System Event ID 20001: Device driver installed
- Event ID
- 20001
- Channel
- System
- Provider
- Microsoft-Windows-UserPnp
- Log file
- System.evtx
- Category
- Devices and drivers
- Default logging
- Logged by default
What event 20001 means
Event 20001 is written by the user-mode Plug and Play manager when it finishes installing a driver for a device. The device is identified by DeviceInstanceID — for a USB mass storage device something like USBSTOR\DISK&VEN_...&PROD_...&REV_...\<serial>&0 — with the driver package, provider and setup class.
Because a driver is installed the first time a given device is seen, 20001 is a classic indicator of the first connection of a USB drive, phone or other peripheral to the host, including the device serial number embedded in the instance ID. Later connections of the same device usually do not produce a new 20001; use Kernel-PnP 400/410 and Partition 1006 for those.
The event data is under UserData, not EventData. InstallStatus 0x0 means success.
When it is logged
Always logged to the System log when a device driver is installed.
Key fields
| Field | What it tells you |
|---|---|
| DeviceInstanceID | Plug and Play instance ID of the device. For USB storage it contains vendor, product, revision and the device serial number (before &0). |
| DriverName | INF of the driver installed, e.g. disk.inf or usbstor.inf. |
| DriverDescription | Friendly description of the driver or device. |
| DriverProvider | Publisher of the driver package. |
| DriverVersion | Version of the driver installed. |
| SetupClass | Device setup class GUID, e.g. 4d36e967-e325-11ce-bfc1-08002be10318 for disk drives or 4d36e972-e325-11ce-bfc1-08002be10318 for network adapters. |
| IsDriverOEM | Whether the driver is a third-party (OEM) package rather than an inbox Windows driver. |
| InstallStatus | Result of the installation; 0x0 is success. |
Common benign sources
- Users connecting new USB drives, phones, printers, docks and headsets.
- Driver installs on first boot, after hardware changes or VM migration.
What attackers do that produces it
- Data theft to removable media: a new
USBSTORdevice appearing on a server or sensitive workstation, especially outside business hours. - Hardware additions such as rogue network adapters or keystroke-injection devices presenting as keyboards.
Investigation tips
- Extract vendor, product and serial number from
DeviceInstanceIDand compare with the approved device inventory. - Build the full USB timeline with Kernel-PnP 400/410 and Partition 1006 (connections, volume details).
- Look for file access and copy activity (4663, Sysmon 11, LNK and jump lists) during the connection window.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.