Skip to content
System

System Event ID 20001: Device driver installed

Driver Management concluded the process to install driver for Device Instance ID with the following statusSystem event 20001 (UserPnp) records a device driver install with the device instance ID. First-connection evidence for USB storage.
20001
Event ID
20001
Channel
System
Provider
Microsoft-Windows-UserPnp
Log file
System.evtx
Category
Devices and drivers
Default logging
Logged by default

What event 20001 means

Event 20001 is written by the user-mode Plug and Play manager when it finishes installing a driver for a device. The device is identified by DeviceInstanceID — for a USB mass storage device something like USBSTOR\DISK&VEN_...&PROD_...&REV_...\<serial>&0 — with the driver package, provider and setup class.

Because a driver is installed the first time a given device is seen, 20001 is a classic indicator of the first connection of a USB drive, phone or other peripheral to the host, including the device serial number embedded in the instance ID. Later connections of the same device usually do not produce a new 20001; use Kernel-PnP 400/410 and Partition 1006 for those.

The event data is under UserData, not EventData. InstallStatus 0x0 means success.

When it is logged

Audit policy / configuration

Always logged to the System log when a device driver is installed.

Key fields

FieldWhat it tells you
DeviceInstanceIDPlug and Play instance ID of the device. For USB storage it contains vendor, product, revision and the device serial number (before &0).
DriverNameINF of the driver installed, e.g. disk.inf or usbstor.inf.
DriverDescriptionFriendly description of the driver or device.
DriverProviderPublisher of the driver package.
DriverVersionVersion of the driver installed.
SetupClassDevice setup class GUID, e.g. 4d36e967-e325-11ce-bfc1-08002be10318 for disk drives or 4d36e972-e325-11ce-bfc1-08002be10318 for network adapters.
IsDriverOEMWhether the driver is a third-party (OEM) package rather than an inbox Windows driver.
InstallStatusResult of the installation; 0x0 is success.

Common benign sources

  • Users connecting new USB drives, phones, printers, docks and headsets.
  • Driver installs on first boot, after hardware changes or VM migration.

What attackers do that produces it

  • Data theft to removable media: a new USBSTOR device appearing on a server or sensitive workstation, especially outside business hours.
  • Hardware additions such as rogue network adapters or keystroke-injection devices presenting as keyboards.

Investigation tips

  • Extract vendor, product and serial number from DeviceInstanceID and compare with the approved device inventory.
  • Build the full USB timeline with Kernel-PnP 400/410 and Partition 1006 (connections, volume details).
  • Look for file access and copy activity (4663, Sysmon 11, LNK and jump lists) during the connection window.

MITRE ATT&CK techniques

TechniqueTactics
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USBExfiltration
T1200 Hardware AdditionsInitial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading