Files
2024-07-26 16:48:49 +08:00

354 lines
86 KiB
CSV

Function,ProviderGuid,ProviderSymbol,ReghandleSymbol,WriteFunction,EventDescriptorSymbol,Id,Version,Channel,Level,Opcode,Task,Keyword,ContainingFunction,CallDepth,ExportedCallDepth,CallPath
NtFsControlFile,c4e507b1-7224-4737-bde0-ced9284e7073,"AttackSurfaceMonitor",,_tlgWriteTransfer,"Ast.IoctlCalled",-,-,11,5,0,-,0x200000000000,IopXxxControlFile,2,0,[NtFsControlFile->IopXxxControlFile]
NtFsControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_FSCTL_SYSTEM_CALLS,35,0,16,0,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtFsControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_FSCTL_SYSTEM_CALLS,36,0,16,3,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtFsControlFile,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"GenericMitigationForProcess",-,-,11,5,0,-,0x200000000000,EtwpTimLogMitigationForProcess,3,0,[NtFsControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtOpenEvent,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenEvent->ObOpenObjectByName->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtQuerySystemInformation,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"FirmwareTableAccessDenied",-,-,11,5,0,-,0x200000000000,ExpGetSystemFirmwareTableInformation,3,0,[NtQuerySystemInformation->ExpQuerySystemInformation->ExpGetSystemFirmwareTableInformation]
NtQuerySystemInformation,Windows Kernel Trace,MEMINFO,MEMORY,EtwTraceKernelEvent,MM_STATS,,,,,,,,MmLogQueryCombineStats,4,0,[NtQuerySystemInformation->ExpQuerySystemInformation->PfQuerySuperfetchInformation->MmLogQueryCombineStats]
NtOpenKey,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenKey->CmOpenKey->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtOpenKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKey->CmOpenKey->CmpUnlockRegistry->CmpRecordRegistryLockRelease->CmpThreadInfoLogStack]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SESSION_DISPLAY_OFF,149,0,16,4,0,185,0x4000400000000404,PopDiagTraceSessionDisplayStateChange,2,0,[NtPowerInformation->PopDiagTraceSessionDisplayStateChange]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SESSION_DISPLAY_ON,150,0,16,4,0,186,0x4000400000000404,PopDiagTraceSessionDisplayStateChange,2,0,[NtPowerInformation->PopDiagTraceSessionDisplayStateChange]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_ADPM_SESSION_CLOSED,401,0,16,4,0,110,0x4000000000000404,PopDiagTraceSessionStates,2,0,[NtPowerInformation->PopDiagTraceSessionStates]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_ADPM_SESSION_CREATED,400,0,16,4,0,109,0x4000000000000404,PopDiagTraceSessionStates,2,0,[NtPowerInformation->PopDiagTraceSessionStates]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDAPP,16,0,16,4,1,37,0x4000000000000808,PopDiagTraceAppPowerMessage,2,0,[NtPowerInformation->PopDiagTraceAppPowerMessage]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDAPP_END,17,0,16,4,2,37,0x4000000000000808,PopDiagTraceAppPowerMessageEnd,2,0,[NtPowerInformation->PopDiagTraceAppPowerMessageEnd]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDSERVICE,18,0,16,4,1,38,0x4000000000000808,PopDiagTraceServiceNotification,2,0,[NtPowerInformation->PopDiagTraceServiceNotification]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_SUSPENDSERVICE_END,19,0,16,4,2,38,0x4000000000000808,PopDiagTraceServiceNotification,2,0,[NtPowerInformation->PopDiagTraceServiceNotification]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SpoilBatteryEstimation",-,-,11,5,0,-,0x0,PopSpoilBatteryEstimate,3,0,[NtPowerInformation->PopUpdateConsoleDisplayState->PopSpoilBatteryEstimate]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_CONSOLE_DISPLAY_STATE,135,0,16,4,0,275,0x4000200000000404,PopDiagTraceConsoleDisplayState,3,0,[NtPowerInformation->PopUpdateConsoleDisplayState->PopDiagTraceConsoleDisplayState]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_BASIC_BRIGHTNESS_ENGINE_OFF,520,0,8,4,0,218,0x8000400000000404,PopDiagTraceEventNoPayload,3,0,[NtPowerInformation->PopPowerInformationInternal->PopDiagTraceEventNoPayload]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopFanReadFanNoiseInfo",-,-,11,2,0,-,0x0,PopFanReadFanNoiseInfo,3,0,[NtPowerInformation->PopPowerInformationInternal->PopFanReadFanNoiseInfo]
NtPowerInformation,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_ADAPTIVE_SESSION_STATE,576,1,16,4,0,279,0x4000000000000004,PopAdaptiveGetSessionStateUnsafe,3,0,[NtPowerInformation->PopPowerInformationInternal->PopAdaptiveGetSessionStateUnsafe]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopDiagTraceExternalDisplayState",-,-,11,5,0,-,0x0,PopUpdateExternalDisplayState,3,0,[NtPowerInformation->PopPowerInformationInternal->PopUpdateExternalDisplayState]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SleepReliabilityDetailedDiag",-,-,11,5,0,-,0x400000000000,PopDiagTraceSleepReliabilityDiagConfigUpdate,3,0,[NtPowerInformation->PopPowerInformationInternal->PopDiagTraceSleepReliabilityDiagConfigUpdate]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteEx,"PlRegisterPowerPlaneStatus",-,-,11,5,0,-,0x0,PopPlRegisterPowerPlane,3,0,[NtPowerInformation->PopPowerInformationInternal->PopPlRegisterPowerPlane]
NtPowerInformation,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,PO_SESSION_CALLOUT,,,,,,,,PopDispatchStateCallout,3,0,[NtPowerInformation->PoPowerOffMonitor->PopDispatchStateCallout]
NtPowerInformation,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,PO_SESSION_CALLOUT_RET,,,,,,,,PopDispatchStateCallout,3,0,[NtPowerInformation->PoPowerOffMonitor->PopDispatchStateCallout]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_InitCurrentSession",-,-,11,5,1,-,0x1,TtmiLogInitCurrentSessionStart,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogInitCurrentSessionStart]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_DeviceAssignmentPolicySet",-,-,11,5,0,-,0x1,TtmiLogSessionDeviceAssignmentPolicySet,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogSessionDeviceAssignmentPolicySet]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_Error",-,-,11,5,0,-,0x2,TtmiLogError,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogError]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_InitCurrentSession",-,-,11,5,2,-,0x1,TtmiLogInitCurrentSessionStop,3,0,[NtPowerInformation->TtmInitCurrentSession->TtmiLogInitCurrentSessionStop]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PowerSettingChangeRegistration",-,-,11,5,0,-,0x400000000000,PopDiagTracePowerSettingRegistration,3,0,[NtPowerInformation->PopGetSettingNotificationName->PopDiagTracePowerSettingRegistration]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"MonitorOnWithLidClosed",-,-,11,5,0,-,0x400000000000,PopDiagTraceMonitorOnWithLidClosed,3,0,[NtPowerInformation->PopMonitorInvocation->PopDiagTraceMonitorOnWithLidClosed]
NtPowerInformation,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"InputSuppressionMonitorOnRequestUserInput",-,-,11,5,0,-,0x400000000000,PopTraceMonitorOnRequestUserInput,3,0,[NtPowerInformation->PopMonitorInvocation->PopTraceMonitorOnRequestUserInput]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_CleanupCurrentSession",-,-,11,5,2,-,0x1,TtmiLogCleanupCurrentSessionStop,3,0,[NtPowerInformation->TtmCleanupCurrentSession->TtmiLogCleanupCurrentSessionStop]
NtPowerInformation,5e753e4d-2b0d-4451-b8f9-0f1253ca0b44,"Microsoft.Windows.Kernel.Ttm",,_tlgWriteTransfer,"TTM_CleanupCurrentSession",-,-,11,5,1,-,0x1,TtmiLogCleanupCurrentSessionStart,3,0,[NtPowerInformation->TtmCleanupCurrentSession->TtmiLogCleanupCurrentSessionStart]
NtOpenTimer,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenTimer->ObOpenObjectByName->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtModifyDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtModifyDriverEntry->ExpSetDriverEntry->IoGetEnvironmentVariableEx]
NtModifyDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtModifyDriverEntry->ExpSetDriverEntry->IoSetEnvironmentVariableEx]
NtTerminateProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_TERMINATEPROCESS,2,0,0,4,0,0,0x0,PspLogAuditTerminateRemoteProcessEvent,2,0,[NtTerminateProcess->PspLogAuditTerminateRemoteProcessEvent]
NtTerminateProcess,Windows Kernel Trace,PROCESS,PROCESS,EtwTraceKernelEvent,PROCESS_TERMINATE,,,,,,,,EtwTraceProcessTerminate,3,0,[NtTerminateProcess->PspTerminateProcess->EtwTraceProcessTerminate]
NtDeviceIoControlFile,c4e507b1-7224-4737-bde0-ced9284e7073,"AttackSurfaceMonitor",,_tlgWriteTransfer,"Ast.IoctlCalled",-,-,11,5,0,-,0x200000000000,IopXxxControlFile,2,0,[NtDeviceIoControlFile->IopXxxControlFile]
NtDeviceIoControlFile,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"GenericMitigationForProcess",-,-,11,5,0,-,0x200000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtDeviceIoControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_FSCTL_SYSTEM_CALLS,35,0,16,0,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtDeviceIoControlFile,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_FSCTL_SYSTEM_CALLS,36,0,16,3,0,18,0x8000000000000000,EtwpTimLogMitigationForProcess,3,0,[NtDeviceIoControlFile->IopXxxControlFile->EtwpTimLogMitigationForProcess]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpCommitPreparedLightWeightTransaction",-,-,11,5,1,-,0x1,CmpCommitPreparedLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpCommitPreparedLightWeightTransaction]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpCommitPreparedLightWeightTransaction",-,-,11,5,2,-,0x1,CmpCommitPreparedLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpCommitPreparedLightWeightTransaction]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,1,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpAbortLightWeightTransaction]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,2,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpAbortLightWeightTransaction]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpPrepareLightWeightTransaction",-,-,11,5,1,-,0x1,CmpPrepareLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpPrepareLightWeightTransaction]
NtCommitRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpPrepareLightWeightTransaction",-,-,11,5,2,-,0x1,CmpPrepareLightWeightTransaction,3,0,[NtCommitRegistryTransaction->CmpCommitLightWeightTransaction->CmpPrepareLightWeightTransaction]
NtSecureConnectPort,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtSecureConnectPort->AlpcpCreateClientPort->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtSetDriverEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetDriverEntryOrder->IoSetEnvironmentVariableEx]
NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpReconfigured",-,-,11,5,0,-,0x400000000000,IopDumpTraceCrashDumpReconfiguration,3,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDumpTraceCrashDumpReconfiguration]
NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_RECONFIGURED,11,0,16,4,21,2,0x8000000000000000,IopDumpTraceCrashDumpReconfiguration,3,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDumpTraceCrashDumpReconfiguration]
NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"FeatureConfigurationUpdateCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerUpdateFeatureConfigurations,3,0,[NtSetSystemInformation->CmUpdateFeatureConfiguration->CmFcManagerUpdateFeatureConfigurations]
NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"FeatureConfigurationOverwriteCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerOverwriteFeatureConfigurationSection,3,0,[NtSetSystemInformation->CmUpdateFeatureConfiguration->CmFcManagerOverwriteFeatureConfigurationSection]
NtSetSystemInformation,f7e83426-2b81-58f9-c5d4-f2db6d0ad473,"Microsoft.Windows.Kernel.FeatureConfigurationManager",,_tlgWriteTransfer,"UsageSubscriptionUpdateCorruptedBuffer",-,-,11,5,0,-,0x400000000001,CmFcManagerUpdateFeatureUsageSubscriptions,3,0,[NtSetSystemInformation->CmUpdateFeatureUsageSubscription->CmFcManagerUpdateFeatureUsageSubscriptions]
NtSetSystemInformation,???,,,_tlgWriteEx,"HvciDriverLoadFail",-,-,11,5,0,-,0x400000000000,MiLogStrongCodeDriverLoadFailure,3,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLogStrongCodeDriverLoadFailure]
NtSetSystemInformation,???,,,_tlgWriteAgg,"NonRetpolineSystemImageLoadedAggregate",-,-,11,5,0,-,0x400000000000,MiLogNonRetpolineImageLoadEvent,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLogRetpolineImageLoadEvents->MiLogNonRetpolineImageLoadEvent]
NtSetSystemInformation,0bf2fb94-7b60-4b4d-9766-e82f658df540,KernelShimEngineProvider,KseEtwHandle,EtwWrite,KseShimsApplied,3,1,17,4,0,0,0x4000000000000000,KsepEvntLogShimsApplied,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->KseDriverLoadImage->KsepEvntLogShimsApplied]
NtSetSystemInformation,Windows Kernel Trace,PMC_PROFILE,PERFINFO,EtwTraceKernelEvent,PMC_INTERRUPT,,,,,,,,EtwpPmcInterrupt,4,0,[NtSetSystemInformation->EtwSetPerformanceTraceInformation->EtwpSetPmcProfileSource->EtwpPmcInterrupt]
NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpDisableFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceDisableCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceDisableCrashDumpFailure]
NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_DISABLE_FAILED,4,0,16,3,14,2,0x8000000000000000,IopDumpTraceDisableCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceDisableCrashDumpFailure]
NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpDisabled",-,-,11,5,0,-,0x400000000000,IopDumpTraceCrashDumpDisabled,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceCrashDumpDisabled]
NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_DISABLED,10,0,16,4,20,2,0x8000000000000000,IopDumpTraceCrashDumpDisabled,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopDisableCrashDump->IopDumpTraceCrashDumpDisabled]
NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpLoadDriverFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceLoadCrashDumpDriverFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure]
NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_LOAD_DRIVER_FAILED,6,0,16,3,16,2,0x8000000000000000,IopDumpTraceLoadCrashDumpDriverFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure]
NtSetSystemInformation,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpInitializeFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceInitializeCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure]
NtSetSystemInformation,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_INITIALIZE_FAILED,5,0,16,3,15,2,0x8000000000000000,IopDumpTraceInitializeCrashDumpFailure,4,0,[NtSetSystemInformation->IoConfigureCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure]
NtSetSystemInformation,???,,,_tlgWriteEx,"SessionHotPatchLoadStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,???,,,_tlgWriteEx,"RegisterHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,???,,,_tlgWriteEx,"ImageHotPatchThreadOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,???,,,_tlgWriteEx,"ImageHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,???,,,_tlgWriteEx,"SecureKernelHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,???,,,_tlgWriteEx,"KernelHotPatchOperationStatus",-,-,11,5,0,-,0x400000000020,MiLogHotPatchOperationStatus,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiLoadHotPatch->MiLogHotPatchOperationStatus]
NtSetSystemInformation,Windows Kernel Trace,,,,,,,,,,,,MiLogPerfMemoryRangeEvent,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiMapSystemImageWithLargePage->MiLogPerfMemoryRangeEvent]
NtSetSystemInformation,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RANGE_RELEASE,,,,,,,,MiDeleteSystemPagableVm,4,0,[NtSetSystemInformation->MmLoadSystemImageEx->MiMapSystemImageWithLargePage->MiDeleteSystemPagableVm]
NtQuerySystemInformationEx,Windows Kernel Trace,MEMINFO,MEMORY,EtwTraceKernelEvent,MM_STATS,,,,,,,,MmLogQueryCombineStats,4,0,[NtQuerySystemInformationEx->ExpQuerySystemInformation->PfQuerySuperfetchInformation->MmLogQueryCombineStats]
NtQuerySystemInformationEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"FirmwareTableAccessDenied",-,-,11,5,0,-,0x200000000000,ExpGetSystemFirmwareTableInformation,3,0,[NtQuerySystemInformationEx->ExpQuerySystemInformation->ExpGetSystemFirmwareTableInformation]
NtSetSystemEnvironmentValueEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtSetSystemEnvironmentValueEx->ExpSetFirmwareEnvironmentVariable->IoSetEnvironmentVariableEx]
NtCreateSection,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSection->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtCreateSection,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSection->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtUnloadKey2,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKey2->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtUnloadKey2,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKey2->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtCreateJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJob,2,0,[NtCreateJobObject->EtwTraceJob]
NtCreateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtCreateJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtCreateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtCreateJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtDeleteKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtDeleteKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtDeleteKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtDeleteKey->CmDeleteKey->CmAddLogForAction->CmpTransWriteLog]
NtTerminateJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_TERMINATE,,,,,,,,EtwTraceJob,2,0,[NtTerminateJobObject->EtwTraceJob]
NtTerminateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtTerminateJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtTerminateJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtTerminateJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtCreateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtCreateKey->CmCreateKey->CmpUnlockRegistry->CmpRecordRegistryLockRelease->CmpThreadInfoLogStack]
NtUnloadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKeyEx->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtUnloadKeyEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKeyEx->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtSetInformationThread,Windows Kernel Trace,THREAD,THREAD,EtwTraceKernelEvent,PERFINFO_LOG_TYPE_0x548,,,,,,,,EtwTraceThreadSetName,2,0,[NtSetInformationThread->EtwTraceThreadSetName]
NtSetInformationThread,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWriteEx,ThreadWorkOnBehalfUpdate,21,0,16,4,0,18,0x8000000000002000,EtwTraceThreadWorkOnBehalfUpdate,3,0,[NtSetInformationThread->PspRevertContainerImpersonation->EtwTraceThreadWorkOnBehalfUpdate]
NtSetInformationThread,Windows Kernel Trace,PRIORITY,THREAD,EtwTraceKernelEvent,THREAD_SET_IO_PRIORITY,,,,,,,,EtwTracePriority,3,0,[NtSetInformationThread->PsSetIoPriorityThread->EtwTracePriority]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_REGISTER,8,0,17,5,16,3,0x4000000000000220,EtwpEventWriteTemplateSessAndProv,3,0,[NtTraceControl->EtwpRegisterUMProvider->EtwpEventWriteTemplateSessAndProv]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_SET_TRAITS_FAILED,28,0,16,2,25,3,0x8000000000000a20,EtwpEventWriteRegistrationStatus,3,0,[NtTraceControl->EtwpSetProviderTraitsUm->EtwpEventWriteRegistrationStatus]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_DEBUG_LOOKUP_FAILED,32,0,16,3,0,3,0x8000000000000030,EtwpEventWriteDebugLookupFailed,4,0,[NtTraceControl->EtwpTrackProviderBinary->EtwpProviderArrivalCallback->EtwpEventWriteDebugLookupFailed]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_ENABLED,14,1,17,5,18,3,0x4000000000000420,EtwpEventWriteProviderEnabled,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteProviderEnabled]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_DISABLED,15,0,17,5,19,3,0x4000000000000420,EtwpEventWriteProviderEnabled,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteProviderEnabled]
NtTraceControl,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"KernelCallbackTiming",-,-,11,5,0,-,0x200000000800,EtwpSendDataBlock,3,0,[NtTraceControl->EtwpEnableGuid->EtwpSendDataBlock]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_CAPTURE_STATE,42,0,17,5,27,3,0x4000000000000120,EtwpEventWriteCaptureState,3,0,[NtTraceControl->EtwpEnableGuid->EtwpEventWriteCaptureState]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_GROUP_JOIN,29,0,17,5,26,3,0x4000000000000a20,EtwpAddRegEntryToGroup,4,0,[NtTraceControl->EtwpSetProviderTraitsUm->EtwpSetProviderTraitsCommon->EtwpAddRegEntryToGroup]
NtTraceControl,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWrite,ETW_EVENT_PROVIDER_ACCESS_DENIED,30,0,17,5,0,3,0x4000000000000220,EtwpEventWriteProviderAccessCheckStatus,4,0,[NtTraceControl->EtwpEnableGuid->EtwpIsRegEntryAllowed->EtwpEventWriteProviderAccessCheckStatus]
NtFlushKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlush",-,-,11,4,1,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushControlDataGenerated",-,-,11,4,0,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlush",-,-,11,4,2,-,0x0,CmpFlushHive,2,0,[NtFlushKey->CmpFlushHive]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtFlushKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtFlushKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpWaitOnHiveWriteQueue,3,0,[NtFlushKey->CmpFlushHive->CmpWaitOnHiveWriteQueue]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushPhase",-,-,11,4,1,-,0x0,CmpLogFlushPhaseStart,3,0,[NtFlushKey->CmpFlushHive->CmpLogFlushPhaseStart]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"LogFileSwap",-,-,11,5,0,-,0x0,HvSwapLogFiles,3,0,[NtFlushKey->CmpFlushHive->HvSwapLogFiles]
NtFlushKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveFlushPhase",-,-,11,4,2,-,0x0,CmpLogFlushPhaseEnd,3,0,[NtFlushKey->CmpFlushHive->CmpLogFlushPhaseEnd]
NtReplaceKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"NtReplaceKeyFailed",-,-,11,5,0,-,0x400000000000,NtReplaceKey,1,0,[NtReplaceKey]
NtReplaceKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"NtReplaceKeySucceeded",-,-,11,5,0,-,0x400000000000,NtReplaceKey,1,0,[NtReplaceKey]
NtAllocateVirtualMemoryEx,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogAllocExecVm,5,0,[NtAllocateVirtualMemoryEx->MmAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->EtwTiLogAllocExecVm]
NtGetEnvironmentVariableEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtGetEnvironmentVariableEx->IoGetEnvironmentVariableEx]
NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_TIME_RESOLUTION_REQUEST_RUNDOWN,97,1,16,4,0,94,0x4000000000004004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution]
NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_STRS,63,2,16,4,0,69,0x4000000000004004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution]
NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_TIME_RESOLUTION_STACK_RUNDOWN,110,0,16,4,0,104,0x4000000000000004,PoTraceSystemTimerResolution,2,0,[NtSetTimerResolution->PoTraceSystemTimerResolution]
NtSetTimerResolution,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_TIME_RESOLUTION_UPDATE,95,0,16,4,0,92,0x4000000000004004,PoTraceSystemTimerResolutionUpdate,3,0,[NtSetTimerResolution->ExpUpdateTimerResolution->PoTraceSystemTimerResolutionUpdate]
NtModifyBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtModifyBootEntry->ExpSetBootEntry->IoSetEnvironmentVariableEx]
NtModifyBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtModifyBootEntry->ExpSetBootEntry->IoGetEnvironmentVariableEx]
NtCreateSectionEx,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSectionEx->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtCreateSectionEx,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateSectionEx->MiCreateSectionCommon->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtAssignProcessToJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_ASSIGN_PROCESS,,,,,,,,EtwTraceJobAssignProcess,2,0,[NtAssignProcessToJobObject->EtwTraceJobAssignProcess]
NtEnumerateBootEntries,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"EnumerateVariables",-,-,11,5,0,-,0x200000000000,IoEnumerateEnvironmentVariablesEx,2,0,[NtEnumerateBootEntries->IoEnumerateEnvironmentVariablesEx]
NtDeleteValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtDeleteValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtDeleteValueKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtDeleteValueKey->CmDeleteValueKey->HvpMarkCellDirty->HvpMarkDirty]
NtDeleteValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtDeleteValueKey->CmDeleteValueKey->CmAddLogForAction->CmpTransWriteLog]
NtMapViewOfSection,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,29888,1,64,1,0,0,0x140017490,EtwTiLogMapExecView,2,0,[NtMapViewOfSection->EtwTiLogMapExecView]
NtMapViewOfSection,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,29840,1,64,1,0,0,0x1400174b0,EtwTiLogMapExecView,2,0,[NtMapViewOfSection->EtwTiLogMapExecView]
NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverLoad_Start,212,0,20,4,1,212,0x400000000002020,PnpDiagnosticTraceObject,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObject]
NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverInit_Start,226,0,20,4,1,226,0x400000000020020,PnpDiagnosticTraceObject,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObject]
NtLoadDriver,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,THREATINT_DRIVER_OBJECT_LOAD,29,1,16,4,0,10,0x8000000040000000,EtwTiLogDriverObjectLoad,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->EtwTiLogDriverObjectLoad]
NtLoadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverInit_Stop,227,0,20,4,2,226,0x400000000020020,PnpDiagnosticTraceObjectWithStatus,5,0,[NtLoadDriver->IopLoadDriverImage->IopLoadUnloadDriver->IopLoadDriver->PnpDiagnosticTraceObjectWithStatus]
NtSetInformationKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSetInformationKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtSetInformationKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtSetInformationKey->CmSetLastWriteTimeKey->CmAddLogForAction->CmpTransWriteLog]
NtSetInformationKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtSetInformationKey->CmSetLastWriteTimeKey->HvpMarkCellDirty->HvpMarkDirty]
NtTraceEvent,b675ec37-bdb6-4648-bc92-f3fdc74d3ca2,EventTracingProvGuid,EtwpEventTracingProvRegHandle,EtwWriteEx,ETW_EVENT_LOST_WPP_EVENT,33,0,0,2,0,11,0x40,EtwpTraceLostWppEvent,3,0,[NtTraceEvent->EtwpTraceMessageVa->EtwpTraceLostWppEvent]
NtTraceEvent,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,AccessCheckLog,14,0,0,2,0,0,0x20,SeLogAccessFailure,4,0,[NtTraceEvent->EtwTraceRaw->EtwpReserveTraceBuffer->SeLogAccessFailure]
NtEnumerateValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtEnumerateValueKey->CmpBounceContextStart]
NtEnumerateValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtEnumerateValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtDeleteDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtDeleteDriverEntry->IoSetEnvironmentVariableEx]
NtDeleteDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtDeleteDriverEntry->IoGetEnvironmentVariableEx]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_POSTSLEEP_NOTIFICATION,107,1,8,4,0,102,0x8000000000000444,PopDiagTracePostSleepNotification,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTracePostSleepNotification]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_MTRR_CHANGED,137,0,8,2,0,276,0x8000000000000404,PopDiagTraceMtrrError,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceMtrrError]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_HIBERNATE_STATUS,34,0,16,4,0,45,0x4000000000002c0c,PopDiagTraceHibernateErrorStatus,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceHibernateErrorStatus]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_NOTIFICATION3,42,3,8,4,0,64,0x8000000000000404,PopDiagTracePreSleepNotification,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTracePreSleepNotification]
NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_POWER_ACTION,,,,,,,,PopExecutePowerAction,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_KERNEL_QUERY_ALLOWED,61,0,16,4,0,67,0x4000000000002404,PopDiagTraceKernelQueriesAllowed,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceKernelQueriesAllowed]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_STATE_TRANSITION_FAILURE,579,0,16,4,0,282,0x4000000000000004,PopDiagTraceStateTransitionFailurePoint,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceStateTransitionFailurePoint]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"StateTransitionFailure",-,-,11,5,0,-,0x800000000000,PopDiagTraceStateTransitionFailurePoint,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceStateTransitionFailurePoint]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_S3FWSTATS_RESUME,131,0,8,4,0,33,0x8000000000000404,PopDiagTraceFirmwareS3Stats,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceFirmwareS3Stats]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_S3FWSTATS_SUSPEND,130,0,8,4,0,33,0x8000000000000404,PopDiagTraceFirmwareS3Stats,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDiagTraceFirmwareS3Stats]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEndScenario,POP_ETW_EVENT_GRACEFULSHUTDOWN_STOP,48,0,16,4,2,48,0x4000000000000009,PopGracefulShutdown,4,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopGracefulShutdown]
NtShutdownSystem,???,,BapdWriteEtwEvents,EtwWriteEx,,,,,,,,,BapdWriteEtwEvents,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdWriteEtwEvents]
NtShutdownSystem,???,,,EtwWrite,BOOT_FW_BOOT_PERF_DATA,30,0,8,4,0,21,0x8000000000000000,BapdRecordFirmwareBootStats,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdRecordFirmwareBootStats]
NtShutdownSystem,23b76a75-ce4f-56ef-f903-c3a2d6ae3f6b,"Microsoft.Windows.Kernel.BootEnvironment",,_tlgWriteTransfer,"FirmwareBootData",-,-,11,4,0,-,0x400000000000,BapdRecordFirmwareBootStats,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopBootLoaderTraceProcess->BapdRecordFirmwareBootStats]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ThermalZonePassiveHistogram",-,-,11,5,0,-,0x400000000000,PopTraceThermalZonePassiveHistogram,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopThermalSxEntry->PopTraceThermalZonePassiveHistogram]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ThermalZoneActiveActivity",-,-,11,5,0,-,0x400000000000,PopTraceThermalZoneActiveActivity,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopThermalSxEntry->PopTraceThermalZoneActiveActivity]
NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_DEVICES_STATE,,,,,,,,PoBroadcastSystemState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSetDevicesSystemState->PoBroadcastSystemState]
NtShutdownSystem,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_DEVICES_STATE_RET,,,,,,,,PoBroadcastSystemState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSetDevicesSystemState->PoBroadcastSystemState]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"PopFanUpdateStatistics_UpdateBucket",-,-,11,5,0,-,0x0,PopFanUpdateStatistics,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopFanSxEntry->PopFanUpdateStatistics]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_EXECUTE_POWER_ACTION,555,1,16,4,0,257,0x4000000000000004,PopDiagTraceExecutePowerAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceExecutePowerAction]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ExecutePowerAction",-,-,11,5,0,-,0x800000000000,PopDiagTraceExecutePowerAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceExecutePowerAction]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_SHUTDOWN_ACTION,109,0,8,4,0,103,0x8000400000000404,PopDiagTraceShutdownAction,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopExecutePowerAction->PopDiagTraceShutdownAction]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"DozeToS4Deferral",-,-,11,5,0,-,0x400000000000,PopDiagTraceDozeDeferralDecision,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopDeferDoze->PopDiagTraceDozeDeferralDecision]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_CALLBACKS_START,68,0,16,4,33,56,0x4000000000000808,PopDiagTraceEventNoPayload,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyCallbacksPreSleep->PopDiagTraceEventNoPayload]
NtShutdownSystem,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_PRESLEEP_CALLBACKS_STOP,69,0,16,4,34,56,0x4000000000000808,PopDiagTraceEventNoPayload,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyCallbacksPreSleep->PopDiagTraceEventNoPayload]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"SpoilBatteryEstimation",-,-,11,5,0,-,0x0,PopSpoilBatteryEstimate,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopSpoilEstimatesOnPowerStateTransitionWorker->PopSpoilBatteryEstimate]
NtShutdownSystem,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"OSStateChange",-,-,11,5,0,-,0x800000000000,PopTransitionTelemetryOsState,5,0,[NtShutdownSystem->NtSetSystemPowerState->PopTransitionSystemPowerStateEx->PopNotifyTelemetryOsState->PopTransitionTelemetryOsState]
NtProtectVirtualMemory,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogProtectExecVm,2,0,[NtProtectVirtualMemory->EtwTiLogProtectExecVm]
NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation]
NtSaveKeyEx,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveStop,3,0,[NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveStop]
NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSaveKeyEx->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent]
NtSaveKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,4,0,[NtSaveKeyEx->CmSaveKey->CmpCreateTemporaryHive->CmpCreateHive]
NtSetTimer,Windows Kernel Trace,TIMER,PERFINFO,EtwTraceKernelEvent,KTIMER2_SET,,,,,,,,KiTraceSetTimer2,5,0,[NtSetTimer->ExpSetTimer->ExpSetTimerObject2->KeSetTimer2->KiTraceSetTimer2]
NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelSystemTimeChange,1,4,8,4,0,5,0x8000000000000010,EtwTraceSystemTimeChange,3,0,[NtSetSystemTime->PoNotifySystemTimeSet->EtwTraceSystemTimeChange]
NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"SystemTimeChange",-,-,11,5,0,-,0x400000000000,EtwTraceSystemTimeChange,3,0,[NtSetSystemTime->PoNotifySystemTimeSet->EtwTraceSystemTimeChange]
NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoQueryFail",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationQueryFail,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationQueryFail]
NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoCutoverFail",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationCutoverFail,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationCutoverFail]
NtSetSystemTime,8944a53c-a561-4e53-a0c6-d565414745fc,"KernelExecutive",,_tlgWriteTransfer,"RefreshTimeZoneInfoSuccess",-,-,11,5,0,-,0x0,ExpLogRefreshTimeZoneInformationSuccess,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->ExpLogRefreshTimeZoneInformationSuccess]
NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelTimeZoneInformationRefresh,24,0,8,4,0,11,0x8000000000000010,EtwTraceTimeZoneInformationRefresh,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneInformationRefresh]
NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"TimeZoneInformationRefresh",-,-,11,5,0,-,0x0,EtwTraceTimeZoneInformationRefresh,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneInformationRefresh]
NtSetSystemTime,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,KernelTimeZoneBiasChange,22,0,8,4,0,8,0x8000000000000010,EtwTraceTimeZoneBiasChange,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneBiasChange]
NtSetSystemTime,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"TimeZoneBiasChange",-,-,11,5,0,-,0x400000000000,EtwTraceTimeZoneBiasChange,3,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->EtwTraceTimeZoneBiasChange]
NtSetSystemTime,Windows Kernel Trace,,,,,,,,,,,,KiTraceSetTimer,4,0,[NtSetSystemTime->ExpRefreshTimeZoneInformation->KiSetTimerEx->KiTraceSetTimer]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeySucceeded(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailedNoInfo(Aggregate)",-,-,11,5,0,-,0x400000000000,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailed(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmLoadKeyFailed",-,-,11,5,0,-,0x8,CmLoadKey,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveLoadStop,4,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmpTraceHiveLoadStop]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadErrorDetected",-,-,11,5,0,-,0x0,SetFailureLocation,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->SetFailureLocation]
NtLoadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadAppHiveImpersonationRequired",-,-,11,5,0,-,0x400000000008,CmpCmdHiveOpen,5,0,[NtLoadKey->NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->CmpCmdHiveOpen]
NtCreateProcessEx,Windows Kernel Trace,SESSION,MEMORY,EtwTraceKernelEvent,CREATE_SESSION,,,,,,,,MiSessionCreate,5,0,[NtCreateProcessEx->PspCreateProcess->PspAllocateProcess->MmInitializeProcessAddressSpace->MiSessionCreate]
NtLoadKeyEx,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveLoadStart,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmpTraceHiveLoadStart]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmLoadKeyFailed",-,-,11,5,0,-,0x8,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeySucceeded(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailedNoInfo(Aggregate)",-,-,11,5,0,-,0x400000000000,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,"CmLoadKeyFailed(Aggregate)",-,-,11,5,0,-,0x400000000008,CmLoadKey,3,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadAppHiveImpersonationRequired",-,-,11,5,0,-,0x400000000008,CmpCmdHiveOpen,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->CmpCmdHiveOpen]
NtLoadKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveLoadErrorDetected",-,-,11,5,0,-,0x0,SetFailureLocation,4,0,[NtLoadKeyEx->CmLoadDifferencingKey->CmLoadKey->SetFailureLocation]
NtQueryBootEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtQueryBootEntryOrder->IoGetEnvironmentVariableEx]
NtEnumerateDriverEntries,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"EnumerateVariables",-,-,11,5,0,-,0x200000000000,IoEnumerateEnvironmentVariablesEx,2,0,[NtEnumerateDriverEntries->IoEnumerateEnvironmentVariablesEx]
NtUnloadKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtUnloadKey->CmUnloadKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtUnloadKey,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtUnloadKey->CmUnloadKey->ObReferenceObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtSetTimerEx,Windows Kernel Trace,TIMER,PERFINFO,EtwTraceKernelEvent,KTIMER2_SET,,,,,,,,KiTraceSetTimer2,5,0,[NtSetTimerEx->ExpSetTimer->ExpSetTimerObject2->KeSetTimer2->KiTraceSetTimer2]
NtOpenThread,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENTHREAD,6,0,0,4,0,0,0x0,PsOpenThread,2,0,[NtOpenThread->PsOpenThread]
NtOpenThread,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ThreadOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenThread,2,0,[NtOpenThread->PsOpenThread]
NtEnumerateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtEnumerateKey->CmpBounceContextStart]
NtEnumerateKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtEnumerateKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtAddDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtAddDriverEntry->ExpSetDriverEntry->IoSetEnvironmentVariableEx]
NtAddDriverEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtAddDriverEntry->ExpSetDriverEntry->IoGetEnvironmentVariableEx]
NtAddBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,3,0,[NtAddBootEntry->ExpSetBootEntry->IoSetEnvironmentVariableEx]
NtAddBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtAddBootEntry->ExpSetBootEntry->IoGetEnvironmentVariableEx]
NtSetBootOptions,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetBootOptions->IoSetEnvironmentVariableEx]
NtOpenKeyTransactedEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKeyTransactedEx->CmOpenKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack]
NtQuerySystemEnvironmentValueEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,3,0,[NtQuerySystemEnvironmentValueEx->ExpGetFirmwareEnvironmentVariable->IoGetEnvironmentVariableEx]
NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PfSnEvt_PrefetchMetadata_Start,3,1,16,4,1,3,0x8000000000000020,EtwpPsProvTraceThread,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceThread->EtwpPsProvTraceThread]
NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ThreadStop,4,1,16,4,2,4,0x8000000000000020,EtwpPsProvTraceThread,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceThread->EtwpPsProvTraceThread]
NtCreateUserProcess,Windows Kernel Trace,,,,,,,,,,,,EtwpEnumerateAddressSpace,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpEnumerateAddressSpace]
NtCreateUserProcess,2839ff94-8f12-4e1b-82e3-af7af77a450f,"KernelProcess",,_tlgWriteTransfer,"ProcessStarted",-,-,11,5,0,-,0x3,EtwpWriteProcessStarted,4,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessStarted]
NtCreateUserProcess,Windows Kernel Trace,SESSION,MEMORY,EtwTraceKernelEvent,CREATE_SESSION,,,,,,,,MiSessionCreate,4,0,[NtCreateUserProcess->PspAllocateProcess->MmInitializeProcessAddressSpace->MiSessionCreate]
NtCreateUserProcess,Windows Kernel Trace,,,,,,,,,,,,MiLogKernelStackEvent,5,0,[NtCreateUserProcess->PspAllocateThread->KeInitThread->MmCreateKernelStack->MiLogKernelStackEvent]
NtCreateUserProcess,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_ASSIGN_PROCESS,,,,,,,,EtwTraceJobAssignProcess,4,0,[NtCreateUserProcess->PspInsertThread->PspAssignProcessToJobList->EtwTraceJobAssignProcess]
NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessStart,1,3,16,4,1,1,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess]
NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessStop,2,2,16,4,2,2,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess]
NtCreateUserProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,ProcessRundown,15,1,16,4,0,15,0x8000000000000010,EtwpPsProvTraceProcess,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpWriteProcessEvent->EtwpPsProvTraceProcess]
NtCreateUserProcess,Windows Kernel Trace,LOADER,IMAGE,EtwTraceKernelEvent,IMAGE_UNLOAD,,,,,,,,EtwpTraceImageUnload,5,0,[NtCreateUserProcess->PspInsertThread->EtwTraceProcess->EtwpEnumerateAddressSpace->EtwpTraceImageUnload]
NtCreateUserProcess,Windows Kernel Trace,PROCESS,PROCESS,EtwTraceKernelEvent,PROCESS_TERMINATE,,,,,,,,EtwTraceProcessTerminate,4,0,[NtCreateUserProcess->PsTerminateProcess->PspTerminateProcess->EtwTraceProcessTerminate]
NtCreateUserProcess,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_AUDIT_PROHIBIT_CHILD_PROCESS_CREATION,3,0,16,0,0,2,0x8000000000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation]
NtCreateUserProcess,fae10392-f0af-4ac0-b8ff-9f4d920c3cdf,SecurityMitigationsProviderGuid,EtwSecurityMitigationsRegHandle,EtwWrite,MITIGATION_ENFORCE_PROHIBIT_CHILD_PROCESS_CREATION,4,0,16,3,0,2,0x8000000000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation]
NtCreateUserProcess,2839ff94-8f12-4e1b-82e3-af7af77a450f,"KernelProcess",,_tlgWriteTransfer,"DeniedTokenCreation",-,-,11,5,0,-,0x200000000001,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation]
NtCreateUserProcess,7614521c-4d0b-4341-bfc9-873082c0f1d3,"KernelGeneral",,_tlgWriteTransfer,"ProhibitChildProcessCreation",-,-,11,5,0,-,0x400000000000,EtwTimLogProhibitChildProcessCreation,5,0,[NtCreateUserProcess->PspAllocateProcess->PspInitializeProcessSecurity->SeSubProcessToken->EtwTimLogProhibitChildProcessCreation]
NtCreateUserProcess,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_CREATE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateUserProcess->MmCreateSpecialImageSection->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtCreateUserProcess,Windows Kernel Trace,PERF_0x20400001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogSectionCreate,5,0,[NtCreateUserProcess->MmCreateSpecialImageSection->MiCreateSection->MiCreatePagingFileMap->MiLogSectionCreate]
NtQueryInformationJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJobSetQuery,2,0,[NtQueryInformationJobObject->EtwTraceJobSetQuery]
NtOpenProcessTokenEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenProcessTokenEx->ObpCreateHandle->ObpInsertOrLocateNamedObject->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtAlpcOpenSenderProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENPROCESS,5,0,0,4,0,0,0x0,PsOpenProcess,2,0,[NtAlpcOpenSenderProcess->PsOpenProcess]
NtAlpcOpenSenderProcess,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ProcessOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenProcess,2,0,[NtAlpcOpenSenderProcess->PsOpenProcess]
NtSetInformationJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PsIoRateControlStart,19,2,16,4,1,17,0x8000000000001000,PspSetJobIoRateControl,2,0,[NtSetInformationJobObject->PspSetJobIoRateControl]
NtSetInformationJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,PsIoRateControlStop,20,2,16,4,2,17,0x8000000000001000,PspSetJobIoRateControl,2,0,[NtSetInformationJobObject->PspSetJobIoRateControl]
NtSetInformationJobObject,Windows Kernel Trace,,,,,,,,,,,,EtwTraceJobSetQuery,2,0,[NtSetInformationJobObject->EtwTraceJobSetQuery]
NtSetIntervalProfile,Windows Kernel Trace,PROFILING,PERFINFO,EtwTraceKernelEvent,SAMPLED_PROFILE_SET_INTERVAL,,,,,,,,KeSetIntervalProfile,2,0,[NtSetIntervalProfile->KeSetIntervalProfile]
NtQueryEnvironmentVariableInfoEx,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"QueryVariables",-,-,11,5,0,-,0x200000000000,IoQueryEnvironmentVariableInfoEx,2,0,[NtQueryEnvironmentVariableInfoEx->IoQueryEnvironmentVariableInfoEx]
NtOpenProcess,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENPROCESS,5,0,0,4,0,0,0x0,PsOpenProcess,2,0,[NtOpenProcess->PsOpenProcess]
NtOpenProcess,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ProcessOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenProcess,2,0,[NtOpenProcess->PsOpenProcess]
NtSetInformationProcess,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWriteEx,ProcessInPrivateSet,27,0,16,4,0,20,0x8000000000000010,EtwTraceProcessSetInPrivateMode,2,0,[NtSetInformationProcess->EtwTraceProcessSetInPrivateMode]
NtSetInformationProcess,Windows Kernel Trace,PRIORITY,THREAD,EtwTraceKernelEvent,THREAD_SET_PAGE_PRIORITY,,,,,,,,EtwTracePriority,3,0,[NtSetInformationProcess->PsSetPagePriorityThread->EtwTracePriority]
NtSetInformationProcess,???,,,_tlgWriteEx,"WsEmptyControl",-,-,11,5,0,-,0x10,MiLogWsEmptyControl,3,0,[NtSetInformationProcess->MmProcessWorkingSetControl->MiLogWsEmptyControl]
NtSetInformationProcess,1dd9b8c9-e078-4075-b9de-4e5125071a18,"MSTelCov",,_tlgWriteTransfer,"CovNew",-,-,11,5,0,-,0x2,EtwpCoverageRecord,3,0,[NtSetInformationProcess->EtwSetProcessTelemetryCoverage->EtwpCoverageRecord]
NtSetInformationProcess,1dd9b8c9-e078-4075-b9de-4e5125071a18,"MSTelCov",,_tlgWriteTransfer,"Cov",-,-,11,5,0,-,0x1,EtwpCoverageRecord,3,0,[NtSetInformationProcess->EtwSetProcessTelemetryCoverage->EtwpCoverageRecord]
NtRollbackRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,1,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtRollbackRegistryTransaction->CmpRollbackLightWeightTransaction->CmpAbortLightWeightTransaction]
NtRollbackRegistryTransaction,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"CmpTransLightWeightRollback",-,-,11,5,2,-,0x1,CmpAbortLightWeightTransaction,3,0,[NtRollbackRegistryTransaction->CmpRollbackLightWeightTransaction->CmpAbortLightWeightTransaction]
NtSaveKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveStart,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveStart]
NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation]
NtSaveKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveSaveTreeCopied,4,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpTraceHiveSaveTreeCopied]
NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,4,0,[NtSaveKey->NtSaveKeyEx->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,5,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent]
NtSaveKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,5,0,[NtSaveKey->NtSaveKeyEx->CmSaveKey->CmpCreateTemporaryHive->CmpCreateHive]
NtOpenKeyEx,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenKeyEx->CmOpenKey->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtOpenKeyEx,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtOpenKeyEx->CmOpenKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpStarted",-,-,11,5,1,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"WriteDumpDataEnded",-,-,11,5,0,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpEnded",-,-,11,5,2,-,0x400000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWrite,LIVEDUMP_EVENT_MEMORY_PRESSURE_ABORT,5,0,16,4,22,1,0x8000000000000000,IoCaptureLiveDump,3,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump]
NtSystemDebugControl,???,,,EtwWriteEx,SQM_INCREMENT_DWORD,6,0,0,4,2,0,0x8008000000000000,DbgkpLkmdSqmIncrementDword,3,0,[NtSystemDebugControl->DbgkCaptureLiveDump->DbgkpLkmdSqmIncrementDword]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_CAPTURE_API_START,1,0,16,4,10,1,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DATA_API_START,201,0,16,4,10,4,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_DISCARD_DEFERRED_DATA_API_START,251,0,16,4,10,5,0x8000000000000000,IopLiveDumpTraceInterfaceStart,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceStart]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpMemoryCaptureEnded",-,-,11,5,0,-,0x400000000000,IopLiveDumpCaptureMemoryPages,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpCaptureMemoryPages]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DUMPDATA_TO_FILE_END,4,1,17,4,13,1,0x4000000000000000,IopLiveDumpTraceDumpFileWriteEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceDumpFileWriteEnd]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DUMPDATA_TO_FILE_END,204,1,17,4,13,4,0x4000000000000000,IopLiveDumpTraceDumpFileWriteEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceDumpFileWriteEnd]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"CaptureDumpMemoryAllocationEnded",-,-,11,5,0,-,0x400000000000,IopLiveDumpAllocAndInitResources,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpAllocAndInitResources]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DUMPDATA_TO_FILE_START,3,0,17,4,12,1,0x4000000000000000,IopLiveDumpTrace,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTrace]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_CAPTURE_API_END,2,5,17,4,11,1,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_WRITE_DEFERRED_DATA_API_END,202,5,17,4,11,4,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd]
NtSystemDebugControl,bef2aa8e-81cd-11e2-a7bb-5eac6188709b,LiveDumpProvGuid,IopLiveDumpEtwRegHandle,EtwWriteEx,LIVEDUMP_EVENT_DISCARD_DEFERRED_DATA_API_END,252,5,17,4,11,5,0x4000000000000000,IopLiveDumpTraceInterfaceEnd,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpTraceInterfaceEnd]
NtSystemDebugControl,a4d16fc5-d1cf-4d72-a055-25f3eb02a70e,"Microsoft.Windows.Kernel.LiveDump",,_tlgWriteTransfer,"OpenVMMemoryPartitionFailure",-,-,11,5,0,-,0x200000000000,IopLiveDumpOpenVMMemoryPartition,4,0,[NtSystemDebugControl->DbgkCaptureLiveKernelDump->IoCaptureLiveDump->IopLiveDumpOpenVMMemoryPartition]
NtQueryBootOptions,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtQueryBootOptions->IoGetEnvironmentVariableEx]
NtSetInformationVirtualMemory,???,,,_tlgWriteEx,"MemoryColdHint",-,-,11,5,0,-,0x40,MiLogNotifyPageHeat,5,0,[NtSetInformationVirtualMemory->MiProcessVaContiguityInformation->MiGetLargePage->MiNotifyPageHeat->MiLogNotifyPageHeat]
NtSetInformationVirtualMemory,???,,,_tlgWriteEx,"MemoryHotHint",-,-,11,5,0,-,0x40,MiLogNotifyPageHeat,5,0,[NtSetInformationVirtualMemory->MiProcessVaContiguityInformation->MiGetLargePage->MiNotifyPageHeat->MiLogNotifyPageHeat]
NtSetInformationVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS,,,,,,,,MiDemoteCombinedPte,5,0,[NtSetInformationVirtualMemory->MiProcessVaRangesInfoClass->MiWalkVaRange->MiActOnPte->MiDemoteCombinedPte]
NtSetInformationVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS_EX,,,,,,,,MiCopyOnWrite,4,0,[NtSetInformationVirtualMemory->MiProcessVaRangesInfoClass->MiWalkVaRange->MiCopyOnWrite]
NtUnloadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverUnload_Start,214,0,20,4,1,214,0x400000000004020,PnpDiagnosticTraceObject,3,0,[NtUnloadDriver->IopUnloadDriver->PnpDiagnosticTraceObject]
NtUnloadDriver,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,THREATINT_DRIVER_OBJECT_UNLOAD,30,1,16,4,0,10,0x8000000040000000,EtwTiLogDriverObjectUnLoad,3,0,[NtUnloadDriver->IopUnloadDriver->EtwTiLogDriverObjectUnLoad]
NtUnloadDriver,???,,PnpEtwHandle,EtwWrite,KMPnPEvt_DriverUnload_Stop,215,0,20,4,2,214,0x400000000004020,PnpDiagnosticTrace,4,0,[NtUnloadDriver->IopUnloadDriver->PnpDiagnosticTraceDriverFullInfo->PnpDiagnosticTrace]
NtAlpcOpenSenderThread,c59673d8-b796-58df-fbf8-a70bad656dca,"Microsoft.Windows.Kernel.ProcessSubsystem",,_tlgWriteTransfer,"ThreadOpenFailedForForcedAccessCheck",-,-,11,5,0,-,0x400000000000,PsOpenThread,2,0,[NtAlpcOpenSenderThread->PsOpenThread]
NtAlpcOpenSenderThread,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_OPENTHREAD,6,0,0,4,0,0,0x0,PsOpenThread,2,0,[NtAlpcOpenSenderThread->PsOpenThread]
NtManagePartition,d1d93ef7-e1f2-4f45-9943-03d245fe6c00,MemoryProvGuid,EtwpMemoryProvRegHandle,EtwWriteEx,KERNEL_MEM_EVENT_MDL_ALLOCATION,10,0,16,4,0,7,0x8000000000000200,MiAllocatePagesForMdl,4,0,[NtManagePartition->MmManagePartitionMoveMemory->MiAllocatePartitionPhysicalPages->MiAllocatePagesForMdl]
NtManagePartition,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RANGE_ACCESS,,,,,,,,MiLogMdlRangeEvent,5,0,[NtManagePartition->MmManagePartitionMoveMemory->MiAllocatePartitionPhysicalPages->MiAllocatePagesForMdl->MiLogMdlRangeEvent]
NtManagePartition,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_INITIALIZE_FAILED,5,0,16,3,15,2,0x8000000000000000,IopDumpTraceInitializeCrashDumpFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure]
NtManagePartition,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpInitializeFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceInitializeCrashDumpFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceInitializeCrashDumpFailure]
NtManagePartition,17d2a329-4539-5f4d-3435-f510634ce3b9,DumpProvGuid,IopDumpEtwRegHandle,EtwWriteEx,DUMP_EVENT_CRASHDUMP_LOAD_DRIVER_FAILED,6,0,16,3,16,2,0x8000000000000000,IopDumpTraceLoadCrashDumpDriverFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure]
NtManagePartition,a51ee86b-8ea5-454c-9a7d-37b6655a535d,"Microsoft.Windows.Kernel.Dump",,_tlgWriteTransfer,"CrashDumpLoadDriverFailed",-,-,11,5,0,-,0x400000000000,IopDumpTraceLoadCrashDumpDriverFailure,5,0,[NtManagePartition->MiCreatePagingFile->IoInitializeCrashDump->IopInitializeCrashDump->IopDumpTraceLoadCrashDumpDriverFailure]
NtNotifyChangeKey,Windows Kernel Trace,REG_NOTIF,REGISTRY,EtwTraceKernelEvent,REG_NOTIF_REGISTER,,,,,,,,CmpNotifyChangeKey,3,0,[NtNotifyChangeKey->NtNotifyChangeMultipleKeys->CmpNotifyChangeKey]
NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtRenameKey->CmRenameKey->CmpLogUnsupportedOperation]
NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtRenameKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtRenameKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtRenameKey->CmRenameKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent]
NtSetValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtSetValueKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtSetValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"AddLogContainer",-,-,11,5,0,-,0x1,CmpTransWriteLog,4,0,[NtSetValueKey->CmSetValueKey->CmAddLogForAction->CmpTransWriteLog]
NtSetValueKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtSetValueKey->CmSetValueKey->HvpMarkCellDirty->HvpMarkDirty]
NtCreateKeyTransacted,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,5,0,[NtCreateKeyTransacted->CmCreateKey->CmpLockRegistry->CmpRecordRegistryLockAcquire->CmpThreadInfoLogStack]
NtQueryValueKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,NtQueryValueKey,1,0,[NtQueryValueKey]
NtCreateSymbolicLinkObject,e02a841c-75a3-4fa7-afc8-ae09cf9b7f23,KernelAuditApiCallsGuid,EtwApiCallsProvRegHandle,EtwWrite,KERNEL_AUDIT_API_CREATESYMBOLICLINKOBJECT,3,0,0,4,0,0,0x0,NtCreateSymbolicLinkObject,1,0,[NtCreateSymbolicLinkObject]
NtFreeVirtualMemory,Windows Kernel Trace,,,,,,,,,,,,MiLogPerfMemoryRangeEvent,5,0,[NtFreeVirtualMemory->MmFreeVirtualMemory->MiFreeVadRange->MiDeleteVad->MiLogPerfMemoryRangeEvent]
NtFreeVirtualMemory,Windows Kernel Trace,MEMORY,MEMORY,EtwTraceKernelEvent,PAGE_RELEASE,,,,,,,,MiDeletePteRun,5,0,[NtFreeVirtualMemory->MmFreeVirtualMemory->MiDeleteEmptyPageTables->MiDeleteEmptyPageTableTail->MiDeletePteRun]
NtDeleteBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"GetVariable",-,-,11,5,0,-,0x200000000000,IoGetEnvironmentVariableEx,2,0,[NtDeleteBootEntry->IoGetEnvironmentVariableEx]
NtDeleteBootEntry,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtDeleteBootEntry->IoSetEnvironmentVariableEx]
NtSetBootEntryOrder,a9fdf37b-d72d-4051-a3cd-d422103ce079,"Microsoft.Windows.Kernel.SysEnv",,_tlgWriteTransfer,"SetVariable",-,-,11,5,0,-,0x200000000000,IoSetEnvironmentVariableEx,2,0,[NtSetBootEntryOrder->IoSetEnvironmentVariableEx]
NtUnlockVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS,,,,,,,,MiDemoteCombinedPte,2,0,[NtUnlockVirtualMemory->MiDemoteCombinedPte]
NtUnlockVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PFMAPPED_SECTION_DELETE,,,,,,,,MiLogCombinedPteDelete,3,0,[NtUnlockVirtualMemory->MiDemoteCombinedPte->MiLogCombinedPteDelete]
NtOpenFile,f39412d1-c9fd-5e79-8a82-9c9cbd8ca809,"Microsoft.Windows.Kernel.ObjectManager",,_tlgWriteTransfer,"SymlinkTraversalBlocked",-,-,11,5,0,-,0x400000000000,ObpParseSymbolicLinkEx,5,0,[NtOpenFile->IopCreateFile->ObOpenObjectByNameEx->ObpLookupObjectName->ObpParseSymbolicLinkEx]
NtQueryKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteAgg,,,,,,,,,CmpBounceContextStart,2,0,[NtQueryKey->CmpBounceContextStart]
NtQueryKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtQueryKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtAllocateVirtualMemory,f4e1897c-bb5d-5668-f1d8-040f4d8dd344,ThreatIntProviderGuid,EtwThreatIntProvRegHandle,EtwWrite,,,,,,,,,EtwTiLogAllocExecVm,4,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->EtwTiLogAllocExecVm]
NtAllocateVirtualMemory,???,,,_tlgWriteEx,"ProcessReserveMemFailed",-,-,11,5,0,-,0x400000000000,MiLogReserveVaFailed,5,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->MiReserveUserMemory->MiLogReserveVaFailed]
NtAllocateVirtualMemory,Windows Kernel Trace,PERF_0x28000001,MEMORY,EtwTraceKernelEvent,PAGE_ACCESS_EX,,,,,,,,MiCopyOnWrite,5,0,[NtAllocateVirtualMemory->MiAllocateVirtualMemoryCommon->MiAllocateVirtualMemory->MiSetProtectionOnSection->MiCopyOnWrite]
NtOpenJobObject,Windows Kernel Trace,PERF_0x80000,JOB,EtwTraceKernelEvent,JOB_OPEN,,,,,,,,EtwTraceJob,2,0,[NtOpenJobObject->EtwTraceJob]
NtOpenJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobTerminate,14,0,16,4,2,14,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtOpenJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtOpenJobObject,22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716,PsProvGuid,EtwpPsProvRegHandle,EtwWrite,JobStart,13,0,16,4,1,13,0x8000000000000400,EtwpPsProvTraceJob,3,0,[NtOpenJobObject->EtwTraceJob->EtwpPsProvTraceJob]
NtRestoreKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveRestoreStart,3,0,[NtRestoreKey->CmRestoreKey->CmpTraceHiveRestoreStart]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveSelfHealed",-,-,11,5,0,-,0x400000000000,CmpCreateHive,3,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive]
NtRestoreKey,70eb4f03-c1de-4f73-a051-33d13d5413bd,RegistryProvGuid,EtwpRegTraceHandle,EtwWrite,,,,,,,,,CmpTraceHiveRestoreStop,3,0,[NtRestoreKey->CmRestoreKey->CmpTraceHiveRestoreStop]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation",-,-,11,5,0,-,0x0,CmpLogUnsupportedOperation,3,0,[NtRestoreKey->CmRestoreKey->CmpLogUnsupportedOperation]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,EtwWriteEx,,,,,,,,,CmpThreadInfoLogStack,3,0,[NtRestoreKey->CmpIsRegistryLockAcquired->CmpThreadInfoLogStack]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationValidationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationResultedInDifferentKeyCount",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganized",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_INITIALIZE,,,,,,,,CmpLogHiveInitializeEvent,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpLogHiveInitializeEvent]
NtRestoreKey,Windows Kernel Trace,REG_HIVE,REGISTRY,EtwTraceKernelEvent,REG_HIVE_DIRTY,,,,,,,,HvpMarkDirty,4,0,[NtRestoreKey->CmRestoreKey->HvpMarkCellDirty->HvpMarkDirty]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"UnsupportedOperation(Aggregate)",-,-,11,5,0,-,0x400000000000,CmpSendUnsupportedOperationTelemetryEvent,4,0,[NtRestoreKey->CmRestoreKey->CmpLogUnsupportedOperation->CmpSendUnsupportedOperationTelemetryEvent]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationValidationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationResultedInDifferentKeyCount",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganized",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtRestoreKey,e9eaf418-0c07-464c-ad14-a7f353349a00,"Microsoft.Windows.Kernel.Registry",,_tlgWriteTransfer,"HiveReorganizationFailed",-,-,11,5,0,-,0x400000000000,CmpReorganizeHive,4,0,[NtRestoreKey->CmRestoreKey->CmpCreateHive->CmpReorganizeHive]
NtAccessCheckAndAuditAlarm,a68ca8b7-004f-d7b6-a698-07e2de0f1f5d,KernelProvGuid,EtwKernelProvRegHandle,EtwWrite,AccessCheckLog,14,0,0,2,0,0,0x20,SeLogAccessFailure,3,0,[NtAccessCheckAndAuditAlarm->SepAccessCheckAndAuditAlarm->SeLogAccessFailure]
NtAccessCheckAndAuditAlarm,45eec9e5-4a1b-5446-7ad8-a4ab1313c437,MS_Windows_Security_LPAC_Provider,EtwLpacProvRegHandle,EtwWrite,LpacAccessFailureLog,1,0,16,2,0,1,0x8000000000000000,EtwTraceLpacAccessFailure,4,0,[NtAccessCheckAndAuditAlarm->SepAccessCheckAndAuditAlarm->SepLogLpacAccessFailure->EtwTraceLpacAccessFailure]
NtInitiatePowerAction,Windows Kernel Trace,POWER,POWER,EtwTraceKernelEvent,SET_POWER_ACTION,,,,,,,,PopExecutePowerAction,2,0,[NtInitiatePowerAction->PopExecutePowerAction]
NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_NTINITIATEPOWERACTION_API_CALL,187,0,8,4,0,243,0x8000400000000404,PopDiagTracePolicyInitiatePowerActionApiCall,2,0,[NtInitiatePowerAction->PopDiagTracePolicyInitiatePowerActionApiCall]
NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWriteEx,POP_ETW_EVENT_SHUTDOWN_ACTION,109,0,8,4,0,103,0x8000400000000404,PopDiagTraceShutdownAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceShutdownAction]
NtInitiatePowerAction,63bca7a1-77ec-4ea7-95d0-98d3f0c0ebf7,"Microsoft.Windows.Kernel.Power",,_tlgWriteTransfer,"ExecutePowerAction",-,-,11,5,0,-,0x800000000000,PopDiagTraceExecutePowerAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceExecutePowerAction]
NtInitiatePowerAction,331c3b3a-2005-44c2-ac5e-77220c37d6b4,POP_ETW_PROVIDER,PopDiagHandle,EtwWrite,POP_ETW_EVENT_EXECUTE_POWER_ACTION,555,1,16,4,0,257,0x4000000000000004,PopDiagTraceExecutePowerAction,3,0,[NtInitiatePowerAction->PopExecutePowerAction->PopDiagTraceExecutePowerAction]