Microsoft-Antimalware-AMFilter

11 events across 1 channel

Event IDTitleChannel
1Application
2Application
3Application
4Application
5Application
6Application
7Application
8Application
9Application
10Application
11Application

Event ID 1 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Event ID 2 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
File_ID

Event ID 3 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
File_ID

Event ID 4 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
File_ID

Event ID 5 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
File_ID

Event ID 6 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Event ID 7 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
Pid
Reason
Trusted
TotalTrusted
TotalUntrusted
Path

Event ID 8 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
Pid
Reason
Flags
ProcessFilterFlags
ProcessName
VmHardenType
ExemptVmHardenedTypes

Event ID 9 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
FileName
Reason
IoStatusBlockForNewFile

Event ID 10 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
File_ID

Event ID 11 —

Provider
Microsoft-Antimalware-AMFilter
Channel
Application

Fields

NameDescription
FileName
Reason
ScanStatus
State
ScanAttributes
FileId
USN