Microsoft-Windows-KernelStreaming
30 events across 3 channels
Event ID 202: KS_StreamingRequest Start, pIrp: pIrp.
#Event ID 202: KS_StreamingRequest Start, pIrp: pIrp.
#Event ID 203: KS_StreamingRequest Stop, pIrp: pIrp.
#Event ID 203: KS_StreamingRequest Stop, pIrp: pIrp.
#Event ID 204: KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.
#Event ID 204: KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.
#Event ID 205: KS_CameraGrab Stop, Status: Status.
#Description
KS_CameraGrab Stop, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 205: KS_CameraGrab Stop, Status: Status.
#Description
KS_CameraGrab Stop, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | NTSTATUS reference |
Event ID 208: KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.
#Event ID 208: KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.
#Event ID 209: KS_WNFNotification Fire, EntryCount: EntryCount.
#Event ID 209: KS_WNFNotification Fire, EntryCount: EntryCount.
#Event ID 211: KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.
#Event ID 211: KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.
#Event ID 212: KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.
#Event ID 212: KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.
#Event ID 213: KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
#Description
KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
pKsDevice Pointer | |
pIrp Pointer | |
InterfaceGuid GUID | |
Status UInt32 | NTSTATUS reference |
Event ID 213: KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
#Description
KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
pKsDevice Pointer | |
pIrp Pointer | |
InterfaceGuid GUID | |
Status UInt32 | NTSTATUS reference |
Event ID 214: KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
#Description
KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
pKsDevice Pointer | |
pIrp Pointer | |
InterfaceGuid GUID | |
Status UInt32 | NTSTATUS reference |
Event ID 214: KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
#Description
KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
pKsDevice Pointer | |
pIrp Pointer | |
InterfaceGuid GUID | |
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 548c4417-ce45-41ff-99dd-528f01ce0fe1
Defined in ks.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4767, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02