Microsoft-Windows-ManagementTools-RegistryProvider
43 events across 2 channels
Event ID 1000: Provider load start: arg0.
#Event ID 1001: Provider load stop: arg0.
#Event ID 1002: Provider load error: arg0.
#Event ID 1003: Provider unload start: arg0.
#Event ID 1004: Provider unload stop: arg0.
#Event ID 1005: Provider unload error: arg0.
#Event ID 1100: Start RegistryKey GetInstance: arg0.
#Event ID 1101: Stop RegistryKey GetInstance: arg0.
#Event ID 1102: Error RegistryKey GetInstance: arg0, arg1.
#Event ID 1103: Start RegistryKey CreateInstance: arg0.
#Event ID 1104: Stop RegistryKey CreateInstance: arg0.
#Event ID 1105: Error RegistryKey CreateInstance: arg0, arg1.
#Event ID 1106: Start RegistryKey DeleteInstance: arg0.
#Event ID 1107: Stop RegistryKey DeleteInstance: arg0.
#Event ID 1108: Error RegistryKey DeleteInstance: arg0, arg1.
#Event ID 1109: Start RegistryKey Rename: arg0 to arg1.
#Event ID 1110: Stop RegistryKey Rename: arg0 to arg1.
#Event ID 1111: Error RegistryKey Rename: arg0, arg1.
#Event ID 1200: Start RegistryValue GetInstance: arg0.
#Event ID 1201: Stop RegistryValue GetInstance: arg0.
#Event ID 1202: Error RegistryValue GetInstance: arg0, arg1.
#Event ID 1203: Start RegistryValue CreateInstance: arg0.
#Event ID 1204: Stop RegistryValue CreateInstance: arg0.
#Event ID 1205: Error RegistryValue CreateInstance: arg0, arg1.
#Event ID 1206: Start RegistryValue ModifyInstance: arg0.
#Event ID 1207: Stop RegistryValue ModifyInstance: arg0.
#Event ID 1208: Error RegistryValue ModifyInstance: arg0, arg1.
#Event ID 1209: Start RegistryValue DeleteInstance: arg0.
#Event ID 1210: Stop RegistryValue DeleteInstance: arg0.
#Event ID 1211: Error RegistryValue DeleteInstance: arg0, arg1.
#Event ID 1212: Start RegistryValue Rename: arg0 to arg1.
#Event ID 1213: Stop RegistryValue Rename: arg0 to arg1.
#Event ID 1214: Error RegistryValue Rename: arg0, arg1.
#Event ID 1300: Start RegistryKey GetSubKeys: arg0.
#Event ID 1301: Stop RegistryKey GetSubKeys: arg0.
#Event ID 1302: Error RegistryKey GetSubKeys: arg0, arg1.
#Event ID 1303: Start RegistryKey GetValues: arg0.
#Event ID 1304: Stop RegistryKey GetValues: arg0.
#Event ID 1305: Error RegistryKey GetValues: arg0, arg1.
#Event ID 1306: Start RegistryTasks Search: arg0, Value: arg1, Options: arg2.
#Event ID 1307: Stop RegistryTasks Search: arg0, Value: arg1, Options: arg2.
#Event ID 1308: Error RegistryTasks Search: arg0, arg1.
#Event ID 1400: Error: arg0, arg1.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 8656ea1b-e71c-4ec8-ab69-4ebff5bac0f3
Defined in regprov.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02