Microsoft-Windows-Sudo

2 events across 1 channel

EventTitleChannelSample
1FullCommandline.AdminN
2FullCommandline.AdminN

Event ID 1: FullCommandline.

#
Provider
Microsoft-Windows-Sudo
Channel
Admin

Description

FullCommandline

Message #

%8

Fields #

NameDescription
Application AnsiString
ArgsCount UInt32
Argument AnsiString
CurrentWorkingDirectory AnsiString
Mode UInt32
InheritEnvironment UInt8
Redirected UInt8
FullCommandline AnsiString
RequestID GUID

Event ID 2: FullCommandline.

#
Provider
Microsoft-Windows-Sudo
Channel
Admin

Description

FullCommandline

Message #

%8

Fields #

NameDescription
Application AnsiString
ArgsCount UInt32
Argument AnsiString
CurrentWorkingDirectory AnsiString
Mode UInt32
InheritEnvironment UInt8
Redirected UInt8
FullCommandline AnsiString
RequestID GUID

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 9d74dc62-b75f-54cd-be9e-c28940b5feed

Defined in sudo.exe, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 1.0.1, captured 2026-06-02

Downloads