Microsoft-Windows-WMI
62 events across 1 channel
Event ID 4: Error Error encountered when trying to load MOF MOF while recovering .
#Event ID 10: Event filter with query "Query" could not be reactivated in namespace "Namespace" because of error Error.
#Event ID 21: Event provider EventProvider attempted to register a syntactically invalid query "Query".
#Description
Event provider EventProvider attempted to register a syntactically invalid query "Query". The query will be ignored. The query can be corrected by examining the WMI repository with CIM studio and updating the permanent subscriptions for the listed provider and query. If the permanent subscription is created with MOF file coming with an installed product, the application vendor must be contacted to correct the faulty registration.
Message #
Fields #
| Name | Description |
|---|---|
EventProvider UnicodeString | |
Query UnicodeString |
Event ID 22: Event provider EventProvider attempted to register an intrinsic event query "Query" in Namespace namespace for which the set of target object classes could not be deter...
#Description
Event provider EventProvider attempted to register an intrinsic event query "Query" in Namespace namespace for which the set of target object classes could not be determined. The query will be ignored.
Message #
Fields #
| Name | Description |
|---|---|
EventProvider UnicodeString | |
Query UnicodeString | |
Namespace UnicodeString |
Event ID 23: Event provider EventProvider attempted to register query "Query" in Namespace namespace which is too broad.
#Description
Event provider EventProvider attempted to register query "Query" in Namespace namespace which is too broad. Event providers cannot provide events that are provided by the system. The query will be ignored. Contact the application vendor.
Message #
Fields #
| Name | Description |
|---|---|
EventProvider UnicodeString | |
Query UnicodeString | |
Namespace UnicodeString |
Event ID 24: Event provider EventProvider attempted to register query "Query" whose target class "Class" in Namespace namespace does not exist.
#Description
Event provider EventProvider attempted to register query "Query" whose target class "Class" in Namespace namespace does not exist. The query will be ignored.
Message #
Fields #
| Name | Description |
|---|---|
data_0x8000003F.EventProvider UnicodeString | |
data_0x8000003F.Query UnicodeString | |
data_0x8000003F.Class UnicodeString | |
data_0x8000003F.Namespace UnicodeString | |
EventProvider UnicodeString | |
Query UnicodeString | |
Class UnicodeString | |
Namespace UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}",
"event_source_name": "",
"event_id": 24,
"version": 2,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-30T03:56:45.0895954+00:00",
"event_record_id": 212189,
"correlation": {
"ActivityID": "{445A94B1-A16A-4D98-8A65-A94B216C456C}"
},
"execution": {
"process_id": 1900,
"thread_id": 5224
},
"channel": "Application",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"data_0x8000003F": {
"EventProvider": "nfscimprov",
"Query": "select * from MSFT_NfsShareEvent",
"Class": "MSFT_NfsShareEvent",
"Namespace": "//./ROOT/Microsoft/Windows/NFS"
}
},
"message": "Event provider nfscimprov attempted to register query \"select * from MSFT_NfsShareEvent\" whose target class \"MSFT_NfsShareEvent\" in //./ROOT/Microsoft/Windows/NFS namespace does not exist. The query will be ignored."
}
Event ID 25: Event provider EventProvider attempted to register query "Query" whose target class "Class" is not an event class.
#Description
Event provider EventProvider attempted to register query "Query" whose target class "Class" is not an event class. The query will be ignored. Contact the application vendor.
Message #
Fields #
| Name | Description |
|---|---|
data_0x8000003F.EventProvider UnicodeString | |
data_0x8000003F.Query UnicodeString | |
data_0x8000003F.Class UnicodeString | |
EventProvider UnicodeString | |
Query UnicodeString | |
Class UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}",
"event_source_name": "",
"event_id": 25,
"version": 2,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:12:03.5515385+00:00",
"event_record_id": 995,
"correlation": {
"ActivityID": "{55D4FF8A-EF8A-0000-BAA6-D5558AEFDC01}"
},
"execution": {
"process_id": 3640,
"thread_id": 4040
},
"channel": "Application",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"data_0x8000003F": {
"EventProvider": "MSCLUSTEREXT",
"Query": "select * from MSCluster_ClusterUpgradedEvent",
"Class": "MSCluster_ClusterUpgradedEvent"
}
},
"message": "Event provider MSCLUSTEREXT attempted to register query \"select * from MSCluster_ClusterUpgradedEvent\" whose target class \"MSCluster_ClusterUpgradedEvent\" is not an event class. The query will be ignored. Contact the application vendor."
}
Event ID 28: Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number ErrorNumber.
#Description
Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number ErrorNumber. This could be due to a badly installed version of WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
Message #
Fields #
| Name | Description |
|---|---|
ErrorNumber UnicodeString |
Event ID 29: Error number ErrorNumber was returned in trying to initialize Windows Management Instrumentation Service.
#Description
Error number ErrorNumber was returned in trying to initialize Windows Management Instrumentation Service. This could be due to a badly installed version of WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
Message #
Fields #
| Name | Description |
|---|---|
ErrorNumber UnicodeString |
Event ID 43: Windows Management Instrumentation ADAP failed to connect to namespace Namespace with the following error Error.
#Event ID 48: Windows Management Instrumentation ADAP was unable to save object Object in namespace Namespace because of the following error Error.
#Event ID 58: Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in Class:Result=Result.
#Event ID 59: Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class Class.
#Event ID 63: A provider, NlbsNicProv, has been registered in the Windows Management Instrumentation namespace Root\microsoftnlb to use the LocalSystem account.
#Description
A provider, data_0x8000003F.Provider, has been registered in the Windows Management Instrumentation namespace data_0x8000003F.Namespace to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Message #
Fields #
| Name | Description |
|---|---|
data_0x8000003F.Provider | |
data_0x8000003F.Namespace |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}",
"event_source_name": "",
"event_id": 63,
"version": 2,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:17:47.2480210+00:00",
"event_record_id": 1007,
"correlation": {},
"execution": {
"process_id": 3640,
"thread_id": 1516
},
"channel": "Application",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"data_0x8000003F": {
"Provider": "WebAdministrationProvider",
"Namespace": "Root\\WebAdministration"
}
},
"message": "A provider, WebAdministrationProvider, has been registered in the Windows Management Instrumentation namespace Root\\WebAdministration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests."
}
Event ID 65: Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
#Description
Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository.
Message #
Event ID 66: The Windows Management Instrumentation Service has recovered from the following backup repository: BackupRepository.
#Event ID 67: The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following f...
#Event ID 68: The Windows Management Instrumentation repository backup operation completed copying data to BackupFile with error Error.
#Event ID 5600: The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system3...
#Description
The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system32\wbem\repository. The WMI service was not able to recover the repository. The WMI repository will now be deleted and a new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 5601: The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.
#Description
The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository. This can be caused by a corruption in the repository files, security settings on this directory, lack of disk space, or other system resource issues like lack of memory. If this error happens every time the machine is rebooted then the administrator on this machine may need to stop WMI Service, review the security setting on this folder and files under this folder, and run WMIDiag to validate the health of Windows Management Instrumentation
Message #
Event ID 5602: The Windows Management Instrumentation service detected an inconsistency in the following backup file: BackupFile.
#Event ID 5604: The Windows Management Instrumentation service encountered the error Error and was not able to restore from the following backup repository: BackupRepository.
#Event ID 5605: The Namespace namespace is marked with the RequiresEncryption flag.
#Description
The Namespace namespace is marked with the RequiresEncryption flag. Access to this namespace might be denied if the script or application does not have the appropriate authentication level. Change the authentication level to Pkt_Privacy and run the script or application again.
Message #
Fields #
| Name | Description |
|---|---|
Namespace UnicodeString |
Event ID 5606: Windows Management Instrumentation Service could not deliver results asynchronously for Namespace namespace.
#Description
Windows Management Instrumentation Service could not deliver results asynchronously for Namespace namespace. The namespace is marked with RequiresEncryption but WinMgmt could not establish a secure connection back to the client computer. Ensure there is a trust relationship between the client and server computers so that the client recognizes the server computer account.
Message #
Fields #
| Name | Description |
|---|---|
Namespace UnicodeString |
Event ID 5611: The Windows Management Instrumentation service has detected an inconsistent system shutdown.
#Description
The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "1EDEEE53-0AFE-4609-B846-D8C0B2075B1F",
"event_source_name": "",
"event_id": 5611,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-14T00:02:46.971764+00:00",
"event_record_id": 4411,
"correlation": {},
"execution": {
"process_id": 4020,
"thread_id": 4688
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 5612: Windows Management Instrumentation has stopped WMIPRVSE.
#Description
Windows Management Instrumentation has stopped WMIPRVSE.EXE because a quota reached a warning value. Quota: QuotaName Value: QuotaValue Maximum value: QuotaThreshold WMIPRVSE PID: HostProcessID Providers hosted in this process: ProvidersInHost.
Message #
Fields #
| Name | Description |
|---|---|
QuotaName UnicodeString | |
QuotaValue UnicodeString | |
QuotaThreshold UnicodeString | |
HostProcessID UnicodeString | |
ProvidersInHost UnicodeString |
Event ID 5614: During the service startup, the Windows Management Instrumentation service was unable to locate the repository files.
#Description
During the service startup, the Windows Management Instrumentation service was unable to locate the repository files. A new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 5615: Windows Management Instrumentation Service started sucessfully
#Description
Windows Management Instrumentation Service started sucessfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}",
"event_source_name": "",
"event_id": 5615,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:33:03.9661171+00:00",
"event_record_id": 712,
"correlation": {},
"execution": {
"process_id": 3616,
"thread_id": 3756
},
"channel": "Application",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Windows Management Instrumentation Service started sucessfully"
}
Event ID 5616: The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
#Description
The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Message #
Event ID 5617: Windows Management Instrumentation Service subsystems initialized successfully
#Description
Windows Management Instrumentation Service subsystems initialized successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}",
"event_source_name": "",
"event_id": 5617,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:33:27.7373929+00:00",
"event_record_id": 720,
"correlation": {},
"execution": {
"process_id": 3616,
"thread_id": 4012
},
"channel": "Application",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Windows Management Instrumentation Service subsystems initialized successfully"
}
Event ID 5631: WMI interop namespace class "Class" has been overwritten.
#Description
WMI interop namespace class "Class" has been overwritten. Some of the Interop scenarios might not work properly. Please issue following commands from elevated command prompt to restore the behavior."mofcomp %windir%\system32\wbem\interop.mof" and similarly mofcomp all the interop.mfl under %windir%\system32\wbem and its subdirectories.
Message #
Fields #
| Name | Description |
|---|---|
Class UnicodeString |
Event ID 1073747424: The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system3...
#Description
The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system32\wbem\repository. The WMI service was not able to recover the repository. The WMI repository will now be deleted and a new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 2147483711: A provider, %1, has been registered in the Windows Management Instrumentation namespace %2 to use the LocalSystem account.
#Description
A provider, %1, has been registered in the Windows Management Instrumentation namespace %2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"event_id": 63,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:32:18.1444246+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Application"
},
"event_data": {
"Namespace": "root\\Microsoft\\Windows\\Hgs",
"Provider": "HgsClientWmi"
}
}
Event ID 3221225476: Error %1 encountered when trying to load MOF %2 while recovering .
#Description
Error encountered when trying to load MOF while recovering .MOF file marked with autorecover.
Message #
Event ID 3221225482: Event filter with query "%2" could not be reactivated in namespace "%1" because of error %3.
#Description
Event filter with query "%2" could not be reactivated in namespace "%1" because of error %3. Events cannot be delivered through this filter until the problem is corrected.
Message #
Event ID 3221225493: Event provider %1 attempted to register a syntactically invalid query "%2".
#Description
Event provider %1 attempted to register a syntactically invalid query "%2". The query will be ignored. The query can be corrected by examining the WMI repository with CIM studio and updating the permanent subscriptions for the listed provider and query. If the permanent subscription is created with MOF file coming with an installed product, the application vendor must be contacted to correct the faulty registration.
Message #
Event ID 3221225494: Event provider %1 attempted to register an intrinsic event query "%2" in %3 namespace for which the set of target object classes could not be deter...
#Description
Event provider %1 attempted to register an intrinsic event query "%2" in %3 namespace for which the set of target object classes could not be determined. The query will be ignored.
Message #
Event ID 3221225495: Event provider %1 attempted to register query "%2" in %3 namespace which is too broad.
#Description
Event provider %1 attempted to register query "%2" in %3 namespace which is too broad. Event providers cannot provide events that are provided by the system. The query will be ignored. Contact the application vendor.
Message #
Event ID 3221225496: Event provider %1 attempted to register query "%2" whose target class "%3" in %4 namespace does not exist.
#Description
Event provider %1 attempted to register query "%2" whose target class "%3" in %4 namespace does not exist. The query will be ignored.
Message #
Event ID 3221225497: Event provider %1 attempted to register query "%2" whose target class "%3" is not an event class.
#Description
Event provider %1 attempted to register query "%2" whose target class "%3" is not an event class. The query will be ignored. Contact the application vendor.
Message #
Event ID 3221225500: Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number %1.
#Description
Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number %1. This could be due to a badly installed version of WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
Message #
Event ID 3221225501: Error number %1 was returned in trying to initialize Windows Management Instrumentation Service.
#Description
Error number %1 was returned in trying to initialize Windows Management Instrumentation Service. This could be due to a badly installed version of WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
Message #
Event ID 3221225515: Windows Management Instrumentation ADAP failed to connect to namespace %1 with the following error %2.
#Description
Windows Management Instrumentation ADAP failed to connect to namespace with the following error.
Message #
Event ID 3221225520: Windows Management Instrumentation ADAP was unable to save object %1 in namespace %2 because of the following error %3.
#Description
Windows Management Instrumentation ADAP was unable to save object in namespace because of the following error.
Message #
Event ID 3221225530: Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in %1:Result=%2.
#Description
Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in :Result=.
Message #
Event ID 3221225531: Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class %1.
#Description
Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class.
Message #
Event ID 3221225537: Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
#Description
Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository.
Message #
Event ID 3221225538: The Windows Management Instrumentation Service has recovered from the following backup repository.
#Description
The Windows Management Instrumentation Service has recovered from the following backup repository: .
Message #
Event ID 3221225539: The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following f...
#Description
The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following file.
Message #
Event ID 3221225540: The Windows Management Instrumentation repository backup operation completed copying data to %1 with error %2.
#Description
The Windows Management Instrumentation repository backup operation completed copying data to with error .
Message #
Event ID 3221231073: The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.
#Description
The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository. This can be caused by a corruption in the repository files, security settings on this directory, lack of disk space, or other system resource issues like lack of memory. If this error happens every time the machine is rebooted then the administrator on this machine may need to stop WMI Service, review the security setting on this folder and files under this folder, and run WMIDiag to validate the health of Windows Management Instrumentation
Message #
Event ID 3221231074: The Windows Management Instrumentation service detected an inconsistency in the following backup file.
#Description
The Windows Management Instrumentation service detected an inconsistency in the following backup file: .
Message #
Event ID 3221231076: The Windows Management Instrumentation service encountered the error %2 and was not able to restore from the following backup repository: %1.
#Description
The Windows Management Instrumentation service encountered the error and was not able to restore from the following backup repository: .
Message #
Event ID 3221231077: The %1 namespace is marked with the RequiresEncryption flag.
#Description
The %1 namespace is marked with the RequiresEncryption flag. Access to this namespace might be denied if the script or application does not have the appropriate authentication level. Change the authentication level to Pkt_Privacy and run the script or application again.
Message #
Event ID 3221231078: Windows Management Instrumentation Service could not deliver results asynchronously for %1 namespace.
#Description
Windows Management Instrumentation Service could not deliver results asynchronously for %1 namespace. The namespace is marked with RequiresEncryption but WinMgmt could not establish a secure connection back to the client computer. Ensure there is a trust relationship between the client and server computers so that the client recognizes the server computer account.
Message #
Event ID 3221231083: The Windows Management Instrumentation service has detected an inconsistent system shutdown.
#Description
The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"event_id": 5611,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-14T00:02:46.9717649+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {}
}
Event ID 3221231084: Windows Management Instrumentation has stopped WMIPRVSE.
#Description
Windows Management Instrumentation has stopped WMIPRVSE.EXE because a quota reached a warning value. Quota: Value: Maximum value: WMIPRVSE PID: Providers hosted in this process.
Message #
Event ID 3221231086: During the service startup, the Windows Management Instrumentation service was unable to locate the repository files.
#Description
During the service startup, the Windows Management Instrumentation service was unable to locate the repository files. A new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 3221231087: Windows Management Instrumentation Service started sucessfully
#Description
Windows Management Instrumentation Service started sucessfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"event_id": 5615,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:31:57.3557576+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Application"
},
"event_data": {}
}
Event ID 3221231088: The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
#Description
The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Message #
Event ID 3221231089: Windows Management Instrumentation Service subsystems initialized successfully
#Description
Windows Management Instrumentation Service subsystems initialized successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"event_id": 5617,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:32:00.1013111+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Application"
},
"event_data": {}
}
Event ID 3221231103: WMI interop namespace class "%1" has been overwritten.
#Description
WMI interop namespace class "%1" has been overwritten. Some of the Interop scenarios might not work properly. Please issue following commands from elevated command prompt to restore the behavior."mofcomp %windir%\system32\wbem\interop.mof" and similarly mofcomp all the interop.mfl under %windir%\system32\wbem and its subdirectories.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1edeee53-0afe-4609-b846-d8c0b2075b1f
Defined in WinMgmtR.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02