Microsoft-Windows-Kernel-Audit-API-Calls
8 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 1 | Operational | |
| 2 | Operational | |
| 3 | Operational | |
| 4 | Operational | |
| 5 | Operational | |
| 6 | Operational | |
| 7 | Operational | |
| 8 | Operational |
Event ID 1 —
Fields #
| Name | Description |
|---|---|
NotifyRoutineAddress Pointer | — |
ReturnCode UInt32 | — |
Event ID 2 —
Fields #
| Name | Description |
|---|---|
TargetProcessId UInt32 | — |
ReturnCode UInt32 | — |
TargetProcessStartKey UInt64 | — |
TargetProcessCreationTime FILETIME | — |
Event ID 3 —
Fields #
| Name | Description |
|---|---|
LinkSourceName UnicodeString | — |
LinkTargetName UnicodeString | — |
DesiredAccess UInt32 | — Process access rights reference |
ReturnCode UInt32 | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
ReturnCode UInt32 | — |
Event ID 5 —
Fields #
| Name | Description |
|---|---|
TargetProcessId UInt32 | — |
DesiredAccess UInt32 | — Process access rights reference |
ReturnCode UInt32 | — |
Event ID 6 —
Fields #
| Name | Description |
|---|---|
TargetProcessId UInt32 | — |
TargetThreatId UInt32 | — |
DesiredAccess UInt32 | — Process access rights reference |
ReturnCode UInt32 | — |
Event ID 7 —
Fields #
| Name | Description |
|---|---|
DriverName UnicodeString | — |
ReturnCode UInt32 | — |
Event ID 8 —
Fields #
| Name | Description |
|---|---|
DriverName UnicodeString | — |
ReturnCode UInt32 | — |