Microsoft-Windows-VIRTDISK
10 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Opening backing store VhdFileName as type VhdVirtualStorageType. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 2 | Opened backing store, returning handle VhdHandle, status VhdStatus. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 3 | Attaching using handle VhdHandle. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 4 | Attached with status VhdStatus. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 5 | Detaching using handle VhdHandle. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 6 | Detached with status VhdStatus. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 1000 | TraceData. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 1001 | TraceData. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 1002 | TraceData. | Microsoft-Windows-VIRTDISK-Analytic | N |
| 1003 | TraceData. | Microsoft-Windows-VIRTDISK-Analytic | N |
Event ID 1: Opening backing store VhdFileName as type VhdVirtualStorageType.
#Event ID 2: Opened backing store, returning handle VhdHandle, status VhdStatus.
#Event ID 3: Attaching using handle VhdHandle.
#Event ID 4: Attached with status VhdStatus.
#Event ID 5: Detaching using handle VhdHandle.
#Event ID 6: Detached with status VhdStatus.
#Event ID 1000: TraceData.
#Event ID 1001: TraceData.
#Event ID 1002: TraceData.
#Event ID 1003: TraceData.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 4d20df22-e177-4514-a369-f1759feedeb3
Defined in virtdisk.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02