Win32_ProcessStartTrace, ROOT\CIMV2

Class | Methods | Properties (7) | Qualifiers (3) | Instances | Namespaces (2)
Samples: VB Script | C# | VB.Net | Search on:Microsoft

Description

The ProcessStartTrace event class indicates a new process has started.

Win32_ProcessStartTrace properties

Win32_ProcessStartTrace has 7 properties (7 Derived)

NameOriginCIMType
ParentProcessIDWin32_ProcessTrace19 [uint32]
ProcessIDWin32_ProcessTrace19 [uint32]
ProcessNameWin32_ProcessTrace8 [string]
SECURITY_DESCRIPTOR__Event17 [uint8]
SessionIDWin32_ProcessTrace19 [uint32]
SidWin32_ProcessTrace17 [uint8]
TIME_CREATED__Event21 [uint64]

Detailed description of Win32_ProcessStartTrace properties

Derived properties (7) of Win32_ProcessStartTrace class

▲ ParentProcessID property
CIMTYPE'uint32'
Description'The ParentProcessID property identifies of the process that actuallycaused the event to happen.'
readTrue
ParentProcessID property is in 4 classes of ROOT\cimv2 and in 2 namespaces
▲ ProcessID property
CIMTYPE'uint32'
Description'The ProcessID property identifies the process involved in the event.'
readTrue
ProcessID property is in 15 classes of ROOT\cimv2 and in 18 namespaces
▲ ProcessName property
CIMTYPE'string'
Description'The ProcessName property contains the name of the process.'
readTrue
ProcessName property is in 3 classes of ROOT\cimv2 and in 5 namespaces
▲ SECURITY_DESCRIPTOR property
CIMTYPE'uint8'
SECURITY_DESCRIPTOR property is in 144 classes of ROOT\cimv2 and in 142 namespaces
▲ SessionID property
CIMTYPE'uint32'
Description'The SessionID property identifies the session under which the process exists.'
readTrue
SessionID property is in 7 classes of ROOT\cimv2 and in 16 namespaces
▲ Sid property
CIMTYPE'uint8'
Description'The Sid property is the security identifier representing the user context under which the event happened.'
readTrue
Sid property is in 18 classes of ROOT\cimv2 and in 142 namespaces
▲ TIME_CREATED property
CIMTYPE'uint64'
TIME_CREATED property is in 149 classes of ROOT\cimv2 and in 142 namespaces

Win32_ProcessStartTrace Qualifiers

NameValueToInstanceToSubclassOverridableAmendedLocal
abstractTrue✓✓✗✗✗
Description'The ProcessStartTrace event class indicates a new process has started.'✗✓✓✓✓
Locale1033✓✗✓✓✓

Win32_ProcessStartTrace System properties

NameValueOriginCIMTypeLocalArray
__PATH'\\.\ROOT\cimv2:Win32_ProcessStartTrace'___SYSTEM8✗✗
__NAMESPACE'ROOT\cimv2'___SYSTEM8✗✗
__SERVER'.'___SYSTEM8✗✗
__DERIVATION['Win32_ProcessTrace', 'Win32_SystemTrace', '__ExtrinsicEvent', '__Event', '__IndicationRelated', '__SystemClass']___SYSTEM8✗✓
__PROPERTY_COUNT7___SYSTEM3✗✗
__RELPATH'Win32_ProcessStartTrace'___SYSTEM8✗✗
__DYNASTY'__SystemClass'___SYSTEM8✗✗
__SUPERCLASS'Win32_ProcessTrace'___SYSTEM8✗✗
__CLASS'Win32_ProcessStartTrace'___SYSTEM8✗✗
__GENUS1___SYSTEM3✗✗

Similar Classes to Win32_ProcessStartTrace

Number of classes:16
comments powered by Disqus
WUtils.com