Microsoft-Windows-Schannel-Events
24 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 257 | AcquireCredentialHandle | Perf | Y |
| 258 | AcquireCredentialHandle | Perf | Y |
| 513 | AcceptSecurityContextStart | Perf | N |
| 514 | AcceptSecurityContextStop | Perf | N |
| 769 | MemoryAllocationAllocate | Perf | N |
| 770 | MemoryAllocationFree | Perf | N |
| 1025 | CAPI2CallsStart | Perf | N |
| 1026 | CAPI2CallsStop | Perf | N |
| 1027 | CAPI2CallsStart1027 | Perf | N |
| 1028 | CAPI2CallsStop1028 | Perf | N |
| 1029 | CAPI2CallsStart1029 | Perf | N |
| 1030 | CAPI2CallsStop1030 | Perf | N |
| 1031 | CAPI2CallsStart1031 | Perf | N |
| 1032 | CAPI2CallsStop1032 | Perf | N |
| 1033 | CAPI2CallsStart1033 | Perf | N |
| 1034 | CAPI2CallsStop1034 | Perf | N |
| 1281 | PKCryptoStart | Perf | N |
| 1282 | PKCryptoStop | Perf | N |
| 1283 | PKCrypto | Perf | Y |
| 1284 | PKCrypto | Perf | Y |
| 1537 | FreeCredentialHandle | Perf | Y |
| 1538 | FreeCredentialHandle | Perf | Y |
| 1793 | A TLS Security Context handle is being deleted. | Perf | Y |
| 1794 | DeleteSecurityContext | Perf | Y |
Event ID 257: AcquireCredentialHandle
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 257,
"version": 0,
"level": 4,
"task": 4096,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.456+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "AcquireCredentialHandle"
}
Event ID 258: AcquireCredentialHandle
#Fields #
| Name | Description |
|---|---|
ReturnValue HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 258,
"version": 0,
"level": 4,
"task": 4096,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.456+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"ReturnValue": "00000000"
},
"message": "AcquireCredentialHandle"
}
Event ID 513: AcceptSecurityContextStart
#Fields #
| Name | Description |
|---|---|
CredHandle Pointer | |
ContextHandle Pointer |
Event ID 514: AcceptSecurityContextStop
#Fields #
| Name | Description |
|---|---|
ContextHandle Pointer | |
ReturnValue HexInt32 |
Event ID 769: MemoryAllocationAllocate
#Fields #
| Name | Description |
|---|---|
Address Pointer | |
AllocationSize HexInt32 |
Event ID 1025: CAPI2CallsStart
#Event ID 1026: CAPI2CallsStop
#Event ID 1027: CAPI2CallsStart1027
#Event ID 1028: CAPI2CallsStop1028
#Event ID 1029: CAPI2CallsStart1029
#Event ID 1030: CAPI2CallsStop1030
#Event ID 1031: CAPI2CallsStart1031
#Event ID 1032: CAPI2CallsStop1032
#Event ID 1033: CAPI2CallsStart1033
#Event ID 1034: CAPI2CallsStop1034
#Event ID 1281: PKCryptoStart
#Event ID 1282: PKCryptoStop
#Event ID 1283: PKCrypto
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1283,
"version": 0,
"level": 4,
"task": 20480,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.542+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "PKCrypto"
}
Event ID 1284: PKCrypto
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1284,
"version": 0,
"level": 4,
"task": 20480,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.542+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "PKCrypto"
}
Event ID 1537: FreeCredentialHandle
#Fields #
| Name | Description |
|---|---|
CredHandle Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1537,
"version": 0,
"level": 4,
"task": 24576,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.898+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"CredHandle": "0x21546C08A40"
},
"message": "FreeCredentialHandle"
}
Event ID 1538: FreeCredentialHandle
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1538,
"version": 0,
"level": 4,
"task": 24576,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.898+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "FreeCredentialHandle"
}
Event ID 1793: A TLS Security Context handle is being deleted.
#Description
A TLS Security Context handle is being deleted.
Message #
Fields #
| Name | Description |
|---|---|
ContextHandle Pointer | |
TargetName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1793,
"version": 0,
"level": 4,
"task": 28672,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.897+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"ContextHandle": "0x21546DBA4D0",
"TargetName": "watson.events.data.microsoft.com"
},
"message": "DeleteSecurityContext"
}
Event ID 1794: DeleteSecurityContext
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Schannel-Events",
"guid": "{91CC1150-71AA-47E2-AE18-C96E61736B6F}",
"event_source_name": "",
"event_id": 1794,
"version": 0,
"level": 4,
"task": 28672,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:18.897+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-E99F-52720FEEDC01}"
},
"execution": {
"process_id": 944,
"thread_id": 14076
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "DeleteSecurityContext"
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {91CC1150-71AA-47E2-AE18-C96E61736B6F}
Defined in schannel.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02