Microsoft-Windows-TSF-msctf
95 events across 1 channel
Event ID 1: InitMSCTFForProcess
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 1,
"opcode": 1,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T05:32:12.637+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 9660,
"thread_id": 16940
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "InitMSCTFForProcess"
}
Event ID 2: InitMSCTFForProcess
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 2,
"version": 0,
"level": 4,
"task": 1,
"opcode": 2,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T05:32:12.637+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 9660,
"thread_id": 16940
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "InitMSCTFForProcess"
}
Event ID 3: UninitMSCTFForProcess
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 4,
"task": 2,
"opcode": 1,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:39.831+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 14036,
"thread_id": 8384
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UninitMSCTFForProcess"
}
Event ID 4: UninitMSCTFForProcess
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 4,
"version": 0,
"level": 4,
"task": 2,
"opcode": 2,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:39.831+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 14036,
"thread_id": 8384
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "UninitMSCTFForProcess"
}
Event ID 5: ActivateCiceroForThread
#Fields #
| Name | Description |
|---|---|
thread_flags UInt32 | |
activation_flags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 5,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:39.495+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"activation_flags": 2147483681,
"thread_flags": 0
},
"message": "ActivateCiceroForThread"
}
Event ID 6: ActivateCiceroForThread
#Event ID 7: ActivateCiceroForThread
#Fields #
| Name | Description |
|---|---|
thread_flags UInt32 | |
activation_flags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 7,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:39.502+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"activation_flags": 0,
"thread_flags": 33
},
"message": "ActivateCiceroForThread"
}
Event ID 8: DeactivateCiceroForThread
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 8,
"version": 0,
"level": 4,
"task": 4,
"opcode": 1,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:40.074+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "DeactivateCiceroForThread"
}
Event ID 9: DeactivateCiceroForThread
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 9,
"version": 0,
"level": 4,
"task": 4,
"opcode": 2,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:40.074+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "DeactivateCiceroForThread"
}
Event ID 10: FLSCallback
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 10,
"version": 0,
"level": 4,
"task": 6,
"opcode": 1,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:40.072+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "FLSCallback"
}
Event ID 11: FLSCallback
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 11,
"version": 0,
"level": 4,
"task": 6,
"opcode": 2,
"keywords": "0x0000000000020000",
"time_created": "2026-06-02T06:05:40.075+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "FLSCallback"
}
Event ID 12: ConnectServer
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 12,
"version": 0,
"level": 4,
"task": 7,
"opcode": 1,
"keywords": "0x0000000000220000",
"time_created": "2026-06-02T06:05:39.496+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ConnectServer"
}
Event ID 13: ConnectServer
#Event ID 14: ConnectServer
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 14,
"version": 0,
"level": 4,
"task": 7,
"opcode": 2,
"keywords": "0x0000000000220000",
"time_created": "2026-06-02T06:05:39.497+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ConnectServer"
}
Event ID 15: task_0
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000210000",
"time_created": "2026-06-02T06:05:39.500+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 16: CreateMessageWindow
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 4,
"task": 17,
"opcode": 0,
"keywords": "0x0000000000010000",
"time_created": "2026-06-02T06:05:39.496+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "CreateMessageWindow"
}
Event ID 17: CreateMessageWindow17
#Event ID 18: task_018
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 18,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000010000",
"time_created": "2026-06-02T06:05:39.499+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 23: CheckLastWindowDestroyedStart
#Event ID 24: CheckLastWindowDestroyedStop
#Event ID 25: CreateAssemblyListStart
#Event ID 26: CreateAssemblyListStop
#Event ID 27: LoadAssemblyListStart
#Event ID 28: LoadAssemblyListStop
#Event ID 31: HandleThreadInputFocusEventStart
#Fields #
| Name | Description |
|---|---|
event UInt32 | |
hwnd Pointer | |
flags UInt32 | |
event_order UInt32 |
Event ID 33: HandleGlobalInputFocusEventStart
#Fields #
| Name | Description |
|---|---|
event UInt32 | |
hwnd Pointer | |
flags UInt32 | |
event_order UInt32 |
Event ID 34: HandleGlobalInputFocusEventStop
#Event ID 35: SendNotification
#Fields #
| Name | Description |
|---|---|
message UInt32 | |
target_tid UInt32 | |
params UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 35,
"version": 0,
"level": 4,
"task": 19,
"opcode": 9,
"keywords": "0x0000000000200000",
"time_created": "2026-06-02T06:05:39.502+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"message": 16777242,
"params": 8,
"target_tid": 0
},
"message": "SendNotification"
}
Event ID 36: SendSyncRequest
#Fields #
| Name | Description |
|---|---|
message UInt32 | |
target_tid UInt32 | |
params UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 36,
"version": 0,
"level": 4,
"task": 20,
"opcode": 8,
"keywords": "0x0000000000200000",
"time_created": "2026-06-02T06:05:39.498+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"message": 21,
"params": 0,
"target_tid": 0
},
"message": "SendSyncRequest"
}
Event ID 37: SendSyncRequest
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-TSF-msctf",
"guid": "{4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}",
"event_source_name": "",
"event_id": 37,
"version": 0,
"level": 4,
"task": 20,
"opcode": 7,
"keywords": "0x0000000000200000",
"time_created": "2026-06-02T06:05:39.499+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 8468,
"thread_id": 17036
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "SendSyncRequest"
}
Event ID 38: SendAsyncRequestStart
#Fields #
| Name | Description |
|---|---|
message UInt32 | |
target_tid UInt32 | |
params UInt32 |
Event ID 39: SendAsyncRequestStop
#Event ID 40: ReceiveALPCMessagesStart
#Event ID 41: ReceiveALPCMessagesStop
#Event ID 42: ProcessALPCMessageStart
#Fields #
| Name | Description |
|---|---|
message UInt32 | |
target_tid UInt32 | |
params UInt32 |
Event ID 44: ProcessALPCMessageStop44
#Event ID 45: ProcessALPCMessageReply
#Fields #
| Name | Description |
|---|---|
message UInt32 | |
target_tid UInt32 | |
params UInt32 | |
hr UInt32 |
Event ID 46: CreateLangBarItemMgrStart
#Event ID 47: CreateLangBarItemMgrStop
#Event ID 48: GetIconFromFileStart
#Event ID 49: GetIconFromFileStop
#Event ID 50: CreateBitmapStart
#Event ID 51: CreateBitmapStop
#Event ID 56: ITfThreadMgrEventSink_OnSetFocusStart
#Fields #
| Name | Description |
|---|---|
pdimNewFocus Pointer | |
pdimPrevFocus Pointer |
Event ID 57: ITfThreadMgrEventSink_OnSetFocusStop
#Fields #
| Name | Description |
|---|---|
pdimNewFocus Pointer | |
pdimPrevFocus Pointer |
Event ID 60: CiceroServer
#Event ID 61: CiceroServer61
#Event ID 62: CiceroServer62
#Event ID 63: CiceroServer63
#Event ID 71: IMELocalServerStart
#Event ID 72: IMELocalServerStop
#Event ID 73: InputProfileActivation
#Event ID 76: InputProfileDeactivation
#Event ID 78: InputProfileDeactivation78
#Event ID 79: DocumentFocusChange
#Fields #
| Name | Description |
|---|---|
DocId UInt32 | |
DocThread UInt32 | |
GainFocus Boolean |
Event ID 83: DocumentContentChange
#Event ID 86: DocumentContentChange86
#Event ID 87: KeyboardEventHandling
#Event ID 88: KeyboardEventHandling88
#Event ID 90: KeyboardEventHandling90
#Event ID 91: KeyboardEventHandling91
#Event ID 92: KeyboardEventHandling92
#Event ID 93: KeyboardEventHandling93
#Event ID 94: KeyboardEventHandling94
#Event ID 95: KeyboardEventHandling95
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {4FBA1227-F606-4E5F-B9E8-FAB9AB5740F3}
Defined in msctf.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02