Microsoft-Windows-DesktopActivityModerator
21 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | StartDriverStart | Diagnostic | N |
| 4 | StartDriver | Diagnostic | N |
| 9 | StartDriverStop | Diagnostic | N |
| 11 | StopDriverStart | Diagnostic | N |
| 19 | StopDriverStop | Diagnostic | N |
| 21 | SuspendResumeStart | Diagnostic | N |
| 22 | SuspendResumeStop | Diagnostic | N |
| 23 | ThrottleStart | Diagnostic | N |
| 24 | ThrottleStop | Diagnostic | N |
| 25 | ResiliencyEngageStart | Diagnostic | N |
| 26 | ResiliencyEngageStop | Diagnostic | N |
| 31 | ProcessActivityStart | Diagnostic | N |
| 32 | ProcessActivityStop | Diagnostic | N |
| 41 | ProcessExempt | Diagnostic | N |
| 42 | PolicyReload | Diagnostic | N |
| 51 | PdcCallback | Diagnostic | N |
| 52 | PdcCallback52 | Diagnostic | N |
| 53 | PdcCallback53 | Diagnostic | N |
| 54 | PdcAcknowledge | Diagnostic | N |
| 60 | IoTrackingPerfTrack | Diagnostic | N |
| 61 | IoTrackingCallback | Diagnostic | N |
Event ID 1: StartDriverStart
#Event ID 4: StartDriver
#Event ID 11: StopDriverStart
#Event ID 19: StopDriverStop
#Event ID 31: ProcessActivityStart
#Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
SessionId UInt32 | |
ImageFileNameLength UInt16 | |
ImageFileName UnicodeString | |
CommandLineLength UInt16 | |
CommandLine UnicodeString |
Event ID 41: ProcessExempt
#Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
SessionId UInt32 | |
ExemptGroup UInt32 | |
RegisterAtLaunch Boolean |
Event ID 54: PdcAcknowledge
#Event ID 60: IoTrackingPerfTrack
#Fields #
| Name | Description |
|---|---|
DeviceBucket UInt32 | |
ElapsedTimeMs UInt32 | |
FastIoCount UInt32 | |
SlowIoCount UInt32 |
Event ID 61: IoTrackingCallback
#Fields #
| Name | Description |
|---|---|
DeviceType UInt16 | |
DeviceBucket UInt32 | |
ElapsedTime UInt64 | |
SlowIo Boolean |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 32dd13df-9c0b-4c3b-b854-ee76c050f5f4
Defined in dam.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02