Microsoft-Windows-Windeploy
8 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | Windeploy. | Analytic | N |
| 1002 | Windeploy. | Analytic | N |
| 2001 | Launching external process "CommandLine". | Analytic | N |
| 2002 | External process "Command" exited with status ExitCode. | Analytic | N |
| 2003 | Failed to start external process "Command" with status ExitCode. | Analytic | N |
| 3001 | Running user-provided script: "CommandLine". | Analytic | N |
| 3002 | Successfully executed script: "Command". | Analytic | N |
| 3003 | Failed to execute script: "Command". | Analytic | N |
Event ID 1001: Windeploy.
#Event ID 1002: Windeploy.
#Event ID 2001: Launching external process "CommandLine".
#Event ID 2002: External process "Command" exited with status ExitCode.
#Event ID 2003: Failed to start external process "Command" with status ExitCode.
#Event ID 3001: Running user-provided script: "CommandLine".
#Event ID 3002: Successfully executed script: "Command".
#Event ID 3003: Failed to execute script: "Command".
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 75ebc33e-c8ae-4f93-9ca1-683a53e20cb6
Defined in windeploy.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02