Microsoft-Windows-Kernel-AppCompat

18 events across 2 channels

Event ID 1: The executable ExecutablePath received an access denied error when trying to modify the registry key RegistryPath.

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
General
Opcode
Info

Description

The executable ExecutablePath received an access denied error when trying to modify the registry key RegistryPath.

Message #

The executable %2 received an access denied error when trying to modify the registry key %4.

Fields #

NameDescription
ExecutablePathLength UInt16
ExecutablePath UnicodeString
RegistryPathLength UInt16
RegistryPath UnicodeString

Event ID 2: CompatCacheInitStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatCacheInit
Opcode
Start

Event ID 3: CompatCacheInitStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatCacheInit
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 4: CompatCacheUpdateStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatCacheUpdate
Opcode
Start

Event ID 5: CompatCacheUpdateStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatCacheUpdate
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 6: CompatCacheQueryStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Level
Informational
Task
CompatCacheQuery
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "6",
    "version": "0",
    "level": "4",
    "task": "2",
    "opcode": "1",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.711292600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10576",
      "thread_id": "12592"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 7: CompatCacheQueryStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
CompatCacheQuery
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "7",
    "version": "0",
    "level": "4",
    "task": "2",
    "opcode": "2",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.711411300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10576",
      "thread_id": "12592"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "StatusCode": "0x0"
  },
  "message": ""
}

Event ID 8: CompatCdbQueryStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Level
Informational
Task
CompatCdbQuery
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "8",
    "version": "0",
    "level": "4",
    "task": "3",
    "opcode": "1",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.584925400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "11396",
      "thread_id": "684"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 9: CompatCdbQueryStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
CompatCdbQuery
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "9",
    "version": "0",
    "level": "4",
    "task": "3",
    "opcode": "2",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.584927900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "11396",
      "thread_id": "684"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "StatusCode": "0x0"
  },
  "message": ""
}

Event ID 10: CompatMapQuirks

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Level
Informational
Task
CompatMapQuirks
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": "0x4000000000000000",
    "time_created": "2026-06-02T05:25:25.034+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 17736,
      "thread_id": 14792
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "CompatMapQuirks"
}

Event ID 11: CompatMapQuirks

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
CompatMapQuirks
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": "0x4000000000000000",
    "time_created": "2026-06-02T05:25:25.034+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 17736,
      "thread_id": 14792
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "StatusCode": "00000000"
  },
  "message": "CompatMapQuirks"
}

Event ID 12: CompatUserModeQueryStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Level
Informational
Task
CompatUserModeQuery
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "12",
    "version": "0",
    "level": "4",
    "task": "6",
    "opcode": "1",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.709619200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "15228",
      "thread_id": "9728"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 13: CompatUserModeQueryStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
CompatUserModeQuery
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "13",
    "version": "0",
    "level": "4",
    "task": "6",
    "opcode": "2",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.710924500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "15228",
      "thread_id": "9728"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "StatusCode": "0x0"
  },
  "message": ""
}

Event ID 14: CompatSdbQueryStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatSdbQuery
Opcode
Start

Event ID 15: CompatSdbQueryStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Task
CompatSdbQuery
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 16: CompatCacheQueryProcessStart

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Level
Informational
Task
CompatCacheQueryProcess
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "16",
    "version": "0",
    "level": "4",
    "task": "8",
    "opcode": "1",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.709698700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "15228",
      "thread_id": "9728"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 17: CompatCacheQueryProcessStop

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
CompatCacheQueryProcess
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-AppCompat",
    "guid": "{16a1adc1-9b7f-4cd9-94b3-d8296ab1b130}",
    "event_source_name": "",
    "event_id": "17",
    "version": "0",
    "level": "4",
    "task": "8",
    "opcode": "2",
    "keywords": 4611686018427387904,
    "time_created": "2026-03-15T04:33:34.710918300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "15228",
      "thread_id": "9728"
    },
    "channel": "Microsoft-Windows-Kernel-AppCompat/Performance",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "StatusCode": "0x0"
  },
  "message": ""
}

Event ID 18: {Remote Registy Service} Access Denied to key: KeyName under parent key: ParentKeyName as the parent is mentioned under AllowedExactPaths and hence subkey cannot b...

#
Provider
Microsoft-Windows-Kernel-AppCompat
Channel
General

Description

{Remote Registy Service} Access Denied to key: KeyName under parent key: ParentKeyName as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.

Message #

{Remote Registy Service} Access Denied to key: %2 under parent key: %4 as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.

Fields #

NameDescription
KeyNameLength UInt16
KeyName UnicodeString
ParentKeyNameLength UInt16
ParentKeyName UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {16A1ADC1-9B7F-4CD9-94B3-D8296AB1B130}

Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.3932, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads