Microsoft-Windows-Kernel-LiveDump

Seen on:

  • Windows 2012

  • Windows 8.1

  • Windows 10 (1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004, 20H2)

  • Windows 2016

  • Windows 2019

  • Windows 11 (21H2)

Name: Microsoft-Windows-Kernel-LiveDump
Identifier: {bef2aa8e-81cd-11e2-a7bb-5eac6188709b}
Event message file(s): %SystemRoot%\system32\Microsoft-Windows-System-Events.dll