viewer9 documentation

DeviceIoControl PML Operation

IoControl ("Control" in Procmon) is an enumerated code.

Example from 64-bit PML

Hover over field values like Time, ResultCode, IoControl, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

DeviceIoControl opcode=3,34

ev=20957 advop=IRP_MJ_DEVICE_CONTROL

Time:2022-05-17 20:18:28.3629093
Duration:0.0000009
ResultCode:FAST IO DISALLOWED
Tid:4508
Path:C:\Windows\System32\catroot2\edb.chk
IoControl:IOCTL_MOUNTDEV_QUERY_DEVICE_NAME

evdata[0-105] file offset 11156045

000 00 72 00 65 00 72 00 ..r.e.r.
800 00 00 00 02 00 00 00 ........
1608 02 00 00 00 00 00 00 ........
2400 00 00 00 00 00 00 00 ........
3208 00 4d 00 00 00 00 00 ..M.....
4000 00 00 00 00 00 00 00 ........
4870 d9 5f 28 a8 00 00 00 p._(....
5600 00 00 00 00 00 00 00 ........
6424 80 2d 00 43 3a 5c 57 $.-.C:\W
7269 6e 64 6f 77 73 5c 53 indows\S
8079 73 74 65 6d 33 32 5c ystem32\
8863 61 74 72 6f 6f 74 32 catroot2
965c 65 64 62 2e 63 68 6b \edb.chk
10400 c0 ..

Call Stack stacksize=25

StackAddressmodModNameModPath
0xfffff8005ed97034143FLTMGR.SYS + 0x7034C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff8005ed954e3143FLTMGR.SYS + 0x54e3C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff8005edd3c0c143FLTMGR.SYS + 0x43c0cC:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff8005dcf8f74140ntoskrnl.exe + 0x6f8f74C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8005dcf8836140ntoskrnl.exe + 0x6f8836C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8005da28a75140ntoskrnl.exe + 0x428a75C:\WINDOWS\system32\ntoskrnl.exe
0x7ffd3a80383465ntdll.dll + 0xa3834C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffd38043ffb41KERNELBASE.dll + 0x33ffbC:\WINDOWS\System32\KERNELBASE.dll
0x7ffd3804373341KERNELBASE.dll + 0x33733C:\WINDOWS\System32\KERNELBASE.dll
0x7ffd3803f95641KERNELBASE.dll + 0x2f956C:\WINDOWS\System32\KERNELBASE.dll
0x7ffd2ab2f6db394ESENT.dll + 0x8f6dbC:\WINDOWS\system32\ESENT.dll
0x7ffd2aad2a33394ESENT.dll + 0x32a33C:\WINDOWS\system32\ESENT.dll
0x7ffd2aad1d1f394ESENT.dll + 0x31d1fC:\WINDOWS\system32\ESENT.dll
0x7ffd2aad3d9d394ESENT.dll + 0x33d9dC:\WINDOWS\system32\ESENT.dll
0x7ffd2aace6f8394ESENT.dll + 0x2e6f8C:\WINDOWS\system32\ESENT.dll
0x7ffd2aace6b1394ESENT.dll + 0x2e6b1C:\WINDOWS\system32\ESENT.dll
0x7ffd2aad0942394ESENT.dll + 0x30942C:\WINDOWS\system32\ESENT.dll
0x7ffd2aad06be394ESENT.dll + 0x306beC:\WINDOWS\system32\ESENT.dll
0x7ffd2aad11ff394ESENT.dll + 0x311ffC:\WINDOWS\system32\ESENT.dll
0x7ffd2aad0625394ESENT.dll + 0x30625C:\WINDOWS\system32\ESENT.dll
0x7ffd2ab54016394ESENT.dll + 0xb4016C:\WINDOWS\system32\ESENT.dll
0x7ffd3a78033365ntdll.dll + 0x20333C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffd3a776fd665ntdll.dll + 0x16fd6C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffd388954e048KERNEL32.DLL + 0x154e0C:\WINDOWS\System32\KERNEL32.DLL
0x7ffd3a76485b65ntdll.dll + 0x485bC:\WINDOWS\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.