viewer9 documentation

FileSystemControl PML Operation

FsControl ("Control" in Procmon) is enumerated codes.

Example from 64-bit PML

Hover over field values like Time, ResultCode, FsControl, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

FileSystemControl opcode=3,33

ev=31 advop=IRP_MJ_FILE_SYSTEM_CONTROL

Time:2022-05-17 16:06:20.1753081
Duration:0.0000056
ResultCode:SUCCESS
Tid:2968
Path:C:
FsControl:FSCTL_READ_USN_JOURNAL

evdata[0-71] file offset 6867

000 07 00 00 57 8b fc fa ....W...
800 08 56 00 01 00 00 00 ..V.....
1600 08 00 00 00 00 00 00 ........
2428 00 00 00 00 00 00 00 (.......
32bb 00 09 00 00 00 00 00 ........
40f0 e4 a4 06 00 00 00 00 ........
48f0 ee a4 06 00 00 00 00 ........
5600 00 00 00 00 00 00 00 ........
6402 80 00 00 43 3a 00 00 ....C:..

Call Stack stacksize=14

StackAddressmodModNameModPath
0xfffff880011730f7194fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001173fc7194fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001191942194fltmgr.sys + 0x20942C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002b491fa161ntoskrnl.exe + 0x2fb1faC:\Windows\system32\ntoskrnl.exe
0xfffff80002d068b1161ntoskrnl.exe + 0x4b88b1C:\Windows\system32\ntoskrnl.exe
0xfffff80002b95fea161ntoskrnl.exe + 0x347feaC:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c89b3a2ntdll.dll + 0x69b3aC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7f3ee943KERNELBASE.dll + 0x23ee9C:\Windows\system32\KERNELBASE.dll
0x77a1587f0kernel32.dll + 0x1587fC:\Windows\system32\kernel32.dll
0x7fef4636c7a525MSSRCH.DLL + 0x6c7aC:\Windows\system32\MSSRCH.DLL
0x7fef465c528525MSSRCH.DLL + 0x2c528C:\Windows\system32\MSSRCH.DLL
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.