Microsoft-Windows-Schannel-Events

24 events across 1 channel

Event ID 257: AcquireCredentialHandle

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Level
Informational
Task
AcquireCredentialHandle
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 257,
    "version": 0,
    "level": 4,
    "task": 4096,
    "opcode": 1,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.456+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "AcquireCredentialHandle"
}

Event ID 258: AcquireCredentialHandle

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Also via
realtime ETW trace
Level
Informational
Task
AcquireCredentialHandle
Opcode
Stop

Fields #

NameDescription
ReturnValue HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 258,
    "version": 0,
    "level": 4,
    "task": 4096,
    "opcode": 2,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.456+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ReturnValue": "00000000"
  },
  "message": "AcquireCredentialHandle"
}

Event ID 513: AcceptSecurityContextStart

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
AcceptSecurityContext
Opcode
Start

Fields #

NameDescription
CredHandle Pointer
ContextHandle Pointer

Event ID 514: AcceptSecurityContextStop

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
AcceptSecurityContext
Opcode
Stop

Fields #

NameDescription
ContextHandle Pointer
ReturnValue HexInt32

Event ID 769: MemoryAllocationAllocate

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
MemoryAllocation
Opcode
Allocate

Fields #

NameDescription
Address Pointer
AllocationSize HexInt32

Event ID 770: MemoryAllocationFree

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
MemoryAllocation
Opcode
Free

Fields #

NameDescription
Address Pointer

Event ID 1025: CAPI2CallsStart

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Start

Event ID 1026: CAPI2CallsStop

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Stop

Event ID 1027: CAPI2CallsStart1027

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Start

Event ID 1028: CAPI2CallsStop1028

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Stop

Event ID 1029: CAPI2CallsStart1029

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Start

Event ID 1030: CAPI2CallsStop1030

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Stop

Event ID 1031: CAPI2CallsStart1031

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Start

Event ID 1032: CAPI2CallsStop1032

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Stop

Event ID 1033: CAPI2CallsStart1033

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Start

Event ID 1034: CAPI2CallsStop1034

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
CAPI2Calls
Opcode
Stop

Event ID 1281: PKCryptoStart

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
PKCrypto
Opcode
Start

Event ID 1282: PKCryptoStop

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Task
PKCrypto
Opcode
Stop

Event ID 1283: PKCrypto

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Level
Informational
Task
PKCrypto
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1283,
    "version": 0,
    "level": 4,
    "task": 20480,
    "opcode": 1,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.542+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "PKCrypto"
}

Event ID 1284: PKCrypto

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Level
Informational
Task
PKCrypto
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1284,
    "version": 0,
    "level": 4,
    "task": 20480,
    "opcode": 2,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.542+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "PKCrypto"
}

Event ID 1537: FreeCredentialHandle

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Also via
realtime ETW trace
Level
Informational
Task
FreeCredentialHandle
Opcode
Start

Fields #

NameDescription
CredHandle Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1537,
    "version": 0,
    "level": 4,
    "task": 24576,
    "opcode": 1,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.898+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CredHandle": "0x21546C08A40"
  },
  "message": "FreeCredentialHandle"
}

Event ID 1538: FreeCredentialHandle

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Level
Informational
Task
FreeCredentialHandle
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1538,
    "version": 0,
    "level": 4,
    "task": 24576,
    "opcode": 2,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.898+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "FreeCredentialHandle"
}

Event ID 1793: A TLS Security Context handle is being deleted.

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Also via
realtime ETW trace
Level
Informational
Task
DeleteSecurityContext
Opcode
Start

Description

A TLS Security Context handle is being deleted.

Message #

A TLS Security Context handle is being deleted.

   Context handle: %1
   Target name: %2

Fields #

NameDescription
ContextHandle Pointer
TargetName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1793,
    "version": 0,
    "level": 4,
    "task": 28672,
    "opcode": 1,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.897+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ContextHandle": "0x21546DBA4D0",
    "TargetName": "watson.events.data.microsoft.com"
  },
  "message": "DeleteSecurityContext"
}

Event ID 1794: DeleteSecurityContext

#
Provider
Microsoft-Windows-Schannel-Events
Channel
Perf
Level
Informational
Task
DeleteSecurityContext
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Schannel-Events",
    "guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
    "event_source_name": "",
    "event_id": 1794,
    "version": 0,
    "level": 4,
    "task": 28672,
    "opcode": 2,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T06:02:18.897+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
    },
    "execution": {
      "process_id": 944,
      "thread_id": 14076
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "DeleteSecurityContext"
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {91CC1150-71AA-47E2-AE18-C96E61736B6F}

Defined in schannel.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads