Elastic Windows Event Explorer


Publisher - Microsoft-Windows-User-Loader

Event ID 5

Message:

Windows component on demand %{ProcessId}.

Event Data:

# Name In Type
Out Type
1 ProcessId win:UInt32 xs:unsignedInt
2 SuspendProcessRequest win:UInt32 xs:unsignedInt
3 DLLName win:UnicodeString xs:string

Observed Windows Versions:

Version: 0

Fingerprint: 3NRAVDTVVJL2A