Microsoft-Windows-Subsys-SMSS

32 events across 2 channels

EventTitleChannelSample
1smss:ExecuteImageStartOperationalN
2smss:ExecuteImageStopOperationalN
3smss:InitializeRegistryStartOperationalN
4smss:InitializeRegistryStopOperationalN
5smss:SetupExecuteListStartOperationalN
6smss:SetupExecuteListStopOperationalN
7smss:BootExecuteListStartOperationalN
8smss:BootExecuteListStopOperationalN
9smss:ProcessFileRenamesStartOperationalN
10smss:ProcessFileRenamesStopOperationalN
11smss:FileRenameOperationalN
12The crash dump file could not be created due to a lack of free space on the …SystemN
13A run level switch from the CurrentRunLevel level to the TargetRunLevel level …SystemN
14A run level switch from the CurrentRunLevel level to the TargetRunLevel level …SystemN
15A run level switch from the CurrentRunLevel level to the TargetRunLevel level …SystemN
16A run level switch from the CurrentRunLevel level to the TargetRunLevel level …SystemN
17A platform binary was successfully executed.SystemN
18An attempt to execute a platform binary failed with error code Status.SystemN
19smss:BootExecuteNoPnpSyncListStartOperationalN
20smss:BootExecuteNoPnpSyncListStopOperationalN
21smss:SerializeBootStartOperationalN
22smss:SerializeBootStopOperationalN
23smss:LoadSubsystemStartOperationalN
24smss:LoadSubsystemStopOperationalN
25smss:InitializeKnownDllsStartOperationalN
26smss:InitializeKnownDllsStopOperationalN
27smss:PlatformExecuteListStartOperationalN
28smss:PlatformExecuteListStopOperationalN
29smss:SetupExecuteNoPnpSyncListStartOperationalN
30smss:SetupExecuteNoPnpSyncListStopOperationalN
31smss:RunSecureKernelTrustletsStartOperationalN
32smss:RunSecureKernelTrustletsStopOperationalN

Event ID 1: smss:ExecuteImageStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:ExecuteImage
Opcode
Start

Fields #

NameDescription
Flags UInt32
ImageNameLength UInt16
ImageName UnicodeString

Event ID 2: smss:ExecuteImageStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:ExecuteImage
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32

Event ID 3: smss:InitializeRegistryStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:InitializeRegistry
Opcode
Start

Event ID 4: smss:InitializeRegistryStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:InitializeRegistry
Opcode
Stop

Event ID 5: smss:SetupExecuteListStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SetupExecuteList
Opcode
Start

Event ID 6: smss:SetupExecuteListStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SetupExecuteList
Opcode
Stop

Event ID 7: smss:BootExecuteListStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:BootExecuteList
Opcode
Start

Event ID 8: smss:BootExecuteListStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:BootExecuteList
Opcode
Stop

Event ID 9: smss:ProcessFileRenamesStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:ProcessFileRenames
Opcode
Start

Event ID 10: smss:ProcessFileRenamesStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:ProcessFileRenames
Opcode
Stop

Event ID 11: smss:FileRename

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:FileRename

Fields #

NameDescription
FromNameLength UInt16
ToNameLength UInt16
FromName UnicodeString
ToName UnicodeString

Event ID 12: The crash dump file could not be created due to a lack of free space on the destination drive.

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

The crash dump file could not be created due to a lack of free space on the destination drive. Increasing the amount of free space on the destination drive may help prevent this error.

Message #

The crash dump file could not be created due to a lack of free space on the destination drive. Increasing the amount of free space on the destination drive may help prevent this error.

Fields #

NameDescription
FileNameLength UInt16
FileName UnicodeString

Event ID 13: A run level switch from the CurrentRunLevel level to the TargetRunLevel level has started.

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

A run level switch from the CurrentRunLevel level to the TargetRunLevel level has started.

Message #

A run level switch from the %1 level to the %2 level has started.

Fields #

NameDescription
CurrentRunLevel UnicodeString
TargetRunLevel UnicodeString

Event ID 14: A run level switch from the CurrentRunLevel level to the TargetRunLevel level has ended successfully.

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

A run level switch from the CurrentRunLevel level to the TargetRunLevel level has ended successfully.

Message #

A run level switch from the %1 level to the %2 level has ended successfully.

Fields #

NameDescription
CurrentRunLevel UnicodeString
TargetRunLevel UnicodeString

Event ID 15: A run level switch from the CurrentRunLevel level to the TargetRunLevel level was failed by AgentName with the following error: Error For more details, please refer to events logged ...

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

A run level switch from the CurrentRunLevel level to the TargetRunLevel level was failed by.

Message #

A run level switch from the %1 level to the %2 level was failed by 
%3 with the following error: 

%4

For more details, please refer to events logged by this agent.

Fields #

NameDescription
CurrentRunLevel UnicodeString
TargetRunLevel UnicodeString
AgentName UnicodeString
Error UnicodeString

Event ID 16: A run level switch from the CurrentRunLevel level to the TargetRunLevel level was succeeded by AgentName with the following warning: Error For more details, please refer to events lo...

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

A run level switch from the CurrentRunLevel level to the TargetRunLevel level was succeeded by.

Message #

A run level switch from the %1 level to the %2 level was succeeded by 
%3 with the following warning: 

%4

For more details, please refer to events logged by this agent.

Fields #

NameDescription
CurrentRunLevel UnicodeString
TargetRunLevel UnicodeString
AgentName UnicodeString
Error UnicodeString

Event ID 17: A platform binary was successfully executed.

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

A platform binary was successfully executed.

Message #

A platform binary was successfully executed.

Event ID 18: An attempt to execute a platform binary failed with error code Status.

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
System
Opcode
Info

Description

An attempt to execute a platform binary failed with error code Status.

Message #

An attempt to execute a platform binary failed with error code %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 19: smss:BootExecuteNoPnpSyncListStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:BootExecuteNoPnpSyncList
Opcode
Start

Event ID 20: smss:BootExecuteNoPnpSyncListStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:BootExecuteNoPnpSyncList
Opcode
Stop

Event ID 21: smss:SerializeBootStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SerializeBoot
Opcode
Start

Event ID 22: smss:SerializeBootStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SerializeBoot
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 23: smss:LoadSubsystemStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:LoadSubsystem
Opcode
Start

Fields #

NameDescription
SessionId UInt32
ImageNameLength UInt16
ImageName UnicodeString

Event ID 24: smss:LoadSubsystemStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:LoadSubsystem
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 25: smss:InitializeKnownDllsStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:InitializeKnownDlls
Opcode
Start

Event ID 26: smss:InitializeKnownDllsStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:InitializeKnownDlls
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 27: smss:PlatformExecuteListStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:PlatformExecuteList
Opcode
Start

Event ID 28: smss:PlatformExecuteListStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:PlatformExecuteList
Opcode
Stop

Event ID 29: smss:SetupExecuteNoPnpSyncListStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SetupExecuteNoPnpSyncList
Opcode
Start

Event ID 30: smss:SetupExecuteNoPnpSyncListStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:SetupExecuteNoPnpSyncList
Opcode
Stop

Event ID 31: smss:RunSecureKernelTrustletsStart

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:RunSecureKernelTrustlets
Opcode
Start

Event ID 32: smss:RunSecureKernelTrustletsStop

#
Provider
Microsoft-Windows-Subsys-SMSS
Channel
Operational
Task
smss:RunSecureKernelTrustlets
Opcode
Stop

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 43e63da5-41d1-4fbf-aded-1bbed98fdd1d

Defined in csrsrv.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads