|
2208 | 2208 | value="0x4002" |
2209 | 2209 | version="1" |
2210 | 2210 | /> |
| 2211 | + <event |
| 2212 | + channel="C_OPERATIONAL" |
| 2213 | + keywords="WDACAudit" |
| 2214 | + level="win:Verbose" |
| 2215 | + message = "$(string.PS_PROVIDER.event.E_A_WDACAudit.message)" |
| 2216 | + opcode="Method" |
| 2217 | + symbol="WDACAudit" |
| 2218 | + task="WDACAudit" |
| 2219 | + template="T_WDACAudit" |
| 2220 | + value="0x4003" |
| 2221 | + version="1" |
| 2222 | + /> |
2211 | 2223 | </events> |
2212 | 2224 | <channels> |
2213 | 2225 | <!--There are two channels defined for Windows PowerShell instrumentation |
|
2432 | 2444 | value="120" |
2433 | 2445 | /> |
2434 | 2446 | <task |
2435 | | - message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
2436 | | - name="Amsi" |
2437 | | - symbol="T_Amsi" |
2438 | | - value="130" |
2439 | | - /> |
| 2447 | + message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
| 2448 | + name="Amsi" |
| 2449 | + symbol="T_Amsi" |
| 2450 | + value="130" |
| 2451 | + /> |
2440 | 2452 | <task |
2441 | 2453 | message="$(string.PS_PROVIDER.task.T_WDACQuery.message)" |
2442 | 2454 | name="WDAC" |
2443 | 2455 | symbol="T_WDAC" |
2444 | 2456 | value="131" |
2445 | 2457 | /> |
| 2458 | + <task |
| 2459 | + message="$(string.PS_PROVIDER.task.T_WDACAudit.message)" |
| 2460 | + name="WDACAudit" |
| 2461 | + symbol="T_WDACAudit" |
| 2462 | + value="132" |
| 2463 | + /> |
2446 | 2464 | </tasks> |
2447 | 2465 | <opcodes> |
2448 | 2466 | <opcode |
|
2604 | 2622 | symbol="K_PSWORKFLOW" |
2605 | 2623 | /> |
2606 | 2624 | <keyword |
2607 | | - mask="0x400" |
2608 | | - message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
2609 | | - name="AmsiState" |
2610 | | - symbol="K_AmsiState" |
2611 | | - /> |
| 2625 | + mask="0x400" |
| 2626 | + message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
| 2627 | + name="AmsiState" |
| 2628 | + symbol="K_AmsiState" |
| 2629 | + /> |
2612 | 2630 | <keyword |
2613 | 2631 | mask="0x800" |
2614 | 2632 | message="$(string.PS_PROVIDER.keyword.K_WDACQuery.message)" |
2615 | 2633 | name="WDACQuery" |
2616 | 2634 | symbol="K_WDACQuery" |
2617 | 2635 | /> |
| 2636 | + <keyword |
| 2637 | + mask="0x1000" |
| 2638 | + message="$(string.PS_PROVIDER.keyword.K_WDACAudit.message)" |
| 2639 | + name="WDACAudit" |
| 2640 | + symbol="K_WDACAudit" |
| 2641 | + /> |
2618 | 2642 | </keywords> |
2619 | 2643 | <maps> |
2620 | 2644 | <!-- please keep in sync with SerializationMethod from |
|
4073 | 4097 | /> |
4074 | 4098 | </template> |
4075 | 4099 | <template tid="T_AmsiState"> |
4076 | | - <data |
4077 | | - inType="win:UnicodeString" |
4078 | | - name="Action" |
4079 | | - /> |
4080 | | - <data |
4081 | | - inType="win:UnicodeString" |
4082 | | - name="AmsiContext" |
4083 | | - /> |
| 4100 | + <data |
| 4101 | + inType="win:UnicodeString" |
| 4102 | + name="Action" |
| 4103 | + /> |
| 4104 | + <data |
| 4105 | + inType="win:UnicodeString" |
| 4106 | + name="AmsiContext" |
| 4107 | + /> |
4084 | 4108 | </template> |
4085 | 4109 | <template tid="T_WDACQuery"> |
4086 | 4110 | <data |
|
4099 | 4123 | inType="win:Int32" |
4100 | 4124 | name="QuerySResult" |
4101 | 4125 | /> |
4102 | | - </template> |
| 4126 | + </template> |
| 4127 | + <template tid="T_WDACAudit"> |
| 4128 | + <data |
| 4129 | + inType="win:UnicodeString" |
| 4130 | + name="Title" |
| 4131 | + /> |
| 4132 | + <data |
| 4133 | + inType="win:UnicodeString" |
| 4134 | + name="Message" |
| 4135 | + /> |
| 4136 | + <data |
| 4137 | + inType="win:UnicodeString" |
| 4138 | + name="FullyQualifiedId" |
| 4139 | + /> |
| 4140 | + </template> |
4103 | 4141 | </templates> |
4104 | 4142 | </provider> |
4105 | 4143 | </events> |
|
5729 | 5767 | id="PS_PROVIDER.task.T_WDACQuery.message" |
5730 | 5768 | value="WDAC Query" |
5731 | 5769 | /> |
| 5770 | + <string |
| 5771 | + id="PS_PROVIDER.event.E_A_WDACAudit.message" |
| 5772 | + value="WDAC Audit. %n %t Title: %1 %n %t Message: %2 %n %t FullyQualifiedId: %3" |
| 5773 | + /> |
| 5774 | + <string |
| 5775 | + id="PS_PROVIDER.keyword.K_WDACAudit.message" |
| 5776 | + value="WDAC Audit" |
| 5777 | + /> |
| 5778 | + <string |
| 5779 | + id="PS_PROVIDER.task.T_WDACAudit.message" |
| 5780 | + value="WDAC Audit" |
| 5781 | + /> |
5732 | 5782 | </stringTable> |
5733 | 5783 | </resources> |
5734 | 5784 | </localization> |
|
0 commit comments