Microsoft-Antimalware-Engine
109 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 1 | Start of engine scan request | Application |
| 2 | End of engine scan request | Application |
| 3 | Application | |
| 4 | Application | |
| 5 | Start of stream scan request | Application |
| 6 | End of stream scan request | Application |
| 7 | Skipped file | Application |
| 8 | Application | |
| 9 | Application | |
| 10 | Application | |
| 11 | Application | |
| 12 | Application | |
| 13 | Application | |
| 14 | Application | |
| 15 | Application | |
| 16 | Application | |
| 17 | Application | |
| 18 | Application | |
| 19 | Application | |
| 20 | Application | |
| 21 | Application | |
| 22 | Application | |
| 23 | Application | |
| 24 | Application | |
| 25 | Application | |
| 26 | Application | |
| 27 | Application | |
| 28 | Application | |
| 29 | Application | |
| 30 | Application | |
| 31 | Application | |
| 32 | Application | |
| 33 | Application | |
| 35 | Application | |
| 36 | Application | |
| 37 | Application | |
| 38 | Application | |
| 39 | Application | |
| 40 | Application | |
| 41 | Application | |
| 42 | Application | |
| 43 | Application | |
| 44 | Application | |
| 45 | Application | |
| 46 | Application | |
| 47 | Application | |
| 48 | Application | |
| 49 | Application | |
| 50 | Application | |
| 51 | Application | |
| 52 | Application | |
| 53 | Application | |
| 58 | Application | |
| 59 | Application | |
| 60 | Application | |
| 61 | Application | |
| 62 | Application | |
| 63 | Application | |
| 64 | Application | |
| 65 | Application | |
| 66 | Application | |
| 67 | Application | |
| 68 | Application | |
| 69 | Application | |
| 70 | Application | |
| 71 | Application | |
| 72 | Application | |
| 73 | Application | |
| 74 | Application | |
| 75 | Application | |
| 76 | Application | |
| 77 | Application | |
| 78 | Application | |
| 79 | Application | |
| 80 | Application | |
| 81 | Application | |
| 82 | Application | |
| 83 | Application | |
| 84 | Application | |
| 85 | Application | |
| 86 | Application | |
| 87 | Application | |
| 88 | Application | |
| 89 | Application | |
| 90 | Application | |
| 91 | Application | |
| 92 | Application | |
| 93 | Application | |
| 94 | Application | |
| 95 | Application | |
| 96 | Application | |
| 97 | Application | |
| 98 | Application | |
| 99 | Application | |
| 100 | Application | |
| 101 | Application | |
| 102 | Application | |
| 103 | Application | |
| 104 | Application | |
| 105 | Application | |
| 106 | Application | |
| 107 | Application | |
| 108 | Application | |
| 109 | Application | |
| 110 | Application | |
| 111 | Application | |
| 112 | Application | |
| 113 | Application | |
| 114 | Application |
Event ID 1 — Start of engine scan request
Event ID 2 — End of engine scan request
Event ID 3 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 5 — Start of stream scan request
Event ID 6 — End of stream scan request
Event ID 7 — Skipped file
Event ID 8 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
GUID GUID | — |
Type UInt32 | — |
Name UnicodeString | — |
SignatureId HexInt64 | — |
ImagePath UnicodeString | — |
Event ID 9 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
PPID UInt32 | — |
ImagePath UnicodeString | — |
Flags HexInt32 | — |
Event ID 10 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
ImagePath UnicodeString | — |
Event ID 11 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
ImagePath UnicodeString | — |
Event ID 12 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
ImageName UnicodeString | — |
FileName UnicodeString | — |
Event ID 13 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 14 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 15 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 16 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
OldFileName UnicodeString | — |
Event ID 17 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 18 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 19 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 20 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
ValueName UnicodeString | — |
Event ID 21 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
ValueName UnicodeString | — |
Event ID 22 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Event ID 23 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Event ID 24 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Event ID 25 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Event ID 26 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Event ID 27 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
DetectionId HexInt64 | — |
Event ID 28 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
RecordType UInt32 | — |
ImagePath UnicodeString | — |
Path UnicodeString | — |
Event ID 29 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
TPID UInt32 | — |
TTID UInt32 | — |
ImageName UnicodeString | — |
Event ID 30 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
ThreadTime FILETIME | — |
Event ID 31 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
ThreadTime FILETIME | — |
StartQPC UInt64 | — |
Event ID 32 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
PID UInt32 | — |
ThreadTime FILETIME | — |
Event ID 33 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
PID UInt32 | — |
ThreadTime FILETIME | — |
StartQPC UInt64 | — |
Event ID 35 —
Fields #
| Name | Description |
|---|---|
ScanSource UInt32 | — |
EventType UInt32 | — |
Classification UInt32 | — |
Info UnicodeString | — |
FileName UnicodeString | — |
FileID UInt32 | — |
FileUSN UInt32 | — |
Result HexInt32 | — |
Event ID 36 —
Fields #
| Name | Description |
|---|---|
ScanSource UInt32 | — |
EventType UInt32 | — |
Classification UInt32 | — |
Info UnicodeString | — |
FileName UnicodeString | — |
FileID UInt32 | — |
FileUSN UInt32 | — |
Result HexInt32 | — |
Event ID 37 —
Fields #
| Name | Description |
|---|---|
ScanSource UInt32 | — |
EventType UInt32 | — |
Classification UInt32 | — |
Info UnicodeString | — |
FileName UnicodeString | — |
FileID UInt32 | — |
FileUSN UInt32 | — |
Result HexInt32 | — |
Event ID 38 —
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | — |
CacheName UnicodeString | — |
Result UnicodeString | — |
Event ID 39 —
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | — |
CacheName UnicodeString | — |
Result UnicodeString | — |
Event ID 40 —
Fields #
| Name | Description |
|---|---|
action UnicodeString | — |
key UInt64 | — |
filename UnicodeString | — |
result UInt32 | — |
Event ID 41 —
Fields #
| Name | Description |
|---|---|
utilization UInt32 | — |
result UInt32 | — |
Event ID 42 —
Fields #
| Name | Description |
|---|---|
key UInt64 | — |
filename UnicodeString | — |
parentKey UInt64 | — |
result UInt32 | — |
Event ID 43 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Name UnicodeString | — |
Data UInt64 | — |
StartStop Boolean | — |
ThreadTime FILETIME | — |
Event ID 44 —
Fields #
| Name | Description |
|---|---|
action UnicodeString | — |
vault UInt32 | — |
key UInt64 | — |
result UInt32 | — |
Event ID 45 —
Fields #
| Name | Description |
|---|---|
vault UInt32 | — |
records UInt64 | — |
result UInt32 | — |
Event ID 46 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 47 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 48 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 49 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 50 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 51 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 52 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 53 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
TargetPID UInt32 | — |
AccessMask UInt32 | — Access mask reference |
WasHardened Boolean | — |
Event ID 58 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
KeyPath UnicodeString | — |
Event ID 59 —
Fields #
| Name | Description |
|---|---|
VName AnsiString | — |
SigSeq HexInt64 | — |
SigSha AnsiString | — |
Result Int8 | — |
Event ID 60 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
Channel UnicodeString | — |
EventId UInt32 | — |
Event ID 61 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FolderName UnicodeString | — |
Event ID 62 —
Fields #
| Name | Description |
|---|---|
Count UInt32 | — |
Event ID 63 —
Fields #
| Name | Description |
|---|---|
TaintReason UInt64 | — |
ReasonImagePath UnicodeString | — |
ProcessImagePath UnicodeString | — |
Event ID 64 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
OldFileName UnicodeString | — |
Event ID 65 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FolderName UnicodeString | — |
Event ID 66 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
FileHardLinkName UnicodeString | — |
Event ID 67 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Name UnicodeString | — |
Data UInt64 | — |
StartStop Boolean | — |
ThreadTime FILETIME | — |
DeltaCPU UInt64 | — |
DeltaWall UInt64 | — |
Event ID 68 —
Fields #
| Name | Description |
|---|---|
SigName AnsiString | — |
SigSeq HexInt64 | — |
SigSha AnsiString | — |
SigTypeName AnsiString | — |
Dimension AnsiString | — |
Value UInt64 | — |
Limit UInt64 | — |
FileName UnicodeString | — |
VPath UnicodeString | — |
FileSha1 AnsiString | — |
PartialCRC1 HexInt32 | — |
PartialCRC2 HexInt32 | — |
PartialCRC3 HexInt32 | — |
FileSize UInt64 | — |
Event ID 69 —
Fields #
| Name | Description |
|---|---|
Guid AnsiString | — |
VolumeSize UInt64 | — |
Attributes HexInt32 | — |
FilesCount HexInt32 | — |
FileGuidsArray AnsiString | — |
FileSizeArray AnsiString | — |
CompressedFileSizeArray AnsiString | — |
FileNameArray UnicodeString | — |
FileAttributesArray AnsiString | — |
EfiFileTypeArray AnsiString | — |
FileSha1Array AnsiString | — |
SmbiosAttributes AnsiString | — |
FileCRCsArray AnsiString | — |
Event ID 70 —
Fields #
| Name | Description |
|---|---|
BasePath UnicodeString | — |
CommandLine UnicodeString | — |
PID UInt32 | — |
ParentPID UInt32 | — |
Flags UInt32 | — |
IntegrityLevel UInt32 | — |
Event ID 71 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 72 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 73 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
CreationTime FILETIME | — |
PID UInt32 | — |
filepath UnicodeString | — |
flags HexInt32 | — |
flags2low HexInt64 | — |
flags2high HexInt64 | — |
oldFlags HexInt32 | — |
oldFlags2low HexInt64 | — |
oldFlags2high HexInt64 | — |
Source UnicodeString | — |
Event ID 74 —
Fields #
| Name | Description |
|---|---|
Sha1 UnicodeString | — |
Sha256 UnicodeString | — |
SigSeq HexInt64 | — |
SigSha UnicodeString | — |
AllSigSeqs UnicodeString | — |
AllSigShas UnicodeString | — |
RealPath UnicodeString | — |
VPath UnicodeString | — |
EtwDataReportType UInt32 | — |
ReportType UInt32 | — |
EngineReportGuid UnicodeString | — |
ResourceData UnicodeString | — |
ResourceSchema UnicodeString | — |
Determination Int32 | — |
ActionStatus HexInt32 | — |
ProcessID UInt32 | — |
ProcessCreationTime UInt64 | — |
ProcessPath UnicodeString | — |
ThreatName UnicodeString | — |
Classification HexInt32 | — |
IsLatent Boolean | — |
IsPassiveMode Boolean | — |
ScanSource UInt32 | — |
ScanType UInt32 | — |
RtpProcessID UInt32 | — |
RtpProcessCreationTime UInt64 | — |
ProcessCommandLine UnicodeString | — |
ExtraDataJson UnicodeString | — |
Event ID 75 —
Fields #
| Name | Description |
|---|---|
DeviceInfo AnsiString | — |
TCGEventsArray AnsiString | — |
PCRsArray AnsiString | — |
Event ID 76 —
Fields #
| Name | Description |
|---|---|
JsonData UnicodeString | — |
Event ID 77 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
Level UInt8 | — |
EffectiveLevel UInt8 | — |
TriggerSigSeq UInt64 | — |
Origin UInt8 | — |
Event ID 78 —
Fields #
| Name | Description |
|---|---|
ImageFilePath UnicodeString | — |
Level UInt8 | — |
EffectiveLevel UInt8 | — |
TriggerSigSeq UInt64 | — |
Origin UInt8 | — |
Event ID 79 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
Level UInt8 | — |
TriggerSigSeq UInt64 | — |
Event ID 80 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
Level UInt8 | — |
TriggerSigSeq UInt64 | — |
StopReason UInt8 | — |
Event ID 81 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
ScanReason UInt8 | — |
Event ID 82 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
ScanReason UInt8 | — |
ScanResult UInt8 | — |
Event ID 83 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Event ID 84 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Event ID 85 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Event ID 86 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Event ID 87 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 88 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 89 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 90 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 91 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 92 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 93 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
PID UInt32 | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 94 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
FilePath UnicodeString | — |
PID UInt32 | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 95 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
CreationTime FILETIME | — |
FileName UnicodeString | — |
FirstOffsetWritten UInt64 | — |
LastOffsetWritten UInt64 | — |
SmallestOffsetWritten UInt64 | — |
BiggestOffsetWritten UInt64 | — |
TotalSizeOfWrites UInt64 | — |
TotalSizeOfAppends UInt64 | — |
NumberOfWrites UInt32 | — |
Event ID 96 —
Fields #
| Name | Description |
|---|---|
OnboardedInfo UnicodeString | — |
Event ID 97 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Id UInt8 | — |
Type AnsiString | — |
Flags HexInt32 | — |
ScanSource UInt32 | — |
ResourceCount UInt32 | — |
FirstResourceType UnicodeString | — |
FirstResourcePath UnicodeString | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 98 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
Id UInt8 | — |
Type AnsiString | — |
Flags HexInt32 | — |
ScanSource UInt32 | — |
ResourceCount UInt32 | — |
FirstResourceType UnicodeString | — |
FirstResourcePath UnicodeString | — |
ThreadId UInt32 | — |
StartQPC UInt64 | — |
Event ID 99 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
CreationTime FILETIME | — |
PID UInt32 | — |
flags HexInt32 | — |
flags2low HexInt64 | — |
flags2high HexInt64 | — |
Event ID 100 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
CreationTime FILETIME | — |
PID UInt32 | — |
flags HexInt32 | — |
flags2low HexInt64 | — |
flags2high HexInt64 | — |
Event ID 101 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 102 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
EngineVersion UnicodeString | — |
AVVersion UnicodeString | — |
ASVersion UnicodeString | — |
Event ID 103 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FileName UnicodeString | — |
Event ID 104 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
FeatureId UInt32 | — |
FirstParam UnicodeString | — |
SecondParam UnicodeString | — |
Event ID 105 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
EventId UnicodeString | — |
KeyPath UnicodeString | — |
ValueName UnicodeString | — |
OldValue UnicodeString | — |
NewValue UnicodeString | — |
UserMode UnicodeString | — |
FeatureType UInt32 | — |
Event ID 106 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
LiveContextCount UInt32 | — |
TotalContextCount UInt32 | — |
Event ID 107 —
Fields #
| Name | Description |
|---|---|
EngineId Pointer | — |
LiveContextCount UInt32 | — |
TotalContextCount UInt32 | — |
Event ID 108 —
Fields #
| Name | Description |
|---|---|
Type AnsiString | — |
Scope AnsiString | — |
ResourceType AnsiString | — |
TargetResource UnicodeString | — |
ParentResource UnicodeString | — |
DetectionName AnsiString | — |
UserName UnicodeString | — |
Event ID 109 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
ProcessContextId Pointer | — |
ImagePath UnicodeString | — |
Event ID 110 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
ProcessContextId Pointer | — |
TerminationTime UInt64 | — |
Event ID 111 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
AttrId UInt32 | — |
AttrSeq UInt32 | — |
AttrSubset UInt32 | — |
Event ID 112 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
AttrId UInt32 | — |
AttrSeq UInt32 | — |
AttrSubset UInt32 | — |
MatchedThreatsNumber UInt32 | — |
IsMultiProcMatch Boolean | — |
IsMultiProcDetection Boolean | — |
Event ID 113 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
DetectionName UnicodeString | — |
SigSeq UInt64 | — |
Event ID 114 —
Fields #
| Name | Description |
|---|---|
PID UInt32 | — |
DetectionName UnicodeString | — |
SigSeq UInt64 | — |
CloudResponse UnicodeString | — |