Microsoft-Windows-Kernel-PnP-Rundown
4 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | ConnectionResourceConsumer | Operational | N |
| 2 | ParentPdo | Operational | N |
| 3 | ParentDevNode_V1 | Operational | N |
| 4 | InterruptResourceConsumer | Operational | N |
Event ID 1: ConnectionResourceConsumer
#Fields #
| Name | Description |
|---|---|
ResourceConsumerPdo Pointer | |
ConnectionId HexInt64 | |
ResourceConsumerInstancePathLength UInt32 | |
ResourceConsumerInstancePath UnicodeString |
Event ID 3: ParentDevNode_V1
#Fields #
| Name | Description |
|---|---|
DevNode Pointer | |
ParentDevNode Pointer | |
InstancePathLength UInt32 | |
InstancePath UnicodeString |
Event ID 4: InterruptResourceConsumer
#Fields #
| Name | Description |
|---|---|
ResourceConsumerPdo Pointer | |
Flags UInt16 | |
Group UInt16 | |
Vector UInt16 | |
Affinity HexInt64 | |
InterruptResourceConsumerInstancePathLength UInt32 | |
InterruptResourceConsumerInstancePath UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID b3a0c2c8-83bb-4ddf-9f8d-4b22d3c38ad7
Defined in microsoft-windows-kernel-pnp-events.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02