Microsoft-Windows-Kernel-AppCompat
18 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | The executable ExecutablePath received an access denied error when trying to … | General | N |
| 2 | CompatCacheInitStart | Performance | N |
| 3 | CompatCacheInitStop | Performance | N |
| 4 | CompatCacheUpdateStart | Performance | N |
| 5 | CompatCacheUpdateStop | Performance | N |
| 6 | CompatCacheQueryStart | Performance | Y |
| 7 | CompatCacheQueryStop | Performance | Y |
| 8 | CompatCdbQueryStart | Performance | Y |
| 9 | CompatCdbQueryStop | Performance | Y |
| 10 | CompatMapQuirks | Performance | Y |
| 11 | CompatMapQuirks | Performance | Y |
| 12 | CompatUserModeQueryStart | Performance | Y |
| 13 | CompatUserModeQueryStop | Performance | Y |
| 14 | CompatSdbQueryStart | Performance | N |
| 15 | CompatSdbQueryStop | Performance | N |
| 16 | CompatCacheQueryProcessStart | Performance | Y |
| 17 | CompatCacheQueryProcessStop | Performance | Y |
| 18 | {Remote Registy Service} Access Denied to key: KeyName under parent key: … | General | N |
Event ID 1: The executable ExecutablePath received an access denied error when trying to modify the registry key RegistryPath.
#Event ID 2: CompatCacheInitStart
#Event ID 3: CompatCacheInitStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Event ID 4: CompatCacheUpdateStart
#Event ID 5: CompatCacheUpdateStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Event ID 6: CompatCacheQueryStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "6",
"version": "0",
"level": "4",
"task": "2",
"opcode": "1",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.711292600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "10576",
"thread_id": "12592"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 7: CompatCacheQueryStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "7",
"version": "0",
"level": "4",
"task": "2",
"opcode": "2",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.711411300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "10576",
"thread_id": "12592"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"StatusCode": "0x0"
},
"message": ""
}
Event ID 8: CompatCdbQueryStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "8",
"version": "0",
"level": "4",
"task": "3",
"opcode": "1",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.584925400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "11396",
"thread_id": "684"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 9: CompatCdbQueryStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "9",
"version": "0",
"level": "4",
"task": "3",
"opcode": "2",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.584927900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "11396",
"thread_id": "684"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"StatusCode": "0x0"
},
"message": ""
}
Event ID 10: CompatMapQuirks
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}",
"event_source_name": "",
"event_id": 10,
"version": 0,
"level": 4,
"task": 4,
"opcode": 1,
"keywords": "0x4000000000000000",
"time_created": "2026-06-02T05:25:25.034+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17736,
"thread_id": 14792
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "CompatMapQuirks"
}
Event ID 11: CompatMapQuirks
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}",
"event_source_name": "",
"event_id": 11,
"version": 0,
"level": 4,
"task": 4,
"opcode": 2,
"keywords": "0x4000000000000000",
"time_created": "2026-06-02T05:25:25.034+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 17736,
"thread_id": 14792
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"StatusCode": "00000000"
},
"message": "CompatMapQuirks"
}
Event ID 12: CompatUserModeQueryStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "12",
"version": "0",
"level": "4",
"task": "6",
"opcode": "1",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.709619200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "15228",
"thread_id": "9728"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 13: CompatUserModeQueryStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "13",
"version": "0",
"level": "4",
"task": "6",
"opcode": "2",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.710924500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "15228",
"thread_id": "9728"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"StatusCode": "0x0"
},
"message": ""
}
Event ID 14: CompatSdbQueryStart
#Event ID 15: CompatSdbQueryStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Event ID 16: CompatCacheQueryProcessStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "16",
"version": "0",
"level": "4",
"task": "8",
"opcode": "1",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.709698700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "15228",
"thread_id": "9728"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 17: CompatCacheQueryProcessStop
#Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-AppCompat",
"guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
"event_source_name": "",
"event_id": "17",
"version": "0",
"level": "4",
"task": "8",
"opcode": "2",
"keywords": 4611686018427387904,
"time_created": "2026-03-15T04:33:34.710918300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "15228",
"thread_id": "9728"
},
"channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"StatusCode": "0x0"
},
"message": ""
}
Event ID 18: {Remote Registy Service} Access Denied to key: KeyName under parent key: ParentKeyName as the parent is mentioned under AllowedExactPaths and hence subkey cannot b...
#Description
{Remote Registy Service} Access Denied to key: KeyName under parent key: ParentKeyName as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.
Message #
Fields #
| Name | Description |
|---|---|
KeyNameLength UInt16 | |
KeyName UnicodeString | |
ParentKeyNameLength UInt16 | |
ParentKeyName UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}
Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.3932, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02