Microsoft-Windows-Kernel-Boot

Seen on:

  • Windows 2008

  • Windows 7

  • Windows 8.0

Log source(s): Microsoft-Windows-Kernel-Boot
Log type: System
Identifier: {15ca44ff-4d7a-4baa-bba5-0998955e531e}
Event message file(s): %systemroot%\system32\advapi32.dll

 

Seen on:

  • Windows 10 (1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004, 20H2)

  • Windows 11 (21H2)

  • Windows 2012

  • Windows 8.1

Log source(s): Microsoft-Windows-Kernel-Boot
Log type: System
Identifier: {15ca44ff-4d7a-4baa-bba5-0998955e531e}
Event message file(s): %systemroot%\system32\microsoft-windows-system-events.dll