Microsoft-Windows-LUA
45 events across 2 channels
Event ID 15001: ConsentUI_GetUserDesktopSnapshotStart
#Event ID 15002: ConsentUI_GetUserDesktopSnapshotStop
#Event ID 15003: ConsentUI_WindowThreadStart
#Event ID 15004: ConsentUI_WindowThreadStop
#Event ID 15005: ConsentUI_WindowThread
#Event ID 15006: ConsentUI_SwitchDesktopStart
#Event ID 15007: ConsentUI_SwitchDesktopStop
#Event ID 15008: ConsentUI_ReturnUserDesktopStart
#Event ID 15009: ConsentUI_ReturnUserDesktopStop
#Event ID 15010: ConsentUI_WindowThreadStart15010
#Event ID 15011: ConsentUI_WindowThreadStop15011
#Event ID 15012: ConsentUI_CheckActiveDesktopStart
#Event ID 15013: ConsentUI_CheckActiveDesktopStop
#Event ID 15014: ConsentUI_CheckActiveDesktopStart15014
#Event ID 15015: ConsentUI_CheckActiveDesktopStop15015
#Event ID 15016: ConsentUI_WindowThreadStart15016
#Event ID 15017: ConsentUI_WindowThreadStop15017
#Event ID 15018: ConsentUI_WindowThreadStart15018
#Event ID 15019: ConsentUI_WindowThreadStop15019
#Event ID 15020: ConsentUI_WindowThreadStart15020
#Event ID 15021: ConsentUI_WindowThreadStop15021
#Event ID 15022: ConsentUI_ExperienceStart
#Event ID 15023: ConsentUI_ExperienceStop
#Event ID 15024: ConsentUI_ExperienceStart15024
#Event ID 15025: ConsentUI_ExperienceStop15025
#Event ID 15026: ConsentUI_ExperienceStart15026
#Event ID 15027: ConsentUI_ExperienceStop15027
#Event ID 15029: ConsentUI_AMScanStart
#Event ID 15030: ConsentUI_AMScanStop
#Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as
#Description
Success: Elevation prompt for executable ( published by ) answered by , will elevate as .
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | |
Publisher UnicodeString | |
FullCommandLine UnicodeString | |
UserName UnicodeString | |
ShadowAdmin UnicodeString | |
ShadowAdminSID UnicodeString | |
ReturnCode UInt32 | |
ReturnMessage UnicodeString |
Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.
#Description
Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.
Message #
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | |
Publisher UnicodeString | |
FullCommandLine UnicodeString | |
UserName UnicodeString | |
ShadowAdmin UnicodeString | |
ShadowAdminSID UnicodeString | |
ReturnCode UInt32 | |
ReturnMessage UnicodeString |
Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by
#Description
Elevation prompt for executable ( published by ) answered by . Error : .
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | |
Publisher UnicodeString | |
FullCommandLine UnicodeString | |
UserName UnicodeString | |
ShadowAdmin UnicodeString | |
ShadowAdminSID UnicodeString | |
ReturnCode UInt32 | |
ReturnMessage UnicodeString |
Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName.
#Description
Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName. Error ReturnCode: ReturnMessage.
Message #
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | |
Publisher UnicodeString | |
FullCommandLine UnicodeString | |
UserName UnicodeString | |
ShadowAdmin UnicodeString | |
ShadowAdminSID UnicodeString | |
ReturnCode UInt32 | |
ReturnMessage UnicodeString |
Event ID 16001: AppInfo_PerfTrack_ElevationPathStart
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16002: AppInfo_PerfTrack_ElevationPathStop
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16003: AppInfo_PerfTrack_ElevationPathStart16003
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16004: AppInfo_PerfTrack_ElevationPathStop16004
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16005: AppInfo_PerfTrack_ElevationPathStart16005
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16006: AppInfo_PerfTrack_ElevationPathStop16006
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16007: AppInfo_PerfTrack_ElevationPathStart16007
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16008: AppInfo_PerfTrack_ElevationPathStop16008
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16009: AppInfo_PerfTrack_ElevationPathStop16009
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16010: AppInfo_PerfTrack_ElevationPathStart16010
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Event ID 16011: AppInfo_PerfTrack_ElevationPathStop16011
#Fields #
| Name | Description |
|---|---|
EventId UInt32 | |
UACElevateFileID UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 93c05d69-51a3-485e-877f-1806a8731346
Defined in appinfo.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02