Microsoft-Windows-Kernel-File

25 events across 1 channel

Event IDTitleChannel
10Analytic
11Analytic
12Analytic
13Analytic
14Analytic
15Analytic
16Analytic
17Analytic
18Analytic
19Analytic
20Analytic
21Analytic
22Analytic
23Analytic
24Analytic
25Analytic
26Analytic
27Analytic
28Analytic
29Analytic
30Analytic
31Analytic
32Analytic
33Analytic
34Analytic

Event ID 10 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
FileKey
FileName

Event ID 11 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
FileKey
FileName

Event ID 12 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
IssuingThreadId
CreateOptions
CreateAttributes
ShareAccess
FileName

Event ID 13 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
IssuingThreadId

Event ID 14 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
IssuingThreadId

Event ID 15 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
ByteOffset
Irp
FileObject
FileKey
IssuingThreadId
IOSize
IOFlags
ExtraFlags

Event ID 16 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
ByteOffset
Irp
FileObject
FileKey
IssuingThreadId
IOSize
IOFlags
ExtraFlags

Event ID 17 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 18 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 19 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 20 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
IssuingThreadId
Length
InfoClass
FileIndex
FileName

Event ID 21 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
IssuingThreadId

Event ID 22 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 23 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 24 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
ExtraInformation
Status

Event ID 25 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
IssuingThreadId
Length
InfoClass
FileIndex
FileName

Event ID 26 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass
FilePath

Event ID 27 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass
FilePath

Event ID 28 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass
FilePath

Event ID 29 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 30 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
IssuingThreadId
CreateOptions
CreateAttributes
ShareAccess
FileName

Event ID 31 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 32 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 33 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass

Event ID 34 —

Provider
Microsoft-Windows-Kernel-File
Channel
Analytic

Fields

NameDescription
Irp
FileObject
FileKey
ExtraInformation
IssuingThreadId
InfoClass