Microsoft-Antimalware-RTP
29 events across 1 channel
Event ID 1 —
Event ID 2 —
Event ID 3 —
Event ID 4 —
Event ID 5 —
Event ID 6 —
Event ID 7 —
Event ID 8 —
Event ID 9 —
Event ID 10 —
Event ID 11 —
Event ID 12 —
Event ID 13 —
Event ID 14 —
Fields #
| Name | Description |
|---|---|
File UnicodeString | — |
Event ID 15 —
Fields #
| Name | Description |
|---|---|
File UnicodeString | — |
Event ID 16 —
Fields #
| Name | Description |
|---|---|
File UnicodeString | — |
Event ID 17 —
Fields #
| Name | Description |
|---|---|
File UnicodeString | — |
Event ID 18 —
Event ID 19 —
Event ID 20 —
Event ID 21 —
Event ID 22 —
Fields #
| Name | Description |
|---|---|
Description UnicodeString | — |
PreviousValue UInt32 | — |
IntendedValueOrHResult UInt32 | — |
LatestValue UInt32 | — |
Event ID 23 —
Fields #
| Name | Description |
|---|---|
Operation UInt32 | — Known values
|
SubOperation UInt32 | — |
AccessCheck UInt32 | — |
Event ID 24 —
Fields #
| Name | Description |
|---|---|
Operation UInt32 | — Known values
|
SubOperation UInt32 | — |
AccessCheck UInt32 | — |
Event ID 25 —
Fields #
| Name | Description |
|---|---|
Timestamp UInt64 | — |
ActionType UnicodeString | — |
Access UnicodeString | — |
Policy UnicodeString | — |
MachineName UnicodeString | — |
MediaName UnicodeString | — |
ClassName UnicodeString | — |
ClassGuid UnicodeString | — |
UserName UnicodeString | — |
VendorId UnicodeString | — |
ProductId UnicodeString | — |
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
SerialNumber UnicodeString | — |
BusType UnicodeString | — |
FilePath UnicodeString | — |
FileSize UInt64 | — |
Tag UInt64 | — |
DomainAuthenticatedNetworkPresent UnicodeString | — |
ActiveVPNConnections UnicodeString | — |
ProcessImageName UnicodeString | — |
PolicyId UnicodeString | — |
AccessChainRuleIds UnicodeString | — |
AccessChainRuleEntryIds UnicodeString | — |
PrinterPortName UnicodeString | — |
Event ID 26 —
Fields #
| Name | Description |
|---|---|
Timestamp UInt64 | — |
Policy UnicodeString | — |
PolicyRuleId UnicodeString | — |
DuplicatedOperation UnicodeString | — |
MachineName UnicodeString | — |
UserName UnicodeString | — |
ClassName UnicodeString | — |
MediaName UnicodeString | — |
InstanceId UnicodeString | — |
SerialNumber UnicodeString | — |
VendorId UnicodeString | — |
ProductId UnicodeString | — |
DeviceFilePath UnicodeString | — |
EvidenceFileSize UInt64 | — |
EvidenceFileLocation UnicodeString | — |
Tag UInt64 | — |
Event ID 27 —
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | — |
ScanReason UInt32 | — |
FileId UInt64 | — |
USN UInt64 | — |
RtpScanResult UInt32 | — |
RtpScanAction UInt32 | — |
DoNotCache UInt32 | — |
Flags UInt32 | — |
ScanResult UInt32 | — |
hr UInt32 | — |
Event ID 28 —
Fields #
| Name | Description |
|---|---|
Timestamp UInt64 | — |
CurrentGrantedAccess UnicodeString | — |
MaximumPossibleGrantedAccess UnicodeString | — |
CurrentDeniedAccess UnicodeString | — |
MinimumGuaranteedDeniedAccess UnicodeString | — |
MachineName UnicodeString | — |
UserName UnicodeString | — |
ClassName UnicodeString | — |
MediaName UnicodeString | — |
BusType UnicodeString | — |
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
SerialNumber UnicodeString | — |
VendorId UnicodeString | — |
ProductId UnicodeString | — |
DomainAuthenticatedNetworkPresent UnicodeString | — |
ActiveVPNConnections UnicodeString | — |
ActiveNetworks UnicodeString | — |
DevicePolicyGroupMembership UnicodeString | — |
Event ID 29 —
Fields #
| Name | Description |
|---|---|
Timestamp UInt64 | — |
State UnicodeString | — |