Microsoft-Windows-DriverFrameworks-UserMode
77 events across 4 channels
Event ID 1000 — The Driver Manager service started successfully
Message
Event ID 1001 — The Driver Manager service failed to start.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1002 — The Driver Manager service was stopped
Message
Event ID 1003 — The Driver Manager service is starting a host process for device %3.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
HostGuid | — |
InstanceId | — |
Event ID 1004 — The host process started successfully.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FinalStatus | — |
Event ID 1005 — The host process failed to start successfully.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FinalStatus | — |
Event ID 1006 — The host process is being asked to shutdown.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Event ID 1007 — The host process has a problem and is being terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Problem | — |
DetectedBy | — |
ActiveOperation | — |
ExitCode | — |
Message | — |
Status | — |
Event ID 1008 — The host process has been shutdown.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
TerminationStatus | — |
ExitCode | — |
Event ID 1009 — The host process has a problem and is being terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Problem | — |
DetectedBy | — |
ActiveOperation | — |
ExitCode | — |
Message | — |
Status | — |
InstanceId | — |
HardwareId | — |
ServiceName | — |
Event ID 2000 — The UMDF Host Process is starting up.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Event ID 2001 — The UMDF Host Process started successfully.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
ExitCode | — |
Event ID 2002 — The UMDF Host Process failed to start successfully.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
ExitCode | — |
Event ID 2003 — The UMDF Host Process (%1) has been asked to load drivers for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Sigma Rules
- USB Device Plugged
Detects plugged/unplugged USB devices
Event ID 2004 — The UMDF Host is loading driver %4 at level %3 for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
Service | — |
ClsId | — |
Event ID 2005 — The UMDF Host Process (%1) has loaded module %3 while loading drivers for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
ModulePath | — |
CompanyName | — |
FileDescription | — |
FileVersion | — |
Event ID 2006 — The UMDF Host successfully loaded the driver at level %3.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
FinalStatus | — |
Event ID 2007 — The UMDF Host failed to load the driver at level %3.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
FinalStatus | — |
Event ID 2010 — The UMDF Host Process (%1) has successfully loaded drivers for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
FinalStatus | — |
Event ID 2011 — The UMDF Host Process (%1) has failed to load drivers for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
FinalStatus | — |
Event ID 2100 — Received a Pnp or Power operation (%3, %4) for device %2.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Sigma Rules
- USB Device Plugged
Detects plugged/unplugged USB devices
Event ID 2101 — Completed a Pnp or Power operation (%3, %4) for device %2 with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Event ID 2102 — Forwarded a finished Pnp or Power operation (%3, %4) to the lower driver for device %2 with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Sigma Rules
- USB Device Plugged
Detects plugged/unplugged USB devices
Event ID 2103 — Completed a Pnp or Power operation (%3, %4) for device %2 with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Event ID 2105 — Forwarded a Pnp or Power operation (%3, %4) for device %2 to the lower driver with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Event ID 2106 — Received a Pnp or Power operation (%3, %4) for device %2 which was completed by the lower drivers with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Event ID 2107 — Received a Pnp or Power operation (%3, %4) for device %2 which was completed by the lower drivers with status %9.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
MajorCode | — |
MinorCode | — |
Argument1 | — |
Argument2 | — |
Argument3 | — |
Argument4 | — |
Status | — |
Event ID 2900 — The UMDF Host has been asked to shutdown.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Event ID 2901 — The UMDF Host has shutdown.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Event ID 3000 — UMDF State Machine %4 start processing event %5 (Queueing %6).
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
StateMachine | — |
Event | — |
Queueing | — |
Event ID 3001 — UMDF State Machine %4 dropped event %5.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
StateMachine | — |
Event | — |
Event ID 3010 — UMDF State Machine %4 state change from %5 to %7 on event %6.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
StateMachine | — |
CurrentState | — |
Event | — |
NewState | — |
Event ID 3011 — UMDF State Machine %4 event processing finished in state %5.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
StateMachine | — |
CurrentState | — |
Event ID 3020 — UMDF State Machine %4 event processing stopped in state %5.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
Level | — |
StateMachine | — |
Event | — |
Event ID 4000 — A runtime failure has occurred in user-mode driver %5 and the hosting process has been terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Category | — |
ErrorNumber | — |
Location | — |
Driver | — |
ImageVersion | — |
UMDFVersion | — |
Event ID 10000 — A driver package which uses user-mode driver framework version %2 is being installed on device %1.
Message
Fields
| Name | Description |
|---|---|
UMDFDeviceInstallBegin.DeviceId | — |
UMDFDeviceInstallBegin.FrameworkVersion | — |
Example Event
system:
provider: Microsoft-Windows-DriverFrameworks-UserMode
guid: 2E35AAEB-857F-4BEB-A418-2E6C0E54D988
event_source_name: ''
event_id: 10000
version: 1
level: 4
task: 48
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T16:53:01.068372+00:00'
event_record_id: 375
correlation: {}
execution:
process_id: 2204
thread_id: 4904
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
user_data:
UMDFDeviceInstallBegin:
DeviceId: SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_VENDORCO&PROD_PRODUCTCODE&REV_2.00#9207032533193411390&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}
FrameworkVersion: 2.33.0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10001 — The UMDF service %1 (CLSID %2) was installed.
Message
Fields
| Name | Description |
|---|---|
UMDFServiceInstall.ServiceName | — |
UMDFServiceInstall.CLSID | — |
UMDFServiceInstall.MinimumFxVersion | — |
UMDFServiceInstall.Upgrade | — |
Example Event
system:
provider: Microsoft-Windows-DriverFrameworks-UserMode
guid: 2E35AAEB-857F-4BEB-A418-2E6C0E54D988
event_source_name: ''
event_id: 10001
version: 1
level: 4
task: 48
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T16:53:01.087249+00:00'
event_record_id: 376
correlation: {}
execution:
process_id: 2204
thread_id: 4904
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
user_data:
UMDFServiceInstall:
ServiceName: WpdFs
CLSID: 112DE495-AC4C-46F8-B663-6A4266C53313
MinimumFxVersion: 2.33.0
Upgrade: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10002 — The UMDF service %1 (CLSID %2) was upgraded.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
CLSID | — |
FxVersion | — |
Upgrade | — |
Event ID 10100 — The driver package installation has succeeded.
Message
Fields
| Name | Description |
|---|---|
UMDFDeviceInstallEnd.FinalStatus | — |
Example Event
system:
provider: Microsoft-Windows-DriverFrameworks-UserMode
guid: 2E35AAEB-857F-4BEB-A418-2E6C0E54D988
event_source_name: ''
event_id: 10100
version: 1
level: 4
task: 48
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T16:53:01.102346+00:00'
event_record_id: 377
correlation: {}
execution:
process_id: 2204
thread_id: 4904
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
user_data:
UMDFDeviceInstallEnd:
FinalStatus: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10101 — The driver package installation has failed.
Message
Fields
| Name | Description |
|---|---|
FinalStatus | — |
Event ID 10110 — A problem has occurred with one or more user-mode drivers and the hosting process has been terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Problem | — |
DetectedBy | — |
ActiveOperation | — |
ExitCode | — |
Message | — |
Status | — |
Event ID 10111 — The device %2 (location %3) is offline due to a user-mode driver crash.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FriendlyName | — |
Location | — |
InstanceId | — |
RestartCount | — |
Event ID 10112 — The device %2 (location %3) is offline due to a user-mode device crash.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FriendlyName | — |
Location | — |
InstanceId | — |
RestartCount | — |
Event ID 10113 — The device %2 was unable to start due to conflict between the settings for driver %5 (%3 - %4) and the other drivers.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
InstanceId | — |
ConflictingParameter | — |
Value | — |
DriverName | — |
Event ID 10114 — {UnstartedService} (part of UMDF) did not load yet.
Message
Fields
| Name | Description |
|---|---|
UnstartedService | — |
Event ID 10115 — The device %2 (location %3) is offline due to a user-mode driver crash.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FriendlyName | — |
Location | — |
InstanceId | — |
RestartCount | — |
Event ID 10116 — The device %2 (location %3) is offline due to a user-mode driver crash.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
FriendlyName | — |
Location | — |
InstanceId | — |
RestartCount | — |
Event ID 10117 — UMDF driver service %1 failed to load because it was compiled using a pre-release version of the Windows Driver Kit(WDK).
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ActualFuntionTableCount | — |
ExpectedFuntionTableCount | — |
Event ID 10118 — UMDF reflector is unable to connect to service control manager (SCM).
Message
Event ID 10120 — A problem has occurred with one or more user-mode drivers and the hosting process has been terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Problem | — |
DetectedBy | — |
ActiveOperation | — |
ExitCode | — |
Message | — |
Status | — |
InstanceId | — |
HardwareId | — |
ServiceName | — |
Event ID 10121 — A runtime failure has occurred in user-mode driver %5 and the hosting process has been terminated.
Message
Fields
| Name | Description |
|---|---|
LifetimeId | — |
Category | — |
ErrorNumber | — |
Location | — |
Driver | — |
ImageVersion | — |
UMDFVersion | — |
Event ID 19999 — UMDF Test Event
Message
Fields
| Name | Description |
|---|---|
String | — |
Event ID 20030 — Power IRP related event in the User-mode Driver Frameworks Host Process
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
DriverName | — |
Event ID 20031 — Power IRP related event in the User-mode Driver Frameworks Host Process
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
Event ID 20032 — Power IRP related event in the User-mode Driver Frameworks Host Process
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
Event ID 20033 — Power IRP related event in the User-mode Driver Frameworks Host Process
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
Event ID 30000 — A driver package which uses user-mode driver framework version {FrameworkVersion} is being installed on device {DeviceId}.
Message
Fields
| Name | Description |
|---|---|
FrameworkVersion | — |
DeviceId | — |
Event ID 30001 — The driver package installation has finished.
Message
Fields
| Name | Description |
|---|---|
FinalStatus | — |
Event ID 30002 — PreDevice installation (UMDF version {FrameworkVersion}) is starting for device {DeviceId}.
Message
Fields
| Name | Description |
|---|---|
FrameworkVersion | — |
DeviceId | — |
Event ID 30003 — PreDevice installation has finished.
Message
Fields
| Name | Description |
|---|---|
FinalStatus | — |
Event ID 30004 — PostDevice installation (UMDF version {FrameworkVersion}) is starting for device {DeviceId}.
Message
Fields
| Name | Description |
|---|---|
FrameworkVersion | — |
DeviceId | — |
Event ID 30005 — PostDevice installation has finished.
Message
Fields
| Name | Description |
|---|---|
FinalStatus | — |
Event ID 30007 — UMDF has been updated.
Message
Fields
| Name | Description |
|---|---|
FinalStatus | — |
Event ID 30008 — DDI to read from hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30009 — DDI to read from hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30010 — Read from hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30011 — Read from hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30012 — DDI to write to hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30013 — DDI to write to hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30014 — Write to hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30015 — Write to hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30016 — Read from hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30017 — Read from hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30018 — Write to hardware begins (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30019 — Write to hardware ends (TargetType: %1, TargetSize: %2, BufferCount: %3).
Message
Fields
| Name | Description |
|---|---|
HwAccessTargetType | — |
HwAccessTargetSize | — |
HwAccessBufferCount | — |
Event ID 30020 — UMDF Reflector sent notification for hardware interrupt (Message ID %1).
Message
Fields
| Name | Description |
|---|---|
InterruptMessageNumber | — |
Event ID 30021 — UMDF framework received notification for hardware interrupt (Message ID %1).
Message
Fields
| Name | Description |
|---|---|
InterruptMessageNumber | — |