Win32_ProcessStopTrace, ROOT\CIMV2

Class | Methods | Properties (8) | Qualifiers (3) | Instances | Namespaces (2)
Samples: VB Script | C# | VB.Net | Search on:Microsoft

Description

The ProcessStopTrace event class indicates a process has terminated.

Win32_ProcessStopTrace properties

Win32_ProcessStopTrace has 8 properties (1 Local, 7 Derived)

NameOriginCIMType
ExitStatusWin32_ProcessStopTrace19 [uint32]
ParentProcessIDWin32_ProcessTrace19 [uint32]
ProcessIDWin32_ProcessTrace19 [uint32]
ProcessNameWin32_ProcessTrace8 [string]
SECURITY_DESCRIPTOR__Event17 [uint8]
SessionIDWin32_ProcessTrace19 [uint32]
SidWin32_ProcessTrace17 [uint8]
TIME_CREATED__Event21 [uint64]

Detailed description of Win32_ProcessStopTrace properties

Local properties (1) of Win32_ProcessStopTrace class

▲ ExitStatus property
CIMTYPE'uint32'
Description'The ExitStatus property contains the exit status of the stopped process '
readTrue
ExitStatus property is in 1 class (Win32_ProcessStopTrace) of ROOT\cimv2 and in 4 namespaces

Derived properties (7) of Win32_ProcessStopTrace class

▲ ParentProcessID property
CIMTYPE'uint32'
Description'The ParentProcessID property identifies of the process that actuallycaused the event to happen.'
readTrue
ParentProcessID property is in 4 classes of ROOT\cimv2 and in 2 namespaces
▲ ProcessID property
CIMTYPE'uint32'
Description'The ProcessID property identifies the process involved in the event.'
readTrue
ProcessID property is in 15 classes of ROOT\cimv2 and in 18 namespaces
▲ ProcessName property
CIMTYPE'string'
Description'The ProcessName property contains the name of the process.'
readTrue
ProcessName property is in 3 classes of ROOT\cimv2 and in 5 namespaces
▲ SECURITY_DESCRIPTOR property
CIMTYPE'uint8'
SECURITY_DESCRIPTOR property is in 144 classes of ROOT\cimv2 and in 142 namespaces
▲ SessionID property
CIMTYPE'uint32'
Description'The SessionID property identifies the session under which the process exists.'
readTrue
SessionID property is in 7 classes of ROOT\cimv2 and in 16 namespaces
▲ Sid property
CIMTYPE'uint8'
Description'The Sid property is the security identifier representing the user context under which the event happened.'
readTrue
Sid property is in 18 classes of ROOT\cimv2 and in 142 namespaces
▲ TIME_CREATED property
CIMTYPE'uint64'
TIME_CREATED property is in 149 classes of ROOT\cimv2 and in 142 namespaces

Win32_ProcessStopTrace Qualifiers

NameValueToInstanceToSubclassOverridableAmendedLocal
abstractTrue✓✓✗✗✗
Description'The ProcessStopTrace event class indicates a process has terminated.'✗✓✓✓✓
Locale1033✓✗✓✓✓

Win32_ProcessStopTrace System properties

NameValueOriginCIMTypeLocalArray
__PATH'\\.\ROOT\cimv2:Win32_ProcessStopTrace'___SYSTEM8✗✗
__NAMESPACE'ROOT\cimv2'___SYSTEM8✗✗
__SERVER'.'___SYSTEM8✗✗
__DERIVATION['Win32_ProcessTrace', 'Win32_SystemTrace', '__ExtrinsicEvent', '__Event', '__IndicationRelated', '__SystemClass']___SYSTEM8✗✓
__PROPERTY_COUNT8___SYSTEM3✗✗
__RELPATH'Win32_ProcessStopTrace'___SYSTEM8✗✗
__DYNASTY'__SystemClass'___SYSTEM8✗✗
__SUPERCLASS'Win32_ProcessTrace'___SYSTEM8✗✗
__CLASS'Win32_ProcessStopTrace'___SYSTEM8✗✗
__GENUS1___SYSTEM3✗✗

Similar Classes to Win32_ProcessStopTrace

Number of classes:16
comments powered by Disqus
WUtils.com