File Kernel Trace; Operation Set 1

43 events across 1 channel

EventTitleChannel
0FileOperationETW Trace
1FileOperationETW Trace
2FileOperationETW Trace
3FileOperationETW Trace
4FileOperationETW Trace
5FileOperationETW Trace
6FileOperationETW Trace
7FileOperationETW Trace
8FileOperationETW Trace
9FileOperationETW Trace
10FileOperationETW Trace
11FileOperationETW Trace
12FileOperationETW Trace
13FileOperationETW Trace
14FileOperationETW Trace
15FileOperationETW Trace
16FileOperationETW Trace
17FileOperationETW Trace
18FileOperationETW Trace
19FileOperationETW Trace
20FileOperationETW Trace
21FileOperationETW Trace
22FileOperationETW Trace
23FileOperationETW Trace
24FileOperationETW Trace
25FileOperationETW Trace
26FileOperationETW Trace
27FileOperationETW Trace
236FileOperationETW Trace
237FileOperationETW Trace
238FileOperationETW Trace
239FileOperationETW Trace
240FileOperationETW Trace
241FileOperationETW Trace
242FileOperationETW Trace
243FileOperationETW Trace
249FileOperationETW Trace
250FileOperationETW Trace
251FileOperationETW Trace
252FileOperationETW Trace
253FileOperationETW Trace
254FileOperationETW Trace
255FileOperationETW Trace

Event ID 0: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 1: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 2: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 3: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 4: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 5: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 6: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 7: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 8: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 9: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 10: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 11: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 12: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 13: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 14: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 15: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 16: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 17: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 18: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 19: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 20: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 21: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 22: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 23: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 24: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 25: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 26: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 27: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 236: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 237: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 238: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 239: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 240: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 241: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 242: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 243: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 249: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 250: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 251: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 252: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 253: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 254: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 255: FileOperation

#
Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Opcode
FileTrace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {D75D8303-6C21-4BDE-9C98-ECC6320F9291}

Observed on:

  • WS2025-26100.0 · schema read from the WMI MOF class · captured 2026-02-26

    Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.

  • WS2022-20348.4893 · schema read from the WMI MOF class · captured 2026-06-02

    MOF class: MSNT_FileBaseTrace_Set1

  • Win11-26200.6584 · schema read from the WMI MOF class · captured 2026-06-02

    MOF class: MSNT_FileBaseTrace_Set1

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests