detection.wiki
?
Blog
Labs
References
Microsoft-Windows-Shell-ZipFolder
28 events across 1 channel
Event ID
Title
Channel
1
Diagnostic
2
Diagnostic
3
Diagnostic
4
Diagnostic
5
Diagnostic
6
Diagnostic
7
Diagnostic
8
Diagnostic
9
Diagnostic
10
Diagnostic
11
Diagnostic
12
Diagnostic
13
Diagnostic
14
Diagnostic
15
Diagnostic
16
Diagnostic
17
Diagnostic
18
Diagnostic
19
Diagnostic
20
Diagnostic
21
Diagnostic
22
Diagnostic
23
Diagnostic
24
Diagnostic
25
Diagnostic
26
Diagnostic
27
Diagnostic
28
Diagnostic
Event ID 1 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ExtractFile
Opcode
Start
Event ID 2 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ExtractFile
Opcode
Stop
Event ID 3 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DeleteFile
Opcode
Start
Event ID 4 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DeleteFile
Opcode
Stop
Event ID 5 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_WizardExtractAll
Opcode
Start
Event ID 6 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_WizardExtractAll
Opcode
Stop
Event ID 7 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CountFiles
Opcode
Start
Event ID 8 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CountFiles
Opcode
Stop
Event ID 9 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_QueryCM
Opcode
Start
Event ID 10 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_QueryCM
Opcode
Stop
Event ID 11 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CheckEncrypted
Opcode
Start
Event ID 12 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CheckEncrypted
Opcode
Stop
Event ID 13 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_BuildEnumerator
Opcode
Start
Event ID 14 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_BuildEnumerator
Opcode
Stop
Event ID 15 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DropIn
Opcode
Start
Event ID 16 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DropIn
Opcode
Stop
Event ID 17 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_OpenItem
Opcode
Start
Event ID 18 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_OpenItem
Opcode
Stop
Event ID 19 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RemoveItem
Opcode
Start
Event ID 20 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RemoveItem
Opcode
Stop
Event ID 21 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RenameItem
Opcode
Start
Event ID 22 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RenameItem
Opcode
Stop
Event ID 23 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ApplyProps
Opcode
Start
Event ID 24 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ApplyProps
Opcode
Stop
Event ID 25 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_LeaveFolder
Opcode
Start
Event ID 26 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_LeaveFolder
Opcode
Stop
Event ID 27 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_AESCheck
Opcode
Start
Event ID 28 —
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_AESCheck
Opcode
Stop
Keyboard Shortcuts
j
/
k
Scroll down / up
d
/
u
Half-page down / up
h
/
l
Go back / forward
g
g
Go to top
G
Go to bottom
f
Follow link (SHIFT = new tab)
/
Focus search
?
Toggle this help
See
Navigation Reference
for search modifiers and filters.