Skip to content
Kernel-PnP

Kernel-PnP Event ID 400: Device configured

Device was configuredKernel-PnP event 400 is logged when a device is configured with a driver: instance ID, driver INF and class. Dates USB storage and other device connections.
400
Event ID
400
Channel
Microsoft-Windows-Kernel-PnP/Configuration
Provider
Microsoft-Windows-Kernel-PnP
Log file
Microsoft-Windows-Kernel-PnP%4Configuration.evtx
Category
Devices and drivers
Default logging
Logged by default

What event 400 means

Event 400 in the Microsoft-Windows-Kernel-PnP/Configuration log is written when the Plug and Play manager configures a device — selecting and binding its driver. It records the DeviceInstanceId, the driver INF (DriverName), the device class and details about the chosen driver.

For USB forensics it complements System 20001: a USB storage device produces a chain of 400/410 records for its USB node (USB\VID_xxxx&PID_xxxx\<serial>) and its storage node (USBSTOR\DISK&VEN_...&PROD_...\<serial>&0). The serial number in the instance ID ties those records to registry artifacts (USBSTOR keys, MountedDevices) and to Partition 1006.

400 is typically written when a device is set up for the first time or its driver changes, so it is strongest as first-connection evidence; 410 (device started) is written on subsequent starts as well.

When it is logged

Audit policy / configuration

Microsoft-Windows-Kernel-PnP/Configuration log, enabled by default.

The log is small by default and rolls over on systems with frequent device activity; collect it early.

Key fields

FieldWhat it tells you
DeviceInstanceIdPlug and Play instance ID. For USB storage it contains vendor and product IDs (or names) and the device serial number.
DriverNameDriver INF selected for the device, e.g. usbstor.inf, disk.inf, wpdmtp.inf.
ClassGuidDevice setup class, e.g. {4d36e967-e325-11ce-bfc1-08002be10318} for disk drives.
DriverProviderPublisher of the selected driver.
DriverInboxWhether the driver ships with Windows (inbox) or is third-party.
DeviceUpdatedWhether an existing device's driver was updated rather than set up for the first time.
ParentDeviceInstanceIdInstance ID of the parent device (for example the USB node of a USBSTOR disk).
StatusResult code; 0x0 is success.

Common benign sources

  • Users connecting USB drives, phones, docks, printers and other peripherals.
  • Driver updates pushed by Windows Update.

What attackers do that produces it

  • An unapproved USB storage device configured on a sensitive system shortly before data exfiltration.
  • Malicious hardware (keystroke injection, rogue network adapters) presenting as a new HID or network device.

Investigation tips

  • Filter on DeviceInstanceId starting with USBSTOR\, SCSI\ or SWD\WPDBUSENUM to find storage and portable devices.
  • Extract the serial number and match it with 410, 20001, Partition 1006 and registry USB artifacts.
  • Check file activity during the connection window (LNK files, jump lists, 4663, Sysmon 11).

MITRE ATT&CK techniques

TechniqueTactics
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USBExfiltration
T1200 Hardware AdditionsInitial Access
T1091 Replication Through Removable MediaLateral Movement, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading