Microsoft-Windows-UserPnp
Event ID 7553: Plug and Play install worker thread has started.
#Fields #
| Name | Description |
|---|---|
ThreadId UInt32 | |
DeviceId UnicodeString |
Event ID 7554: Plug and Play install worker thread has exited.
#Fields #
| Name | Description |
|---|---|
ThreadId UInt32 |
Event ID 7555: Parent of current device is already ahead in the install queue.
#Fields #
| Name | Description |
|---|---|
ChildDevice UnicodeString | |
ParentDevice UnicodeString |
Event ID 7556: Current device is a volume snapshot device.
#Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString |
Event ID 7600: Client {ClientName} successfully registered for device notifications.
#Fields #
| Name | Description |
|---|---|
ClientName |
Event ID 7601: Error sending device event notification window message to client {WindowName} (hWnd={hWnd}; Session={SessionId}; Err={ErrorCode}).
#Fields #
| Name | Description |
|---|---|
WindowName | |
hWnd | |
SessionId | |
ErrorCode |
Event ID 7602: Error sending service control for device event notification to client {ClientName} (Session={SessionId}; Err={ErrorCode}).
#Fields #
| Name | Description |
|---|---|
ClientName | |
SessionId | |
ErrorCode |
Event ID 7603: Error broadcasting system message for device event notification (Err={ErrorCode}).
#Fields #
| Name | Description |
|---|---|
ErrorCode |
Event ID 7604: Sending notification for event {EventType} for device: {DeviceID}.
#Fields #
| Name | Description |
|---|---|
EventType | |
DeviceID |
Event ID 7650: Received device event from Kernel PnP (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).
#Fields #
| Name | Description |
|---|---|
EventGuid | |
EventCategory | |
IsEventAsync |
Event ID 7651: User PnP completed handling of the device event (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).
#Fields #
| Name | Description |
|---|---|
EventGuid | |
EventCategory | |
IsEventAsync |
Event ID 7700: Start processing 'DIF_CODE'.
#Event ID 7701: Finished processing 'DIF_CODE' (Err=ErrorCode).
#Event ID 7702: START: Core device install operations.
#Event ID 7703: END: Core device install operations.
#Event ID 7704: ENTER: Synchronization wait for core device install.
#Event ID 7705: EXIT: Synchronization wait for core device install.
#Event ID 7708: ENTER: Stage driver package
#Event ID 7709: EXIT: Stage driver package
#Event ID 7714: ENTER: Sending event notification to service ({ClientName}).
#Fields #
| Name | Description |
|---|---|
ClientName |
Event ID 7715: EXIT: Sending event notification to service ({ClientName}).
#Fields #
| Name | Description |
|---|---|
ClientName |
Event ID 7716: ENTER: Sending event notification to window ({ClientName}).
#Fields #
| Name | Description |
|---|---|
ClientName |
Event ID 7717: EXIT: Sending event notification to window ({ClientName}).
#Fields #
| Name | Description |
|---|---|
ClientName |
Event ID 7718: ENTER: Device installation restrictions policy check.
#Event ID 7719: EXIT: Device installation restrictions policy check.
#Event ID 7720: ENTER: Build driver info list.
#Event ID 7721: EXIT: Build driver info list.
#Event ID 7722: ENTER: Build driver info list - search published INFs.
#Event ID 7723: EXIT: Build driver info list - search published INFs.
#Event ID 7724: ENTER: Build driver info list - search Device Path.
#Event ID 7725: EXIT: Build driver info list - search Device Path.
#Event ID 7728: ENTER: Build driver info list - search caller specified folder.
#Event ID 7729: EXIT: Build driver info list - search caller specified folder.
#Event ID 7730: ENTER: PnpInstallDevice - install device instance.
#Event ID 7731: EXIT: PnpInstallDevice - install device instance.
#Event ID 7800: START: Searching WMIS for metadata package
#Event ID 7801: STOP: Searching WMIS for metadata package
#Event ID 7802: START: Downloading metadata package from WMIS
#Event ID 7803: STOP: Downloading metadata package from WMIS
#Event ID 7804: START: Searching local index for metadata package
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7804,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.472Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7805: STOP: Searching local index for metadata package
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7805,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.472Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7806: START: Unpacking metadata package into cache
#Event ID 7807: STOP: Unpacking metadata package into cache
#Event ID 7808: START: Parsing packageinfo.
#Description
START: Parsing packageinfo.xml for metadata properties.
Message #
Event ID 7809: STOP: Parsing packageinfo.
#Description
STOP: Parsing packageinfo.xml for metadata properties.
Message #
Event ID 7810: START: Scanning local store for new metadata packages
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7810,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.470Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7811: STOP: Scanning local store for new metadata packages
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7811,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.471Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7812: START: Initializing DMRC
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7812,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.468Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7813: STOP: Initializing DMRC
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7813,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.471Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7814: START: Uninitialize DMRC
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7814,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 8428,
"thread_id": 2112
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:58:57.997Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7815: STOP: Uninitializing DMRC
#Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/Performance",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7815,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 8428,
"thread_id": 2112
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:58:58.020Z",
"version": 0
},
"event_data": {},
"message": ""
}
Event ID 7900: Message (Package: Package Error Code = ErrorCode, Win32 Error Code = Win32ErrorCode).
#Event ID 7901: A new device metadata package was downloaded from WMIS.
#Event ID 7902: Message (Package: Package Error Code = ErrorCode, Win32 Error Code = Win32ErrorCode).
#Event ID 7903: Successfully parsed device metadata file.
#Event ID 7950: A new device metadata package was discovered.
#Event ID 7951: DMRC was queried for type 'QueryType' with lookup key 'LookupKey'.
#Message #
Fields #
| Name | Description |
|---|---|
QueryType UnicodeString | |
LookupKey UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-UserPnp/DeviceMetadata/Debug",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7951,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 11720,
"thread_id": 11376
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-UserPnp",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:59:31.472Z",
"version": 0
},
"event_data": {
"LookupKey": "ComputerMetadata\\{CA0957D0-549A-5699-84D5-1C8A462925A4}",
"QueryType": "Hardware Id (display object)"
},
"message": ""
}
Event ID 7952: Message (Error Code = NetworkErrorCode, Last Http Status Code = HttpStatusCode).
#Event ID 8000: A reboot is required to complete device installation of device 'ERR_DEVICE_ID.DeviceId'.
#Message #
Fields #
| Name | Description |
|---|---|
DeviceId |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 8000,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2023-10-25T22:50:39.873740+00:00",
"event_record_id": 21,
"correlation": {},
"execution": {
"process_id": 3600,
"thread_id": 1060
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"ERR_DEVICE_ID": {
"DeviceId": "ACPI\\VMW0003\\4&1BD7F811&0"
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8001: The DeviceInstall service has started.
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
"event_source_name": "",
"event_id": 8001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2026-05-28T04:47:58.4674435+00:00",
"event_record_id": 13,
"correlation": {},
"execution": {
"process_id": 4536,
"thread_id": 5956
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The DeviceInstall service has started."
}
Event ID 8002: The DeviceInstall service is stopping (idle).
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
"event_source_name": "",
"event_id": 8002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2026-05-28T04:50:31.7833993+00:00",
"event_record_id": 14,
"correlation": {},
"execution": {
"process_id": 4536,
"thread_id": 2572
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The DeviceInstall service is stopping (idle)."
}
Event ID 8003: The DeviceInstall service is stopping (stop control).
#Event ID 8004: The DeviceInstall service is stopping (shutdown).
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 8004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2023-11-06T06:23:40.089953+00:00",
"event_record_id": 27,
"correlation": {},
"execution": {
"process_id": 1068,
"thread_id": 1072
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8005: The DeviceInstall service has stopped.
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
"event_source_name": "",
"event_id": 8005,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2026-05-28T04:50:31.7839977+00:00",
"event_record_id": 15,
"correlation": {},
"execution": {
"process_id": 4536,
"thread_id": 2572
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The DeviceInstall service has stopped."
}
Event ID 8006: There are pending driver updates to install.
#Event ID 8007: A timeout was detected during the installation of device 'DeviceId'.
#Event ID 8008: The DeviceInstall service is starting.
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 8008,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2023-11-06T06:25:29.340577+00:00",
"event_record_id": 29,
"correlation": {},
"execution": {
"process_id": 1080,
"thread_id": 1096
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8009: The DeviceInstall service failed to start with error ErrorCode.
#Event ID 8010: Finish install operation state changed to hc_stateid.
#Event ID 8020: Device installation is currently disabled.
#Event ID 8021: Device installation has been disabled.
#Event ID 8022: Device installation has been enabled.
#Event ID 8030: The DeviceInstall service will not idle stop.
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 8030,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423490,
"time_created": "2023-11-06T06:25:29.352092+00:00",
"event_record_id": 31,
"correlation": {},
"execution": {
"process_id": 1080,
"thread_id": 1096
},
"channel": "Microsoft-Windows-UserPnp/DeviceInstall",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8040: task_08040
#Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | |
HardwareIds UnicodeString | |
CompatibleIds UnicodeString | |
MatchingDeviceId UnicodeString | |
OriginalInfName UnicodeString | |
DriverDate FILETIME | |
DriverVersion UnicodeString | |
SubmissionId UnicodeString | |
FlightIds UnicodeString |
Event ID 20001: Driver Management concluded the process to install driver http://schemas.
#Description
Driver Management concluded the process to install driver for Device Instance ID with the following status: .
Message #
Fields #
| Name | Description |
|---|---|
DriverName | |
DriverVersion | |
DriverProvider | |
DeviceInstanceID | |
SetupClass | |
RebootOption | |
UpgradeDevice | |
IsDriverOEM | |
InstallStatus | |
DriverDescription |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 20001,
"version": 0,
"level": 4,
"task": 7005,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2013-10-23T16:17:53.968750+00:00",
"event_record_id": 250,
"correlation": {},
"execution": {
"process_id": 1536,
"thread_id": 1900
},
"channel": "System",
"computer": "37L4247D28-05",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"InstallDeviceID": {
"xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
"DriverName": "FileRepository\\rdpbus.inf_x86_neutral_27637529205407be\\rdpbus.inf",
"DriverVersion": "6.1.7600.16385",
"DriverProvider": "Microsoft",
"DeviceInstanceID": "ROOT\\RDPBUS\\0000",
"SetupClass": "4D36E97D-E325-11CE-BFC1-08002BE10318",
"RebootOption": false,
"UpgradeDevice": false,
"IsDriverOEM": false,
"InstallStatus": 0,
"DriverDescription": "Remote Desktop Device Redirector Bus"
}
},
"message": "Driver Management concluded the process to install driver http://schemas.microsoft.com/win/2004/08/events for Device Instance ID Microsoft with the following status: false."
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 20002: Driver Management concluded the process to remove driver DriverName from Device Instance ID DeviceInstanceID with the following status: InstallStatus.
#Event ID 20003: Driver Management has concluded the process to add Service AddServiceID.ServiceName for Device Instance ID AddServiceID.DeviceInstanceID with the following status: AddServiceID.AddServiceStatus.
#Message #
Fields #
| Name | Description |
|---|---|
ServiceName | |
DriverFileName | |
DeviceInstanceID | |
PrimaryService | |
UpdateService | |
AddServiceStatus |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 20003,
"version": 0,
"level": 4,
"task": 7005,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:30:40.551666+00:00",
"event_record_id": 1844,
"correlation": {},
"execution": {
"process_id": 7864,
"thread_id": 8460
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"AddServiceID": {
"ServiceName": "VM3DService",
"DriverFileName": "%SystemRoot%\\system32\\vm3dservice.exe",
"DeviceInstanceID": "PCI\\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\\3&61AAA01&0&78",
"PrimaryService": false,
"UpdateService": false,
"AddServiceStatus": 0
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 20004: Driver Management has concluded the process to remove Service ServiceName for Device Instance ID DeviceInstanceID with the following status: AddServiceStatus.
#Event ID 20005: Driver Management has restricted the installation of Device Instance ID DeviceId because of a Device Installation Restriction policy setting.
#Event ID 20006: Driver Management has deferred the process to install Device Instance ID DeviceId until a driver has been selected because of a Device Installation Restr...
#Event ID 20007: Driver Management has removed Device Instance ID DeviceId because of a Device Installation Restriction policy setting.
#Event ID 20008: Driver Management has not removed Device Instance ID DeviceId with matching policy restriction because it is a required system device.
#Event ID 20009: Driver Management will reboot the system in RebootTime seconds to enforce a Device Installation Restriction policy setting.
#Event ID 20010
#Fields #
| Name | Description |
|---|---|
INFO_PNP_STATE.xmlns:auto-ns2 | |
INFO_PNP_STATE.InstallSubsystemState | |
INFO_PNP_STATE.CachingSubsystemState |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UserPnp",
"guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
"event_source_name": "",
"event_id": 20010,
"version": 0,
"level": 4,
"task": 7010,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2013-10-23T16:18:04.750000+00:00",
"event_record_id": 255,
"correlation": {},
"execution": {
"process_id": 616,
"thread_id": 1644
},
"channel": "System",
"computer": "37L4247D28-05",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"INFO_PNP_STATE": {
"xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
"InstallSubsystemState": true,
"CachingSubsystemState": true
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Provenance
ETW provider GUID 96f4a050-7e31-453c-88be-9634f4e02139
Defined in umpnpmgr.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB