Microsoft-Windows-Dwm-Udwm
156 events across 1 channel
Event ID 6: UdwmEstablishTransportStart
#Event ID 7: UdwmEstablishTransportStop
#Event ID 8: UdwmEstablishStructuralRedirectionStart
#Event ID 9: UdwmEstablishStructuralRedirectionStop
#Event ID 10: UdwmEstablishDesktopCompositionStart
#Event ID 11: UdwmEstablishDesktopCompositionStop
#Event ID 12: UdwmEstablishKernelRedirectionStart
#Event ID 13: UdwmEstablishKernelRedirectionStop
#Event ID 14: UdwmRefreshDesktopComposition
#Event ID 15: UdwmResetGraphicsStream
#Event ID 5001: UdwmShutdownMessage
#Event ID 5002: UdwmAnimation
#Fields #
| Name | Description |
|---|---|
AnimationType UInt32 | |
Hwnd Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5002,
"version": 0,
"level": 4,
"task": 5002,
"opcode": 1,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.759+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 1704
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"AnimationType": 1,
"Hwnd": "0x2F0626"
},
"message": "UdwmAnimation"
}
Event ID 5003: UdwmAnimation
#Fields #
| Name | Description |
|---|---|
AnimationType UInt32 | |
Hwnd Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5003,
"version": 0,
"level": 4,
"task": 5002,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:57.073+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"AnimationType": 1,
"Hwnd": "0x2F0626"
},
"message": "UdwmAnimation"
}
Event ID 5004: UdwmAnimation
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5004,
"version": 0,
"level": 4,
"task": 5002,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.807+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UdwmAnimation"
}
Event ID 5011: UdwmLivePreviewAnimationStart
#Event ID 5012: UdwmLivePreviewAnimationStop
#Event ID 5013: UdwmAllAnimationFinished
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5013,
"version": 0,
"level": 4,
"task": 5008,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:57.105+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UdwmAllAnimationFinished"
}
Event ID 5018: UdwmGlassSheetAnimationStart
#Event ID 5019: UdwmGlassSheetAnimation
#Event ID 5020: UdwmGlassSheetAnimationStop
#Fields #
| Name | Description |
|---|---|
Left Int32 | |
Top Int32 | |
Right Int32 | |
Bottom Int32 |
Event ID 5021: UdwmRippleAnimation
#Event ID 5022: UdwmRippleAnimation5022
#Event ID 5023: UdwmGlassSheetFadeOut
#Event ID 5024: UdwmGlassSheetFadeOut5024
#Event ID 5025: UdwmLoadThemeStart
#Event ID 5026: UdwmLoadThemeStop
#Event ID 5036: UdwmAnimationInitializationStop
#Event ID 5037: UdwmAnimationRecalc
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5037,
"version": 0,
"level": 4,
"task": 5020,
"opcode": 1,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.807+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UdwmAnimationRecalc"
}
References #
Event ID 5038: UdwmAnimationRecalc
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5038,
"version": 0,
"level": 4,
"task": 5020,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.807+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UdwmAnimationRecalc"
}
References #
Event ID 5050: UdwmTetherVisualStop
#References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5050
Event ID 5059: UdwmAnimationEngineStart
#Fields #
| Name | Description |
|---|---|
AnimationID UInt32 | |
StoryboardID Int32 | |
TickCount UInt32 |
Event ID 5060: UdwmAnimationEngineStop
#Event ID 5061: UdwmLoginTransitionStart
#Event ID 5063: UdwmTransitionVisualControllerStart
#Event ID 5065: UdwmTransitionVisualControllerStop
#Event ID 5071: UdwmAnimationEngine
#Fields #
| Name | Description |
|---|---|
AnimationID UInt32 | |
x0 Float | |
y0 Float | |
x1 Float | |
y1 Float |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5071
Event ID 5077: UdwmGradientLoadStart
#Event ID 5078: UdwmGradientLoadStop
#Event ID 5079: UdwmGradientColorizeStart
#Event ID 5080: UdwmGradientColorizeStop
#Event ID 5082: UdwmAccentLoadStop
#Event ID 5083: UdwmAnimationComponent
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
StoryboardId Int32 | |
Target Int32 |
Event ID 5084: UdwmAnimationComponent5084
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
StoryboardId Int32 | |
Target Int32 |
Event ID 5085: UdwmAnimationComponent5085
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
StoryboardId Int32 | |
Target Int32 |
Event ID 5086: UdwmAnimationComponent5086
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
StoryboardId Int32 | |
Target Int32 |
Event ID 5089: UdwmAnimatedTransitionVisual
#Fields #
| Name | Description |
|---|---|
StoryboardId Int32 | |
TargetId Int32 | |
BeginLeft Int32 | |
BeginTop Int32 | |
BeginRight Int32 | |
BeginBottom Int32 | |
EndLeft Int32 | |
EndTop Int32 | |
EndRight Int32 | |
EndBottom Int32 | |
BeginOpacity Float | |
EndOpacity Float | |
BeginDepth Float | |
EndDepth Float | |
ResourceHandle UInt32 | |
StaggerOrder UInt32 | |
AnimationId UInt32 |
Event ID 5094: UdwmTransitionCVISnapshot
#Event ID 5095: UdwmTransitionProcessSnapshotOnVisual
#Event ID 5097: UdwmSecondaryWindowMakeStatic
#Event ID 5098: UdwmScreenRotationPreDelayAnimationStart
#Event ID 5099: UdwmScreenRotationPreDelayAnimationStop
#Event ID 5100: UdwmScreenRotationPostDelayAnimationStart
#Event ID 5101: UdwmScreenRotationPostDelayAnimationStop
#Event ID 5102: UdwmScreenRotationHintDelayStart
#Event ID 5103: UdwmScreenRotationHintDelayStop
#Event ID 5104: UdwmScreenRotationHintFired
#Event ID 5105: UdwmHardwareExpressionCapture
#Event ID 5106: UdwmHardwareExpressionDelayStart
#Event ID 5107: UdwmHardwareExpressionDelayStop
#Event ID 5108: UdwmHardwareExpressionHintDelayStart
#Event ID 5109: UdwmHardwareExpressionHintDelayStop
#Event ID 5110: UdwmHardwareExpressionPreDelayAnimationStart
#Event ID 5111: UdwmHardwareExpressionPreDelayAnimationStop
#Event ID 5112: UdwmHardwareExpressionPostDelayAnimationStart
#Event ID 5113: UdwmHardwareExpressionPostDelayAnimationStop
#Event ID 5114: UdwmHardwareExpressionAnimationStart
#Event ID 5116: UdwmHardwareExpressionHintFired
#Event ID 5117: UdwmSystemAnimation
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
Cloaked UInt32 | |
Tracked UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5117,
"version": 0,
"level": 4,
"task": 5021,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.759+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 1704
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Cloaked": 0,
"Tracked": 0,
"hwnd": "0x2F0626"
},
"message": "UdwmSystemAnimation"
}
Event ID 5120: UdwmSystemAnimation5120
#Fields #
| Name | Description |
|---|---|
StoryboardID Int32 |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5120
Event ID 5121: UdwmSystemAnimation5121
#Fields #
| Name | Description |
|---|---|
StoryboardID Int32 |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5121
Event ID 5122: UdwmSystemAnimation5122
#Fields #
| Name | Description |
|---|---|
StoryboardID Int32 |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5122
Event ID 5123: UdwmSystemAnimation5123
#Fields #
| Name | Description |
|---|---|
hwndCloned Pointer | |
hwndAfter Pointer |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5123
Event ID 5124: UdwmSystemAnimation5124
#Fields #
| Name | Description |
|---|---|
hwnd Pointer |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5124
Event ID 5125: UdwmSystemAnimationStart
#Fields #
| Name | Description |
|---|---|
hwnd Pointer |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5125
Event ID 5127: UdwmAnimationClockStart
#Fields #
| Name | Description |
|---|---|
clockId GUID | |
timespan UInt32 |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5127
Event ID 5129: UdwmAnimationClockStart5129
#Fields #
| Name | Description |
|---|---|
clockId GUID | |
timespan UInt32 | |
count Int64 |
Event ID 5134: UdwmAnimationClock5134
#Fields #
| Name | Description |
|---|---|
clockId GUID | |
oldValue Int32 | |
newValue Int32 |
Event ID 5151: UdwmSystemAnimation5151
#Event ID 5152: UdwmAnimationResource
#Event ID 5153: UdwmWindowDPIChange
#Fields #
| Name | Description |
|---|---|
hwnd Pointer | |
DPI Int32 | |
LogicalOriginX Int32 | |
LogicalOriginY Int32 | |
PhysicalOriginX Int32 | |
PhysicalOriginY Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 5153,
"version": 0,
"level": 4,
"task": 5127,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:56.595+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 1704
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"DPI": 96,
"LogicalOriginX": 0,
"LogicalOriginY": 0,
"PhysicalOriginX": 0,
"PhysicalOriginY": 0,
"hwnd": "0x2F0626"
},
"message": "UdwmWindowDPIChange"
}
References #
Event ID 5154: UdwmSystemAnimation5154
#Event ID 5155: UdwmSystemAnimation5155
#Event ID 5156: UdwmSystemAnimation5156
#Event ID 5157: UdwmMaximizeSnapTransition
#Event ID 9001: wr RemoveSecondaryWindowRepresentation secondarywindowpointer{secondarywindowpointer}, hwnd{hwnd}.
#Event ID 9002: RemoveSecondaryWindowRepresentation secondarywindowpointer{secondarywindowpointer}, hwnd{hwnd} representationType{representationType}.
#Description
RemoveSecondaryWindowRepresentation secondarywindowpointer{secondarywindowpointer}, hwnd{hwnd} representationType{representationType}.
Message #
Fields #
| Name | Description |
|---|---|
secondarywindowpointer Pointer | |
hwnd Pointer | |
representationType Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 9002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:57.073+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"hwnd": "0x2F0626",
"representationType": 1,
"secondarywindowpointer": "0x1B7FF783DC0"
},
"message": ""
}
Event ID 9003: RemoveSecondaryWindowRepresentation secondarywindowpointer{secondarywindowpointer}, hwnd{hwnd}.
#Description
RemoveSecondaryWindowRepresentation secondarywindowpointer{secondarywindowpointer}, hwnd{hwnd}.
Message #
Fields #
| Name | Description |
|---|---|
secondarywindowpointer Pointer | |
hwnd Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 9003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:57.073+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 2508
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"hwnd": "0x2F0626",
"secondarywindowpointer": "0x1B7FF783DC0"
},
"message": ""
}
Event ID 9004: _StopTrackingWindow CWindowData{CWindowData}.
#Event ID 9005: Thumbnail hwndDestination{hwndDestination}.
#Event ID 9006: ownedWindow pwd{pwd}, hwnd{hwnd}.
#Event ID 9007: UpdateScene
#Description
UpdateScene.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dwm-Udwm",
"guid": "{A2D1C713-093B-43A7-B445-D09370EC9F47}",
"event_source_name": "",
"event_id": 9007,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T04:52:54.632+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1648,
"thread_id": 1704
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 9009: Snapshot pSnapshot{pSnapshot}.
#Event ID 10000: PerfTrack_UdwmLivePreviewAnimation_FirstFrameFinished
#Fields #
| Name | Description |
|---|---|
PerfTrackId UInt32 |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {A2D1C713-093B-43A7-B445-D09370EC9F47}
Defined in udwm.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02