Skip to content
Kernel-PnP

Kernel-PnP Event ID 410: Device started

Device was startedKernel-PnP event 410 is logged when a device is started with its driver and service. Dates USB storage connections, including repeat ones.
410
Event ID
410
Channel
Microsoft-Windows-Kernel-PnP/Configuration
Provider
Microsoft-Windows-Kernel-PnP
Log file
Microsoft-Windows-Kernel-PnP%4Configuration.evtx
Category
Devices and drivers
Default logging
Logged by default

What event 410 means

Event 410 in the Microsoft-Windows-Kernel-PnP/Configuration log is written when the Plug and Play manager starts a device, naming the DeviceInstanceId, driver INF, class and the driver service (ServiceName, e.g. USBSTOR, disk).

Where 400 mostly marks the first configuration of a device, 410 is useful for dating connections of devices already known to the system. For a USB drive, look for the pair of nodes: the USB\VID_...&PID_...\<serial> device started by USBSTOR, and the USBSTOR\DISK&VEN_... child started by disk.

Combine it with Partition 1006 (disk and volume details) and System 20001 (first driver install) to reconstruct when a device was attached and what it was.

When it is logged

Audit policy / configuration

Microsoft-Windows-Kernel-PnP/Configuration log, enabled by default.

The log is small by default and rolls over quickly on busy hosts.

Key fields

FieldWhat it tells you
DeviceInstanceIdPlug and Play instance ID; contains vendor, product and serial number for USB storage.
DriverNameDriver INF used, e.g. usbstor.inf.
ClassGuidDevice setup class GUID.
ServiceNameDriver service that started the device, e.g. USBSTOR, disk, WUDFRd.
StatusResult code; 0x0 is success.

Common benign sources

  • Every device start at boot, and every hot-plug of known peripherals.

What attackers do that produces it

  • Repeated connections of the same USB storage device during a data theft window.
  • New network or HID devices started on a server (hardware additions).

Investigation tips

  • Filter for storage-related ServiceName values (USBSTOR, disk) and group by serial number.
  • Line up start times with user logons (4624, 4800/4801) to attribute the connection to a session.
  • Correlate with 1006 to get capacity, vendor and volume serial for the same disk.

MITRE ATT&CK techniques

TechniqueTactics
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USBExfiltration
T1200 Hardware AdditionsInitial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading