Microsoft-Windows-Sdstor
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 100 | Request servicing time taken by SD stack. | Analytic | N | N |
| 101 | Packed Command Read Received. | Analytic | N | N |
| 102 | Packed Command Write Received. | Analytic | N | N |
| 103 | HPI Timer Queued | Analytic | N | N |
| 104 | HPI Irp Sent | Analytic | N | N |
| 105 | HPI Irp Completed (0xResultCode). | Analytic | N | N |
| 106 | Flush received | Analytic | N | N |
| 107 | Discard received (LBA LBA Length Length). | Analytic | N | N |
Event ID 100: Request servicing time taken by SD stack.
#Fields #
| Name | Description |
|---|---|
Port UInt8 | |
Bus UInt8 | |
Target UInt8 | |
LUN UInt8 | |
RequestDuration UInt64 | |
CDBLength UInt32 | |
CDB Binary | |
SrbStatus UInt8 | |
Irp Pointer | |
OriginalIrp Pointer |
Event ID 101: Packed Command Read Received.
#Event ID 102: Packed Command Write Received.
#Event ID 103: HPI Timer Queued
#Event ID 104: HPI Irp Sent
#Event ID 106: Flush received
#Provenance
ETW provider GUID afe654eb-0a83-4eb4-948f-d4510ec39c30
Defined in sdstor.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB