Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Before Posting... Please check out the Community Guidelines in the
Announcements and Administration Category.

Can Read and Write IRPs come before IOCTL_VOLUME_ONLINE to a volume

vidhyavidhya Posts: 102
I need to start tracking the write IRPs happening on the volume. To do that I thought of starting my tracking once I receive IOCTL_VOLUME_ONLINE to that volume.
Can Read and Write IRPs come before IOCTL_VOLUME_ONLINE to a volume.
or should I rely on IRP_MN_MOUNT_VOLUME.
Basically should I start tracking once I receive IRP_MN_MOUNT_VOLUME.
which one is more reliable.

I remember I saw somewhere where people have mentioned that they have seen Read IRPs before IOCTL_VOLUME_ONLINE.

Thanks in Advance

Comments

  • Jamey_KirbyJamey_Kirby Posts: 371
    You do not need to filter ONLINE, and you surely do not need to filter any
    sort of MOUNT IRPS in the file system. You can do everything you need in
    the volume filter. Your tracking should start when you receive the first
    write to the volume.

    On Fri, Aug 3, 2018 at 7:07 AM xxxxx@yahoo.co.in <
    xxxxx@lists.osr.com> wrote:

    > I need to start tracking the write IRPs happening on the volume. To do
    > that I thought of starting my tracking once I receive IOCTL_VOLUME_ONLINE
    > to that volume.
    > Can Read and Write IRPs come before IOCTL_VOLUME_ONLINE to a volume.
    > or should I rely on IRP_MN_MOUNT_VOLUME.
    > Basically should I start tracking once I receive IRP_MN_MOUNT_VOLUME.
    > which one is more reliable.
    >
    > I remember I saw somewhere where people have mentioned that they have seen
    > Read IRPs before IOCTL_VOLUME_ONLINE.
    >
    > Thanks in Advance
    >
    > ---
    > NTDEV is sponsored by OSR
    >
    > Visit the list online at: <
    > http://www.osronline.com/showlists.cfm?list=ntdev>;
    >
    > MONTHLY seminars on crash dump analysis, WDF, Windows internals and
    > software drivers!
    > Details at
    >
    > To unsubscribe, visit the List Server section of OSR Online at <
    > http://www.osronline.com/page.cfm?name=ListServer>;
    >


    --
    Jamey Kirby
    Disrupting the establishment since 1964

    *This is a personal email account and as such, emails are not subject to
    archiving. Nothing else really matters.*
Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!