Microsoft-Windows-Crypto-DSSEnh
15 events across 1 channel
Event ID 1: Operation failed.
#Description
Operation failed.
Message #
Fields #
| Name | Description |
|---|---|
OperationType UInt32 | Known values
|
ProcessName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 2: ProcessName Process: Process Provider type: Provider_type MachineKeyset: MachineKeyset AppContainer: AppContainer Error code: Error_code.
#Description
ErrorDescription Process: ProcessName Provider type: ProviderType MachineKeyset: MachineKeyset AppContainer: AppContainer Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
ProviderType UInt32 | |
MachineKeyset UInt32 | |
AppContainer Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 3: DesiredAccess Process: Process User Storage Area: Container_Name Container Name: MachineKeyset MachineKeyset: Error_code Error code: ProcessName.
#Description
ErrorDescription Process: ProcessName User Storage Area: DesiredAccess Container Name: UserStorageArea MachineKeyset: FileName Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
MachineKeyset Boolean | |
DesiredAccess UInt32 | Process access rights reference |
UserStorageArea UnicodeString | |
FileName UnicodeString | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 4: ProcessName Process: Process User Storage Area: User_Storage_Area New file name: New_file_name Error code: Error_code.
#Description
ErrorDescription Process: ProcessName User Storage Area: UserStoragePath New file name: FileName Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
UserStoragePath UnicodeString | |
FileName UnicodeString | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 5: ProcessName Process: Process User Storage Area: User_Storage_Area File name: File_name AppContainer: AppContainer Error code: Error_code.
#Description
ErrorDescription Process: ProcessName User Storage Area: UserStoragePath File name: FileName AppContainer: AppContainer Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
UserStoragePath UnicodeString | |
FileName AnsiString | |
AppContainer Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 6: ProcessName Process: Process File Path: File_Path Desired Access: Desired_Access Share Mode: Share_Mode Creation Disposition: Creation_Disposition Attributes: Attributes.
#Description
Attributes Process: ProcessName File Path: MachineKeyset Desired Access: FilePath Share Mode: DesiredAccess Creation Disposition: ShareMode Attributes: CreationDisposition
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
MachineKeyset Boolean | |
FilePath UnicodeString | |
DesiredAccess UInt32 | Process access rights reference |
ShareMode UInt32 | |
CreationDisposition UInt32 | |
Attributes UInt32 | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 7: ProcessName Process: Process File Path: File_Path MachineKeyset: MachineKeyset SecurityInformation: SecurityInformation AppContainer: AppContainer Error code: Error_code.
#Description
Status Process: ProcessName File Path: FileName MachineKeyset: ProviderType SecurityInformation: MachineKeyset AppContainer: SecurityInformation Error code: AppContainer
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
FileName UnicodeString | |
ProviderType UInt32 | |
MachineKeyset Boolean | |
SecurityInformation UInt32 | |
AppContainer Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 8: ProcessName Process: Process File Path: File_Path Provider Type: Provider_Type MachineKeyset: MachineKeyset Security Info: Security_Info AppContainer: AppContainer Error code: Error_code.
#Description
ErrorDescription Process: ProcessName File Path: FilePath Provider Type: DesiredAccess MachineKeyset: ShareMode Security Info: CreationDisposition AppContainer: Attributes Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
FilePath UnicodeString | |
DesiredAccess UInt32 | Process access rights reference |
ShareMode UInt32 | |
CreationDisposition UInt32 | |
Attributes UInt32 | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 9: ProcessName Process: Process File Path: File_Path Error code: Error_code.
#Description
ErrorDescription Process: ProcessName File Path: FilePath Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
FilePath UnicodeString | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 10: ProcessName Process: Process Provider Type: Provider_Type Container Name: Container_Name Machine Keyset: Machine_Keyset Error code: Error_code.
#Description
ErrorDescription Process: ProcessName Provider Type: ProviderType Container Name: ContainerName Machine Keyset: MachineKeyset Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
ProviderType UInt32 | |
ContainerName AnsiString | |
MachineKeyset Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 11: ProcessName Process: Process Provider Type: Provider_Type Container Name: Container_Name Machine Keyset: Machine_Keyset Error code: Error_code.
#Description
ErrorDescription Process: ProcessName Provider Type: ProviderType Container Name: ContainerName Machine Keyset: MachineKeyset Error code: Status
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
ProviderType UInt32 | |
ContainerName UnicodeString | |
MachineKeyset Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 12: ProcessName Process: Process Provider Type: Provider_Type Container Name: Container_Name Machine Keyset: Machine_Keyset Error code: Error_code.
#Description
Status Process: ProcessName Provider Type: ProviderType Container Name: ContainerName Machine Keyset: MachineKeyset Error code: AppContainer
Message #
Fields #
| Name | Description |
|---|---|
ProcessName UnicodeString | |
ProviderType UInt32 | |
ContainerName AnsiString | |
MachineKeyset Boolean | |
AppContainer Boolean | |
Status UInt32 | NTSTATUS reference |
ErrorDescription UnicodeString |
Event ID 13: Attempting to read key container info.
#Event ID 14: Attempting to write key container info.
#Event ID 15: Attempting to delete key container info.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 43dad447-735f-4829-a6ff-9829a87419ff
Defined in dssenh.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02