Microsoft-Antimalware-UacScan

1 events across 1 channel

EventTitleChannelSample
1201UacScanDebugN

Event ID 1201: UacScan

#
Provider
Microsoft-Antimalware-UacScan
Channel
Debug

Description

UacScan

Message #

UacScan

Fields #

NameDescription
requestorProcessId UInt32
uacRequestType UInt8
uacTrustState UInt8
autoElevateRequest Boolean
exeApplicationName UnicodeString
exeCommandLine UnicodeString
exeDllParam UnicodeString
comServerBinary UnicodeString
comRequestor UnicodeString
comClsid GUID

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID d37e7910-79c8-57c4-da77-52bb646364cd

Defined in amsi.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads