Microsoft-Windows-Security-IdentityStore
27 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | CreateConnectedUserStart | Performance | N |
| 2 | CreateConnectedUserStart2 | Performance | N |
| 3 | CreateConnectedUserStop | Performance | N |
| 4 | ConnectDisconnectUserStart | Performance | N |
| 5 | ConnectDisconnectUserStop | Performance | N |
| 6 | ConnectDisconnectUserStart6 | Performance | N |
| 7 | ConnectDisconnectUserStop7 | Performance | N |
| 8 | ConnectDisconnectUserStart8 | Performance | N |
| 9 | ConnectDisconnectUserStop9 | Performance | N |
| 10 | ConnectDisconnectUserStart10 | Performance | N |
| 11 | ConnectDisconnectUserStop11 | Performance | N |
| 12 | IdentityQueryStart | Performance | N |
| 13 | IdentityQueryStop | Performance | N |
| 14 | IdentityQuery | Performance | Y |
| 15 | IdentityQuery | Performance | Y |
| 16 | IdentityQuery | Performance | Y |
| 17 | IdentityQuery | Performance | Y |
| 18 | IdentityQueryStart18 | Performance | N |
| 19 | IdentityQueryStop19 | Performance | N |
| 20 | IdentityQueryStart20 | Performance | N |
| 21 | IdentityQueryStop21 | Performance | N |
| 22 | CreateConnectedUserStart22 | Performance | N |
| 23 | CreateConnectedUserStop23 | Performance | N |
| 24 | CreateConnectedUserStart24 | Performance | N |
| 25 | CreateConnectedUserStop25 | Performance | N |
| 26 | ConnectDisconnectUserStart26 | Performance | N |
| 27 | ConnectDisconnectUserStop27 | Performance | N |
Event ID 1: CreateConnectedUserStart
#Event ID 2: CreateConnectedUserStart2
#Event ID 3: CreateConnectedUserStop
#Event ID 4: ConnectDisconnectUserStart
#Event ID 5: ConnectDisconnectUserStop
#Event ID 6: ConnectDisconnectUserStart6
#Event ID 7: ConnectDisconnectUserStop7
#Event ID 8: ConnectDisconnectUserStart8
#Event ID 9: ConnectDisconnectUserStop9
#Event ID 10: ConnectDisconnectUserStart10
#Event ID 11: ConnectDisconnectUserStop11
#Event ID 12: IdentityQueryStart
#Event ID 13: IdentityQueryStop
#Event ID 14: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 14,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.425+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 15: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.519+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 16: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.515+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 17: IdentityQuery
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-IdentityStore",
"guid": "{00B7E1DF-B469-4C69-9C41-53A6576E3DAD}",
"event_source_name": "",
"event_id": 17,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:02:39.516+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17172,
"thread_id": 13652
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "IdentityQuery"
}
Event ID 18: IdentityQueryStart18
#Event ID 19: IdentityQueryStop19
#Event ID 20: IdentityQueryStart20
#Event ID 21: IdentityQueryStop21
#Event ID 22: CreateConnectedUserStart22
#Event ID 23: CreateConnectedUserStop23
#Event ID 24: CreateConnectedUserStart24
#Event ID 25: CreateConnectedUserStop25
#Event ID 26: ConnectDisconnectUserStart26
#Event ID 27: ConnectDisconnectUserStop27
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {00B7E1DF-B469-4C69-9C41-53A6576E3DAD}
Defined in idstore.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.5074, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02