Function,ProviderGuid,ProviderSymbol,ReghandleSymbol,WriteFunction,EventDescriptorSymbol,Id,Version,Channel,Level,Opcode,Task,Keyword,ContainingFunction,CallDepth,ExportedCallDepth,CallPath NtFsControlFile,c4e507b1-7224-4737-bde0-ced9284e7073,"AttackSurfaceMonitor",,_tlgWriteTransfer,"Ast.IoctlCalled",-,-,11,5,0,-,0x200000000000,IopXxxControlFile,2,0,[NtFsControlFile->IopXxxControlFile] NtFsControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_FSCTL_SYSTEM_CALLS,35,0,16,0,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtFsControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_FSCTL_SYSTEM_CALLS,36,0,16,3,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtFsControlFile,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"GenericMitigationForProcess",-,-,11,5,0,-,0x200000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtOpenEvent,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenEvent->ObOpenObjectByName->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtQuerySystemInformation,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"FirmwareTableAccessDenied",-,-,11,5,0,-,0x200000000000,ExpGetSystemFirmwareTableInformation,3,0,[NtQuerySystemInformation->ExpQuerySystemInformation->ExpGetSystemFirmwareTableInformation] NtQuerySystemInformation,Windows Kernel Trace,MEMINFO,MEMORY,EtwTraceKernelEvent,MM_STATS,,,,,,,,MmLogQueryCombineStats,4,0,[NtQuerySystemInformation->ExpQuerySystemInformation->PfQuerySuperfetchInformation->MmLogQueryCombineStats] NtOpenKey,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenKey->CmOpenKey->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtOpenKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKey->CmOpenKey->CmpUnlockRegistry->CmpRecordRegistryLockRelease->CmpThreadInfoLogStack] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SESSION_DISPLAY_OFF,149,0,16,4,0,185,0x4000400000000404,PopDiagTraceSessionDisplayStateChange,2,0,[NtPowerInformation->PopDiagTraceSessionDisplayStateChange] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SESSION_DISPLAY_ON,150,0,16,4,0,186,0x4000400000000404,PopDiagTraceSessionDisplayStateChange,2,0,[NtPowerInformation->PopDiagTraceSessionDisplayStateChange] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_ADPM_SESSION_CLOSED,401,0,16,4,0,110,0x4000000000000404,PopDiagTraceSessionStates,2,0,[NtPowerInformation->PopDiagTraceSessionStates] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_ADPM_SESSION_CREATED,400,0,16,4,0,109,0x4000000000000404,PopDiagTraceSessionStates,2,0,[NtPowerInformation->PopDiagTraceSessionStates] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDAPP,16,0,16,4,1,37,0x4000000000000808,PopDiagTraceAppPowerMessage,2,0,[NtPowerInformation->PopDiagTraceAppPowerMessage] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDAPP_END,17,0,16,4,2,37,0x4000000000000808,PopDiagTraceAppPowerMessageEnd,2,0,[NtPowerInformation->PopDiagTraceAppPowerMessageEnd] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDSERVICE,18,0,16,4,1,38,0x4000000000000808,PopDiagTraceServiceNotification,2,0,[NtPowerInformation->PopDiagTraceServiceNotification] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDSERVICE_END,19,0,16,4,2,38,0x4000000000000808,PopDiagTraceServiceNotification,2,0,[NtPowerInformation->PopDiagTraceServiceNotification] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SpoilBatteryEstimation",-,-,11,5,0,-,0x0,PopSpoilBatteryEstimate,3,0,[NtPowerInformation->PopUpdateConsoleDisplayState->PopSpoilBatteryEstimate] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_CONSOLE_DISPLAY_STATE,135,0,16,4,0,275,0x4000200000000404,PopDiagTraceConsoleDisplayState,3,0,[NtPowerInformation->PopUpdateConsoleDisplayState->PopDiagTraceConsoleDisplayState] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_BASIC_BRIGHTNESS_ENGINE_OFF,520,0,8,4,0,218,0x8000400000000404,PopDiagTraceEventNoPayload,3,0,[NtPowerInformation->PopPowerInformationInternal->PopDiagTraceEventNoPayload] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopFanReadFanNoiseInfo",-,-,11,2,0,-,0x0,PopFanReadFanNoiseInfo,3,0,[NtPowerInformation->PopPowerInformationInternal->PopFanReadFanNoiseInfo] NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_ADAPTIVE_SESSION_STATE,576,1,16,4,0,279,0x4000000000000004,PopAdaptiveGetSessionStateUnsafe,3,0,[NtPowerInformation->PopPowerInformationInternal->PopAdaptiveGetSessionStateUnsafe] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopDiagTraceExternalDisplayState",-,-,11,5,0,-,0x0,PopUpdateExternalDisplayState,3,0,[NtPowerInformation->PopPowerInformationInternal->PopUpdateExternalDisplayState] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SleepReliabilityDetailedDiag",-,-,11,5,0,-,0x400000000000,PopDiagTraceSleepReliabilityDiagConfigUpdate,3,0,[NtPowerInformation->PopPowerInformationInternal->PopDiagTraceSleepReliabilityDiagConfigUpdate] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteEx,"PlRegisterPowerPlaneStatus",-,-,11,5,0,-,0x0,PopPlRegisterPowerPlane,3,0,[NtPowerInformation->PopPowerInformationInternal->PopPlRegisterPowerPlane] NtPowerInformation,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,PO_SESSION_CALLOUT,,,,,,,,PopDispatchStateCallout,3,0,[NtPowerInformation->PoPowerOffMonitor->PopDispatchStateCallout] NtPowerInformation,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,PO_SESSION_CALLOUT_RET,,,,,,,,PopDispatchStateCallout,3,0,[NtPowerInformation->PoPowerOffMonitor->PopDispatchStateCallout] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_InitCurrentSession",-,-,11,5,1,-,0x1,TtmiLogInitCurrentSessionStart,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogInitCurrentSessionStart] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_DeviceAssignmentPolicySet",-,-,11,5,0,-,0x1,TtmiLogSessionDeviceAssignmentPolicySet,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogSessionDeviceAssignmentPolicySet] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_Error",-,-,11,5,0,-,0x2,TtmiLogError,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogError] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_InitCurrentSession",-,-,11,5,2,-,0x1,TtmiLogInitCurrentSessionStop,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogInitCurrentSessionStop] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PowerSettingChangeRegistration",-,-,11,5,0,-,0x400000000000,PopDiagTracePowerSettingRegistration,3,0,[NtPowerInformation->PopGetSettingNotificationName->PopDiagTracePowerSettingRegistration] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"MonitorOnWithLidClosed",-,-,11,5,0,-,0x400000000000,PopDiagTraceMonitorOnWithLidClosed,3,0,[NtPowerInformation->PopMonitorInvocation->PopDiagTraceMonitorOnWithLidClosed] NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"InputSuppressionMonitorOnRequestUserInput",-,-,11,5,0,-,0x400000000000,PopTraceMonitorOnRequestUserInput,3,0,[NtPowerInformation->PopMonitorInvocation->PopTraceMonitorOnRequestUserInput] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_CleanupCurrentSession",-,-,11,5,2,-,0x1,TtmiLogCleanupCurrentSessionStop,3,0,[NtPowerInformation->TtmCleanupCurrentSession->TtmiLogCleanupCurrentSessionStop] NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_CleanupCurrentSession",-,-,11,5,1,-,0x1,TtmiLogCleanupCurrentSessionStart,3,0,[NtPowerInformation->TtmCleanupCurrentSession->TtmiLogCleanupCurrentSessionStart] NtOpenTimer,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenTimer->ObOpenObjectByName->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtModifyDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtModifyDriverEntry->ExpSetDriverEntry->IoGetEnvironmentVariableEx] NtModifyDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtModifyDriverEntry->ExpSetDriverEntry->IoSetEnvironmentVariableEx] NtTerminateProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_TERMINATEPROCESS,2,0,0,4,0,0,0x0,PspLogAuditTerminateRemoteProcessEvent,2,0,[NtTerminateProcess->PspLogAuditTerminateRemoteProcessEvent] NtTerminateProcess,Windows Kernel Trace,PROCESS,PROCESS,EtwTraceKernelEvent,PROCESS_TERMINATE,,,,,,,,EtwTraceProcessTerminate,3,0,[NtTerminateProcess->PspTerminateProcess->EtwTraceProcessTerminate] NtDeviceIoControlFile,c4e507b1-7224-4737-bde0-ced9284e7073,"AttackSurfaceMonitor",,_tlgWriteTransfer,"Ast.IoctlCalled",-,-,11,5,0,-,0x200000000000,IopXxxControlFile,2,0,[NtDeviceIoControlFile->IopXxxControlFile] NtDeviceIoControlFile,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"GenericMitigationForProcess",-,-,11,5,0,-,0x200000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtDeviceIoControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_FSCTL_SYSTEM_CALLS,35,0,16,0,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtDeviceIoControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_FSCTL_SYSTEM_CALLS,36,0,16,3,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpCommitPreparedLightWeightTransaction",-,-,11,5,1,-,0x1,CmpCommitPreparedLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpCommitPreparedLightWeightTransaction] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpCommitPreparedLightWeightTransaction",-,-,11,5,2,-,0x1,CmpCommitPreparedLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpCommitPreparedLightWeightTransaction] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,1,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpAbortLightWeightTransaction] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,2,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpAbortLightWeightTransaction] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpPrepareLightWeightTransaction",-,-,11,5,1,-,0x1,CmpPrepareLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpPrepareLightWeightTransaction] NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpPrepareLightWeightTransaction",-,-,11,5,2,-,0x1,CmpPrepareLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpPrepareLightWeightTransaction] NtSecureConnectPort,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtSecureConnectPort->AlpcpCreateClientPort->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtSetDriverEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetDriverEntryOrder->IoSetEnvironmentVariableEx] NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpReconfigured",-,-,11,5,0,-,0x400000000000,IopDumpTraceCrashDumpReconfiguration,3,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDumpTraceCrashDumpReconfiguration] NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_RECONFIGURED,11,0,16,4,21,2,0x8000000000000000,IopDumpTraceCrashDumpReconfiguration,3,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDumpTraceCrashDumpReconfiguration] NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"FeatureConfigurationUpdateCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerUpdateFeatureConfigurations,3,0,[NtSetSystemInformation->CmUpdateFeatureConfiguration->CmFcManagerUpdateFeatureConfigurations] NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"FeatureConfigurationOverwriteCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerOverwriteFeatureConfigurationSection,3,0,[NtSetSystemInformation->CmUpdateFeatureConfiguration->CmFcManagerOverwriteFeatureConfigurationSection] NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"UsageSubscriptionUpdateCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerUpdateFeatureUsageSubscriptions,3,0,[NtSetSystemInformation->CmUpdateFeatureUsageSubscription->CmFcManagerUpdateFeatureUsageSubscriptions] NtSetSystemInformation,???,,,_tlgWriteEx,"HvciDriverLoadFail",-,-,11,5,0,-,0x400000000000,MiLogStrongCodeDriverLoadFailure,3,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLogStrongCodeDriverLoadFailure] NtSetSystemInformation,???,,,_tlgWriteAgg,"NonRetpolineSystemImageLoadedAggregate",-,-,11,5,0,-,0x400000000000,MiLogNonRetpolineImageLoadEvent,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLogRetpolineImageLoadEvents->MiLogNonRetpolineImageLoadEvent] NtSetSystemInformation,0bf2fb94-7b60-4b4d-9766-e82f658df540,KernelShimEngineProvider,KseEtwHandle,EtwWrite,KseShimsApplied,3,1,17,4,0,0,0x4000000000000000,KsepEvntLogShimsApplied,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->KseDriverLoadImage->KsepEvntLogShimsApplied] NtSetSystemInformation,Windows Kernel Trace,PMC_PROFILE,PERFINFO,EtwTraceKernelEvent,PMC_INTERRUPT,,,,,,,,EtwpPmcInterrupt,4,0,[NtSetSystemInformation->EtwSetPerformanceTraceInformation->EtwpSetPmcProfileSource->EtwpPmcInterrupt] NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpDisableFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceDisableCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceDisableCrashDumpFailure] NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_DISABLE_FAILED,4,0,16,3,14,2,0x8000000000000000,IopDumpTraceDisableCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceDisableCrashDumpFailure] NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpDisabled",-,-,11,5,0,-,0x400000000000,IopDumpTraceCrashDumpDisabled,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceCrashDumpDisabled] NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_DISABLED,10,0,16,4,20,2,0x8000000000000000,IopDumpTraceCrashDumpDisabled,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceCrashDumpDisabled] NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpLoadDriverFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceLoadCrashDumpDriverFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure] NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_LOAD_DRIVER_FAILED,6,0,16,3,16,2,0x8000000000000000,IopDumpTraceLoadCrashDumpDriverFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure] NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpInitializeFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceInitializeCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure] NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_INITIALIZE_FAILED,5,0,16,3,15,2,0x8000000000000000,IopDumpTraceInitializeCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure] NtSetSystemInformation,???,,,_tlgWriteEx,"SessionHotPatchLoadStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,???,,,_tlgWriteEx,"RegisterHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,???,,,_tlgWriteEx,"ImageHotPatchThreadOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,???,,,_tlgWriteEx,"ImageHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,???,,,_tlgWriteEx,"SecureKernelHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,???,,,_tlgWriteEx,"KernelHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus] NtSetSystemInformation,Windows Kernel Trace,,,,,,,,,,,,MiLogPerfMemoryRangeEvent,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiMapSystemImageWithLargePage->MiLogPerfMemoryRangeEvent] NtSetSystemInformation,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RANGE_RELEASE,,,,,,,,MiDeleteSystemPagableVm,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiMapSystemImageWithLargePage->MiDeleteSystemPagableVm] NtQuerySystemInformationEx,Windows Kernel Trace,MEMINFO,MEMORY,EtwTraceKernelEvent,MM_STATS,,,,,,,,MmLogQueryCombineStats,4,0,[NtQuerySystemInformationEx->ExpQuerySystemInformation->PfQuerySuperfetchInformation->MmLogQueryCombineStats] NtQuerySystemInformationEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"FirmwareTableAccessDenied",-,-,11,5,0,-,0x200000000000,ExpGetSystemFirmwareTableInformation,3,0,[NtQuerySystemInformationEx->ExpQuerySystemInformation->ExpGetSystemFirmwareTableInformation] NtSetSystemEnvironmentValueEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtSetSystemEnvironmentValueEx->ExpSetFirmwareEnvironmentVariable->IoSetEnvironmentVariableEx] NtCreateSection,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSection->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtCreateSection,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSection->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtUnloadKey2,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKey2->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtUnloadKey2,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKey2->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtCreateJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJob,2,0,[NtCreateJobObject->EtwTraceJob] NtCreateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtCreateJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtCreateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtCreateJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtDeleteKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtDeleteKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtDeleteKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtDeleteKey->CmDeleteKey->CmAddLogForAction->CmpTransWriteLog] NtTerminateJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_TERMINATE,,,,,,,,EtwTraceJob,2,0,[NtTerminateJobObject->EtwTraceJob] NtTerminateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtTerminateJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtTerminateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtTerminateJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtCreateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtCreateKey->CmCreateKey->CmpUnlockRegistry->CmpRecordRegistryLockRelease->CmpThreadInfoLogStack] NtUnloadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKeyEx->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtUnloadKeyEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKeyEx->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtSetInformationThread,Windows Kernel Trace,THREAD,THREAD,EtwTraceKernelEvent,PERFINFO_LOG_TYPE_0x548,,,,,,,,EtwTraceThreadSetName,2,0,[NtSetInformationThread->EtwTraceThreadSetName] NtSetInformationThread,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWriteEx,ThreadWorkOnBehalfUpdate,21,0,16,4,0,18,0x8000000000002000,EtwTraceThreadWorkOnBehalfUpdate,3,0,[NtSetInformationThread->PspRevertContainerImpersonation->EtwTraceThreadWorkOnBehalfUpdate] NtSetInformationThread,Windows Kernel Trace,PRIORITY,THREAD,EtwTraceKernelEvent,THREAD_SET_IO_PRIORITY,,,,,,,,EtwTracePriority,3,0,[NtSetInformationThread->PsSetIoPriorityThread->EtwTracePriority] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_REGISTER,8,0,17,5,16,3,0x4000000000000220,EtwpEventWriteTemplateSessAndProv,3,0,[NtTraceControl->EtwpRegisterUMProvider->EtwpEventWriteTemplateSessAndProv] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_SET_TRAITS_FAILED,28,0,16,2,25,3,0x8000000000000a20,EtwpEventWriteRegistrationStatus,3,0,[NtTraceControl->EtwpSetProviderTraitsUm->EtwpEventWriteRegistrationStatus] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_DEBUG_LOOKUP_FAILED,32,0,16,3,0,3,0x8000000000000030,EtwpEventWriteDebugLookupFailed,4,0,[NtTraceControl->EtwpTrackProviderBinary->EtwpProviderArrivalCallback->EtwpEventWriteDebugLookupFailed] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_ENABLED,14,1,17,5,18,3,0x4000000000000420,EtwpEventWriteProviderEnabled,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteProviderEnabled] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_DISABLED,15,0,17,5,19,3,0x4000000000000420,EtwpEventWriteProviderEnabled,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteProviderEnabled] NtTraceControl,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"KernelCallbackTiming",-,-,11,5,0,-,0x200000000800,EtwpSendDataBlock,3,0,[NtTraceControl->EtwpEnableGuid->EtwpSendDataBlock] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_CAPTURE_STATE,42,0,17,5,27,3,0x4000000000000120,EtwpEventWriteCaptureState,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteCaptureState] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_GROUP_JOIN,29,0,17,5,26,3,0x4000000000000a20,EtwpAddRegEntryToGroup,4,0,[NtTraceControl->EtwpSetProviderTraitsUm->EtwpSetProviderTraitsCommon->EtwpAddRegEntryToGroup] NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_ACCESS_DENIED,30,0,17,5,0,3,0x4000000000000220,EtwpEventWriteProviderAccessCheckStatus,4,0,[NtTraceControl->EtwpEnableGuid->EtwpIsRegEntryAllowed->EtwpEventWriteProviderAccessCheckStatus] NtFlushKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlush",-,-,11,4,1,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushControlDataGenerated",-,-,11,4,0,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlush",-,-,11,4,2,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtFlushKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtFlushKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpWaitOnHiveWriteQueue,3,0,[NtFlushKey->CmpFlushHive->CmpWaitOnHiveWriteQueue] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushPhase",-,-,11,4,1,-,0x0,CmpLogFlushPhaseStart,3,0,[NtFlushKey->CmpFlushHive->CmpLogFlushPhaseStart] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"LogFileSwap",-,-,11,5,0,-,0x0,HvSwapLogFiles,3,0,[NtFlushKey->CmpFlushHive->HvSwapLogFiles] NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushPhase",-,-,11,4,2,-,0x0,CmpLogFlushPhaseEnd,3,0,[NtFlushKey->CmpFlushHive->CmpLogFlushPhaseEnd] NtReplaceKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"NtReplaceKeyFailed",-,-,11,5,0,-,0x400000000000,NtReplaceKey,1,0,[NtReplaceKey] NtReplaceKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"NtReplaceKeySucceeded",-,-,11,5,0,-,0x400000000000,NtReplaceKey,1,0,[NtReplaceKey] NtAllocateVirtualMemoryEx,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogAllocExecVm,5,0,[NtAllocateVirtualMemoryEx->MmAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->EtwTiLogAllocExecVm] NtGetEnvironmentVariableEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtGetEnvironmentVariableEx->IoGetEnvironmentVariableEx] NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_TIME_RESOLUTION_REQUEST_RUNDOWN,97,1,16,4,0,94,0x4000000000004004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution] NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_STRS,63,2,16,4,0,69,0x4000000000004004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution] NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_TIME_RESOLUTION_STACK_RUNDOWN,110,0,16,4,0,104,0x4000000000000004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution] NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_TIME_RESOLUTION_UPDATE,95,0,16,4,0,92,0x4000000000004004,PoTraceSystemTimerResolutionUpdate,3,0,[NtSetTimerResolution->ExpUpdateTimerResolution->PoTraceSystemTimerResolutionUpdate] NtModifyBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtModifyBootEntry->ExpSetBootEntry->IoSetEnvironmentVariableEx] NtModifyBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtModifyBootEntry->ExpSetBootEntry->IoGetEnvironmentVariableEx] NtCreateSectionEx,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSectionEx->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtCreateSectionEx,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSectionEx->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtAssignProcessToJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_ASSIGN_PROCESS,,,,,,,,EtwTraceJobAssignProcess,2,0,[NtAssignProcessToJobObject->EtwTraceJobAssignProcess] NtEnumerateBootEntries,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"EnumerateVariables",-,-,11,5,0,-,0x200000000000,IoEnumerateEnvironmentVariablesEx,2,0,[NtEnumerateBootEntries->IoEnumerateEnvironmentVariablesEx] NtDeleteValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtDeleteValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtDeleteValueKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtDeleteValueKey->CmDeleteValueKey->HvpMarkCellDirty->HvpMarkDirty] NtDeleteValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtDeleteValueKey->CmDeleteValueKey->CmAddLogForAction->CmpTransWriteLog] NtMapViewOfSection,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,29888,1,64,1,0,0,0x140017490,EtwTiLogMapExecView,2,0,[NtMapViewOfSection->EtwTiLogMapExecView] NtMapViewOfSection,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,29840,1,64,1,0,0,0x1400174b0,EtwTiLogMapExecView,2,0,[NtMapViewOfSection->EtwTiLogMapExecView] NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverLoad_Start,212,0,20,4,1,212,0x400000000002020,PnpDiagnosticTraceObject,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObject] NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverInit_Start,226,0,20,4,1,226,0x400000000020020,PnpDiagnosticTraceObject,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObject] NtLoadDriver,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,THREATINT_DRIVER_OBJECT_LOAD,29,1,16,4,0,10,0x8000000040000000,EtwTiLogDriverObjectLoad,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->EtwTiLogDriverObjectLoad] NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverInit_Stop,227,0,20,4,2,226,0x400000000020020,PnpDiagnosticTraceObjectWithStatus,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObjectWithStatus] NtSetInformationKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSetInformationKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtSetInformationKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtSetInformationKey->CmSetLastWriteTimeKey->CmAddLogForAction->CmpTransWriteLog] NtSetInformationKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtSetInformationKey->CmSetLastWriteTimeKey->HvpMarkCellDirty->HvpMarkDirty] NtTraceEvent,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWriteEx,ETW_EVENT_LOST_WPP_EVENT,33,0,0,2,0,11,0x40,EtwpTraceLostWppEvent,3,0,[NtTraceEvent->EtwpTraceMessageVa->EtwpTraceLostWppEvent] NtTraceEvent,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,AccessCheckLog,14,0,0,2,0,0,0x20,SeLogAccessFailure,4,0,[NtTraceEvent->EtwTraceRaw->EtwpReserveTraceBuffer->SeLogAccessFailure] NtEnumerateValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtEnumerateValueKey->CmpBounceContextStart] NtEnumerateValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtEnumerateValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtDeleteDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtDeleteDriverEntry->IoSetEnvironmentVariableEx] NtDeleteDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtDeleteDriverEntry->IoGetEnvironmentVariableEx] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_POSTSLEEP_NOTIFICATION,107,1,8,4,0,102,0x8000000000000444,PopDiagTracePostSleepNotification,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTracePostSleepNotification] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_MTRR_CHANGED,137,0,8,2,0,276,0x8000000000000404,PopDiagTraceMtrrError,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceMtrrError] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_HIBERNATE_STATUS,34,0,16,4,0,45,0x4000000000002c0c,PopDiagTraceHibernateErrorStatus,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceHibernateErrorStatus] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_NOTIFICATION3,42,3,8,4,0,64,0x8000000000000404,PopDiagTracePreSleepNotification,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTracePreSleepNotification] NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_POWER_ACTION,,,,,,,,PopExecutePowerAction,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_KERNEL_QUERY_ALLOWED,61,0,16,4,0,67,0x4000000000002404,PopDiagTraceKernelQueriesAllowed,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceKernelQueriesAllowed] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_STATE_TRANSITION_FAILURE,579,0,16,4,0,282,0x4000000000000004,PopDiagTraceStateTransitionFailurePoint,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceStateTransitionFailurePoint] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"StateTransitionFailure",-,-,11,5,0,-,0x800000000000,PopDiagTraceStateTransitionFailurePoint,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceStateTransitionFailurePoint] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_S3FWSTATS_RESUME,131,0,8,4,0,33,0x8000000000000404,PopDiagTraceFirmwareS3Stats,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceFirmwareS3Stats] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_S3FWSTATS_SUSPEND,130,0,8,4,0,33,0x8000000000000404,PopDiagTraceFirmwareS3Stats,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceFirmwareS3Stats] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEndScenario,POP_ETW_EVENT_GRACEFULSHUTDOWN_STOP,48,0,16,4,2,48,0x4000000000000009,PopGracefulShutdown,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopGracefulShutdown] NtShutdownSystem,???,,BapdWriteEtwEvents,EtwWriteEx,,,,,,,,,BapdWriteEtwEvents,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdWriteEtwEvents] NtShutdownSystem,???,,,EtwWrite,BOOT_FW_BOOT_PERF_DATA,30,0,8,4,0,21,0x8000000000000000,BapdRecordFirmwareBootStats,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdRecordFirmwareBootStats] NtShutdownSystem,23b76a75-ce4f-56ef-f903-c3a2d6ae3f6b,"Microsoft.Windows.Kernel.BootEnvironment",,_tlgWriteTransfer,"FirmwareBootData",-,-,11,4,0,-,0x400000000000,BapdRecordFirmwareBootStats,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdRecordFirmwareBootStats] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ThermalZonePassiveHistogram",-,-,11,5,0,-,0x400000000000,PopTraceThermalZonePassiveHistogram,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopThermalSxEntry->PopTraceThermalZonePassiveHistogram] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ThermalZoneActiveActivity",-,-,11,5,0,-,0x400000000000,PopTraceThermalZoneActiveActivity,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopThermalSxEntry->PopTraceThermalZoneActiveActivity] NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_DEVICES_STATE,,,,,,,,PoBroadcastSystemState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSetDevicesSystemState->PoBroadcastSystemState] NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_DEVICES_STATE_RET,,,,,,,,PoBroadcastSystemState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSetDevicesSystemState->PoBroadcastSystemState] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopFanUpdateStatistics_UpdateBucket",-,-,11,5,0,-,0x0,PopFanUpdateStatistics,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopFanSxEntry->PopFanUpdateStatistics] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_EXECUTE_POWER_ACTION,555,1,16,4,0,257,0x4000000000000004,PopDiagTraceExecutePowerAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceExecutePowerAction] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ExecutePowerAction",-,-,11,5,0,-,0x800000000000,PopDiagTraceExecutePowerAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceExecutePowerAction] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_SHUTDOWN_ACTION,109,0,8,4,0,103,0x8000400000000404,PopDiagTraceShutdownAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceShutdownAction] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"DozeToS4Deferral",-,-,11,5,0,-,0x400000000000,PopDiagTraceDozeDeferralDecision,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDeferDoze->PopDiagTraceDozeDeferralDecision] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_CALLBACKS_START,68,0,16,4,33,56,0x4000000000000808,PopDiagTraceEventNoPayload,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyCallbacksPreSleep->PopDiagTraceEventNoPayload] NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_CALLBACKS_STOP,69,0,16,4,34,56,0x4000000000000808,PopDiagTraceEventNoPayload,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyCallbacksPreSleep->PopDiagTraceEventNoPayload] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SpoilBatteryEstimation",-,-,11,5,0,-,0x0,PopSpoilBatteryEstimate,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSpoilEstimatesOnPowerStateTransitionWorker->PopSpoilBatteryEstimate] NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"OSStateChange",-,-,11,5,0,-,0x800000000000,PopTransitionTelemetryOsState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyTelemetryOsState->PopTransitionTelemetryOsState] NtProtectVirtualMemory,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogProtectExecVm,2,0,[NtProtectVirtualMemory->EtwTiLogProtectExecVm] NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation] NtSaveKeyEx,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveStop,3,0,[NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveStop] NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSaveKeyEx->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent] NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,4,0,[NtSaveKeyEx->CmSaveKey->CmpCreateTemporaryHive->CmpCreateHive] NtSetTimer,Windows Kernel Trace,TIMER,PERFINFO,EtwTraceKernelEvent,KTIMER2_SET,,,,,,,,KiTraceSetTimer2,5,0,[NtSetTimer->ExpSetTimer->ExpSetTimerObject2->KeSetTimer2->KiTraceSetTimer2] NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelSystemTimeChange,1,4,8,4,0,5,0x8000000000000010,EtwTraceSystemTimeChange,3,0,[NtSetSystemTime->PoNotifySystemTimeSet->EtwTraceSystemTimeChange] NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"SystemTimeChange",-,-,11,5,0,-,0x400000000000,EtwTraceSystemTimeChange,3,0,[NtSetSystemTime->PoNotifySystemTimeSet->EtwTraceSystemTimeChange] NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoQueryFail",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationQueryFail,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationQueryFail] NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoCutoverFail",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationCutoverFail,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationCutoverFail] NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoSuccess",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationSuccess,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationSuccess] NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelTimeZoneInformationRefresh,24,0,8,4,0,11,0x8000000000000010,EtwTraceTimeZoneInformationRefresh,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneInformationRefresh] NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"TimeZoneInformationRefresh",-,-,11,5,0,-,0x0,EtwTraceTimeZoneInformationRefresh,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneInformationRefresh] NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelTimeZoneBiasChange,22,0,8,4,0,8,0x8000000000000010,EtwTraceTimeZoneBiasChange,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneBiasChange] NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"TimeZoneBiasChange",-,-,11,5,0,-,0x400000000000,EtwTraceTimeZoneBiasChange,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneBiasChange] NtSetSystemTime,Windows Kernel Trace,,,,,,,,,,,,KiTraceSetTimer,4,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->KiSetTimerEx->KiTraceSetTimer] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeySucceeded(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailedNoInfo(Aggregate)",-,-,11,5,0,-,0x400000000000,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailed(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmLoadKeyFailed",-,-,11,5,0,-,0x8,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveLoadStop,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmpTraceHiveLoadStop] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadErrorDetected",-,-,11,5,0,-,0x0,SetFailureLocation,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->SetFailureLocation] NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadAppHiveImpersonationRequired",-,-,11,5,0,-,0x400000000008,CmpCmdHiveOpen,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->CmpCmdHiveOpen] NtCreateProcessEx,Windows Kernel Trace,SESSION,MEMORY,EtwTraceKernelEvent,CREATE_SESSION,,,,,,,,MiSessionCreate,5,0,[NtCreateProcessEx->PspCreateProcess->PspAllocateProcess->MmInitializeProcessAddressSpace->MiSessionCreate] NtLoadKeyEx,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveLoadStart,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmpTraceHiveLoadStart] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmLoadKeyFailed",-,-,11,5,0,-,0x8,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeySucceeded(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailedNoInfo(Aggregate)",-,-,11,5,0,-,0x400000000000,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailed(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadAppHiveImpersonationRequired",-,-,11,5,0,-,0x400000000008,CmpCmdHiveOpen,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->CmpCmdHiveOpen] NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadErrorDetected",-,-,11,5,0,-,0x0,SetFailureLocation,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->SetFailureLocation] NtQueryBootEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtQueryBootEntryOrder->IoGetEnvironmentVariableEx] NtEnumerateDriverEntries,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"EnumerateVariables",-,-,11,5,0,-,0x200000000000,IoEnumerateEnvironmentVariablesEx,2,0,[NtEnumerateDriverEntries->IoEnumerateEnvironmentVariablesEx] NtUnloadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKey->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtUnloadKey,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKey->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtSetTimerEx,Windows Kernel Trace,TIMER,PERFINFO,EtwTraceKernelEvent,KTIMER2_SET,,,,,,,,KiTraceSetTimer2,5,0,[NtSetTimerEx->ExpSetTimer->ExpSetTimerObject2->KeSetTimer2->KiTraceSetTimer2] NtOpenThread,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENTHREAD,6,0,0,4,0,0,0x0,PsOpenThread,2,0,[NtOpenThread->PsOpenThread] NtOpenThread,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ThreadOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenThread,2,0,[NtOpenThread->PsOpenThread] NtEnumerateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtEnumerateKey->CmpBounceContextStart] NtEnumerateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtEnumerateKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtAddDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtAddDriverEntry->ExpSetDriverEntry->IoSetEnvironmentVariableEx] NtAddDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtAddDriverEntry->ExpSetDriverEntry->IoGetEnvironmentVariableEx] NtAddBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtAddBootEntry->ExpSetBootEntry->IoSetEnvironmentVariableEx] NtAddBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtAddBootEntry->ExpSetBootEntry->IoGetEnvironmentVariableEx] NtSetBootOptions,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetBootOptions->IoSetEnvironmentVariableEx] NtOpenKeyTransactedEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKeyTransactedEx->CmOpenKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack] NtQuerySystemEnvironmentValueEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtQuerySystemEnvironmentValueEx->ExpGetFirmwareEnvironmentVariable->IoGetEnvironmentVariableEx] NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PfSnEvt_PrefetchMetadata_Start,3,1,16,4,1,3,0x8000000000000020,EtwpPsProvTraceThread,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceThread->EtwpPsProvTraceThread] NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ThreadStop,4,1,16,4,2,4,0x8000000000000020,EtwpPsProvTraceThread,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceThread->EtwpPsProvTraceThread] NtCreateUserProcess,Windows Kernel Trace,,,,,,,,,,,,EtwpEnumerateAddressSpace,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpEnumerateAddressSpace] NtCreateUserProcess,2839ff94-8f12-4e1b-82e3-af7af77a450f,"KernelProcess",,_tlgWriteTransfer,"ProcessStarted",-,-,11,5,0,-,0x3,EtwpWriteProcessStarted,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessStarted] NtCreateUserProcess,Windows Kernel Trace,SESSION,MEMORY,EtwTraceKernelEvent,CREATE_SESSION,,,,,,,,MiSessionCreate,4,0,[NtCreateUserProcess->PspAllocateProcess->MmInitializeProcessAddressSpace->MiSessionCreate] NtCreateUserProcess,Windows Kernel Trace,,,,,,,,,,,,MiLogKernelStackEvent,5,0,[NtCreateUserProcess->PspAllocateThread->KeInitThread->MmCreateKernelStack->MiLogKernelStackEvent] NtCreateUserProcess,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_ASSIGN_PROCESS,,,,,,,,EtwTraceJobAssignProcess,4,0,[NtCreateUserProcess->PspInsertThread->PspAssignProcessToJobList->EtwTraceJobAssignProcess] NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessStart,1,3,16,4,1,1,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess] NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessStop,2,2,16,4,2,2,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess] NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessRundown,15,1,16,4,0,15,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess] NtCreateUserProcess,Windows Kernel Trace,LOADER,IMAGE,EtwTraceKernelEvent,IMAGE_UNLOAD,,,,,,,,EtwpTraceImageUnload,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpEnumerateAddressSpace->EtwpTraceImageUnload] NtCreateUserProcess,Windows Kernel Trace,PROCESS,PROCESS,EtwTraceKernelEvent,PROCESS_TERMINATE,,,,,,,,EtwTraceProcessTerminate,4,0,[NtCreateUserProcess->PsTerminateProcess->PspTerminateProcess->EtwTraceProcessTerminate] NtCreateUserProcess,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_CHILD_PROCESS_CREATION,3,0,16,0,0,2,0x8000000000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation] NtCreateUserProcess,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_CHILD_PROCESS_CREATION,4,0,16,3,0,2,0x8000000000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation] NtCreateUserProcess,2839ff94-8f12-4e1b-82e3-af7af77a450f,"KernelProcess",,_tlgWriteTransfer,"DeniedTokenCreation",-,-,11,5,0,-,0x200000000001,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation] NtCreateUserProcess,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"ProhibitChildProcessCreation",-,-,11,5,0,-,0x400000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation] NtCreateUserProcess,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateUserProcess->MmCreateSpecialImageSection->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtCreateUserProcess,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateUserProcess->MmCreateSpecialImageSection->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate] NtQueryInformationJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJobSetQuery,2,0,[NtQueryInformationJobObject->EtwTraceJobSetQuery] NtOpenProcessTokenEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenProcessTokenEx->ObpCreateHandle->ObpInsertOrLocateNamedObject->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtAlpcOpenSenderProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENPROCESS,5,0,0,4,0,0,0x0,PsOpenProcess,2,0,[NtAlpcOpenSenderProcess->PsOpenProcess] NtAlpcOpenSenderProcess,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ProcessOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenProcess,2,0,[NtAlpcOpenSenderProcess->PsOpenProcess] NtSetInformationJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PsIoRateControlStart,19,2,16,4,1,17,0x8000000000001000,PspSetJobIoRateControl,2,0,[NtSetInformationJobObject->PspSetJobIoRateControl] NtSetInformationJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PsIoRateControlStop,20,2,16,4,2,17,0x8000000000001000,PspSetJobIoRateControl,2,0,[NtSetInformationJobObject->PspSetJobIoRateControl] NtSetInformationJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJobSetQuery,2,0,[NtSetInformationJobObject->EtwTraceJobSetQuery] NtSetIntervalProfile,Windows Kernel Trace,PROFILING,PERFINFO,EtwTraceKernelEvent,SAMPLED_PROFILE_SET_INTERVAL,,,,,,,,KeSetIntervalProfile,2,0,[NtSetIntervalProfile->KeSetIntervalProfile] NtQueryEnvironmentVariableInfoEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"QueryVariables",-,-,11,5,0,-,0x200000000000,IoQueryEnvironmentVariableInfoEx,2,0,[NtQueryEnvironmentVariableInfoEx->IoQueryEnvironmentVariableInfoEx] NtOpenProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENPROCESS,5,0,0,4,0,0,0x0,PsOpenProcess,2,0,[NtOpenProcess->PsOpenProcess] NtOpenProcess,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ProcessOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenProcess,2,0,[NtOpenProcess->PsOpenProcess] NtSetInformationProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWriteEx,ProcessInPrivateSet,27,0,16,4,0,20,0x8000000000000010,EtwTraceProcessSetInPrivateMode,2,0,[NtSetInformationProcess->EtwTraceProcessSetInPrivateMode] NtSetInformationProcess,Windows Kernel Trace,PRIORITY,THREAD,EtwTraceKernelEvent,THREAD_SET_PAGE_PRIORITY,,,,,,,,EtwTracePriority,3,0,[NtSetInformationProcess->PsSetPagePriorityThread->EtwTracePriority] NtSetInformationProcess,???,,,_tlgWriteEx,"WsEmptyControl",-,-,11,5,0,-,0x10,MiLogWsEmptyControl,3,0,[NtSetInformationProcess->MmProcessWorkingSetControl->MiLogWsEmptyControl] NtSetInformationProcess,1dd9b8c9-e078-4075-b9de-4e5125071a18,"MSTelCov",,_tlgWriteTransfer,"CovNew",-,-,11,5,0,-,0x2,EtwpCoverageRecord,3,0,[NtSetInformationProcess->EtwSetProcessTelemetryCoverage->EtwpCoverageRecord] NtSetInformationProcess,1dd9b8c9-e078-4075-b9de-4e5125071a18,"MSTelCov",,_tlgWriteTransfer,"Cov",-,-,11,5,0,-,0x1,EtwpCoverageRecord,3,0,[NtSetInformationProcess->EtwSetProcessTelemetryCoverage->EtwpCoverageRecord] NtRollbackRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,1,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtRollbackRegistryTransaction->CmpRollbackLightWeightTransaction->CmpAbortLightWeightTransaction] NtRollbackRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,2,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtRollbackRegistryTransaction->CmpRollbackLightWeightTransaction->CmpAbortLightWeightTransaction] NtSaveKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveStart,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveStart] NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation] NtSaveKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveTreeCopied,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveTreeCopied] NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtSaveKey->NtSaveKeyEx->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,5,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent] NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,5,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpCreateTemporaryHive->CmpCreateHive] NtOpenKeyEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenKeyEx->CmOpenKey->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtOpenKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKeyEx->CmOpenKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpStarted",-,-,11,5,1,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"WriteDumpDataEnded",-,-,11,5,0,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpEnded",-,-,11,5,2,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWrite,LIVEDUMP_EVENT_MEMORY_PRESSURE_ABORT,5,0,16,4,22,1,0x8000000000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump] NtSystemDebugControl,???,,,EtwWriteEx,SQM_INCREMENT_DWORD,6,0,0,4,2,0,0x8008000000000000,DbgkpLkmdSqmIncrementDword,3,0,[NtSystemDebugControl->DbgkCaptureLiveDump->DbgkpLkmdSqmIncrementDword] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_CAPTURE_API_START,1,0,16,4,10,1,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DATA_API_START,201,0,16,4,10,4,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_DISCARD_DEFERRED_DATA_API_START,251,0,16,4,10,5,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpMemoryCaptureEnded",-,-,11,5,0,-,0x400000000000,IopLiveDumpCaptureMemoryPages,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpCaptureMemoryPages] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DUMPDATA_TO_FILE_END,4,1,17,4,13,1,0x4000000000000000,IopLiveDumpTraceDumpFileWriteEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceDumpFileWriteEnd] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DUMPDATA_TO_FILE_END,204,1,17,4,13,4,0x4000000000000000,IopLiveDumpTraceDumpFileWriteEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceDumpFileWriteEnd] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpMemoryAllocationEnded",-,-,11,5,0,-,0x400000000000,IopLiveDumpAllocAndInitResources,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpAllocAndInitResources] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DUMPDATA_TO_FILE_START,3,0,17,4,12,1,0x4000000000000000,IopLiveDumpTrace,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTrace] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_CAPTURE_API_END,2,5,17,4,11,1,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DATA_API_END,202,5,17,4,11,4,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd] NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_DISCARD_DEFERRED_DATA_API_END,252,5,17,4,11,5,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd] NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"OpenVMMemoryPartitionFailure",-,-,11,5,0,-,0x200000000000,IopLiveDumpOpenVMMemoryPartition,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpOpenVMMemoryPartition] NtQueryBootOptions,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtQueryBootOptions->IoGetEnvironmentVariableEx] NtSetInformationVirtualMemory,???,,,_tlgWriteEx,"MemoryColdHint",-,-,11,5,0,-,0x40,MiLogNotifyPageHeat,5,0,[NtSetInformationVirtualMemory->MiProcessVaContiguityInformation->MiGetLargePage->MiNotifyPageHeat->MiLogNotifyPageHeat] NtSetInformationVirtualMemory,???,,,_tlgWriteEx,"MemoryHotHint",-,-,11,5,0,-,0x40,MiLogNotifyPageHeat,5,0,[NtSetInformationVirtualMemory->MiProcessVaContiguityInformation->MiGetLargePage->MiNotifyPageHeat->MiLogNotifyPageHeat] NtSetInformationVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS,,,,,,,,MiDemoteCombinedPte,5,0,[NtSetInformationVirtualMemory->MiProcessVaRangesInfoClass->MiWalkVaRange->MiActOnPte->MiDemoteCombinedPte] NtSetInformationVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS_EX,,,,,,,,MiCopyOnWrite,4,0,[NtSetInformationVirtualMemory->MiProcessVaRangesInfoClass->MiWalkVaRange->MiCopyOnWrite] NtUnloadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverUnload_Start,214,0,20,4,1,214,0x400000000004020,PnpDiagnosticTraceObject,3,0,[NtUnloadDriver->IopUnloadDriver->PnpDiagnosticTraceObject] NtUnloadDriver,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,THREATINT_DRIVER_OBJECT_UNLOAD,30,1,16,4,0,10,0x8000000040000000,EtwTiLogDriverObjectUnLoad,3,0,[NtUnloadDriver->IopUnloadDriver->EtwTiLogDriverObjectUnLoad] NtUnloadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverUnload_Stop,215,0,20,4,2,214,0x400000000004020,PnpDiagnosticTrace,4,0,[NtUnloadDriver->IopUnloadDriver->PnpDiagnosticTraceDriverFullInfo->PnpDiagnosticTrace] NtAlpcOpenSenderThread,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ThreadOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenThread,2,0,[NtAlpcOpenSenderThread->PsOpenThread] NtAlpcOpenSenderThread,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENTHREAD,6,0,0,4,0,0,0x0,PsOpenThread,2,0,[NtAlpcOpenSenderThread->PsOpenThread] NtManagePartition,d1d93ef7-e1f2-4f45-9943-03d245fe6c00,MemoryProvGuid,EtwpMemoryProvRegHandle,EtwWriteEx,KERNEL_MEM_EVENT_MDL_ALLOCATION,10,0,16,4,0,7,0x8000000000000200,MiAllocatePagesForMdl,4,0,[NtManagePartition->MmManagePartitionMoveMemory->MiAllocatePartitionPhysicalPages->MiAllocatePagesForMdl] NtManagePartition,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RANGE_ACCESS,,,,,,,,MiLogMdlRangeEvent,5,0,[NtManagePartition->MmManagePartitionMoveMemory->MiAllocatePartitionPhysicalPages->MiAllocatePagesForMdl->MiLogMdlRangeEvent] NtManagePartition,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_INITIALIZE_FAILED,5,0,16,3,15,2,0x8000000000000000,IopDumpTraceInitializeCrashDumpFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure] NtManagePartition,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpInitializeFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceInitializeCrashDumpFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure] NtManagePartition,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_LOAD_DRIVER_FAILED,6,0,16,3,16,2,0x8000000000000000,IopDumpTraceLoadCrashDumpDriverFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure] NtManagePartition,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpLoadDriverFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceLoadCrashDumpDriverFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure] NtNotifyChangeKey,Windows Kernel Trace,REG_NOTIF,REGISTRY,EtwTraceKernelEvent,REG_NOTIF_REGISTER,,,,,,,,CmpNotifyChangeKey,3,0,[NtNotifyChangeKey->NtNotifyChangeMultipleKeys->CmpNotifyChangeKey] NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtRenameKey->CmRenameKey->CmpLogUnsupportedOperation] NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtRenameKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtRenameKey->CmRenameKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent] NtSetValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSetValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtSetValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtSetValueKey->CmSetValueKey->CmAddLogForAction->CmpTransWriteLog] NtSetValueKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtSetValueKey->CmSetValueKey->HvpMarkCellDirty->HvpMarkDirty] NtCreateKeyTransacted,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtCreateKeyTransacted->CmCreateKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack] NtQueryValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,NtQueryValueKey,1,0,[NtQueryValueKey] NtCreateSymbolicLinkObject,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_CREATESYMBOLICLINKOBJECT,3,0,0,4,0,0,0x0,NtCreateSymbolicLinkObject,1,0,[NtCreateSymbolicLinkObject] NtFreeVirtualMemory,Windows Kernel Trace,,,,,,,,,,,,MiLogPerfMemoryRangeEvent,5,0,[NtFreeVirtualMemory->MmFreeVirtualMemory->MiFreeVadRange->MiDeleteVad->MiLogPerfMemoryRangeEvent] NtFreeVirtualMemory,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RELEASE,,,,,,,,MiDeletePteRun,5,0,[NtFreeVirtualMemory->MmFreeVirtualMemory->MiDeleteEmptyPageTables->MiDeleteEmptyPageTableTail->MiDeletePteRun] NtDeleteBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtDeleteBootEntry->IoGetEnvironmentVariableEx] NtDeleteBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtDeleteBootEntry->IoSetEnvironmentVariableEx] NtSetBootEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetBootEntryOrder->IoSetEnvironmentVariableEx] NtUnlockVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS,,,,,,,,MiDemoteCombinedPte,2,0,[NtUnlockVirtualMemory->MiDemoteCombinedPte] NtUnlockVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogCombinedPteDelete,3,0,[NtUnlockVirtualMemory->MiDemoteCombinedPte->MiLogCombinedPteDelete] NtOpenFile,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenFile->IopCreateFile->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx] NtQueryKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtQueryKey->CmpBounceContextStart] NtQueryKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtQueryKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtAllocateVirtualMemory,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogAllocExecVm,4,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->EtwTiLogAllocExecVm] NtAllocateVirtualMemory,???,,,_tlgWriteEx,"ProcessReserveMemFailed",-,-,11,5,0,-,0x400000000000,MiLogReserveVaFailed,5,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->MiReserveUserMemory->MiLogReserveVaFailed] NtAllocateVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS_EX,,,,,,,,MiCopyOnWrite,5,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->MiSetProtectionOnSection->MiCopyOnWrite] NtOpenJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_OPEN,,,,,,,,EtwTraceJob,2,0,[NtOpenJobObject->EtwTraceJob] NtOpenJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtOpenJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtOpenJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtOpenJobObject->EtwTraceJob->EtwpPsProvTraceJob] NtRestoreKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveRestoreStart,3,0,[NtRestoreKey->CmRestoreKey->CmpTraceHiveRestoreStart] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,3,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive] NtRestoreKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveRestoreStop,3,0,[NtRestoreKey->CmRestoreKey->CmpTraceHiveRestoreStop] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtRestoreKey->CmRestoreKey->CmpLogUnsupportedOperation] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtRestoreKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationValidationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationResultedInDifferentKeyCount",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganized",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_INITIALIZE,,,,,,,,CmpLogHiveInitializeEvent,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpLogHiveInitializeEvent] NtRestoreKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtRestoreKey->CmRestoreKey->HvpMarkCellDirty->HvpMarkDirty] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtRestoreKey->CmRestoreKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationValidationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationResultedInDifferentKeyCount",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganized",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive] NtAccessCheckAndAuditAlarm,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,AccessCheckLog,14,0,0,2,0,0,0x20,SeLogAccessFailure,3,0,[NtAccessCheckAndAuditAlarm->SepAccessCheckAndAuditAlarm->SeLogAccessFailure] NtAccessCheckAndAuditAlarm,45eec9e5-4a1b-5446-7ad8-a4ab1313c437,MS_Windows_Security_LPAC_Provider,EtwLpacProvRegHandle,EtwWrite,LpacAccessFailureLog,1,0,16,2,0,1,0x8000000000000000,EtwTraceLpacAccessFailure,4,0,[NtAccessCheckAndAuditAlarm->SepAccessCheckAndAuditAlarm->SepLogLpacAccessFailure->EtwTraceLpacAccessFailure] NtInitiatePowerAction,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_POWER_ACTION,,,,,,,,PopExecutePowerAction,2,0,[NtInitiatePowerAction->PopExecutePowerAction] NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_NTINITIATEPOWERACTION_API_CALL,187,0,8,4,0,243,0x8000400000000404,PopDiagTracePolicyInitiatePowerActionApiCall,2,0,[NtInitiatePowerAction->PopDiagTracePolicyInitiatePowerActionApiCall] NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_SHUTDOWN_ACTION,109,0,8,4,0,103,0x8000400000000404,PopDiagTraceShutdownAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceShutdownAction] NtInitiatePowerAction,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ExecutePowerAction",-,-,11,5,0,-,0x800000000000,PopDiagTraceExecutePowerAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceExecutePowerAction] NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_EXECUTE_POWER_ACTION,555,1,16,4,0,257,0x4000000000000004,PopDiagTraceExecutePowerAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceExecutePowerAction]