Microsoft-Windows-Kernel-PnP-Rundown

4 events across 1 channel

EventTitleChannelSample
1ConnectionResourceConsumerOperationalN
2ParentPdoOperationalN
3ParentDevNode_V1OperationalN
4InterruptResourceConsumerOperationalN

Event ID 1: ConnectionResourceConsumer

#
Provider
Microsoft-Windows-Kernel-PnP-Rundown
Channel
Operational
Task
ConnectionResourceConsumer

Fields #

NameDescription
ResourceConsumerPdo Pointer
ConnectionId HexInt64
ResourceConsumerInstancePathLength UInt32
ResourceConsumerInstancePath UnicodeString

Event ID 2: ParentPdo

#
Provider
Microsoft-Windows-Kernel-PnP-Rundown
Channel
Operational
Task
ParentPdo

Fields #

NameDescription
Pdo Pointer
ParentPdo Pointer

Event ID 3: ParentDevNode_V1

#
Provider
Microsoft-Windows-Kernel-PnP-Rundown
Channel
Operational
Task
ParentDevNode

Fields #

NameDescription
DevNode Pointer
ParentDevNode Pointer
InstancePathLength UInt32
InstancePath UnicodeString

Event ID 4: InterruptResourceConsumer

#
Provider
Microsoft-Windows-Kernel-PnP-Rundown
Channel
Operational
Task
InterruptResourceConsumer

Fields #

NameDescription
ResourceConsumerPdo Pointer
Flags UInt16
Group UInt16
Vector UInt16
Affinity HexInt64
InterruptResourceConsumerInstancePathLength UInt32
InterruptResourceConsumerInstancePath UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID b3a0c2c8-83bb-4ddf-9f8d-4b22d3c38ad7

Defined in microsoft-windows-kernel-pnp-events.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads