Microsoft-Windows-Wmbclass-Opn
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | Sending command MessageType: MessageType, MessageLength: MessageLength, … | Operational | N | N |
| 2 | Receiving command done MessageType: MessageType, MessageLength: MessageLength, … | Operational | N | N |
| 3 | Receiving indication MessageType: MessageType, MessageLength: MessageLength, … | Operational | N | N |
| 4 | Receiving MessageType: MessageType, MessageLength: MessageLength, … | Operational | N | N |
| 5 | Receiving MessageType: MessageType, MessageLength: MessageLength, … | Operational | N | N |
Event ID 1: Sending command MessageType: MessageType, MessageLength: MessageLength, MessageTransactionId: MessageTransactionId, TotalFragments: TotalFragments, CurrentFragment: CurrentFragment, ServiceId: Serv...
#Description
Sending command MessageType: , MessageLength: , MessageTransactionId: , TotalFragments: , CurrentFragment: , ServiceId: , CommandId: , CommandType: , InformationBufferLength: , InformationBuffer.
Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | |
MessageLength UInt32 | |
MessageTransactionId UInt32 | |
TotalFragments UInt32 | |
CurrentFragment UInt32 | |
ServiceId GUID | |
CommandId UInt32 | |
CommandType UInt32 | |
InformationBufferLength UInt32 | |
InformationBuffer Binary |
Event ID 2: Receiving command done MessageType: MessageType, MessageLength: MessageLength, MessageTransactionId: MessageTransactionId, TotalFragments: TotalFragments, CurrentFragment: CurrentFragment, ServiceI...
#Description
Receiving command done MessageType: , MessageLength: , MessageTransactionId: , TotalFragments: , CurrentFragment: , ServiceId: , CommandId: , Status: , InformationBufferLength: , InformationBuffer.
Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | |
MessageLength UInt32 | |
MessageTransactionId UInt32 | |
TotalFragments UInt32 | |
CurrentFragment UInt32 | |
ServiceId GUID | |
CommandId UInt32 | |
Status UInt32 | NTSTATUS reference |
InformationBufferLength UInt32 | |
InformationBuffer Binary |
Event ID 3: Receiving indication MessageType: MessageType, MessageLength: MessageLength, MessageTransactionId: MessageTransactionId, TotalFragments: TotalFragments, CurrentFragment: CurrentFragment, ServiceId:...
#Description
Receiving indication MessageType: , MessageLength: , MessageTransactionId: , TotalFragments: , CurrentFragment: , ServiceId: , CommandId: , InformationBufferLength: , InformationBuffer.
Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | |
MessageLength UInt32 | |
MessageTransactionId UInt32 | |
TotalFragments UInt32 | |
CurrentFragment UInt32 | |
ServiceId GUID | |
CommandId UInt32 | |
InformationBufferLength UInt32 | |
InformationBuffer Binary |
Event ID 4: Receiving MessageType: MessageType, MessageLength: MessageLength, MessageTransactionId: MessageTransactionId, Uint32 payload: Status.
#Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | |
MessageLength UInt32 | |
MessageTransactionId UInt32 | |
Status UInt32 | NTSTATUS reference |
Provenance
ETW provider GUID a42fe227-a7bf-4483-a502-6bcda428cd96
Defined in mbbcx.sys, the binary that emits these events.
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02 — Manifest XML pack, 2.0 MB