Microsoft-Windows-BitLocker-Driver-Performance

46 events across 1 channel

EventTitleChannelSample
1fve:ReadRequestOperationalY
2fve:ReadRequestOperationalY
3fve:WriteRequestOperationalY
4fve:WriteRequestOperationalY
5fve:ReadSubRequestOperationalN
6fve:WriteSubRequestOperationalN
7fve:ReadSubRequestStartOperationalN
8fve:ReadSubRequestStopOperationalN
9fve:WriteSubRequestStartOperationalN
10fve:WriteSubRequestStopOperationalN
11fve:VolumeStackCreateOperationalN
12fve:VolumeStackDeleteOperationalN
13fve:VolumeDiscoveryStartOperationalN
14fve:VolumeDiscoveryStopOperationalN
15fve:MetadataWriteStartOperationalN
16fve:MetadataWriteStopOperationalN
17fve:FveIoctlStartOperationalN
18fve:FveIoctlStopOperationalN
19fve:FveActionStartOperationalN
20fve:FveActionStopOperationalN
21fve:ConversionStartOperationalN
22fve:ConversionStopOperationalN
23fve:ConversionStepStartOperationalN
24fve:ConversionStepStopOperationalN
25fve:SliderMoveStartOperationalN
26fve:SliderMoveStopOperationalN
27fve:IoDecryptRequestStartOperationalN
28fve:IoDecryptRequestStopOperationalN
29fve:IoEncryptRequestStartOperationalN
30fve:IoEncryptRequestStopOperationalN
31fve:BCryptEncryptRequestStartOperationalN
32fve:BCryptEncryptRequestStopOperationalN
33fve:BCryptDecryptRequestStartOperationalN
34fve:BCryptDecryptRequestStopOperationalN
35fve:BCryptEncryptRequestStart35OperationalN
36fve:BCryptEncryptRequestStop36OperationalN
37fve:BCryptEncryptRequestStart37OperationalN
38fve:BCryptEncryptRequestStop38OperationalN
39fve:BCryptDecryptRequestStart39OperationalN
40fve:BCryptDecryptRequestStop40OperationalN
41fve:BCryptDecryptRequestStart41OperationalN
42fve:BCryptDecryptRequestStop42OperationalN
43fve:BCryptEncryptRequestStart43OperationalN
44fve:BCryptEncryptRequestStop44OperationalN
45fve:BCryptDecryptRequestStart45OperationalN
46fve:BCryptDecryptRequestStop46OperationalN

Event ID 1: fve:ReadRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
fve:ReadRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-BitLocker-Driver-Performance",
    "guid": "{1DE130E1-C026-4CBF-BA0F-AB608E40AEEA}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": "0x0000000000000020",
    "time_created": "2026-06-02T05:41:26.365+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 3756,
      "thread_id": 15096
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DevObjPtr": "0xFFFFBD09E2D09030",
    "IrpPtr": "0xFFFFBD09F3553010"
  },
  "message": "fve:ReadRequest"
}

Event ID 2: fve:ReadRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
fve:ReadRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-BitLocker-Driver-Performance",
    "guid": "{1DE130E1-C026-4CBF-BA0F-AB608E40AEEA}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": "0x0000000000000020",
    "time_created": "2026-06-02T05:41:26.366+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 10660,
      "thread_id": 13648
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DevObjPtr": "0xFFFFBD09E2D09030",
    "IrpPtr": "0xFFFFBD09F3553010"
  },
  "message": "fve:ReadRequest"
}

Event ID 3: fve:WriteRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
fve:WriteRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-BitLocker-Driver-Performance",
    "guid": "{1DE130E1-C026-4CBF-BA0F-AB608E40AEEA}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 1,
    "keywords": "0x0000000000000020",
    "time_created": "2026-06-02T05:41:25.566+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 1496
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DevObjPtr": "0xFFFFBD09E2D09030",
    "IrpPtr": "0xFFFFBD09F2E7F520"
  },
  "message": "fve:WriteRequest"
}

Event ID 4: fve:WriteRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
fve:WriteRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-BitLocker-Driver-Performance",
    "guid": "{1DE130E1-C026-4CBF-BA0F-AB608E40AEEA}",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 2,
    "keywords": "0x0000000000000020",
    "time_created": "2026-06-02T05:41:25.567+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 14172,
      "thread_id": 6176
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DevObjPtr": "0xFFFFBD09E2D09030",
    "IrpPtr": "0xFFFFBD09F2E7F520"
  },
  "message": "fve:WriteRequest"
}

Event ID 5: fve:ReadSubRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:ReadSubRequest

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer
SubIrpPtr Pointer

Event ID 6: fve:WriteSubRequest

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:WriteSubRequest

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer
SubIrpPtr Pointer

Event ID 7: fve:ReadSubRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:ReadSubRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Event ID 8: fve:ReadSubRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:ReadSubRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Event ID 9: fve:WriteSubRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:WriteSubRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Event ID 10: fve:WriteSubRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:WriteSubRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
IrpPtr Pointer

Event ID 11: fve:VolumeStackCreate

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:VolumeStackCreate

Fields #

NameDescription
DevObjPtr Pointer
PdoPtr Pointer

Event ID 12: fve:VolumeStackDelete

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:VolumeStackDelete

Fields #

NameDescription
DevObjPtr Pointer
PdoPtr Pointer

Event ID 13: fve:VolumeDiscoveryStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:VolumeDiscovery
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer

Event ID 14: fve:VolumeDiscoveryStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:VolumeDiscovery
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer

Event ID 15: fve:MetadataWriteStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:MetadataWrite
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
Index UInt32
Offset UInt64

Event ID 16: fve:MetadataWriteStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:MetadataWrite
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
Index UInt32
Offset UInt64

Event ID 17: fve:FveIoctlStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:FveIoctl
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 18: fve:FveIoctlStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:FveIoctl
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 19: fve:FveActionStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:FveAction
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 20: fve:FveActionStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:FveAction
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 21: fve:ConversionStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:Conversion
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 22: fve:ConversionStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:Conversion
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
Command UInt32

Event ID 23: fve:ConversionStepStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:ConversionStep
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
Offset UInt64
Size UInt32
Command UInt32

Event ID 24: fve:ConversionStepStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:ConversionStep
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
Offset UInt64
Size UInt32
Command UInt32

Event ID 25: fve:SliderMoveStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:SliderMove
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
PrevOffset UInt64
NextOffset UInt64
Size UInt64

Event ID 26: fve:SliderMoveStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:SliderMove
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
PrevOffset UInt64
NextOffset UInt64
Size UInt64

Event ID 27: fve:IoDecryptRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:IoDecryptRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
SubIrpPtr Pointer
Offset UInt64
Size UInt32

Event ID 28: fve:IoDecryptRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:IoDecryptRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
SubIrpPtr Pointer
Offset UInt64
Size UInt32

Event ID 29: fve:IoEncryptRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:IoEncryptRequest
Opcode
Start

Fields #

NameDescription
DevObjPtr Pointer
SubIrpPtr Pointer
Offset UInt64
Size UInt32

Event ID 30: fve:IoEncryptRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:IoEncryptRequest
Opcode
Stop

Fields #

NameDescription
DevObjPtr Pointer
SubIrpPtr Pointer
Offset UInt64
Size UInt32

Event ID 31: fve:BCryptEncryptRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 32: fve:BCryptEncryptRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 33: fve:BCryptDecryptRequestStart

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 34: fve:BCryptDecryptRequestStop

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 35: fve:BCryptEncryptRequestStart35

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 36: fve:BCryptEncryptRequestStop36

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 37: fve:BCryptEncryptRequestStart37

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 38: fve:BCryptEncryptRequestStop38

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 39: fve:BCryptDecryptRequestStart39

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 40: fve:BCryptDecryptRequestStop40

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 41: fve:BCryptDecryptRequestStart41

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 42: fve:BCryptDecryptRequestStop42

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 43: fve:BCryptEncryptRequestStart43

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 44: fve:BCryptEncryptRequestStop44

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptEncryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 45: fve:BCryptDecryptRequestStart45

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Start

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Event ID 46: fve:BCryptDecryptRequestStop46

#
Provider
Microsoft-Windows-BitLocker-Driver-Performance
Channel
Operational
Task
fve:BCryptDecryptRequest
Opcode
Stop

Fields #

NameDescription
BufferPtr Pointer
Size UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {1DE130E1-C026-4CBF-BA0F-AB608E40AEEA}

Defined in fvevol.sys, the binary that emits these events.

Observed on:

  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.4768, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02

Downloads