Microsoft-Antimalware-RTP

29 events across 1 channel

Event IDTitleChannel
1Application
2Application
3Application
4Application
5Application
6Application
7Application
8Application
9Application
10Application
11Application
12Application
13Application
14Application
15Application
16Application
17Application
18Application
19Application
20Application
21Application
22Application
23Application
24Application
25Application
26Application
27Application
28Application
29Application

Event ID 1 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 2 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 3 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 4 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 5 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 6 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 7 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 8 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 9 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 10 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 11 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 12 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 13 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 14 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
File

Event ID 15 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
File

Event ID 16 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
File

Event ID 17 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
File

Event ID 18 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 19 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 20 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 21 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Event ID 22 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Description
PreviousValue
IntendedValueOrHResult
LatestValue

Event ID 23 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Operation
SubOperation
AccessCheck

Event ID 24 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Operation
SubOperation
AccessCheck

Event ID 25 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Timestamp
ActionType
Access
Policy
MachineName
MediaName
ClassName
ClassGuid
UserName
VendorId
ProductId
DeviceId
InstanceId
SerialNumber
BusType
FilePath
FileSize
Tag
DomainAuthenticatedNetworkPresent
ActiveVPNConnections
ProcessImageName
PolicyId
AccessChainRuleIds
AccessChainRuleEntryIds
PrinterPortName

Event ID 26 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Timestamp
Policy
PolicyRuleId
DuplicatedOperation
MachineName
UserName
ClassName
MediaName
InstanceId
SerialNumber
VendorId
ProductId
DeviceFilePath
EvidenceFileSize
EvidenceFileLocation
Tag

Event ID 27 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
FileName
ScanReason
FileId
USN
RtpScanResult
RtpScanAction
DoNotCache
Flags
ScanResult
hr

Event ID 28 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Timestamp
CurrentGrantedAccess
MaximumPossibleGrantedAccess
CurrentDeniedAccess
MinimumGuaranteedDeniedAccess
MachineName
UserName
ClassName
MediaName
BusType
DeviceId
InstanceId
SerialNumber
VendorId
ProductId
DomainAuthenticatedNetworkPresent
ActiveVPNConnections
ActiveNetworks
DevicePolicyGroupMembership

Event ID 29 —

Provider
Microsoft-Antimalware-RTP
Channel
Application

Fields

NameDescription
Timestamp
State