Skip to content
Security

Event ID 6416: External device recognized

A new external device was recognized by the SystemSecurity event 6416 records a new device recognized by Windows, such as a USB drive, with device ID, class and vendor IDs. Needs Audit PNP Activity.
6416
Event ID
6416
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Devices and drivers
Default logging
Needs configuration

What event 6416 means

Event 6416 is written when Windows recognizes a new external device — for example a USB mass-storage device, phone, keyboard or network adapter being connected or enabled. It records the device instance path (DeviceId), its friendly name (DeviceDescription), the device setup class (ClassName, ClassId) and the hardware and compatible IDs that identify vendor and model (VendorIds, CompatibleIds).

For investigations it answers "which device, when": USB storage used for data theft, rogue keyboards (HID injection devices), or unauthorized network adapters. The VendorIds string usually contains the vendor and product identifiers and, for storage, a product name, which can be matched with registry artifacts (USBSTOR) and partition events.

Expect entries for internal and virtual devices too, especially after driver updates or on virtual machines. Filter by ClassName — DiskDrive, USB, WPD, HIDClass, Net — to focus on what matters.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Detailed Tracking > Audit PNP Activity (Success). Not enabled in the default audit policy.

Windows 10 / Server 2016 and later. DeviceId, DeviceDescription and ClassName were added in event version 1 (Windows 10 1511).

Key fields

FieldWhat it tells you
SubjectUserNameNormally the computer account (SYSTEM). Microsoft suggests reviewing any other value.
DeviceIdDevice instance path, e.g. USBSTOR\Disk&Ven_...&Prod_...\<serial>. The last part is often the device serial number — a key pivot across hosts and registry artifacts.
DeviceDescriptionFriendly device name, e.g. the drive model.
ClassNameDevice setup class, e.g. DiskDrive, USB, HIDClass, WPD, Net.
ClassIdGUID of the device setup class; {4D36E967-E325-11CE-BFC1-08002BE10318} is the disk drive class.
VendorIdsHardware IDs reported by the device, including vendor and product identifiers.
CompatibleIdsCompatible IDs used by Windows to pick a generic driver (e.g. USB\Class_08 for mass storage).
LocationInformationPhysical location on the bus (port, hub, bus/target/LUN numbers).

Common benign sources

  • Users plugging in approved peripherals — mice, headsets, webcams, docking stations.
  • Virtual and internal devices enumerated after driver or Windows updates, or when VMs are provisioned.

What attackers do that produces it

  • Insiders or intruders copying data to a USB storage device.
  • Keystroke-injection devices presenting themselves as keyboards (HIDClass) to type commands at the console.
  • Rogue network adapters (USB Ethernet, cellular modems) used to bypass network controls.

Investigation tips

  • Filter on ClassName DiskDrive / WPD and review DeviceId serials against your list of approved devices.
  • Correlate with Microsoft-Windows-Partition/Diagnostic 1006 and Kernel-PnP 400/410 for volume and driver details, and with file access or process activity right after insertion.
  • Check which user was logged on interactively at the time (4624, 4800/4801) to attribute the device use.

MITRE ATT&CK techniques

TechniqueTactics
T1200 Hardware AdditionsInitial Access
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USBExfiltration
T1091 Replication Through Removable MediaLateral Movement, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading