Microsoft-Windows-HostGuardianClient-Service
15 events across 3 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Host guardian client service is launched. | Operational | N |
| 2 | Host guardian client service is shutdown. | Operational | N |
| 3 | Host guardian client is started. | Operational | N |
| 4 | Host guardian client service is stopped. | Operational | N |
| 5 | Message. | Debug | N |
| 5 | Event ID 5 | Operational | N |
| 6 | Message --> Win32Error. | Debug | N |
| 6 | Event ID 6 | Operational | N |
| 7 | Message --> Win32Error. | Debug | N |
| 7 | Event ID 7 | Operational | N |
| 8 | 'Win32Error' error registering service with service control manager. | Admin | N |
| 8 | Event ID 8 | Operational | N |
| 9 | Failed to load the attestation WMI provider (Str1) at namespace Str2 from path … | Operational | N |
| 10 | Failed to load the service plugin from path Message. | Operational | N |
| 11 | Failed to initialize global configuration with error Win32Error. | Operational | N |
Event ID 1: Host guardian client service is launched.
#Description
Host guardian client service is launched.
Message #
Event ID 2: Host guardian client service is shutdown.
#Description
Host guardian client service is shutdown.
Message #
Event ID 4: Host guardian client service is stopped.
#Description
Host guardian client service is stopped.
Message #
Event ID 6: Message --> Win32Error.
#Event ID 7: Message --> Win32Error.
#Event ID 8: 'Win32Error' error registering service with service control manager.
#Event ID 8
#Description
'Win32Error' error registering service with service control manager.
Fields #
| Name | Description |
|---|---|
Win32Error UInt32 |
Event ID 9: Failed to load the attestation WMI provider (Str1) at namespace Str2 from path Str3.
#Event ID 10: Failed to load the service plugin from path Message.
#Event ID 11: Failed to initialize global configuration with error Win32Error.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 5d487fad-104b-5ca6-ca4e-14c206850501
Defined in hgclientservice.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02