtualSize mof:Object
PeakWorkingSetSize mof:Object
PeakPagefileUsage mof:Object
QuotaPeakPagedPoolUsage mof:Object
QuotaPeakNonPagedPoolUsage mof:Object
VirtualSize mof:Object
WorkingSetSize mof:Object
PagefileUsage mof:Object
QuotaPagedPoolUsage mof:Object
QuotaNonPagedPoolUsage mof:Object
PrivatePageCount mof:Object

Event ID 34: ObHandleDuplicateEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Counter1 mof:UInt64
Counter2 mof:UInt64
Counter3 mof:UInt64
Counter4 mof:UInt64
Counter5 mof:UInt64
Counter6 mof:UInt64
Counter7 mof:UInt64
Counter8 mof:UInt64
Counter9 mof:UInt64
Counter10 mof:UInt64
Counter11 mof:UInt64

Event ID 35: FileIo_Name

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
FileObject mof:UInt32
FileName mof:String

Event ID 36: CSwitch_V4

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
NewThreadId mof:UInt32
OldThreadId mof:UInt32
NewThreadPriority mof:SInt8
OldThreadPriority mof:SInt8
PreviousCState mof:UInt8
SpareByte mof:SInt8
OldThreadWaitReason mof:SInt8
ThreadFlags mof:SInt8
OldThreadState mof:SInt8
OldThreadWaitIdealProcessor mof:SInt8
NewThreadWaitTime mof:UInt32
Reserved mof:UInt32

Event ID 37: FileIo_V2_MapFile

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BootFlags mof:UInt64
FirmwareType mof:UInt32
SecureBootEnabled mof:UInt8
SecureBootCapable mof:UInt8
Reserved1 mof:UInt8
Reserved2 mof:UInt8

Event ID 38: FileIo_V2_MapFile

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Object mof:UInt32
ProcessId mof:UInt32
Handle mof:UInt32
ObjectType mof:UInt16
ObjectName mof:String

Event ID 39: Process_Defunct_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
UniqueProcessKey mof:UInt32
ProcessId mof:UInt32
ParentId mof:UInt32
SessionId mof:UInt32
ExitStatus mof:SInt32
DirectoryTableBase mof:UInt32
Flags mof:UInt32
UserSID mof:Object
ImageFileName mof:String
CommandLine mof:String
PackageFullName mof:String
ApplicationId mof:String
ExitTime mof:UInt64

Event ID 40: FileIo_V2_MapFile

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ViewBase mof:UInt32
FileObject mof:UInt32
MiscInfo mof:UInt64
ViewSize mof:Object
ProcessId mof:UInt32

Event ID 41: SpinLock

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
SpinLockAddress mof:UInt32
CallerAddress mof:UInt32
AcquireTime mof:UInt64
ReleaseTime mof:UInt64
WaitTimeInCycles mof:UInt32
SpinCount mof:UInt32
ThreadId mof:UInt32
InterruptCount mof:UInt32
Irql mof:UInt8
AcquireDepth mof:UInt8
Flag mof:UInt8
Reserved mof:UInt8

Event ID 42: PoolSnapshot

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 43: PoolSnapshot

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 44: PoolSnapshot

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 45: PoolSnapshot

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 46: SampledProfile

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InstructionPointer mof:UInt32
ThreadId mof:UInt32
Count mof:UInt16
Reserved mof:UInt16

Event ID 47: PmcCounterProfile

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InstructionPointer mof:UInt32
ThreadId mof:UInt32
ProfileSource mof:UInt16
Reserved mof:UInt16

Event ID 48: ThreadPriority

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
OldPriority mof:UInt8
NewPriority mof:UInt8
Reserved mof:UInt16

Event ID 49: ThreadPriority

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
OldPriority mof:UInt8
NewPriority mof:UInt8
Reserved mof:UInt16

Event ID 50: ObReferenceEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:Object
Routine mof:UInt32
ReturnValue mof:UInt8
Vector mof:UInt16
Reserved mof:UInt8
MessageNumber mof:UInt32

Event ID 51: ThreadPriority

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
OldPriority mof:UInt8
NewPriority mof:UInt8
Reserved mof:UInt16

Event ID 52: ThreadPriority

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
OldPriority mof:UInt8
NewPriority mof:UInt8
Reserved mof:UInt16

Event ID 53: ThreadAffinity

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Affinity mof:UInt32
ThreadId mof:UInt32
Group mof:UInt16
Reserved mof:UInt16

Event ID 55: DiskIo_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt32
IrpFlags mof:UInt32
TransferSize mof:UInt32
Reserved mof:UInt32
ByteOffset mof:UInt64
FileObject mof:UInt32
Irp mof:UInt32
HighResResponseTime mof:UInt64
IssuingThreadId mof:UInt32

Event ID 56: DiskIo_TypeGroup1

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt32
IrpFlags mof:UInt32
TransferSize mof:UInt32
Reserved mof:UInt32
ByteOffset mof:UInt64
FileObject mof:UInt32
Irp mof:UInt32
HighResResponseTime mof:UInt64
IssuingThreadId mof:UInt32

Event ID 57: DiskIo_TypeGroup3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DiskNumber mof:UInt32
IrpFlags mof:UInt32
HighResResponseTime mof:UInt64
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 58: DiskIo_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 59: DiskIo_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 60: DiskIo_TypeGroup2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Irp mof:UInt32
IssuingThreadId mof:UInt32

Event ID 61: ThreadMigration

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
SourceProcessorIndex mof:UInt16
TargetProcessorIndex mof:UInt16
Priority mof:UInt8
IdealProcessorAdjust mof:Boolean
OldIdealProcessorIndex mof:UInt16

Event ID 62: KernelQueueEnqueue

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Entry mof:UInt32
ThreadId mof:UInt32

Event ID 63: KernelQueueDequeue

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
ThreadId mof:UInt32
EntryCount mof:UInt32
Entries mof:UInt32

Event ID 64: FileIo_Create

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
TTID mof:UInt32
CreateOptions mof:UInt32
FileAttributes mof:UInt32
ShareAccess mof:UInt32
OpenPath mof:String

Event ID 65: FileIo_SimpleOp

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32

Event ID 66: FileIo_SimpleOp

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32

Event ID 67: FileIo_ReadWrite

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Offset mof:UInt64
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32
IoSize mof:UInt32
IoFlags mof:UInt32

Event ID 68: FileIo_ReadWrite

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Offset mof:UInt64
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32
IoSize mof:UInt32
IoFlags mof:UInt32

Event ID 69: FileIo_Info

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32

Event ID 70: FileIo_Info

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32

Event ID 71: FileIo_Info

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32

Event ID 72: FileIo_DirEnum

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32
Length mof:UInt32
InfoClass mof:UInt32
FileIndex mof:UInt32
FileName mof:String

Event ID 73: SampledProfileInterval_V3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32

Event ID 74: SampledProfileInterval_V3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32

Event ID 75: SpinLockConfig_V3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32

Event ID 76: SpinLockConfig_V3

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
SpinLockSpinThreshold mof:UInt32
SpinLockContentionSampleRate mof:UInt32
SpinLockAcquireSampleRate mof:UInt32
SpinLockHoldThreshold mof:UInt32

Event ID 77: FileIo_DirEnum

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
TTID mof:UInt32
Length mof:UInt32
InfoClass mof:UInt32
FileIndex mof:UInt32
FileName mof:String

Event ID 79: FileIo_PathOperation

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32
FileName mof:String

Event ID 80: FileIo_PathOperation

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32
FileName mof:String

Event ID 81: FileIo_PathOperation

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
IrpPtr mof:UInt32
FileObject mof:UInt32
FileKey mof:UInt32
ExtraInfo mof:UInt32
TTID mof:UInt32
InfoClass mof:UInt32
FileName mof:String

Event ID 82: Header_LastDroppedTimes_TypeGroup

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Object mof:UInt32
Tag mof:UInt32
ProcessId mof:UInt32
Count mof:UInt32

Event ID 83: Process_V2_TypeGroup4

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Object mof:UInt32
Tag mof:UInt32
ProcessId mof:UInt32
Count mof:UInt32

Event ID 84: Process_V2_TypeGroup4

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Object mof:UInt32
Tag mof:UInt32
ProcessId mof:UInt32
Count mof:UInt32

Event ID 92: ISR_Unexpected

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Vector mof:UInt16

Event ID 93: IoTimerEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DeviceObject mof:UInt32
TimerRoutine mof:UInt32

Event ID 94: IoTimerEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DeviceObject mof:UInt32
TimerRoutine mof:UInt32

Event ID 95: ISR

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:Object
Routine mof:UInt32
ReturnValue mof:UInt8
Vector mof:UInt16
Reserved mof:UInt8

Event ID 96: FltIoInit

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
RoutineAddr mof:UInt32
FileObject mof:UInt32
FileContext mof:UInt32
IrpPtr mof:UInt32
CallbackDataPtr mof:UInt32
MajorFunction mof:UInt32

Event ID 97: FltIoInit

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
RoutineAddr mof:UInt32
FileObject mof:UInt32
FileContext mof:UInt32
IrpPtr mof:UInt32
CallbackDataPtr mof:UInt32
MajorFunction mof:UInt32

Event ID 98: FltIoCompletion

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:Object
RoutineAddr mof:UInt32
FileObject mof:UInt32
FileContext mof:UInt32
IrpPtr mof:UInt32
CallbackDataPtr mof:UInt32
MajorFunction mof:UInt32

Event ID 99: FltIoCompletion

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
InitialTime mof:Object
RoutineAddr mof:UInt32
FileObject mof:UInt32
FileContext mof:UInt32
IrpPtr mof:UInt32
CallbackDataPtr mof:UInt32
MajorFunction mof:UInt32

Event ID 100: PageFault_HeapRangeRundown

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
HeapHandle mof:UInt32
HRFlags mof:UInt32
HRPid mof:UInt32
HRRangeCount mof:UInt32
HRHeapTag mof:UInt64

Event ID 101: FltIoFailure

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
RoutineAddr mof:UInt32
FileObject mof:UInt32
FileContext mof:UInt32
IrpPtr mof:UInt32
CallbackDataPtr mof:UInt32
MajorFunction mof:UInt32
Status mof:UInt32NTSTATUS reference

Event ID 102: PageFault_HeapRangeTypeGroup

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
HeapHandle mof:UInt32
HRAddress mof:UInt32
HRSize mof:Object

Event ID 103: PageFault_HeapRangeTypeGroup

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
HeapHandle mof:UInt32
HRAddress mof:UInt32
HRSize mof:Object

Event ID 104: PageFault_HeapRangeDestroy

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DueTime mof:UInt64
MaximumDueTime mof:UInt64
Period mof:UInt64
Timer mof:UInt32
Callback mof:UInt32
CallbackContext mof:UInt32
TimerFlags mof:UInt8

Event ID 105: PageFault_ImageLoadBacked

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
DueTime mof:UInt64
MaximumDueTime mof:UInt64
Period mof:UInt64
Timer mof:UInt32
Callback mof:UInt32
CallbackContext mof:UInt32
TimerFlags mof:UInt8

Event ID 106: CancelKTimer2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Timer mof:UInt32

Event ID 107: DisableKTimer2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Timer mof:UInt32
DisableCallback mof:UInt32
DisableContext mof:UInt32
TimerFlags mof:UInt8

Event ID 108: FinalizeKTimer2

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Timer mof:UInt32
DisableCallback mof:UInt32
DisableContext mof:UInt32

Event ID 114: HV_Hypercall

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
CallCode mof:UInt32
IsFast mof:UInt8
IsNested mof:UInt8

Event ID 122: ContextRegistersAMD64

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Rip mof:UInt64
Rax mof:UInt64
Rcx mof:UInt64
Rdx mof:UInt64
Rbx mof:UInt64
Rsp mof:UInt64
Rsi mof:UInt64
Rdi mof:UInt64
R8 mof:UInt64
R9 mof:UInt64
R10 mof:UInt64
R11 mof:UInt64
R12 mof:UInt64
R13 mof:UInt64
R14 mof:UInt64
R15 mof:UInt64

Event ID 123: ContextRegistersARM64

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Cpsr mof:UInt32
X0 mof:UInt64
X1 mof:UInt64
X2 mof:UInt64
X3 mof:UInt64
X4 mof:UInt64
X5 mof:UInt64
X6 mof:UInt64
X7 mof:UInt64
X8 mof:UInt64
X9 mof:UInt64
X10 mof:UInt64
X11 mof:UInt64
X12 mof:UInt64
X13 mof:UInt64
X14 mof:UInt64
X15 mof:UInt64
X16 mof:UInt64
X17 mof:UInt64
X18 mof:UInt64
X19 mof:UInt64
X20 mof:UInt64
X21 mof:UInt64
X22 mof:UInt64
X23 mof:UInt64
X24 mof:UInt64
X25 mof:UInt64
X26 mof:UInt64
X27 mof:UInt64
X28 mof:UInt64
Fp mof:UInt64
Lr mof:UInt64
Sp mof:UInt64
Pc mof:UInt64

Event ID 127: PageFault_VirtualRotate

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt32
SizeInBytes mof:Object
Flags mof:UInt32

Event ID 128: PageFault_VirtualAllocRundown

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt32
RegionSize mof:Object
ProcessId mof:UInt32
Flags mof:UInt32
CommitSizeInBytes mof:Object

Event ID 129: PageFault_VirtualAllocRundown

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt32
RegionSize mof:Object
ProcessId mof:UInt32
Flags mof:UInt32
CommitSizeInBytes mof:Object

Event ID 130: LoaderBasicEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 131: LoaderBasicEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 132: LoaderBasicEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 133: LoaderBasicEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 134: PageFault_MemReset

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt32
SizeInBytes mof:Object
Flags mof:UInt32

Event ID 135: LoaderBasicEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Event ID 144: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 145: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 146: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 147: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 148: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 149: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 150: LoaderBaseEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64

Event ID 160: LoaderCodedEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 161: LoaderCodedEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 162: LoaderCodedEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 163: LoaderCodedEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 164: LoaderCodedEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 165: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 166: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 167: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 168: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 169: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 170: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 171: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 172: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 173: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 174: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 176: LoaderNewDllEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
NewDllBaseAddress mof:UInt32
ParentDllBaseAddress mof:UInt32
LoadReason mof:UInt32
FilePath mof:String

Event ID 177: LoaderNewDllEvent

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
NewDllBaseAddress mof:UInt32
ParentDllBaseAddress mof:UInt32
LoadReason mof:UInt32
FilePath mof:String

Event ID 192: LoaderCodedEventPath

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String1 mof:String
String2 mof:String

Event ID 193: LoaderCodedEventPath

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String1 mof:String
String2 mof:String

Event ID 208: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 209: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 210: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 211: LoaderCodedEventStatus

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
BaseAddress mof:UInt64
ErrorOpcode mof:UInt8
Code mof:SInt8
String mof:String

Event ID 212: LoaderDllSearchResults

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
LdrLoadFlags mof:UInt32
LdrSearchFlags mof:UInt32
SearchInfo mof:UInt32
LoadReason mof:UInt32
FullDllName mof:String

Event ID 213: LoaderPathSearchResults

#
Provider
Windows Kernel Trace
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
SearchInfo mof:UInt32
Cwd mof:String
AppDir mof:String
DllDir mof:String
DllLoadDir mof:String

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {9E814AAD-3204-11D2-9A82-006008A86939}

Observed on:

  • WS2025-26100.0 · schema read from the WMI MOF class · captured 2026-02-26

    Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.

  • WS2022-20348.4893 · schema read from the WMI MOF class · captured 2026-06-02

    MOF class: MSNT_SystemTrace

  • Win11-26200.6584 · schema read from the WMI MOF class · captured 2026-06-02

    MOF class: MSNT_SystemTrace

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests