StartTraceW custom system logger: SeSystemProfilePrivilege present but disabled

敏明 金子 0 Reputation points
2026-09-17T21:27:36+00:00

On Windows build 26200.9457 (DisplayVersion 25H2), consider an elevated Administrator caller whose token contains SeSystemProfilePrivilege, but that privilege is Disabled. This is a direct StartTraceW custom controller, not WPR; the controller does not call AdjustTokenPrivileges.

Selected configuration: a unique custom session name (not "NT Kernel Logger"), a newly generated session GUID (not SystemTraceControlGuid), and a file-backed system/kernel logger. EVENT_TRACE_PROPERTIES is initially zeroed, with:

  • Allocation and Wnode.BufferSize: 4096 bytes; Wnode.Flags: 0x00020000 (WNODE_FLAG_TRACED_GUID); Wnode.ClientContext: 1.
  • BufferSize: 64 KiB; MinimumBuffers: 16; MaximumBuffers: 64; MaximumFileSize: 256 MiB; FlushTimer: 1 second.
  • LogFileMode: 0x02000002 = EVENT_TRACE_SYSTEM_LOGGER_MODE | EVENT_TRACE_FILE_MODE_CIRCULAR.
  • EnableFlags: 0x06000817 = EVENT_TRACE_FLAG_PROCESS (0x1) | EVENT_TRACE_FLAG_THREAD (0x2) | EVENT_TRACE_FLAG_IMAGE_LOAD (0x4) | EVENT_TRACE_FLAG_CSWITCH (0x10) | EVENT_TRACE_FLAG_DISPATCHER (0x800) | EVENT_TRACE_FLAG_FILE_IO (0x02000000) | EVENT_TRACE_FLAG_FILE_IO_INIT (0x04000000).
  • LoggerNameOffset: sizeof(EVENT_TRACE_PROPERTIES), 120 bytes in the selected layout; LogFileNameOffset: 1024; Unicode session name and output filename within the allocation. Other initial fields are zero.

For this exact configuration, must SeSystemProfilePrivilege already be ENABLED in the caller token before StartTraceW, or is PRESENT/assigned but currently Disabled sufficient? Does StartTraceW/the ETW subsystem enable it internally, or require/check its enabled state? Please identify the documented access-check behavior or an authoritative Microsoft reference, and any build-specific qualification.

Windows development | Windows Performance Toolkit
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.