Microsoft-Windows-BestPractices
8 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 0 | Model scanning | Operational | N |
| 1 | Finished model scan | Operational | N |
| 2 | Started scan of model 'String' submodel 'String2'. | Operational | N |
| 3 | Finished starting scan of model 'String' submodel 'String2'. | Operational | N |
| 4 | String. | Operational | N |
| 5 | The model is a Windows 7 model | Operational | N |
| 6 | The model will be scanned remotely | Operational | N |
| 7 | The model requires starting the scan on this local computer. | Operational | N |
Event ID 2: Started scan of model 'String' submodel 'String2'.
#Event ID 3: Finished starting scan of model 'String' submodel 'String2'.
#Event ID 6: The model will be scanned remotely
#Description
The model will be scanned remotely.
Message #
Event ID 7: The model requires starting the scan on this local computer.
#Description
The model requires starting the scan on this local computer.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 5218e51a-3996-4a9a-a75a-70ba4eb66312
Defined in BPAInst.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02