Microsoft-Windows-Serial-ClassExtension
9 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1000 | The Serial WDF class extension has started. | Analytic | N |
| 1001 | The Serial WDF class extension failed to start (error Status). | Analytic | N |
| 1002 | Received request Request for IoControlCodeString. | Analytic | N |
| 1003 | Request Complete. | Analytic | N |
| 1004 | Transmitting request Request for Length byte(s). | Analytic | N |
| 1005 | Receiving request Request for Length byte(s). | Analytic | N |
| 1006 | Completed request Request for Length byte(s) with status Status. | Analytic | N |
| 1007 | Data. | Analytic | N |
| 1008 | EvtIoStop for request Request in queue Queue, invoke cancel. | Analytic | N |
Event ID 1000: The Serial WDF class extension has started.
#Description
The Serial WDF class extension has started. The control object name is ControlDeviceName.
Message #
Fields #
| Name | Description |
|---|---|
ControlDeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1001: The Serial WDF class extension failed to start (error Status).
#Description
The Serial WDF class extension failed to start (error Status). The control object name is ControlDeviceName.
Message #
Fields #
| Name | Description |
|---|---|
ControlDeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1002: Received request Request for IoControlCodeString.
#Event ID 1003: Request Complete.
#Event ID 1004: Transmitting request Request for Length byte(s).
#Event ID 1005: Receiving request Request for Length byte(s).
#Event ID 1006: Completed request Request for Length byte(s) with status Status.
#Description
Completed request Request for Length byte(s) with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Length UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1008: EvtIoStop for request Request in queue Queue, invoke cancel.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 47bc9477-a8ba-452e-b951-4f2ed3593cf9
Defined in SerCx.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1150, captured 2026-06-02