Microsoft-Windows-DesktopActivityModerator

21 events across 1 channel

EventTitleChannelSample
1StartDriverStartDiagnosticN
4StartDriverDiagnosticN
9StartDriverStopDiagnosticN
11StopDriverStartDiagnosticN
19StopDriverStopDiagnosticN
21SuspendResumeStartDiagnosticN
22SuspendResumeStopDiagnosticN
23ThrottleStartDiagnosticN
24ThrottleStopDiagnosticN
25ResiliencyEngageStartDiagnosticN
26ResiliencyEngageStopDiagnosticN
31ProcessActivityStartDiagnosticN
32ProcessActivityStopDiagnosticN
41ProcessExemptDiagnosticN
42PolicyReloadDiagnosticN
51PdcCallbackDiagnosticN
52PdcCallback52DiagnosticN
53PdcCallback53DiagnosticN
54PdcAcknowledgeDiagnosticN
60IoTrackingPerfTrackDiagnosticN
61IoTrackingCallbackDiagnosticN

Event ID 1: StartDriverStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver
Opcode
Start

Event ID 4: StartDriver

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver

Event ID 9: StartDriverStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StartDriver
Opcode
Stop

Fields #

NameDescription
NTSTATUS UInt32

Event ID 11: StopDriverStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StopDriver
Opcode
Start

Event ID 19: StopDriverStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
StopDriver
Opcode
Stop

Event ID 21: SuspendResumeStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
SuspendResume
Opcode
Start

Fields #

NameDescription
SuspendFlag Boolean

Event ID 22: SuspendResumeStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
SuspendResume
Opcode
Stop

Fields #

NameDescription
SuspendFlag Boolean

Event ID 23: ThrottleStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
Throttle
Opcode
Start

Fields #

NameDescription
SuspendFlag Boolean

Event ID 24: ThrottleStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
Throttle
Opcode
Stop

Fields #

NameDescription
SuspendFlag Boolean

Event ID 25: ResiliencyEngageStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ResiliencyEngage
Opcode
Start

Fields #

NameDescription
ActiveFlag Boolean

Event ID 26: ResiliencyEngageStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ResiliencyEngage
Opcode
Stop

Fields #

NameDescription
ActiveFlag Boolean

Event ID 31: ProcessActivityStart

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessActivity
Opcode
Start

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32
ImageFileNameLength UInt16
ImageFileName UnicodeString
CommandLineLength UInt16
CommandLine UnicodeString

Event ID 32: ProcessActivityStop

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessActivity
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32

Event ID 41: ProcessExempt

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
ProcessExempt

Fields #

NameDescription
ProcessId UInt32
SessionId UInt32
ExemptGroup UInt32
RegisterAtLaunch Boolean

Event ID 42: PolicyReload

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PolicyReload

Fields #

NameDescription
PolicyRecords UInt32

Event ID 51: PdcCallback

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
State UInt32
NTSTATUS UInt32
WorkItemQueued Boolean

Event ID 52: PdcCallback52

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
ClientState UInt32

Event ID 53: PdcCallback53

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcCallback

Fields #

NameDescription
Flags UInt32

Event ID 54: PdcAcknowledge

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
PdcAcknowledge

Event ID 60: IoTrackingPerfTrack

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
IoTrackingPerfTrack
Opcode
Info

Fields #

NameDescription
DeviceBucket UInt32
ElapsedTimeMs UInt32
FastIoCount UInt32
SlowIoCount UInt32

Event ID 61: IoTrackingCallback

#
Provider
Microsoft-Windows-DesktopActivityModerator
Channel
Diagnostic
Task
IoTrackingCallback
Opcode
Info

Fields #

NameDescription
DeviceType UInt16
DeviceBucket UInt32
ElapsedTime UInt64
SlowIo Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 32dd13df-9c0b-4c3b-b854-ee76c050f5f4

Defined in dam.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads