Intel-iaLPSS-GPIO
22 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | Created WDFDEVICE WDFDEVICE. | Analytic | N |
| 1002 | WDFDEVICE FxDevice IO Addr IOAddr. | Analytic | N |
| 1003 | FailReason. | System | N |
| 1004 | Resource for WDFDEVICE Released. | Analytic | N |
| 1005 | StartController Start | Analytic | N |
| 1006 | StartController End | Analytic | N |
| 1007 | StopController Start | Analytic | N |
| 1008 | StopController End | Analytic | N |
| 1015 | DriverEntry Start | Analytic | N |
| 1016 | DriverEntry End | Analytic | N |
| 1017 | DeviceAdd Start | Analytic | N |
| 1018 | DeviceAdd End | Analytic | N |
| 1019 | OnPrepareHardware Start | Analytic | N |
| 1020 | OnPrepareHardware End | Analytic | N |
| 1030 | DriverUnloaded | Analytic | N |
| 1040 | Query Stop WDFDEVICE. | Analytic | N |
| 1041 | Surprise Removal WDFDEVICE. | Analytic | N |
| 1042 | QueryBasicInformation | Analytic | N |
| 1045 | ConnectIO BankId = BankId, PinCount = PinCount, ConnectMode = ConnectMode, … | Analytic | N |
| 1046 | DisconnectIO BankId = BankId, PinCount = PinCount, DisconnectMode = … | Analytic | N |
| 1048 | ReadIoPins BankID:ReadIoPins_BankID PinValues:PinValues. | Analytic | N |
| 1049 | WriteIoPins BankID:WriteIoPins_BankID SetValue:SetValue ClearValue:ClearValue. | Analytic | N |
Event ID 1001: Created WDFDEVICE WDFDEVICE.
#Event ID 1002: WDFDEVICE FxDevice IO Addr IOAddr.
#Event ID 1003: FailReason.
#Description
FailReason. WDFDEVICE WDFDEVICE.
Message #
Fields #
| Name | Description |
|---|---|
FailReason UnicodeString | |
Status UInt32 | NTSTATUS reference |
WDFDEVICE Pointer |
Event ID 1004: Resource for WDFDEVICE Released.
#Event ID 1040: Query Stop WDFDEVICE.
#Event ID 1041: Surprise Removal WDFDEVICE.
#Event ID 1045: ConnectIO BankId = BankId, PinCount = PinCount, ConnectMode = ConnectMode, PullConfiguration = PullConfig.
#Event ID 1046: DisconnectIO BankId = BankId, PinCount = PinCount, DisconnectMode = DisconnectMode.
#Event ID 1048: ReadIoPins BankID:ReadIoPins_BankID PinValues:PinValues.
#Event ID 1049: WriteIoPins BankID:WriteIoPins_BankID SetValue:SetValue ClearValue:ClearValue.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID d386cc7a-620a-41c1-abf5-55018c6c699a
Defined in iaLPSSi_GPIO.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 1.1.250.0, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 1.1.250.0, captured 2026-06-02