File tree 1 file changed +66
-11
lines changed
src/PowerShell.Core.Instrumentation
1 file changed +66
-11
lines changed Original file line number Diff line number Diff line change 2184
2184
value="0x6017"
2185
2185
version="1"
2186
2186
/>
2187
- <event
2187
+ <event
2188
2188
channel="C_ANALYTIC"
2189
2189
keywords="AmsiState"
2190
2190
level="win:Verbose"
2196
2196
value="0x4001"
2197
2197
version="1"
2198
2198
/>
2199
+ <event
2200
+ channel="C_ANALYTIC"
2201
+ keywords="WDACQuery"
2202
+ level="win:Verbose"
2203
+ message="$(string.PS_PROVIDER.event.E_A_WDACQuery.message)"
2204
+ opcode="Method"
2205
+ symbol="WDACQuery"
2206
+ task="WDAC"
2207
+ template="T_WDACQuery"
2208
+ value="0x4002"
2209
+ version="1"
2210
+ />
2211
+ </events>
2199
2212
</events>
2200
2213
<channels>
2201
2214
<!--There are two channels defined for Windows PowerShell instrumentation
2419
2432
symbol="T_ISEOperation"
2420
2433
value="120"
2421
2434
/>
2422
- <task
2435
+ <task
2423
2436
message="$(string.PS_PROVIDER.task.T_AmsiState.message)"
2424
2437
name="Amsi"
2425
2438
symbol="T_Amsi"
2426
2439
value="130"
2440
+ />
2441
+ <task
2442
+ message="$(string.PS_PROVIDER.task.T_WDACQuery.message)"
2443
+ name="WDAC"
2444
+ symbol="T_WDAC"
2445
+ value="131"
2427
2446
/>
2428
2447
</tasks>
2429
2448
<opcodes>
2585
2604
name="PSWorkflow"
2586
2605
symbol="K_PSWORKFLOW"
2587
2606
/>
2588
- <keyword
2607
+ <keyword
2589
2608
mask="0x400"
2590
2609
message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)"
2591
2610
name="AmsiState"
2592
2611
symbol="K_AmsiState"
2612
+ />
2613
+ <keyword
2614
+ mask="0x800"
2615
+ message="$(string.PS_PROVIDER.keyword.K_WDACQuery.message)"
2616
+ name="WDACQuery"
2617
+ symbol="K_WDACQuery"
2593
2618
/>
2594
2619
</keywords>
2595
2620
<maps>
4048
4073
name="FileName"
4049
4074
/>
4050
4075
</template>
4051
- <template tid="T_AmsiState">
4052
- <data
4053
- inType="win:UnicodeString"
4054
- name="Action"
4076
+ <template tid="T_AmsiState">
4077
+ <data
4078
+ inType="win:UnicodeString"
4079
+ name="Action"
4080
+ />
4081
+ <data
4082
+ inType="win:UnicodeString"
4083
+ name="AmsiContext"
4084
+ />
4085
+ </template>
4086
+ <template tid="T_WDACQuery">
4087
+ <data
4088
+ inType="win:UnicodeString"
4089
+ name="QueryName"
4055
4090
/>
4056
- <data
4057
- inType="win:UnicodeString"
4058
- name="AmsiContext"
4091
+ <data
4092
+ inType="win:UnicodeString"
4093
+ name="FileName"
4094
+ />
4095
+ <data
4096
+ inType="win:Int32"
4097
+ name="QuerySuccess"
4059
4098
/>
4060
- </template>
4099
+ <data
4100
+ inType="win:Int32"
4101
+ name="QuerySResult"
4102
+ />
4103
+ </template>
4061
4104
</templates>
4062
4105
</provider>
4063
4106
</events>
5675
5718
id="PS_PROVIDER.event.E_O_REMOTE_NAMEDPIPE_DISCONNECT.message"
5676
5719
value="Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3."
5677
5720
/>
5721
+ <string
5722
+ id="PS_PROVIDER.event.E_A_WDACQuery.message"
5723
+ value="WDAC Query. %n %t Query: %1 %n %t File: %2 %n %t SuccessCode: %3 %n %t ResultCode: %4"
5724
+ />
5725
+ <string
5726
+ id="PS_PROVIDER.keyword.K_WDACQuery.message"
5727
+ value="WDAC Query"
5728
+ />
5729
+ <string
5730
+ id="PS_PROVIDER.task.T_WDACQuery.message"
5731
+ value="WDAC Query"
5732
+ />
5678
5733
</stringTable>
5679
5734
</resources>
5680
5735
</localization>
You can’t perform that action at this time.
0 commit comments