File Kernel Trace; Operation Set 1
43 events across 1 channel
Event ID 0: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 1: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 2: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 3: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 4: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 5: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 6: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 7: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 8: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 9: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 10: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 11: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 12: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 13: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 14: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 15: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 16: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 17: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 18: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 19: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 20: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 21: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 22: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 23: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 24: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 25: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 26: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 27: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 236: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 237: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 238: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 239: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 240: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 241: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 242: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 243: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 249: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 250: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 251: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 252: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 253: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 254: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Event ID 255: FileOperation
#Fields #
| Name | Description |
|---|---|
Status mof:UInt32 | NTSTATUS reference |
Operation mof:UInt8 | Known values
|
MinorOperation mof:UInt8 | |
SequenceNumber mof:UInt32 | |
IsPagingIO mof:UInt8 | |
IsFastIO mof:UInt8 | |
IsDirectory mof:UInt8 | |
CreateOnExisting mof:UInt8 | |
StartTime mof:SInt64 | |
ProcessId mof:UInt32 | |
ProcessCreateTime mof:SInt64 | |
FileObject mof:UInt64 | |
LastAccessTime mof:SInt64 | |
SessionId mof:UInt32 | |
WindowStation mof:UInt64 | |
AccessToken mof:UInt32 | |
SidLength mof:UInt32 | |
ParametersLength mof:UInt32 | |
ResultLength mof:UInt32 | |
PreviousValueLength mof:UInt32 | |
UserSID mof:Object | |
OperationalParameters mof:UInt8 | |
ResultData mof:UInt8 | |
PreviousValue mof:UInt8 | |
FileName mof:String | |
VolumeDosName mof:String | |
VolumeGuidName mof:String | |
VolumeName mof:String |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {D75D8303-6C21-4BDE-9C98-ECC6320F9291}
Observed on:
- WS2025-26100.0, schema read from the WMI MOF class, captured 2026-02-26
Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.
- WS2022-20348.4893, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSNT_FileBaseTrace_Set1
- Win11-26200.6584, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSNT_FileBaseTrace_Set1