Microsoft-Windows-Dwm-Dwm
15 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | CompositionStateAndInput | Diagnostic | N |
| 2 | CompositionStateOutput | Diagnostic | N |
| 3 | TraceGraphicsCapabilities | Diagnostic | N |
| 4 | CompositionOverriden | Diagnostic | N |
| 5 | CompositionEnabledByPolicy | Diagnostic | N |
| 6 | RemotingCaps | Diagnostic | N |
| 7 | SystemMemoryLockingThreshold | Diagnostic | N |
| 8 | SlowCompositionTime | Diagnostic | N |
| 9 | StartDWMTransport | Diagnostic | N |
| 10 | StopDWMTransport | Diagnostic | N |
| 11 | AddGhost | Diagnostic | N |
| 12 | DuplicateGhost | Diagnostic | N |
| 13 | VetoCreateGhostWindow | Diagnostic | N |
| 14 | PolicyOrModeChange | Diagnostic | N |
| 15 | EstablishKernelRedirection | Diagnostic | N |
Event ID 6: RemotingCaps
#Fields #
| Name | Description |
|---|---|
IsCapable UInt32 | |
AllowDwmcoreInSession UInt32 | |
RemoteAppEnabled UInt32 | |
AllowDwmcoreInClient UInt32 | |
AllowThemesInCLient UInt32 |
Event ID 7: SystemMemoryLockingThreshold
#Event ID 8: SlowCompositionTime
#Event ID 10: StopDWMTransport
#Event ID 15: EstablishKernelRedirection
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID d29d56ea-4867-4221-b02e-cfd998834075
Defined in dwm.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02