Microsoft-Windows-Subsys-SMSS
32 events across 2 channels
Event ID 1: smss:ExecuteImageStart
#Fields #
| Name | Description |
|---|---|
Flags UInt32 | |
ImageNameLength UInt16 | |
ImageName UnicodeString |
Event ID 3: smss:InitializeRegistryStart
#Event ID 4: smss:InitializeRegistryStop
#Event ID 5: smss:SetupExecuteListStart
#Event ID 6: smss:SetupExecuteListStop
#Event ID 7: smss:BootExecuteListStart
#Event ID 8: smss:BootExecuteListStop
#Event ID 9: smss:ProcessFileRenamesStart
#Event ID 10: smss:ProcessFileRenamesStop
#Event ID 11: smss:FileRename
#Fields #
| Name | Description |
|---|---|
FromNameLength UInt16 | |
ToNameLength UInt16 | |
FromName UnicodeString | |
ToName UnicodeString |
Event ID 12: The crash dump file could not be created due to a lack of free space on the destination drive.
#Event ID 13: A run level switch from the CurrentRunLevel level to the TargetRunLevel level has started.
#Event ID 14: A run level switch from the CurrentRunLevel level to the TargetRunLevel level has ended successfully.
#Event ID 15: A run level switch from the CurrentRunLevel level to the TargetRunLevel level was failed by AgentName with the following error: Error For more details, please refer to events logged ...
#Event ID 16: A run level switch from the CurrentRunLevel level to the TargetRunLevel level was succeeded by AgentName with the following warning: Error For more details, please refer to events lo...
#Event ID 17: A platform binary was successfully executed.
#Description
A platform binary was successfully executed.
Message #
Event ID 18: An attempt to execute a platform binary failed with error code Status.
#Description
An attempt to execute a platform binary failed with error code Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 19: smss:BootExecuteNoPnpSyncListStart
#Event ID 20: smss:BootExecuteNoPnpSyncListStop
#Event ID 21: smss:SerializeBootStart
#Event ID 22: smss:SerializeBootStop
#Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 23: smss:LoadSubsystemStart
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
ImageNameLength UInt16 | |
ImageName UnicodeString |
Event ID 24: smss:LoadSubsystemStop
#Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 25: smss:InitializeKnownDllsStart
#Event ID 26: smss:InitializeKnownDllsStop
#Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 27: smss:PlatformExecuteListStart
#Event ID 28: smss:PlatformExecuteListStop
#Event ID 29: smss:SetupExecuteNoPnpSyncListStart
#Event ID 30: smss:SetupExecuteNoPnpSyncListStop
#Event ID 31: smss:RunSecureKernelTrustletsStart
#Event ID 32: smss:RunSecureKernelTrustletsStop
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 43e63da5-41d1-4fbf-aded-1bbed98fdd1d
Defined in csrsrv.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02