@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

Audit PNP Activity and ID 6416

Note:I translated Japanese into English using Google Translate.
Thank you, Google.

When audit setting "Audit PNP Activity" is enabled on Windows 10, event ID 6416 is recorded. Auditing is not enabled for this item by default.

Let's check the record when connecting the USB memory.

f:id:hideakii:20181028170012p:plain

Connect the USB memory. This USB memory was connected to the system for the first time.

f:id:hideakii:20181028170343p:plain

Three records were recorded in the security log.

f:id:hideakii:20181028170612p:plain

ID 6416

f:id:hideakii:20181028170938p:plain

f:id:hideakii:20181028171006p:plain

f:id:hideakii:20181028171036p:plain

The user name is the computer account. It seems that it is necessary to confirm the account connected the USB device to the system with another item.

Slightly later, another 6416 records are also recorded. Volume name is recorded in the item of DeviceDescription.

f:id:hideakii:20181028171701p:plain

f:id:hideakii:20181028172043p:plain

Event IDs 6419 and 6420 are recorded when device is disabled.

Interesting, ID 6419 has recorded the user who disabled the device.

f:id:hideakii:20181028172451p:plain

f:id:hideakii:20181028172533p:plain

f:id:hideakii:20181028172616p:plain

When you enable the device, IDs 6421 and 6422 are recorded.
Event ID 6421 records the user who activated the device.

f:id:hideakii:20181028173020p:plain

f:id:hideakii:20181028173058p:plain

Perform removal of the device.

f:id:hideakii:20181028173412p:plain

Unfortunately, no record was recorded on removal of the device.

While shutting down the system with the USB device connected, records were not recorded.

When rebooting the system with the USB device connected, ID 6416 is recorded after system startup. (There was only one record related to the USB device.)

f:id:hideakii:20181028174625p:plain

 

Verification environment: Windows 10 1083

Reference URL:

docs.microsoft.com

6416(S) A new external device was recognized by the System. (Windows 10) | Microsoft Docs

 

f:id:hideakii:20181028165248j:plain