Microsoft-Windows-Kernel-XDV

4 events across 2 channels

Event ID 1: XDV driver loaded!

#
Provider
Microsoft-Windows-Kernel-XDV
Channel
System
Opcode
Start

Description

XDV driver loaded!

Message #

XDV driver loaded!

Event ID 2: XDV driver unloaded!

#
Provider
Microsoft-Windows-Kernel-XDV
Channel
Analytic
Opcode
Stop

Description

XDV driver unloaded!

Message #

XDV driver unloaded!

Event ID 3: Driver Event: entry function/DDI calls

#
Provider
Microsoft-Windows-Kernel-XDV
Channel
Analytic
Opcode
Start

Description

Driver Event: entry function/DDI calls.

Message #

Driver Event: entry function/DDI calls

Fields #

NameDescription
IRP_Address Pointer
IRP_Stack_Loc_Code UInt32
IRP_Parameters UInt32
Module UnicodeString
UInt32_Event_Number UInt32
Address_Stack Pointer

Event ID 4: A Driver Verifier rule violation has been detected by VerifierExt.

#
Provider
Microsoft-Windows-Kernel-XDV
Channel
System
Opcode
Start

Description

A Driver Verifier rule violation has been detected by VerifierExt.

Message #

A Driver Verifier rule violation has been detected by VerifierExt.

Fields #

NameDescription
RuleId HexInt32
ErrorMessage AnsiString
Module UnicodeString
Irql UInt8
ErrorLevel HexInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID f029ac39-38f0-4a40-b7de-404d244004cb

Defined in VerifierExt.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads