Microsoft-Windows-MSPaint
38 events across 2 channels
Event ID 1: Intializing current instance of the application
#Description
Intializing current instance of the application.
Message #
Event ID 2: Exiting current Instance of the application
#Description
Exiting current Instance of the application.
Message #
Event ID 7: Select Tool(ID: ToolID) Start.
#Event ID 9: Commit Tool(ID: ToolID)b Start.
#Event ID 13: Change Tool(ID: ToolID) Thickness(ToolThickness).
#Event ID 14: Change Stroke Color(RGB: Color).
#Event ID 15: Change Fill Color(RGB: Color).
#Event ID 16: Change DrawMode(ShapeDrawMode).
#Event ID 17: Change Brush CrossSection(ToolCrosssection).
#Event ID 18: Change Caligraphic Brush CrossSection(ToolCrosssection).
#Event ID 19: Change Glitter Color(Color).
#Event ID 20: Error enabling/disabling RTS
#Event ID 26: Stop save drawing
#Event ID 38: Stop resize skew operation
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1d75856d-36a7-4ecb-a3f5-b13152222d29
Defined in mspaint.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02