Microsoft-Windows-Wcmsvc
67 events across 2 channels
Event ID 1003: CDE reported a state change.
#Description
CDE reported a state change.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Name UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-11-06T06:25:42.259570+00:00",
"event_record_id": 100,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Status": 1,
"Name": 2
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1004: A Group Policy change was processed
#Description
A Group Policy change was processed.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T06:21:48.6534269+00:00",
"event_record_id": 98,
"correlation": {},
"execution": {
"process_id": 2204,
"thread_id": 4052
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "A Group Policy change was processed"
}
Event ID 1005: A Power change was processed.
#Event ID 1006: A Terminal Services session change was processed.
#Description
A Terminal Services session change was processed.
Message #
Fields #
| Name | Description |
|---|---|
Reason UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:33:57.0710322+00:00",
"event_record_id": 110,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Reason": "5"
},
"message": "A Terminal Services session change was processed. \r\n\r\n Reason: A user has logged on to the session"
}
Event ID 1007: CDE reported a state change.
#Description
CDE reported a state change.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1008: NLA interface property change.
#Event ID 1009: CDE reported an L2 adapter arrival.
#Description
CDE reported an L2 adapter arrival.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:32:57.3855017+00:00",
"event_record_id": 107,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
"MediaType": "1"
},
"message": "CDE reported an L2 adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}
Event ID 1010: CDE reported an L2 adapter removal.
#Description
CDE reported an L2 adapter removal.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255303+00:00",
"event_record_id": 170,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1011: CDE reported a successful connection.
#Event ID 1012: CDE reported a connection failure.
#Description
CDE reported a connection failure.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1013: CDE reported a disconnection.
#Event ID 1014: WcmSetParameter Called.
#Event ID 1015: Interface Token Applied.
#Event ID 1016: Interface Token Failed.
#Event ID 1017: Soft disconnect over thresholds for interface: InterfaceGUID.
#Event ID 1018: Soft disconnect under thresholds for interface: InterfaceGUID.
#Event ID 1019: CDE reported an unblocked profile.
#Event ID 1020: WCM Preferred Order List.
#Description
WCM Preferred Order List.
Message #
Fields #
| Name | Description |
|---|---|
WCMPreferredOrderList |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1020,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-10-26T04:17:43.215170+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 2288,
"thread_id": 2612
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"WCM Preferred Order List": "0: {3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}, Ethernet, 1\n1: {8E4162AD-6500-4899-BA95-24051405E207}, Ethernet, 1\n"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1024: Acquired NDIS NIC Active Reference for interface: InterfaceGUID.
#Event ID 1025: Released NDIS NIC Active Reference for interface: InterfaceGUID.
#Event ID 1026: CDE reported an NDIS adapter arrival.
#Description
CDE reported an NDIS adapter arrival.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1026,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:32:57.3851898+00:00",
"event_record_id": 106,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
"MediaType": "1"
},
"message": "CDE reported an NDIS adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}
Event ID 1027: CDE reported an NDIS adapter removal.
#Description
CDE reported an NDIS adapter removal.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1027,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255300+00:00",
"event_record_id": 169,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1030: Billing Cycle Reset Successful
#Event ID 1031: Server Time Retrieval Failure
#Event ID 1032: Acquire NDIS NIC Active Reference Failed for interface: InterfaceGUID.
#Event ID 1033: Release NDIS NIC Active Reference Failed for interface: InterfaceGUID.
#Event ID 1034: OnDemandInterfaceStateChanged.
#Description
OnDemandInterfaceStateChanged. OnDemandType:OnDemandType, Interface: InterfaceGUID, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, NewState:NewState, Ref counter:Refcount.
Message #
Fields #
| Name | Description |
|---|---|
OnDemandType UInt32 | |
InterfaceGUID GUID | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
NewState UInt32 | |
Refcount UInt32 |
Event ID 1035: OnDemand PDP Profile Created.
#Event ID 1036: OnDemand PDP Profile Deleted.
#Event ID 1037: OnDemand Request opened.
#Description
OnDemand Request opened. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1038: OnDemand Request closed.
#Description
OnDemand Request closed. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1039: OnDemand Request started.
#Description
OnDemand Request started. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1040: OnDemand Request cancelled.
#Description
OnDemand Request cancelled. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1050: WcmSvc acquired the NIC reference for Interface: InterfaceGUID for reason: ActionType.
#Event ID 1051: WcmSvc released the NIC reference for Interface: InterfaceGUID for reason: ActionType.
#Event ID 1052: WcmSvc signalled disconnected standby
#Description
WcmSvc signalled disconnected standby.
Message #
Event ID 1053: WcmSvc signalled end of disconnected standby
#Description
WcmSvc signalled end of disconnected standby.
Message #
Event ID 1054: WcmSvc received power policy update for networking in standby - the new policy value is PolicyValue.
#Event ID 4020: End of Wwan Resume Reconnect
#Event ID 4021: End of Wlan Resume Reconnect to Same Network
#Event ID 4022: End of Wlan Resume Reconnect to Same Network OneX
#Event ID 4023: End of Wlan Resume Reconnect to Different Network
#Event ID 4024: End of Wlan Resume Reconnect to Different Network OneX
#Event ID 4025: Cancel of Wlan Resume Reconnect2
#Event ID 4027: WcmSvc CmPdcActivationClientRegister - Status [Status].
#Description
WcmSvc CmPdcActivationClientRegister - Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 4028: WcmSvc CmPdcActivationClientUnregister - Status [Status].
#Description
WcmSvc CmPdcActivationClientUnregister - Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 4029: WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].
#Description
WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Activity Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 4030: WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppNa...
#Description
WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Activate Boolean | |
Result UInt32 | |
TotalNetworkRefCount UInt32 | |
ProcessId UInt32 | |
ProcessNetworkRefCount UInt32 | |
AppName UnicodeString |
Event ID 4031: WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], TotalNetworkRefCount [TotalNetworkRefCount].
#Event ID 4032: WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
#Description
WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Result UInt32 | |
TotalCmNdisRefCount UInt32 | |
ProcessId UInt32 | |
PerProcessCmNdisRefCount UInt32 | |
AppName UnicodeString |
Event ID 4033: WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
#Description
WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Result UInt32 | |
TotalCmNdisRefCount UInt32 | |
ProcessId UInt32 | |
PerProcessCmNdisRefCount UInt32 | |
AppName UnicodeString |
Event ID 4034: WcmSvc ReleaseNdisReferenceInProcess - ProcessId [ProcessId], PerProcessCmNdisRefCount [ProcessNetworkRefCount], TotalCmNdisRefCount [TotalNetworkRefCount].
#Event ID 4035: WcmSvc NdisReferenceError - [FunctionName]: Result [Error].
#Event ID 4036: CmService::NdisReference - [AcquireRelease] InterfaceLuid [InterfaceLuid], Result [Result].
#Event ID 10001: WCMSVC: Start WCM Service Startup
#Description
WCMSVC: Start WCM Service Startup.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:57.3454710+00:00",
"event_record_id": 105,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3020
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Start WCM Service Startup"
}
Event ID 10002: WCMSVC: Complete WCM Service Startup
#Description
WCMSVC: Complete WCM Service Startup.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:57.3868780+00:00",
"event_record_id": 108,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3020
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Complete WCM Service Startup"
}
Event ID 10003: WCMSVC: Start Service Shutdown
#Description
WCMSVC: Start Service Shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:22:34.5250615+00:00",
"event_record_id": 114,
"correlation": {},
"execution": {
"process_id": 3004,
"thread_id": 2064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Start Service Shutdown"
}
Event ID 10004: WCMSVC: Complete Service Shutdown
#Description
WCMSVC: Complete Service Shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:22:34.5306208+00:00",
"event_record_id": 115,
"correlation": {},
"execution": {
"process_id": 3004,
"thread_id": 2064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Complete Service Shutdown"
}
Event ID 10005: Tethering Manager Loaded Successfully
#Description
Tethering Manager Loaded Successfully.
Message #
Event ID 10006: Tethering Manager Unloaded Successfully
#Description
Tethering Manager Unloaded Successfully.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 67d07935-283a-4791-8f8d-fa9117f3e6f2
Defined in wcmsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02