Microsoft-Windows-Kernel-Audit-API-Calls

8 events across 1 channel

Event IDTitleChannel
1Operational
2Operational
3Operational
4Operational
5Operational
6Operational
7Operational
8Operational

Event ID 1 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
NotifyRoutineAddress
ReturnCode

Event ID 2 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
TargetProcessId
ReturnCode
TargetProcessStartKey
TargetProcessCreationTime

Event ID 3 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
LinkSourceName
LinkTargetName
DesiredAccess
ReturnCode

Event ID 4 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
ReturnCode

Event ID 5 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
TargetProcessId
DesiredAccess
ReturnCode

Event ID 6 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
TargetProcessId
TargetThreatId
DesiredAccess
ReturnCode

Event ID 7 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
DriverName
ReturnCode

Event ID 8 —

Provider
Microsoft-Windows-Kernel-Audit-API-Calls
Channel
Operational

Fields

NameDescription
DriverName
ReturnCode