Microsoft-Windows-Shsvcs

14 events across 1 channel

Event ID 11501: HDSrv_Service_Start

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Service_Start
Opcode
Start

Event ID 11502: HDSrv_Service_StartStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Service_Start
Opcode
Stop

Event ID 11503: HDSrv_Service_StopStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Service_Stop
Opcode
Start

Event ID 11504: HDSrv_Service_Stop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Service_Stop
Opcode
Stop

Event ID 11505: HDSrv_Volume_Arrived_UpdatedStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Volume_Arrived_Updated
Opcode
Start

Fields #

NameDescription
ContainerIdentifier UnicodeString
DeviceIdentifier UnicodeString

Event ID 11506: HDSrv_Volume_Arrived_UpdatedStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Volume_Arrived_Updated
Opcode
Stop

Event ID 11507: HDSrv_Volume_RemovedStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Volume_Removed
Opcode
Start

Fields #

NameDescription
ContainerIdentifier UnicodeString
DeviceIdentifier UnicodeString

Event ID 11508: HDSrv_Volume_RemovedStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_Volume_Removed
Opcode
Stop

Event ID 11509: HDSrv_NonVolume_NotifyShellStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_NonVolume_NotifyShell
Opcode
Start

Fields #

NameDescription
ContainerIdentifier UnicodeString
DeviceIdentifier UnicodeString

Event ID 11510: HDSrv_NonVolume_NotifyShellStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_NonVolume_NotifyShell
Opcode
Stop

Event ID 11511: HDSrv_ProcessInterfaceCallbackStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_ProcessInterfaceCallback
Opcode
Start

Fields #

NameDescription
ContainerIdentifier UnicodeString
DeviceIdentifier UnicodeString

Event ID 11512: HDSrv_ProcessInterfaceCallbackStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_ProcessInterfaceCallback
Opcode
Stop

Event ID 11513: HDSrv_CreateSafeFileHandleStart

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_CreateSafeFileHandle
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
DesiredAccess UInt32Process access rights reference

Event ID 11514: HDSrv_CreateSafeFileHandleStop

#
Provider
Microsoft-Windows-Shsvcs
Channel
Diagnostic
Task
HDSrv_CreateSafeFileHandle
Opcode
Stop

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 059c3e04-5535-4929-85e1-93030e78f47b

Defined in shsvcs.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads