Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why Service Control Manager provider doesn't generate any event id? #225

Open
subvert0r opened this issue Jan 17, 2024 · 2 comments
Open

Comments

@subvert0r
Copy link

subvert0r commented Jan 17, 2024

I am trying to get events related to service creation, and so far I have tried these:

Microsoft-Windows-Services
Service Control Manager
Service Control Manager Trace

But strangely, non of the above providers produce events when a service is created or started.

Then I looked into it, and figured that Service Control Manager and Service Control Manager Trace don't generate any event id at all! At least the Microsoft-Windows-Services generates some events at some point.

Question: Why when I register with Service Control Manager and Service Control Manager Trace without any filter, I don't get any event at all, no matter how long I keep it running and do all sorts of service related activity? When their callback is called, the event id and opcode id is just 0, and there is no property. Their event header is basically junk.

@swannman
Copy link
Member

Hi @subvert0r, we aren't able to provide general assistance with Windows ETW providers in this repo.

@subvert0r
Copy link
Author

subvert0r commented Jan 18, 2024

Hi @subvert0r, we aren't able to provide general assistance with Windows ETW providers in this repo.

Understood, I edited the question title to make it less generic.
My main question is:

Question: Why when I register with Service Control Manager and Service Control Manager Trace without any filter, I don't get any event at all, no matter how long I keep it running and do all sorts of service related activity? When their callback is called, the event id and opcode id is just 0, and there is no property. Their event header is basically junk.

@subvert0r subvert0r changed the title Which provider gives events regarding service creation? Why Service Control Manager provider doesn't generate any event? Jan 18, 2024
@subvert0r subvert0r changed the title Why Service Control Manager provider doesn't generate any event? Why Service Control Manager provider doesn't generate any event id? Jan 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants