Skip to content

A–Z

Glossary

Plain-language definitions of the WMI and CIM repository terms used across the blog.

CCM_RecentlyUsedApps (SCCM software metering)
ConfigMgr client WMI class recording, per user and executable, the path, last launch time, launch count and file version information.
ActiveScriptEventConsumer
The standard WMI consumer that runs VBScript or JScript, inline (ScriptText) or from a file (ScriptFilename), in scrcons.exe as SYSTEM.
CIM repository (WMI repository)
The on-disk database where WMI stores class definitions and instances: OBJECTS.DATA, INDEX.BTR and MAPPING1-3.MAP in System32\wbem\Repository.
CommandLineEventConsumer
The standard WMI consumer that starts a process: CommandLineTemplate, ExecutablePath and WorkingDirectory, launched as SYSTEM when its filter fires.
Event consumer (__EventConsumer)
The WMI object that says what to do when a filter fires: run a command line or a script, write a log line, an event log entry or an e-mail.
__EventFilter
The WMI class that describes the trigger of an event subscription: a named WQL query, its language and the namespace it watches.
__FilterToConsumerBinding
The WMI object that links an event filter to an event consumer. Without it, neither fires; with it, the consumer runs every time the filter matches.
INDEX.BTR
The WMI repository's B-tree index: text keys made of hashed namespace, class and instance names that point to records in OBJECTS.DATA.
MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP
The WMI repository's page maps: they translate logical page numbers of OBJECTS.DATA and INDEX.BTR into physical pages. Three generations are kept.
OBJECTS.DATA
The WMI repository file that holds every class definition and instance in 8 KiB pages, including event filters, consumers and bindings.
scrcons.exe (WMI Standard Event Consumer)
The Windows process that runs ActiveScriptEventConsumer scripts. Seeing it run, or its children, points to a WMI script subscription.
WMI namespace (root\subscription)
A folder-like container of WMI classes and instances, such as root\cimv2. Permanent event subscriptions normally live in root\subscription.
WMI (Windows Management Instrumentation)
Windows' management layer: it exposes system information as classes and instances, answers WQL queries and can run actions when events happen.
WQL (WMI Query Language)
The SQL-like language WMI uses for data and event queries; event filters use it to describe the event that triggers a subscription.