Microsoft-Windows-Kernel-Memory

Seen on:

  • Windows 2008

  • Windows 7

  • Windows 8.0

Name: Microsoft-Windows-Kernel-Memory
Identifier: {d1d93ef7-e1f2-4f45-9943-03d245fe6c00}
Event message file(s): %SystemRoot%\system32\advapi32.dll

 

Seen on:

  • Windows 2012

  • Windows 8.1

  • Windows 10 (1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004, 20H2)

  • Windows 2016

  • Windows 2019

  • Windows 11 (21H2)

Name: Microsoft-Windows-Kernel-Memory
Identifier: {d1d93ef7-e1f2-4f45-9943-03d245fe6c00}
Event message file(s): %SystemRoot%\system32\Microsoft-Windows-System-Events.dll