Microsoft-Windows-Wcmsvc
Event ID 1001: WCMSVC: Service Startup
#Event ID 1002: WCMSVC: Service Shutdown
#Event ID 1003: CDE reported a state change.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Name UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-11-06T06:25:42.259570+00:00",
"event_record_id": 100,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Status": 1,
"Name": 2
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1004: A Group Policy change was processed
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T06:21:48.6534269+00:00",
"event_record_id": 98,
"correlation": {},
"execution": {
"process_id": 2204,
"thread_id": 4052
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "A Group Policy change was processed"
}
Event ID 1006: A Terminal Services session change was processed.
#Message #
Fields #
| Name | Description |
|---|---|
Reason UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:33:57.0710322+00:00",
"event_record_id": 110,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Reason": "5"
},
"message": "A Terminal Services session change was processed. \r\n\r\n Reason: A user has logged on to the session"
}
Event ID 1007: CDE reported a state change.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1008: NLA interface property change.
#Event ID 1009: CDE reported an L2 adapter arrival.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:32:57.3855017+00:00",
"event_record_id": 107,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
"MediaType": "1"
},
"message": "CDE reported an L2 adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}
Event ID 1010: CDE reported an L2 adapter removal.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255303+00:00",
"event_record_id": 170,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1011: CDE reported a successful connection.
#Event ID 1012: CDE reported a connection failure.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1013: CDE reported a disconnection.
#Event ID 1014: WcmSetParameter Called.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGUID GUID | |
ProfileName UnicodeString | |
WcmOpcode UInt32 | |
Datalength UInt32 | |
CallerProcessID UInt32 | |
ReturnValue UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Wcmsvc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 1014,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3584,
"thread_id": 12632
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-Wcmsvc",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-21 23:51:53.357Z",
"version": 0
},
"event_data": {
"Caller Process ID": 3352,
"Data length": 4,
"Interface GUID": "{129E86BD-BBE0-4F5A-9644-8FBDA23B24F5}",
"Profile Name": "NULL",
"Return Value": 0,
"Wcm Opcode": 304
},
"message": ""
}
Example keys not documented in the fields table: Caller Process ID, Data length, Interface GUID, Profile Name, Return Value, Wcm Opcode
Event ID 1015: Interface Token Applied.
#Event ID 1016: Interface Token Failed.
#Event ID 1017: Soft disconnect over thresholds for interface: InterfaceGUID.
#Event ID 1018: Soft disconnect under thresholds for interface: InterfaceGUID.
#Event ID 1019: CDE reported an unblocked profile.
#Event ID 1020: WCM Preferred Order List.
#Message #
Fields #
| Name | Description |
|---|---|
WCMPreferredOrderList |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1020,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-10-26T04:17:43.215170+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 2288,
"thread_id": 2612
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"WCM Preferred Order List": "0: {3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}, Ethernet, 1\n1: {8E4162AD-6500-4899-BA95-24051405E207}, Ethernet, 1\n"
},
"message": ""
}
Example keys not documented in the fields table: WCM Preferred Order List
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1022: WCM entered connected standby
#Event ID 1023: WCM exited connected standby
#Event ID 1024: Acquired NDIS NIC Active Reference for interface: InterfaceGUID.
#Event ID 1025: Released NDIS NIC Active Reference for interface: InterfaceGUID.
#Event ID 1026: CDE reported an NDIS adapter arrival.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 1026,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775776,
"time_created": "2026-05-29T16:32:57.3851898+00:00",
"event_record_id": 106,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
"MediaType": "1"
},
"message": "CDE reported an NDIS adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}
Event ID 1027: CDE reported an NDIS adapter removal.
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
MediaType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1027,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255300+00:00",
"event_record_id": 169,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1028: WCM entered net quiet mode
#Event ID 1029: WCM exited net quiet mode
#Event ID 1030: Billing Cycle Reset Successful
#Fields #
| Name | Description |
|---|---|
ProfileName UnicodeString | |
InterfaceGuid GUID | |
ProfileUpdatedorDeleted UnicodeString |
Event ID 1031: Server Time Retrieval Failure
#Fields #
| Name | Description |
|---|---|
ConfigtoSyncWithTimeServer Boolean | |
TimeServerName UnicodeString | |
NumServerTimeRetries UInt32 | |
ServerTimeRetrievalError UInt32 |
Event ID 1032: Acquire NDIS NIC Active Reference Failed for interface: InterfaceGUID.
#Event ID 1033: Release NDIS NIC Active Reference Failed for interface: InterfaceGUID.
#Event ID 1034: OnDemandInterfaceStateChanged.
#Description
OnDemandInterfaceStateChanged. OnDemandType:OnDemandType, Interface: InterfaceGUID, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, NewState:NewState, Ref counter:Refcount.
Message #
Fields #
| Name | Description |
|---|---|
OnDemandType UInt32 | |
InterfaceGUID GUID | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
NewState UInt32 | |
Refcount UInt32 |
Event ID 1035: OnDemand PDP Profile Created.
#Event ID 1036: OnDemand PDP Profile Deleted.
#Event ID 1037: OnDemand Request opened.
#Description
OnDemand Request opened. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1038: OnDemand Request closed.
#Description
OnDemand Request closed. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1039: OnDemand Request started.
#Description
OnDemand Request started. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1040: OnDemand Request cancelled.
#Description
OnDemand Request cancelled. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | |
ProcessID UInt32 | |
OnDemandType UInt32 | |
OnDemandInfo UnicodeString | |
ProviderID UnicodeString | |
Error UInt32 |
Event ID 1050: WcmSvc acquired the NIC reference for Interface: InterfaceGUID for reason: ActionType.
#Event ID 1051: WcmSvc released the NIC reference for Interface: InterfaceGUID for reason: ActionType.
#Event ID 1052: WcmSvc signalled disconnected standby
#Event ID 1053: WcmSvc signalled end of disconnected standby
#Event ID 1054: WcmSvc received power policy update for networking in standby - the new policy value is PolicyValue.
#Event ID 4021: End of Wlan Resume Reconnect to Same Network
#Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID |
Event ID 4022: End of Wlan Resume Reconnect to Same Network OneX
#Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID |
Event ID 4023: End of Wlan Resume Reconnect to Different Network
#Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID |
Event ID 4027: WcmSvc CmPdcActivationClientRegister - Status [Status].
#Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 4028: WcmSvc CmPdcActivationClientUnregister - Status [Status].
#Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 4029: WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].
#Message #
Fields #
| Name | Description |
|---|---|
Activity Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 4030: WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppNa...
#Description
WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Activate Boolean | |
Result UInt32 | |
TotalNetworkRefCount UInt32 | |
ProcessId UInt32 | |
ProcessNetworkRefCount UInt32 | |
AppName UnicodeString |
Event ID 4031: WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], TotalNetworkRefCount [TotalNetworkRefCount].
#Event ID 4032: WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
#Event ID 4033: WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
#Event ID 4034: WcmSvc ReleaseNdisReferenceInProcess - ProcessId [ProcessId], PerProcessCmNdisRefCount [ProcessNetworkRefCount], TotalCmNdisRefCount [TotalNetworkRefCount].
#Event ID 4035: WcmSvc NdisReferenceError - [FunctionName]: Result [Error].
#Event ID 4036: CmService::NdisReference - [AcquireRelease] InterfaceLuid [InterfaceLuid], Result [Result].
#Event ID 10001: WCMSVC: Start WCM Service Startup
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:57.3454710+00:00",
"event_record_id": 105,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3020
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Start WCM Service Startup"
}
Event ID 10002: WCMSVC: Complete WCM Service Startup
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:57.3868780+00:00",
"event_record_id": 108,
"correlation": {},
"execution": {
"process_id": 2992,
"thread_id": 3020
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Complete WCM Service Startup"
}
Event ID 10003: WCMSVC: Start Service Shutdown
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:22:34.5250615+00:00",
"event_record_id": 114,
"correlation": {},
"execution": {
"process_id": 3004,
"thread_id": 2064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Start Service Shutdown"
}
Event ID 10004: WCMSVC: Complete Service Shutdown
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
"event_source_name": "",
"event_id": 10004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:22:34.5306208+00:00",
"event_record_id": 115,
"correlation": {},
"execution": {
"process_id": 3004,
"thread_id": 2064
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": "WCMSVC: Complete Service Shutdown"
}
Event ID 10005: Tethering Manager Loaded Successfully
#Event ID 10006: Tethering Manager Unloaded Successfully
#Provenance
ETW provider GUID 67d07935-283a-4791-8f8d-fa9117f3e6f2
Defined in wcmsvc.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB