Microsoft-Windows-Kernel-IO
14 events across 2 channels
| Event ID | Title | Channel |
|---|---|---|
| 1 | Windows has started processing the volume mount request. | Operational |
| 2 | The volume has been successfully mounted. | Operational |
| 3 | Windows failed to mount the volume. | Operational |
| 1205 | Windows is configured to block legacy file system filters. | System |
| 1206 | Legacy file system filters cannot attach to byte addressable volumes. | System |
| 1207 | Dumps are disabled on the machine since there was an error enabling dump … | System |
| 1212 | Failed to automatically attach a VHD during system startup. | System |
| 1213 | This volume is configured to block legacy file system filters. | System |
| 1300 | Operational | |
| 1301 | Operational | |
| 1302 | Operational | |
| 1303 | Operational | |
| 1304 | Operational | |
| 1305 | Operational |
Event ID 1 — Windows has started processing the volume mount request.
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-IO
guid: ABF1F586-2E50-4BA8-928D-49044E6F0DB7
event_source_name: ''
event_id: 1
version: 0
level: 4
task: 1
opcode: 1
keywords: 9223372036854775809
time_created: '2022-04-07T17:41:20.068195+00:00'
event_record_id: 981
correlation: {}
execution:
process_id: 3228
thread_id: 4516
channel: Microsoft-Windows-Kernel-IO/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
VolumeGuid: 00000000-0000-0000-0000-000000000000
VolumeNameLength: 0
VolumeName: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2 — The volume has been successfully mounted.
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-IO
guid: ABF1F586-2E50-4BA8-928D-49044E6F0DB7
event_source_name: ''
event_id: 2
version: 0
level: 4
task: 1
opcode: 2
keywords: 9223372036854775809
time_created: '2022-04-07T17:41:19.983659+00:00'
event_record_id: 958
correlation: {}
execution:
process_id: 3228
thread_id: 3296
channel: Microsoft-Windows-Kernel-IO/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
VolumeGuid: 00000000-0000-0000-0000-000000000000
VolumeNameLength: 0
VolumeName: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3 — Windows failed to mount the volume.
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
Error | Status. |
Example Event
system:
provider: Microsoft-Windows-Kernel-IO
guid: ABF1F586-2E50-4BA8-928D-49044E6F0DB7
event_source_name: ''
event_id: 3
version: 0
level: 3
task: 1
opcode: 2
keywords: 9223372036854775809
time_created: '2022-04-07T17:41:20.068196+00:00'
event_record_id: 982
correlation: {}
execution:
process_id: 3228
thread_id: 4516
channel: Microsoft-Windows-Kernel-IO/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
VolumeGuid: 00000000-0000-0000-0000-000000000000
VolumeNameLength: 0
VolumeName: ''
Error: '0xc0000001'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1205 — Windows is configured to block legacy file system filters.
Message
Fields
| Name | Description |
|---|---|
Filter_name | — |
FilterNameLength | — |
FilterName | — |
Event ID 1206 — Legacy file system filters cannot attach to byte addressable volumes.
Message
Fields
| Name | Description |
|---|---|
Filter_name | — |
Volume_name | — |
FilterNameLength | — |
FilterName | — |
VolumeNameLength | — |
VolumeName | — |
Event ID 1207 — Dumps are disabled on the machine since there was an error enabling dump encryption.
Message
Fields
| Name | Description |
|---|---|
DumpEncryptionFailureReason | — |
Event ID 1212 — Failed to automatically attach a VHD during system startup.
Message
Fields
| Name | Description |
|---|---|
VHD_name | — |
Status | — |
NameLength | — |
Name | — |
Event ID 1213 — This volume is configured to block legacy file system filters.
Message
Fields
| Name | Description |
|---|---|
Filter_name | — |
Volume_name | — |
FilterNameLength | — |
FilterName | — |
VolumeNameLength | — |
VolumeName | — |
Event ID 1300 —
Event ID 1301 —
Event ID 1302 —
Fields
| Name | Description |
|---|---|
Phase | — |
Event ID 1303 —
Event ID 1304 —
Event ID 1305 —
Fields
| Name | Description |
|---|---|
Status | — |