Kernel-PnP Event ID 410: Device started
- Event ID
- 410
- Channel
- Microsoft-Windows-Kernel-PnP/Configuration
- Provider
- Microsoft-Windows-Kernel-PnP
- Log file
- Microsoft-Windows-Kernel-PnP%4Configuration.evtx
- Category
- Devices and drivers
- Default logging
- Logged by default
What event 410 means
Event 410 in the Microsoft-Windows-Kernel-PnP/Configuration log is written when the Plug and Play manager starts a device, naming the DeviceInstanceId, driver INF, class and the driver service (ServiceName, e.g. USBSTOR, disk).
Where 400 mostly marks the first configuration of a device, 410 is useful for dating connections of devices already known to the system. For a USB drive, look for the pair of nodes: the USB\VID_...&PID_...\<serial> device started by USBSTOR, and the USBSTOR\DISK&VEN_... child started by disk.
Combine it with Partition 1006 (disk and volume details) and System 20001 (first driver install) to reconstruct when a device was attached and what it was.
When it is logged
Microsoft-Windows-Kernel-PnP/Configuration log, enabled by default.
The log is small by default and rolls over quickly on busy hosts.
Key fields
| Field | What it tells you |
|---|---|
| DeviceInstanceId | Plug and Play instance ID; contains vendor, product and serial number for USB storage. |
| DriverName | Driver INF used, e.g. usbstor.inf. |
| ClassGuid | Device setup class GUID. |
| ServiceName | Driver service that started the device, e.g. USBSTOR, disk, WUDFRd. |
| Status | Result code; 0x0 is success. |
Common benign sources
- Every device start at boot, and every hot-plug of known peripherals.
What attackers do that produces it
- Repeated connections of the same USB storage device during a data theft window.
- New network or HID devices started on a server (hardware additions).
Investigation tips
- Filter for storage-related
ServiceNamevalues (USBSTOR,disk) and group by serial number. - Line up start times with user logons (4624, 4800/4801) to attribute the connection to a session.
- Correlate with 1006 to get capacity, vendor and volume serial for the same disk.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.