Microsoft-Windows-Ncasvc
29 events across 1 channel
Event ID 1: NCA service status changed.
#Description
NCA service status changed. New Status: (Status).
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 2: NCA status update.
#Description
NCA status update. New Status: (Status, Substatus).
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Substatus UInt32 | NTSTATUS reference |
Event ID 3: NCA API Activity Start, function: (ApiFunction).
#Event ID 4: NCA API Activity End, function: (ApiFunction), error: (Error).
#Event ID 5: NCA Evidence Collector Update, evcoll: (EvColl), old: (Old), new: (New).
#Event ID 6: NCA Probe Start, type: (Type), resource: (Resource).
#Event ID 7: NCA Probe End, type: (Type), resource: (Resource), result: (Result).
#Event ID 8: NCA Probe Callback, type: (Type), code: (Code), error: (Error).
#Event ID 9: NCA Source Configuration Update started.
#Event ID 10: NCA Source Configuration Update complete.
#Event ID 11: NCA Module ModuleName Initialization started.
#Event ID 12: NCA Module ModuleName Initialization complete with error Error.
#Event ID 13: NCA Module ModuleName Shutdown started.
#Event ID 14: NCA Module ModuleName Shutdown complete.
#Event ID 15: NCA Trigger Source.
#Event ID 10001: NCA PerfTrack Scenario Event.
#Event ID 10002: NCA PerfTrack Scenario Event.
#Event ID 10003: NCA PerfTrack Scenario Event.
#Event ID 10004: NCA PerfTrack Scenario Event.
#Event ID 10005: NCA PerfTrack Scenario Event.
#Event ID 10006: NCA PerfTrack Scenario Event.
#Event ID 10007: NCA PerfTrack Scenario Event.
#Event ID 10008: NCA PerfTrack Scenario Event.
#Event ID 10009: NCA PerfTrack Scenario Event.
#Event ID 10010: NCA PerfTrack Scenario Event.
#Event ID 10011: NCA PerfTrack Scenario Event.
#Event ID 10012: NCA PerfTrack Scenario Event.
#Event ID 10013: NCA PerfTrack Scenario Event.
#Event ID 10014: NCA PerfTrack Scenario Event.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 126ded58-a28d-4113-8e7a-59d7444b2af1
Defined in ncasvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02