Microsoft-Windows-SendTo

EventTitleChannelSampleRule
1SendTo_DllLoadedDiagnosticNN
2SendTo_DllUnloadedDiagnosticNN
3SendTo_EmailStartDiagnosticNN
4SendTo_EmailStopDiagnosticNN
5SendTo_EmailCancelStartDiagnosticNN
6SendTo_EmailCancelStopDiagnosticNN
7SendTo_PagesInitializedDiagnosticNN

Event ID 1: SendTo_DllLoaded

#
Channel
Diagnostic
Task
SendTo_DllLoaded

Event ID 2: SendTo_DllUnloaded

#
Channel
Diagnostic
Task
SendTo_DllUnloaded

Event ID 3: SendTo_EmailStart

#
Channel
Diagnostic
Task
SendTo_Email
Opcode
Start

Event ID 4: SendTo_EmailStop

#
Channel
Diagnostic
Task
SendTo_Email
Opcode
Stop

Event ID 5: SendTo_EmailCancelStart

#
Channel
Diagnostic
Task
SendTo_EmailCancel
Opcode
Start

Event ID 6: SendTo_EmailCancelStop

#
Channel
Diagnostic
Task
SendTo_EmailCancel
Opcode
Stop

Event ID 7: SendTo_PagesInitialized

#
Channel
Diagnostic
Task
SendTo_PagesInitialized

Provenance

ETW provider GUID 35642cf5-da5e-410b-9d9c-a45f3638042b

Defined in sendmail.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB