diff --git a/evtx/Maps/Microsoft-Windows-Storage-ClassPnP-Operational_Microsoft-Windows-Storage-ClassPnP_507.map b/evtx/Maps/Microsoft-Windows-Storage-ClassPnP-Operational_Microsoft-Windows-Storage-ClassPnP_507.map new file mode 100644 index 00000000..54b8a585 --- /dev/null +++ b/evtx/Maps/Microsoft-Windows-Storage-ClassPnP-Operational_Microsoft-Windows-Storage-ClassPnP_507.map @@ -0,0 +1,83 @@ +Author: Andrew Rathbun +Description: Completing a failed non-ReadWrite SCSI SRB request +EventId: 507 +Channel: "Microsoft-Windows-Storage-ClassPnP/Operational" +Provider: "Microsoft-Windows-StorDiag" +Maps: + - + Property: PayloadData1 + PropertyValue: "DeviceGUID: %DeviceGUID%" + Values: + - + Name: DeviceGUID + Value: "/Event/EventData/Data[@Name=\"DeviceGUID\"]" + - + Property: PayloadData2 + PropertyValue: "Vendor: %Vendor%" + Values: + - + Name: Vendor + Value: "/Event/EventData/Data[@Name=\"Vendor\"]" + - + Property: PayloadData3 + PropertyValue: "Model: %Model%" + Values: + - + Name: Model + Value: "/Event/EventData/Data[@Name=\"Model\"]" + - + Property: PayloadData4 + PropertyValue: "SerialNumber: %SerialNumber%" + Values: + - + Name: SerialNumber + Value: "/Event/EventData/Data[@Name=\"SerialNumber\"]" + - + Property: PayloadData5 + PropertyValue: "FirmwareVersion: %FirmwareVersion%" + Values: + - + Name: FirmwareVersion + Value: "/Event/EventData/Data[@Name=\"FirmwareVersion\"]" + +# Documentation: +# https://forensixchange.com/posts/19_08_03_usb_storage_forensics_1/ +# https://www.mcbsys.com/blog/2016/08/stordiag-errors-after-windows-10-upgrade/ +# https://www.windowsphoneinfo.com/threads/event-507-completing-a-failed-non-readwrite-scsi-srb-request.275718/ +# +# Example Event Data: +# +# +# +# 507 +# 1 +# 2 +# 200 +# 101 +# 0x800000038000000 +# +# 2 +# +# +# Microsoft-Windows-Storage-ClassPnP/Operational +# HOSTNAME +# +# +# +# 3c1723fd-1386-004c-ea45-358679129f24 +# 3 +# Msft +# Virtual Disk +# 1.0 +# NULL +# 0xC0000185 +# 4 +# 2 +# 0 +# 0 +# 0 +# 10 +# 35-00-00-00-00-00-00-00-00-00 +# 5 +# +#