|
2208 | 2208 | value="0x4002"
|
2209 | 2209 | version="1"
|
2210 | 2210 | />
|
| 2211 | + <event |
| 2212 | + channel="C_OPERATIONAL" |
| 2213 | + keywords="WDACAudit" |
| 2214 | + level="win:Verbose" |
| 2215 | + message = "$(string.PS_PROVIDER.event.E_A_WDACAudit.message)" |
| 2216 | + opcode="Method" |
| 2217 | + symbol="WDACAudit" |
| 2218 | + task="WDACAudit" |
| 2219 | + template="T_WDACAudit" |
| 2220 | + value="0x4003" |
| 2221 | + version="1" |
| 2222 | + /> |
2211 | 2223 | </events>
|
2212 | 2224 | <channels>
|
2213 | 2225 | <!--There are two channels defined for Windows PowerShell instrumentation
|
|
2432 | 2444 | value="120"
|
2433 | 2445 | />
|
2434 | 2446 | <task
|
2435 |
| - message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
2436 |
| - name="Amsi" |
2437 |
| - symbol="T_Amsi" |
2438 |
| - value="130" |
2439 |
| - /> |
| 2447 | + message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
| 2448 | + name="Amsi" |
| 2449 | + symbol="T_Amsi" |
| 2450 | + value="130" |
| 2451 | + /> |
2440 | 2452 | <task
|
2441 | 2453 | message="$(string.PS_PROVIDER.task.T_WDACQuery.message)"
|
2442 | 2454 | name="WDAC"
|
2443 | 2455 | symbol="T_WDAC"
|
2444 | 2456 | value="131"
|
2445 | 2457 | />
|
| 2458 | + <task |
| 2459 | + message="$(string.PS_PROVIDER.task.T_WDACAudit.message)" |
| 2460 | + name="WDACAudit" |
| 2461 | + symbol="T_WDACAudit" |
| 2462 | + value="132" |
| 2463 | + /> |
2446 | 2464 | </tasks>
|
2447 | 2465 | <opcodes>
|
2448 | 2466 | <opcode
|
|
2604 | 2622 | symbol="K_PSWORKFLOW"
|
2605 | 2623 | />
|
2606 | 2624 | <keyword
|
2607 |
| - mask="0x400" |
2608 |
| - message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
2609 |
| - name="AmsiState" |
2610 |
| - symbol="K_AmsiState" |
2611 |
| - /> |
| 2625 | + mask="0x400" |
| 2626 | + message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
| 2627 | + name="AmsiState" |
| 2628 | + symbol="K_AmsiState" |
| 2629 | + /> |
2612 | 2630 | <keyword
|
2613 | 2631 | mask="0x800"
|
2614 | 2632 | message="$(string.PS_PROVIDER.keyword.K_WDACQuery.message)"
|
2615 | 2633 | name="WDACQuery"
|
2616 | 2634 | symbol="K_WDACQuery"
|
2617 | 2635 | />
|
| 2636 | + <keyword |
| 2637 | + mask="0x1000" |
| 2638 | + message="$(string.PS_PROVIDER.keyword.K_WDACAudit.message)" |
| 2639 | + name="WDACAudit" |
| 2640 | + symbol="K_WDACAudit" |
| 2641 | + /> |
2618 | 2642 | </keywords>
|
2619 | 2643 | <maps>
|
2620 | 2644 | <!-- please keep in sync with SerializationMethod from
|
|
4073 | 4097 | />
|
4074 | 4098 | </template>
|
4075 | 4099 | <template tid="T_AmsiState">
|
4076 |
| - <data |
4077 |
| - inType="win:UnicodeString" |
4078 |
| - name="Action" |
4079 |
| - /> |
4080 |
| - <data |
4081 |
| - inType="win:UnicodeString" |
4082 |
| - name="AmsiContext" |
4083 |
| - /> |
| 4100 | + <data |
| 4101 | + inType="win:UnicodeString" |
| 4102 | + name="Action" |
| 4103 | + /> |
| 4104 | + <data |
| 4105 | + inType="win:UnicodeString" |
| 4106 | + name="AmsiContext" |
| 4107 | + /> |
4084 | 4108 | </template>
|
4085 | 4109 | <template tid="T_WDACQuery">
|
4086 | 4110 | <data
|
|
4099 | 4123 | inType="win:Int32"
|
4100 | 4124 | name="QuerySResult"
|
4101 | 4125 | />
|
4102 |
| - </template> |
| 4126 | + </template> |
| 4127 | + <template tid="T_WDACAudit"> |
| 4128 | + <data |
| 4129 | + inType="win:UnicodeString" |
| 4130 | + name="Title" |
| 4131 | + /> |
| 4132 | + <data |
| 4133 | + inType="win:UnicodeString" |
| 4134 | + name="Message" |
| 4135 | + /> |
| 4136 | + <data |
| 4137 | + inType="win:UnicodeString" |
| 4138 | + name="FullyQualifiedId" |
| 4139 | + /> |
| 4140 | + </template> |
4103 | 4141 | </templates>
|
4104 | 4142 | </provider>
|
4105 | 4143 | </events>
|
|
5729 | 5767 | id="PS_PROVIDER.task.T_WDACQuery.message"
|
5730 | 5768 | value="WDAC Query"
|
5731 | 5769 | />
|
| 5770 | + <string |
| 5771 | + id="PS_PROVIDER.event.E_A_WDACAudit.message" |
| 5772 | + value="WDAC Audit. %n %t Title: %1 %n %t Message: %2 %n %t FullyQualifiedId: %3" |
| 5773 | + /> |
| 5774 | + <string |
| 5775 | + id="PS_PROVIDER.keyword.K_WDACAudit.message" |
| 5776 | + value="WDAC Audit" |
| 5777 | + /> |
| 5778 | + <string |
| 5779 | + id="PS_PROVIDER.task.T_WDACAudit.message" |
| 5780 | + value="WDAC Audit" |
| 5781 | + /> |
5732 | 5782 | </stringTable>
|
5733 | 5783 | </resources>
|
5734 | 5784 | </localization>
|
|
0 commit comments