Microsoft-Windows-Sysprep
14 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | Executing sysprep providers from registry location "BasePath" during Phase. | Analytic | N |
| 1002 | Finished executing sysprep providers with status ErrorCode. | Analytic | N |
| 2001 | Calling external function "FunctionName" from "DllName". | Analytic | N |
| 2002 | External function returned with status DllName. | Analytic | N |
| 3001 | Loading meta-data file "ActionFilePath". | Analytic | N |
| 3002 | Loading of meta-data file "ActionFilePath" completed. | Analytic | N |
| 4001 | Creating action list for component "ComponentName". | Analytic | N |
| 4002 | Action list for component "ComponentName" created. | Analytic | N |
| 5001 | Deleting file(s) "FilePattern" from directory "DirectoryPath". | Analytic | N |
| 5002 | File deletion of "FilePattern" from directory "DirectoryPath" returned with … | Analytic | N |
| 6001 | Deleting directory "DirectoryPath". | Analytic | N |
| 6002 | Directory deletion for "DirectoryPath" returned with status ErrorCode. | Analytic | N |
| 7001 | Starting execution of phase "Phase". | Analytic | N |
| 7002 | Execution of phase returned status ErrorCode. | Analytic | N |
Event ID 1001: Executing sysprep providers from registry location "BasePath" during Phase.
#Event ID 1002: Finished executing sysprep providers with status ErrorCode.
#Event ID 2001: Calling external function "FunctionName" from "DllName".
#Event ID 2002: External function returned with status DllName.
#Event ID 3001: Loading meta-data file "ActionFilePath".
#Event ID 3002: Loading of meta-data file "ActionFilePath" completed.
#Event ID 4001: Creating action list for component "ComponentName".
#Event ID 4002: Action list for component "ComponentName" created.
#Event ID 5001: Deleting file(s) "FilePattern" from directory "DirectoryPath".
#Event ID 5002: File deletion of "FilePattern" from directory "DirectoryPath" returned with status ErrorCode.
#Event ID 6001: Deleting directory "DirectoryPath".
#Event ID 6002: Directory deletion for "DirectoryPath" returned with status ErrorCode.
#Event ID 7001: Starting execution of phase "Phase".
#Event ID 7002: Execution of phase returned status ErrorCode.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 75ebc33e-77b8-4ba8-9474-4f4a9db2f5c6
Defined in sysprep.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02