Microsoft-Windows-ReadyBoostDriver
33 events across 2 channels
Event ID 1: StoreReadStart_V2
#Fields #
| Name | Description |
|---|---|
ByteOffset UInt64 | |
Irp Pointer | |
ByteLength UInt32 | |
Flags UInt32 | |
FileKey Pointer | |
StoreId UInt16 | |
VolumeId UInt16 |
Event ID 2: StoreReadStop_V1
#Fields #
| Name | Description |
|---|---|
Irp Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 3: StoreAdd_V2
#Fields #
| Name | Description |
|---|---|
DataKey UInt64 | |
DataMgr Pointer | |
StoreOffset UInt32 | |
CompressedSize UInt16 | |
Flags UInt16 |
Event ID 5: StoreCreate
#Fields #
| Name | Description |
|---|---|
StoreKey Pointer | |
StoreFileKey Pointer | |
UserDataMgr Pointer | |
MetadataMgr Pointer | |
RegionSize UInt32 | |
RegionCount UInt32 | |
BlockSize UInt32 | |
SectorSize UInt32 | |
EncryptionStrength UInt32 | |
StoreType UInt16 | |
StoreId UInt16 | |
BlocksStored UInt32 | |
RegionsInUse UInt32 | |
TotalSpaceUsed UInt32 | |
Flags UInt32 | |
MetaRegionCount UInt32 | |
MetaRegionsInUse UInt32 | |
MetaRegionsSpaceUsed UInt32 | |
StoreTime UInt32 | |
OwnerProcessId UInt32 | |
PartitionId UInt32 |
Event ID 7: StoreRundown
#Fields #
| Name | Description |
|---|---|
StoreKey Pointer | |
StoreFileKey Pointer | |
UserDataMgr Pointer | |
MetadataMgr Pointer | |
RegionSize UInt32 | |
RegionCount UInt32 | |
BlockSize UInt32 | |
SectorSize UInt32 | |
EncryptionStrength UInt32 | |
StoreType UInt16 | |
StoreId UInt16 | |
BlocksStored UInt32 | |
RegionsInUse UInt32 | |
TotalSpaceUsed UInt32 | |
Flags UInt32 | |
MetaRegionCount UInt32 | |
MetaRegionsInUse UInt32 | |
MetaRegionsSpaceUsed UInt32 | |
StoreTime UInt32 | |
OwnerProcessId UInt32 | |
PartitionId UInt32 |
Event ID 8: VolumeMapRundown
#Fields #
| Name | Description |
|---|---|
VolumeId UInt16 | |
VolumeNameLength UInt16 | |
VolumePath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ReadyBoostDriver",
"guid": "{2A274310-42D5-4019-B816-E4B8C7ABE95C}",
"event_source_name": "",
"event_id": 8,
"version": 1,
"level": 4,
"task": 7,
"opcode": 0,
"keywords": "0x0000000000000010",
"time_created": "2026-06-02T06:00:43.283+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 5852,
"thread_id": 16092
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"VolumeId": 0,
"VolumeNameLength": 23,
"VolumePath": "\\Device\\HarddiskVolume4"
},
"message": "VolumeMapRundown"
}
Event ID 9: VolumeMapCreate_V1
#Fields #
| Name | Description |
|---|---|
VolumeId UInt16 | |
VolumeNameLength UInt16 | |
VolumePath UnicodeString |
Event ID 10: VolumeMapRemove_V1
#Fields #
| Name | Description |
|---|---|
VolumeId UInt16 | |
VolumeNameLength UInt16 | |
VolumePath UnicodeString |
Event ID 12: ReadyBootIO_V2
#Fields #
| Name | Description |
|---|---|
StartTime UInt64 | |
ByteOffset UInt64 | |
FileKey Pointer | |
ProcessKey Pointer | |
ByteLength UInt32 | |
Flags UInt32 |
Event ID 13: VirtualAddress Virtual Address: Physical_Address Physical Address: Corruption_Window_Size Corruption Window Size: DataMgr.
#Event ID 14: StorePageRundown_V1
#Fields #
| Name | Description |
|---|---|
DataKey UInt64 | |
DataMgr Pointer | |
StoreOffset UInt32 | |
CompressedSize UInt16 | |
Flags UInt16 |
Event ID 15: RegionEvict_V2
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 16: RegionWrite_V2
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 17: A ReadyBoost cache partially or fully failed to persist across boot.
#Description
A ReadyBoost cache partially or fully failed to persist across boot. This may happen if the cache device was modified on another computer or if this computer was booted into another operating system.
Message #
Fields #
| Name | Description |
|---|---|
FailReason UInt32 | |
FailStatus HexInt32 | |
ObjectPathLength UInt16 | |
ObjectPath UnicodeString |
Event ID 20: GlobalStats
#Fields #
| Name | Description |
|---|---|
Size UInt32 | |
Data Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ReadyBoostDriver",
"guid": "{2A274310-42D5-4019-B816-E4B8C7ABE95C}",
"event_source_name": "",
"event_id": 20,
"version": 1,
"level": 4,
"task": 19,
"opcode": 0,
"keywords": "0x0000000000000010",
"time_created": "2026-06-02T06:00:43.283+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 5852,
"thread_id": 16092
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Data": "00040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000008000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001800000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000F401000000000000E803000000000000B80B00000000000088130000000000001027000000000000204E00000000000050C3000000000000FFFFFFFF00000000",
"Size": 896
},
"message": "GlobalStats"
}
Event ID 22: RegionRelease_V1
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 23: RegionCompactStart_V1
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 24: RegionCompactStop_V1
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 25: RegionRundown_V1
#Fields #
| Name | Description |
|---|---|
DataMgr Pointer | |
RegionIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
SpaceUsed UInt16 | |
LastAccessTime UInt16 |
Event ID 27: Device_name Device name: FailStatus Cache path: DeviceDescription.
#Event ID 29: task_0
#Fields #
| Name | Description |
|---|---|
SqmType UInt32 | |
SqmSessionGuid GUID | |
SqmID UInt32 | |
SqmStreamRowLength UInt32 | |
SqmStreamRow Int16 |
Event ID 30: ReadyBootCacheOp_V1
#Fields #
| Name | Description |
|---|---|
Key Pointer | |
Operation UInt32 | Known values
|
Flags UInt32 |
Event ID 31: HbdrvIrpTag_V1
#Fields #
| Name | Description |
|---|---|
VolumeOffset UInt64 | |
Length UInt32 | |
Read UInt8 | |
Priority UInt16 | |
PartialBmpHit UInt8 |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {2A274310-42D5-4019-B816-E4B8C7ABE95C}
Defined in rdyboost.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.5074, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02