Skip to content

Glossary

WMI namespace (root\subscription)

A folder-like container of WMI classes and instances, such as root\cimv2. Permanent event subscriptions normally live in root\subscription.

A WMI namespace groups classes and instances, like a folder: root\cimv2 holds the Win32 classes, root\subscription the standard event consumers and, normally, the permanent subscriptions. __SystemClass holds system classes such as __EventFilter.

A subscription can be registered in another namespace and still work, which is why investigators check more than root\subscription. In the repository, namespace names appear only as hashes in INDEX.BTR; records carved from OBJECTS.DATA do not say which namespace they came from.