Microsoft-Windows-Kernel-Audit-API-Calls
8 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 1 | Operational | |
| 2 | Operational | |
| 3 | Operational | |
| 4 | Operational | |
| 5 | Operational | |
| 6 | Operational | |
| 7 | Operational | |
| 8 | Operational |
Event ID 1 —
Fields
| Name | Description |
|---|---|
NotifyRoutineAddress | — |
ReturnCode | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
TargetProcessId | — |
ReturnCode | — |
TargetProcessStartKey | — |
TargetProcessCreationTime | — |
Event ID 3 —
Fields
| Name | Description |
|---|---|
LinkSourceName | — |
LinkTargetName | — |
DesiredAccess | — |
ReturnCode | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
ReturnCode | — |
Event ID 5 —
Fields
| Name | Description |
|---|---|
TargetProcessId | — |
DesiredAccess | — |
ReturnCode | — |
Event ID 6 —
Fields
| Name | Description |
|---|---|
TargetProcessId | — |
TargetThreatId | — |
DesiredAccess | — |
ReturnCode | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
DriverName | — |
ReturnCode | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
DriverName | — |
ReturnCode | — |