Microsoft-Windows-Threat-Intelligence

34 events across 1 channel

Event IDTitleChannel
1Analytic
2Analytic
3Analytic
4Analytic
5Analytic
6Analytic
7Analytic
8Analytic
11Analytic
12Analytic
13Analytic
14Analytic
15Analytic
16Analytic
17Analytic
18Analytic
19Analytic
20Analytic
21Analytic
22Analytic
23Analytic
24Analytic
25Analytic
26Analytic
27Analytic
28Analytic
29Analytic
30Analytic
31Analytic
32Analytic
33Analytic
34Analytic
35Analytic
36Analytic

Event ID 1 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_ALLOCVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 2 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_PROTECTVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize UInt64
ProtectionMask UInt32
LastProtectionMask UInt32
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString
TargetAddress Pointer
FullRegionSize UInt64

Event ID 3 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_MAPVIEW

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
ViewSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 4 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_QUEUEUSERAPC

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
TargetThreadAlertable UInt8
ApcRoutine Pointer
ApcArgument1 Pointer
ApcArgument2 Pointer
ApcArgument3 Pointer
RealEventTime FILETIME
ApcRoutineVadQueryResult UInt32
ApcRoutineVadAllocationBase Pointer
ApcRoutineVadAllocationProtect UInt32
ApcRoutineVadRegionType UInt32
ApcRoutineVadRegionSize Pointer
ApcRoutineVadCommitSize Pointer
ApcRoutineVadMmfName UnicodeString
ApcArgument1VadQueryResult UInt32
ApcArgument1VadAllocationBase Pointer
ApcArgument1VadAllocationProtect UInt32
ApcArgument1VadRegionType UInt32
ApcArgument1VadRegionSize Pointer
ApcArgument1VadCommitSize Pointer
ApcArgument1VadMmfName UnicodeString

Event ID 5 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SETTHREADCONTEXT

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME
ContextFlags UInt32
ContextMask UInt16
Pc Pointer
Sp Pointer
Lr Pointer
Fp Pointer
Reg0 Pointer
Reg1 Pointer
Reg2 Pointer
Reg3 Pointer
Reg4 Pointer
Reg5 Pointer
Reg6 Pointer
Reg7 Pointer
RealEventTime FILETIME
PcVadQueryResult UInt32
PcVadAllocationBase Pointer
PcVadAllocationProtect UInt32
PcVadRegionType UInt32
PcVadRegionSize Pointer
PcVadCommitSize Pointer
PcVadMmfName UnicodeString

Event ID 6 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_ALLOCVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 7 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_PROTECTVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize UInt64
ProtectionMask UInt32
LastProtectionMask UInt32
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString
TargetAddress Pointer
FullRegionSize UInt64

Event ID 8 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_MAPVIEW

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
ViewSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 11 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_READVM

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
BytesCopied Pointer
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString

Event ID 12 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_WRITEVM

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
BytesCopied Pointer
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString

Event ID 13 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_READVM

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
BytesCopied Pointer
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString

Event ID 14 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_WRITEVM

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
BytesCopied Pointer
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString

Event ID 15 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_THREAD

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME

Event ID 16 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_THREAD

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME

Event ID 17 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_PROCESS

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8

Event ID 18 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_PROCESS

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8

Event ID 19 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_PROCESS

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8

Event ID 20 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SUSPENDRESUME_PROCESS

Fields #

NameDescription
OperationStatus UInt32
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8

Event ID 21 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_ALLOCVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 22 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_PROTECTVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize UInt64
ProtectionMask UInt32
LastProtectionMask UInt32
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString
TargetAddress Pointer
FullRegionSize UInt64

Event ID 23 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_MAPVIEW

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
ViewSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 24 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_QUEUEUSERAPC

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
TargetThreadAlertable UInt8
ApcRoutine Pointer
ApcArgument1 Pointer
ApcArgument2 Pointer
ApcArgument3 Pointer
RealEventTime FILETIME
ApcRoutineVadQueryResult UInt32
ApcRoutineVadAllocationBase Pointer
ApcRoutineVadAllocationProtect UInt32
ApcRoutineVadRegionType UInt32
ApcRoutineVadRegionSize Pointer
ApcRoutineVadCommitSize Pointer
ApcRoutineVadMmfName UnicodeString
ApcArgument1VadQueryResult UInt32
ApcArgument1VadAllocationBase Pointer
ApcArgument1VadAllocationProtect UInt32
ApcArgument1VadRegionType UInt32
ApcArgument1VadRegionSize Pointer
ApcArgument1VadCommitSize Pointer
ApcArgument1VadMmfName UnicodeString

Event ID 25 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_SETTHREADCONTEXT

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
TargetThreadId UInt32
TargetThreadCreateTime FILETIME
ContextFlags UInt32
ContextMask UInt16
Pc Pointer
Sp Pointer
Lr Pointer
Fp Pointer
Reg0 Pointer
Reg1 Pointer
Reg2 Pointer
Reg3 Pointer
Reg4 Pointer
Reg5 Pointer
Reg6 Pointer
Reg7 Pointer
RealEventTime FILETIME
PcVadQueryResult UInt32
PcVadAllocationBase Pointer
PcVadAllocationProtect UInt32
PcVadRegionType UInt32
PcVadRegionSize Pointer
PcVadCommitSize Pointer
PcVadMmfName UnicodeString

Event ID 26 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_ALLOCVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 27 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_PROTECTVM

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
OriginalProcessId UInt32
OriginalProcessCreateTime FILETIME
OriginalProcessStartKey UInt64
OriginalProcessSignatureLevel UInt8
OriginalProcessSectionSignatureLevel UInt8
OriginalProcessProtection UInt8
BaseAddress Pointer
RegionSize UInt64
ProtectionMask UInt32
LastProtectionMask UInt32
VaVadQueryResult UInt32
VaVadAllocationBase Pointer
VaVadAllocationProtect UInt32
VaVadRegionType UInt32
VaVadRegionSize Pointer
VaVadCommitSize Pointer
VaVadMmfName UnicodeString
TargetAddress Pointer
FullRegionSize UInt64

Event ID 28 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_MAPVIEW

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
TargetProcessId UInt32
TargetProcessCreateTime FILETIME
TargetProcessStartKey UInt64
TargetProcessSignatureLevel UInt8
TargetProcessSectionSignatureLevel UInt8
TargetProcessProtection UInt8
BaseAddress Pointer
ViewSize Pointer
AllocationType UInt32
ProtectionMask UInt32

Event ID 29 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_DRIVER_DEVICE

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
CodeIntegrityOption UInt32

Event ID 30 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_DRIVER_DEVICE

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 31 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_DRIVER_DEVICE

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString

Event ID 32 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_TASK_DRIVER_DEVICE

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString

Event ID 33 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_PROCESS_IMPERSONATION_UP

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
PreviousTokenQueryResult UInt32
PreviousTokenType UInt32
PreviousTokenElevation UInt32
PreviousTokenElevationType UInt32
PreviousTokenImpersonationLevel UInt32
PreviousTokenUser SID
PreviousTokenTrustLevelCount UInt32
PreviousTokenTrustLevel 36
PreviousTokenIntegrityLevel UInt32
PreviousTokenSessionId UInt32
PreviousTokenLowBoxNumber UInt32
PreviousTokenAuthenticationId HexInt64
PreviousTokenGroupsCount UInt32
PreviousTokenGroups 37
CurrentTokenQueryResult UInt32
CurrentTokenType UInt32
CurrentTokenElevation UInt32
CurrentTokenElevationType UInt32
CurrentTokenImpersonationLevel UInt32
CurrentTokenUser SID
CurrentTokenTrustLevelCount UInt32
CurrentTokenTrustLevel 39
CurrentTokenIntegrityLevel UInt32
CurrentTokenSessionId UInt32
CurrentTokenLowBoxNumber UInt32
CurrentTokenAuthenticationId HexInt64
CurrentTokenGroupsCount UInt32
CurrentTokenGroups 40

Event ID 34 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_PROCESS_IMPERSONATION_REVERT

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME

Event ID 35 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_PROCESS_SYSCALL_USAGE

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
SessionId UInt32
SyscallEnum UInt32
IsSandboxedToken Boolean

Event ID 36 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic
Task
KERNEL_THREATINT_PROCESS_IMPERSONATION_DOWN

Fields #

NameDescription
CallingProcessId UInt32
CallingProcessCreateTime FILETIME
CallingProcessStartKey UInt64
CallingProcessSignatureLevel UInt8
CallingProcessSectionSignatureLevel UInt8
CallingProcessProtection UInt8
CallingThreadId UInt32
CallingThreadCreateTime FILETIME
PreviousTokenQueryResult UInt32
PreviousTokenType UInt32
PreviousTokenElevation UInt32
PreviousTokenElevationType UInt32
PreviousTokenImpersonationLevel UInt32
PreviousTokenUser SID
PreviousTokenTrustLevelCount UInt32
PreviousTokenTrustLevel 36
PreviousTokenIntegrityLevel UInt32
PreviousTokenSessionId UInt32
PreviousTokenLowBoxNumber UInt32
PreviousTokenAuthenticationId HexInt64
PreviousTokenGroupsCount UInt32
PreviousTokenGroups 37
CurrentTokenQueryResult UInt32
CurrentTokenType UInt32
CurrentTokenElevation UInt32
CurrentTokenElevationType UInt32
CurrentTokenImpersonationLevel UInt32
CurrentTokenUser SID
CurrentTokenTrustLevelCount UInt32
CurrentTokenTrustLevel 39
CurrentTokenIntegrityLevel UInt32
CurrentTokenSessionId UInt32
CurrentTokenLowBoxNumber UInt32
CurrentTokenAuthenticationId HexInt64
CurrentTokenGroupsCount UInt32
CurrentTokenGroups 40