File Kernel Trace; Operation Set 1

43 events across 1 channel

Event IDTitleChannel
0ETW Trace
1ETW Trace
2ETW Trace
3ETW Trace
4ETW Trace
5ETW Trace
6ETW Trace
7ETW Trace
8ETW Trace
9ETW Trace
10ETW Trace
11ETW Trace
12ETW Trace
13ETW Trace
14ETW Trace
15ETW Trace
16ETW Trace
17ETW Trace
18ETW Trace
19ETW Trace
20ETW Trace
21ETW Trace
22ETW Trace
23ETW Trace
24ETW Trace
25ETW Trace
26ETW Trace
27ETW Trace
236ETW Trace
237ETW Trace
238ETW Trace
239ETW Trace
240ETW Trace
241ETW Trace
242ETW Trace
243ETW Trace
249ETW Trace
250ETW Trace
251ETW Trace
252ETW Trace
253ETW Trace
254ETW Trace
255ETW Trace

Event ID 0 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 1 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 2 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 3 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 4 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 5 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 6 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 7 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 8 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 9 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 10 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 11 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 12 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 13 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 14 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 15 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 16 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 17 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 18 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 19 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 20 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 21 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 22 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 23 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 24 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 25 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 26 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 27 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 236 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 237 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 238 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 239 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 240 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 241 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 242 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 243 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 249 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 250 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 251 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 252 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 253 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 254 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String

Event ID 255 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace
Source
Trace

Fields #

NameDescription
Status mof:UInt32NTSTATUS reference
Operation mof:UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
MinorOperation mof:UInt8
SequenceNumber mof:UInt32
IsPagingIO mof:UInt8
IsFastIO mof:UInt8
IsDirectory mof:UInt8
CreateOnExisting mof:UInt8
StartTime mof:SInt64
ProcessId mof:UInt32
ProcessCreateTime mof:SInt64
FileObject mof:UInt64
LastAccessTime mof:SInt64
SessionId mof:UInt32
WindowStation mof:UInt64
AccessToken mof:UInt32
SidLength mof:UInt32
ParametersLength mof:UInt32
ResultLength mof:UInt32
PreviousValueLength mof:UInt32
UserSID mof:Object
OperationalParameters mof:UInt8
ResultData mof:UInt8
PreviousValue mof:UInt8
FileName mof:String
VolumeDosName mof:String
VolumeGuidName mof:String
VolumeName mof:String