"Time of Day","Process Name","PID","Operation","Path","Result","Detail" "13:48:27.5486279","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:27.5486430","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","Desired Access: Read/Write" "13:48:27.5487033","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:27.5487114","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NAME NOT FOUND","Desired Access: Read" "13:48:27.5487301","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NO MORE ENTRIES","Index: 0, Length: 220" "13:48:27.5487496","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","" "13:48:27.5771694","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.5771900","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 144’256, Length: 4’096" "13:48:27.5772238","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 403’816, Length: 4’096" "13:48:27.5772477","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.5775423","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.5775761","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 399’696, Length: 4’096" "13:48:27.5776013","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.5835398","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.5835887","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.5836207","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.5836339","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.5837392","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.5837908","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.5838018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.5838093","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:27.5846645","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.5846816","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 395’576, Length: 4’096" "13:48:27.5847044","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.5854297","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.5854567","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.5854879","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.5854967","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 148’376, Length: 4’096" "13:48:27.5855268","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 679’856, Length: 4’096" "13:48:27.5855498","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.5855746","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.5860527","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.5860818","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.5860965","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976" "13:48:27.5861087","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.5861142","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976" "13:48:27.5861221","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.5861303","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:27.5861475","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:27.6098690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6099149","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6099290","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6099395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:27.6103226","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6103637","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6103722","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136" "13:48:27.6103935","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6104073","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136" "13:48:27.6104186","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6104270","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:27.6104488","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:27.6105220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6105433","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6105521","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6105714","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:27.6107812","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6108005","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6108165","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008" "13:48:27.6108514","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6108570","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008" "13:48:27.6108649","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6108817","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:27.6108948","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:27.6114914","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6115505","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6115761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6115853","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:27.6117397","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6117811","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6117915","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6117997","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:27.6118829","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6119405","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6119516","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192" "13:48:27.6119609","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6119660","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192" "13:48:27.6119745","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6119821","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:27.6120045","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:27.6120412","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6120716","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6120804","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6120876","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:27.6122052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6122414","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6122493","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6122567","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:27.6124017","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6126810","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6127107","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768" "13:48:27.6127962","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6128189","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768" "13:48:27.6128333","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6129082","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:27.6129750","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:27.6136426","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6137211","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6137333","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6137415","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS","" "13:48:27.6144921","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6151458","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6152471","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520" "13:48:27.6154232","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6154744","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520" "13:48:27.6157337","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6157806","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:27.6158874","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:27.6159486","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6159879","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6159980","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6160061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS","" "13:48:27.6164003","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\fltLib.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6164789","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6164907","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6165002","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\fltLib.dll","SUCCESS","" "13:48:27.6171188","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\newdev.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6171656","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6171766","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6171848","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\newdev.dll","SUCCESS","" "13:48:27.6177155","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6177819","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6177993","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552" "13:48:27.6178130","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(಼�㈀" "13:48:27.6178193","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552" "13:48:27.6178282","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6178359","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:27.6178574","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:27.6178784","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6179311","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6179408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6179553","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:27.6180384","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6180593","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6186380","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msdelta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6187227","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6187581","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6187677","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msdelta.dll","SUCCESS","" "13:48:27.6187807","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6188917","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6189036","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560" "13:48:27.6189156","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6189222","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560" "13:48:27.6189423","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6189536","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\setupapi.dll","SUCCESS","" "13:48:27.6189691","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS","" "13:48:27.6192022","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptsp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6192430","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6192541","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6192616","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptsp.dll","SUCCESS","" "13:48:27.6197451","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6198096","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6198174","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cabinet.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6198208","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736" "13:48:27.6198313","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6198377","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736" "13:48:27.6198567","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6198592","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6198679","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\bcrypt.dll","SUCCESS","" "13:48:27.6198692","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6198769","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cabinet.dll","SUCCESS","" "13:48:27.6198830","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS","" "13:48:27.6200180","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6200461","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6202065","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\fltLib.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6202608","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6202686","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312" "13:48:27.6202774","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6202827","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312" "13:48:27.6202905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6203085","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\fltLib.dll","SUCCESS","" "13:48:27.6203220","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\fltLib.dll","SUCCESS","" "13:48:27.6204470","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6204602","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6205803","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\newdev.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6206222","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ" "13:48:27.6206442","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160" "13:48:27.6206728","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6206802","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160" "13:48:27.6206893","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6206972","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\newdev.dll","SUCCESS","" "13:48:27.6207095","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\newdev.dll","SUCCESS","" "13:48:27.6210475","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6210988","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ" "13:48:27.6211175","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280" "13:48:27.6211364","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6211895","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280" "13:48:27.6212124","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6212206","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:27.6212381","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:27.6213952","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6214089","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6215052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msdelta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6215325","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6215394","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360" "13:48:27.6215468","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ" "13:48:27.6215703","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360" "13:48:27.6215811","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6215885","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msdelta.dll","SUCCESS","" "13:48:27.6216009","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msdelta.dll","SUCCESS","" "13:48:27.6218401","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptsp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6235566","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6235764","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304" "13:48:27.6235868","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6235995","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304" "13:48:27.6236107","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6236193","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cryptsp.dll","SUCCESS","" "13:48:27.6236387","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptsp.dll","SUCCESS","" "13:48:27.6239253","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cabinet.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6239720","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6239844","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024" "13:48:27.6239953","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6240004","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024" "13:48:27.6240092","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6240250","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cabinet.dll","SUCCESS","" "13:48:27.6240748","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cabinet.dll","SUCCESS","" "13:48:27.6309257","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6309663","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6309906","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6310005","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:27.6313950","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6314425","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6314543","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6314565","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6314787","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "13:48:27.6315075","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6315186","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784" "13:48:27.6315301","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6315361","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784" "13:48:27.6315561","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6315796","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:27.6315957","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:27.6323592","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6324402","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6324529","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984" "13:48:27.6324633","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6324685","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984" "13:48:27.6324762","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6324834","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\SHCore.dll","SUCCESS","" "13:48:27.6325112","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "13:48:27.6333499","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6334200","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6334334","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6334407","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "13:48:27.6338266","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WofUtil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6338278","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6338615","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6338667","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6338749","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120" "13:48:27.6338828","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6338840","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6338909","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120" "13:48:27.6338935","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WofUtil.dll","SUCCESS","" "13:48:27.6338988","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6339166","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "13:48:27.6339300","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "13:48:27.6340113","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\devrtl.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6340405","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6340633","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6340646","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6340742","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\devrtl.dll","SUCCESS","" "13:48:27.6340789","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6341773","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WofUtil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6342017","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6342197","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440" "13:48:27.6342285","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6342337","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440" "13:48:27.6342409","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6342480","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\WofUtil.dll","SUCCESS","" "13:48:27.6342597","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WofUtil.dll","SUCCESS","" "13:48:27.6344055","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6344188","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6347807","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\devrtl.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6348444","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6348546","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112" "13:48:27.6348643","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6348698","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112" "13:48:27.6348784","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6348974","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\devrtl.dll","SUCCESS","" "13:48:27.6349111","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\devrtl.dll","SUCCESS","" "13:48:27.6405153","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6406282","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6406763","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6407083","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS","" "13:48:27.6409561","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6409824","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6571981","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rsaenh.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6572385","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6572487","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6572567","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rsaenh.dll","SUCCESS","" "13:48:27.6575479","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rsaenh.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6575986","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6576073","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488" "13:48:27.6576160","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6576210","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488" "13:48:27.6576287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6576365","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\rsaenh.dll","SUCCESS","" "13:48:27.6576626","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rsaenh.dll","SUCCESS","" "13:48:27.6586879","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6587335","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6587519","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6587624","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptbase.dll","SUCCESS","" "13:48:27.6590178","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6590189","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6590412","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.6590570","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320" "13:48:27.6590572","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6590696","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6590731","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6590759","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320" "13:48:27.6590839","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6590922","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cryptbase.dll","SUCCESS","" "13:48:27.6591060","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptbase.dll","SUCCESS","" "13:48:27.6591454","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:27.6594151","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6594423","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6594509","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800" "13:48:27.6594942","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win怀" "13:48:27.6595061","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800" "13:48:27.6595293","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6595418","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:27.6595573","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:27.6786002","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spinf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6786532","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6786680","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6786777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spinf.dll","SUCCESS","" "13:48:27.6788949","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6789179","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6790385","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spinf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6790818","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6790924","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976" "13:48:27.6791032","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6791098","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976" "13:48:27.6791193","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6791455","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\spinf.dll","SUCCESS","" "13:48:27.6791616","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spinf.dll","SUCCESS","" "13:48:27.6805104","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6805531","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6805817","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6805916","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:27.6807569","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6807755","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6807781","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6808022","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6808097","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6808255","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:27.6809834","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6810355","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6810497","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920" "13:48:27.6810614","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6810677","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920" "13:48:27.6810773","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6810960","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:27.6811140","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:27.6813632","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6813990","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6814098","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920" "13:48:27.6814212","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6814274","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920" "13:48:27.6814375","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6814543","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:27.6814735","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:27.6829721","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spfileq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6830160","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6830251","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6830325","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spfileq.dll","SUCCESS","" "13:48:27.6831971","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.6832126","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.6834129","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spfileq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6834450","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6834522","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264" "13:48:27.6834609","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6834747","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264" "13:48:27.6838485","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6838604","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\spfileq.dll","SUCCESS","" "13:48:27.6838849","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spfileq.dll","SUCCESS","" "13:48:27.6848873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6849423","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6849763","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6849972","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:27.6854787","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6855032","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6855119","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6855298","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:27.6855485","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6856346","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6856486","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872" "13:48:27.6856698","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6856783","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872" "13:48:27.6856905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6856996","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:27.6857118","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6857156","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:27.6857601","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6857694","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6857763","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:27.6861703","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6862206","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6862309","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6862462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6862549","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6862627","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:27.6862635","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920" "13:48:27.6862873","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6862941","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920" "13:48:27.6863041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6863129","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:27.6863269","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:27.6863551","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6863820","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6863916","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6864048","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:27.6867690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6867828","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6868059","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.6868146","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232" "13:48:27.6868211","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6868309","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6868373","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6868411","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:27.6868465","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232" "13:48:27.6868587","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6868677","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:27.6868933","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:27.6873265","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6873769","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6873885","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392" "13:48:27.6873991","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.6874054","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392" "13:48:27.6874145","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6874229","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:27.6874626","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:27.6877239","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6878021","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6878137","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904" "13:48:27.6878227","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.6878280","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904" "13:48:27.6878351","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6878421","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:27.6878620","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:27.6878666","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6879086","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.6879172","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.6879350","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:27.6886650","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.6887003","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.6887185","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128" "13:48:27.6887310","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win?" "13:48:27.6887372","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128" "13:48:27.6887455","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.6887628","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:27.6887766","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:27.7030359","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7030753","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7030866","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7030966","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:27.7033874","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7034105","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7035319","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7035800","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7035890","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592" "13:48:27.7036154","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7036233","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592" "13:48:27.7036340","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7036431","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:27.7036586","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:27.7040260","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\WindowsShell.Manifest","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:27.7040408","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\WindowsShell.Manifest","SUCCESS","AllocationSize: 4’096, EndOfFile: 670, NumberOfLinks: 4, DeletePending: False, Directory: False" "13:48:27.7060038","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msctf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7060421","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7060525","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7060604","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msctf.dll","SUCCESS","" "13:48:27.7063141","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msctf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7063507","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7063594","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240" "13:48:27.7063681","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7063732","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240" "13:48:27.7063807","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7063882","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msctf.dll","SUCCESS","" "13:48:27.7064106","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msctf.dll","SUCCESS","" "13:48:27.7140642","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7140893","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7140981","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7141145","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:27.7144992","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7145217","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.7145426","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280" "13:48:27.7145548","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7145695","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280" "13:48:27.7145813","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7145899","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:27.7146173","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:27.7148925","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7149479","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7149652","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7149770","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "13:48:27.7154325","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7154950","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.7155064","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816" "13:48:27.7155574","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7158252","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816" "13:48:27.7158815","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7159262","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\oleaut32.dll","SUCCESS","" "13:48:27.7159673","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "13:48:27.7203923","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7204151","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7204234","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7204410","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","" "13:48:27.7207056","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7207283","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7208684","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7209567","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7210020","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128" "13:48:27.7210146","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7210210","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128" "13:48:27.7210291","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7210372","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\TextInputFramework.dll","SUCCESS","" "13:48:27.7210644","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","" "13:48:27.7324914","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\Fonts\StaticCache.dat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:27.7325032","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","AllocationSize: 9’203’712, EndOfFile: 20’381’696, NumberOfLinks: 2, DeletePending: False, Directory: False" "13:48:27.7378599","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7378807","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7412452","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextShaping.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7412831","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7412953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7413214","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextShaping.dll","SUCCESS","" "13:48:27.7416000","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7416304","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7418481","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextShaping.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7418847","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ" "13:48:27.7418945","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328" "13:48:27.7419051","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.7419218","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328" "13:48:27.7419359","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7419493","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\TextShaping.dll","SUCCESS","" "13:48:27.7419674","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextShaping.dll","SUCCESS","" "13:48:27.7493089","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7493339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7493442","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7493517","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "13:48:27.7497009","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7497435","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.7497687","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584" "13:48:27.7498270","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:27.7503231","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584" "13:48:27.7503472","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7503602","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\windows.storage.dll","SUCCESS","" "13:48:27.7503768","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "13:48:27.7507536","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7507905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7507991","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7508065","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:27.7514323","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7527477","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:27.7527836","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504" "13:48:27.7527960","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7528016","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504" "13:48:27.7528098","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7528175","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:27.7528317","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:27.7560581","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7560947","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7561041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7561117","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS","" "13:48:27.7565416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7566698","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.7566820","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632" "13:48:27.7566929","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7566986","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632" "13:48:27.7567278","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7567514","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ntmarta.dll","SUCCESS","" "13:48:27.7567694","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS","" "13:48:27.7574225","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7574386","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:27.7574877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:27.7574994","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7575971","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\drivers\SET9BED.tmp","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:27.7576124","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\drivers\SET9BED.tmp","SUCCESS","AllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:27.7600356","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7600878","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7601007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7601089","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","" "13:48:27.7603229","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7603476","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7603550","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272" "13:48:27.7603631","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.7603904","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272" "13:48:27.7604018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7604099","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\CoreMessaging.dll","SUCCESS","" "13:48:27.7604232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","" "13:48:27.7636945","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7637274","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7637908","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7637996","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","" "13:48:27.7651722","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7652114","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7653998","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7655395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:27.7865004","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7871100","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drvstore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7871462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7871706","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7871826","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drvstore.dll","SUCCESS","" "13:48:27.7873186","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7876666","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7876940","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7877300","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976" "13:48:27.7877437","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7877567","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976" "13:48:27.7877682","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7877734","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7877824","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","" "13:48:27.7877996","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","" "13:48:27.7878091","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.7878182","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.7878261","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:27.7880496","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7881130","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ" "13:48:27.7881230","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496" "13:48:27.7881329","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7881460","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496" "13:48:27.7881849","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7881979","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:27.7882121","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:27.7883592","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7884133","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.7884272","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288" "13:48:27.7884391","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.7884529","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288" "13:48:27.7884661","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7884739","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:27.7885043","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:27.7887420","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.7887659","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.7889541","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drvstore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.7889922","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.7890003","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672" "13:48:27.7908322","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ" "13:48:27.7908394","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672" "13:48:27.7908499","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.7908575","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drvstore.dll","SUCCESS","" "13:48:27.7908806","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drvstore.dll","SUCCESS","" "13:48:27.8065418","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8065827","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8216806","MsMpEng.exe","3220","Thread Create","","SUCCESS","Thread ID: 9140" "13:48:27.8228289","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8228603","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8231013","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8231398","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8231492","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880" "13:48:27.8231701","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8231760","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880" "13:48:27.8231856","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8231951","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:27.8232278","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:27.8261304","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\services.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8261695","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\services.exe","SUCCESS","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A" "13:48:27.8261780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\services.exe","SUCCESS","" "13:48:27.8262905","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\services.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8263211","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\services.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ" "13:48:27.8263406","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\services.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376" "13:48:27.8263515","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\services.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8263580","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\services.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376" "13:48:27.8264144","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\services.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8264333","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\services.exe","SUCCESS","" "13:48:27.8264628","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\services.exe","SUCCESS","" "13:48:27.8346701","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8347249","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","CreationTime: 30.09.2025 13:54:23, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:23, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A" "13:48:27.8347407","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","" "13:48:27.8348586","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8349088","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\wtsapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:27.8349357","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\wtsapi32.dll","SUCCESS","SyncType: SyncTypeOther" "13:48:27.8350376","MsMpEng.exe","3220","Load Image","C:\Windows\System32\wtsapi32.dll","SUCCESS","Image Base: 0x7ff90e510000, Image Size: 0x2a000" "13:48:27.8353968","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","" "13:48:27.8368735","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\winsta.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8369175","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\winsta.dll","SUCCESS","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A" "13:48:27.8369271","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\winsta.dll","SUCCESS","" "13:48:27.8371144","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\winsta.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8371670","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\winsta.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:27.8371865","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\winsta.dll","SUCCESS","SyncType: SyncTypeOther" "13:48:27.8373002","MsMpEng.exe","3220","Load Image","C:\Windows\System32\winsta.dll","SUCCESS","Image Base: 0x7ff911100000, Image Size: 0x63000" "13:48:27.8374034","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\winsta.dll","SUCCESS","" "13:48:27.8383400","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8383833","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8383982","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8384067","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:27.8385942","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8386381","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8386472","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8386550","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:27.8398249","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8400229","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8403402","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8406491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8408413","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8411750","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8415556","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8418233","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:27.8466492","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8469234","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 263’736, Length: 4’096" "13:48:27.8469672","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 119’536, Length: 4’096" "13:48:27.8470610","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 255’496, Length: 4’096" "13:48:27.8470954","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 848’776, Length: 4’096" "13:48:27.8471154","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 115’416, Length: 4’096" "13:48:27.8471325","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 832’296, Length: 4’096" "13:48:27.8471641","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 852’896, Length: 4’096" "13:48:27.8472315","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8473085","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8473288","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8474541","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8474933","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8475541","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8475783","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8476799","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8477274","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8478381","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8478497","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8479435","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8479546","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8480213","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8480298","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8481434","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8481550","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 251’376, Length: 4’096" "13:48:27.8481846","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8517858","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8518503","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8518607","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8518700","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8518758","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8518842","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8518936","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8519222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8520017","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8520512","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.8520884","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8521704","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ" "13:48:27.8521871","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8522002","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8522130","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8526818","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8533594","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8533782","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8533950","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8534191","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8534434","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8534532","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8534621","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8534902","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8535744","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8535936","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8536028","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8540513","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8540726","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8540812","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8540891","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ" "13:48:27.8541025","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:27.8541126","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8541211","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8541921","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:27.8554461","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8554857","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.8555079","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8555210","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8555288","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:27.8556086","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 844’656, Length: 4’096" "13:48:27.8556392","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8556488","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 836’416, Length: 4’096" "13:48:27.8556589","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8556663","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8556725","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:27.8556966","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.8569509","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8570030","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8570165","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8570262","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:27.8577655","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8577965","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8578055","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8578135","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:27.8579274","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8579629","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8579715","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8579785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:27.8616801","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8617279","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8617403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8617611","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:27.8619105","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8619462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8619568","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8619654","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:27.8671965","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8672557","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8672682","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8672772","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:27.8674147","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8674461","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8674548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8674709","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:27.8679100","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8679505","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8679593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8679666","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:27.8681926","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8682651","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8682750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8682917","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:27.8684329","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8684774","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.8684871","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432" "13:48:27.8684978","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.8685157","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432" "13:48:27.8685314","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.8685436","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:27.8685886","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:27.8688099","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8688415","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8688502","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8688575","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:27.8690106","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8690348","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8690430","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8690584","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:27.8692846","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8693516","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8693647","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8693727","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:27.8694757","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8694970","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8695150","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8695220","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:27.8696145","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8696529","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8696607","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8696671","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:27.8697570","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8697836","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8697910","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8697973","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:27.8704046","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8704420","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8704503","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8704817","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:27.8706575","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8706951","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8707031","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8707099","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "13:48:27.8721067","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8721459","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8721553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8721632","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:27.8848903","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8849237","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8849359","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8849542","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "13:48:27.8885109","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8885436","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8885548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8885763","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:27.8897427","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8897723","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8897814","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8897976","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:27.8908487","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8908783","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8908875","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8909061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:27.8972384","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8972850","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8972965","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8973129","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "13:48:27.8996849","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.8997979","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.8998169","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.8998279","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "13:48:27.9025718","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9026260","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9026375","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9026457","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS","" "13:48:27.9028773","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9029077","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9029152","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912" "13:48:27.9029305","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9029375","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912" "13:48:27.9029476","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9029562","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\propsys.dll","SUCCESS","" "13:48:27.9029773","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS","" "13:48:27.9038224","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9038562","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9038752","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9038840","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS","" "13:48:27.9040821","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9041178","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(찚㈀" "13:48:27.9041312","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552" "13:48:27.9041411","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.9041467","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552" "13:48:27.9041557","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9041652","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\clbcatq.dll","SUCCESS","" "13:48:27.9041902","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS","" "13:48:27.9131771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9132194","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9132305","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9132381","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS","" "13:48:27.9134907","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9135363","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ" "13:48:27.9135771","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136" "13:48:27.9135920","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9135976","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136" "13:48:27.9136051","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9136123","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\profapi.dll","SUCCESS","" "13:48:27.9136258","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS","" "13:48:27.9393615","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9394573","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9394780","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9395134","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","" "13:48:27.9401344","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9401628","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9401721","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608" "13:48:27.9401911","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9401970","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608" "13:48:27.9402069","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9402162","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","" "13:48:27.9402454","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","" "13:48:27.9631334","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9632045","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9632372","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9632581","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS","" "13:48:27.9638337","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9638741","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9638841","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936" "13:48:27.9638934","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9638987","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936" "13:48:27.9639075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9639165","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\edputil.dll","SUCCESS","" "13:48:27.9639522","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS","" "13:48:27.9646724","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9647356","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9647594","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9647744","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS","" "13:48:27.9651470","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.9652157","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.9652887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9653151","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9653313","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9653412","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS","" "13:48:27.9653771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9654258","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9654390","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024" "13:48:27.9654648","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9654737","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024" "13:48:27.9654872","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9654988","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\urlmon.dll","SUCCESS","" "13:48:27.9655321","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS","" "13:48:27.9660518","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9660945","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9661025","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640" "13:48:27.9661107","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9661159","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640" "13:48:27.9661339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9661469","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\iertutil.dll","SUCCESS","" "13:48:27.9661615","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS","" "13:48:27.9665746","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9666171","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9666408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9666551","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS","" "13:48:27.9669618","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9670101","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:27.9670230","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080" "13:48:27.9670369","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.9670462","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080" "13:48:27.9670673","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9670824","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\srvcli.dll","SUCCESS","" "13:48:27.9671031","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS","" "13:48:27.9672008","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9672298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9672395","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9672469","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS","" "13:48:27.9676479","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9677081","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ" "13:48:27.9677225","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336" "13:48:27.9677380","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:27.9677582","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336" "13:48:27.9677731","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9677868","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\netutils.dll","SUCCESS","" "13:48:27.9678439","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS","" "13:48:27.9721593","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9722298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9722412","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9722509","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS","" "13:48:27.9725350","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9725959","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ" "13:48:27.9726070","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200" "13:48:27.9726182","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ" "13:48:27.9726320","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200" "13:48:27.9726448","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9726542","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\sspicli.dll","SUCCESS","" "13:48:27.9726707","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS","" "13:48:27.9800473","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9800961","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9801095","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9801200","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS","" "13:48:27.9803349","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.9803580","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.9805848","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9806591","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ" "13:48:27.9807015","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832" "13:48:27.9807171","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9807323","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832" "13:48:27.9807481","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9807586","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\virtdisk.dll","SUCCESS","" "13:48:27.9807769","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS","" "13:48:27.9826642","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9827308","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:27.9827539","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:27.9827648","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:27.9880251","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:27.9880560","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:27.9883606","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:27.9884272","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9884388","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056" "13:48:27.9884499","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:27.9884644","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056" "13:48:27.9884780","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:27.9884881","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:27.9885044","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:28.0042802","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\en-US\grpconv.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:28.0042927","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","AllocationSize: 4’096, EndOfFile: 3’072, NumberOfLinks: 2, DeletePending: False, Directory: False" "13:48:28.0048210","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0048550","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0048650","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0048969","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:28.0050482","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0050860","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0051060","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0051174","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:28.0055984","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0056270","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.0056356","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.0057689","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0057844","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.0058009","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.0058804","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0059048","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.0059990","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.0060720","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0060890","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.0061069","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.0061960","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.0063817","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0064082","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.0064189","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.0068237","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.0092005","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.0096665","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0096864","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.0096950","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.0097856","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.0098965","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0099148","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.0099340","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.0110987","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0111248","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0111327","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","" "13:48:28.0112696","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0112923","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0113004","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","" "13:48:28.0114297","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0114588","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0114663","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","" "13:48:28.0114915","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.0115170","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.0116491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0116657","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0116729","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","" "13:48:28.0117447","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0117768","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0117855","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:28.0117934","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0118056","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4曘;","SUCCESS","SyncType: SyncTypeOther" "13:48:28.0119523","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.0119611","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’167" "13:48:28.0120931","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0121091","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0121241","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","" "13:48:28.0121690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0121961","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0122012","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0122189","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0122329","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:28.0122461","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","AllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0122561","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:28.0122637","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","AllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0122760","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4ꗔ","SUCCESS","SyncType: SyncTypeOther" "13:48:28.0123650","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.0123759","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","BUFFER OVERFLOW","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’180" "13:48:28.0123909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0124182","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0124275","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0124364","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:28.0125050","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0125239","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.0125304","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","" "13:48:28.0126349","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0126563","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","AllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0126721","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:28.0126812","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","AllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0126940","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4뎨","SUCCESS","SyncType: SyncTypeOther" "13:48:28.0128182","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.0128270","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 87’970" "13:48:28.0128677","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","" "13:48:28.0129061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","" "13:48:28.0129452","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","" "13:48:28.0130287","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0130647","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0131316","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: RH, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0131620","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False" "13:48:28.0131707","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A" "13:48:28.0131824","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Offset: 0, Length: 68’167, Priority: Normal" "13:48:28.0136797","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0137181","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0137288","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0137374","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:28.0138794","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0139273","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0139403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0139707","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:28.0141277","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0141774","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0141871","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0142081","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:28.0143059","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0144061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","" "13:48:28.0144222","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","" "13:48:28.0144848","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0144973","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0145070","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:28.0147675","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0147962","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0148143","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0148169","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0148217","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:28.0148382","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.0148497","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","" "13:48:28.0148752","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","" "13:48:28.0149734","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0150797","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0150940","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0151036","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:28.0154734","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0155249","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0155353","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0155443","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:28.0156942","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0157157","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0157231","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0157306","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:28.0158285","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0158469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0158535","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0158597","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:28.0160074","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0160319","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0160399","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0168866","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:28.0174862","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0176858","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0177148","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0177265","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:28.0182979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0183767","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0183953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0184058","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:28.0198161","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0198546","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0198636","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0198712","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:28.0199743","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0199956","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0200038","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0200194","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:28.0201140","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0202701","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0202843","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0203061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:28.0204664","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0205163","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0205283","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0205483","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:28.0254379","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0254602","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0254695","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0254771","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:28.0257540","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0257761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0258005","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0258105","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:28.0270441","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0270816","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0270936","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0271013","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:28.0286892","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.0287268","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.0287378","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.0287457","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:28.0340751","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.0341071","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.0346317","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.0346543","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.3342979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3344175","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.3345044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3345523","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","" "13:48:28.3345903","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:28.3346020","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL" "13:48:28.3346147","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:28.3346358","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:28.3563838","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.3564103","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.3898769","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3899185","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.3899397","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3899493","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.3900002","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3900367","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.3900483","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3900732","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3901603","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3901784","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.3901853","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3902050","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.3902102","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3902190","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.3902267","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3902383","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3903599","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3903847","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.3903918","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3903994","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.3904205","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.3904454","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.3904563","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3904729","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3905725","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3905983","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.3906072","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.3907981","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wintrust.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3908339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.3908549","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.3909303","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wintrust.dll","SUCCESS","" "13:48:28.3910627","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3910981","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.3911167","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.3911292","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS","" "13:48:28.3912624","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3912986","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.3913117","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.3913213","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS","" "13:48:28.3914343","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.3914514","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.3914587","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.3914651","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4062534","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wintrust.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4063170","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.4063250","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344" "13:48:28.4063657","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win," "13:48:28.4063736","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344" "13:48:28.4064095","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4064335","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\wintrust.dll","SUCCESS","" "13:48:28.4065552","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wintrust.dll","SUCCESS","" "13:48:28.4070978","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4071431","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ" "13:48:28.4071665","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408" "13:48:28.4071832","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.4071900","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408" "13:48:28.4072064","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4072169","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\crypt32.dll","SUCCESS","" "13:48:28.4072333","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS","" "13:48:28.4073460","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4074062","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4074363","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4074449","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248" "13:48:28.4074530","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ" "13:48:28.4074658","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248" "13:48:28.4074768","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4074841","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msasn1.dll","SUCCESS","" "13:48:28.4074966","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS","" "13:48:28.4075532","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment","REPARSE","Desired Access: Read" "13:48:28.4076521","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4076751","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:28.4076830","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4076908","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4076964","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4077111","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4077213","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Desired Access: Read" "13:48:28.4077252","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4077370","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4078235","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Query: Cached, SubKeys: 0, Values: 15" "13:48:28.4078596","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4078989","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ" "13:48:28.4079086","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4079167","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4079216","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4079287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4079379","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4079578","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4079653","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 0, Type: REG_EXPAND_SZ" "13:48:28.4080685","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4081275","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4081348","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4081438","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.4081492","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.4081565","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4081602","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\ComSpec","SUCCESS","Type: REG_EXPAND_SZ, Length: 60, Data: %SystemRoot%\system32\cmd.exe" "13:48:28.4081655","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4081871","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4082884","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4083152","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4083252","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4084074","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4084385","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.4085031","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4085268","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4085447","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4086514","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4087427","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.4089002","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\DriverData","SUCCESS","Type: REG_SZ, Length: 78, Data: C:\Windows\System32\Drivers\DriverData" "13:48:28.4090547","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.4091814","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\OS","SUCCESS","Type: REG_SZ, Length: 22, Data: Windows_NT" "13:48:28.4093401","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 3, Type: REG_EXPAND_SZ" "13:48:28.4095410","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path","BUFFER OVERFLOW","Length: 144" "13:48:28.4095466","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4096645","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path","SUCCESS","Type: REG_EXPAND_SZ, Length: 514, Data: " "13:48:28.4097914","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.4099007","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PATHEXT","SUCCESS","Type: REG_SZ, Length: 108, Data: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC" "13:48:28.4099163","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.4100824","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.4101942","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_ARCHITECTURE","SUCCESS","Type: REG_SZ, Length: 12, Data: AMD64" "13:48:28.4103225","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 6, Type: REG_EXPAND_SZ" "13:48:28.4104192","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath","BUFFER OVERFLOW","Length: 144" "13:48:28.4106832","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 188, Data: " "13:48:28.4108727","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 7, Type: REG_EXPAND_SZ" "13:48:28.4111180","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TEMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP" "13:48:28.4114699","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 8, Type: REG_EXPAND_SZ" "13:48:28.4119680","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP" "13:48:28.4121491","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.4122589","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\USERNAME","SUCCESS","Type: REG_SZ, Length: 14, Data: SYSTEM" "13:48:28.4123776","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 10, Type: REG_EXPAND_SZ" "13:48:28.4124750","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\windir","SUCCESS","Type: REG_EXPAND_SZ, Length: 26, Data: %SystemRoot%" "13:48:28.4126314","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 11, Type: REG_SZ" "13:48:28.4127466","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\NUMBER_OF_PROCESSORS","SUCCESS","Type: REG_SZ, Length: 4, Data: 4" "13:48:28.4129272","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 12, Type: REG_SZ" "13:48:28.4130339","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_LEVEL","SUCCESS","Type: REG_SZ, Length: 6, Data: 25" "13:48:28.4131439","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 13, Type: REG_SZ" "13:48:28.4132525","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_IDENTIFIER","SUCCESS","Type: REG_SZ, Length: 100, Data: AMD64 Family 25 Model 33 Stepping 0, AuthenticAMD" "13:48:28.4133289","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 14, Type: REG_SZ" "13:48:28.4134232","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_REVISION","SUCCESS","Type: REG_SZ, Length: 10, Data: 2100" "13:48:28.4135187","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","" "13:48:28.4136168","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4144746","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SFC","REPARSE","Desired Access: Read" "13:48:28.4145954","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\SFC","NAME NOT FOUND","Desired Access: Read" "13:48:28.4147199","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4148243","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion","SUCCESS","Desired Access: Read" "13:48:28.4149953","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Query: Cached, SubKeys: 167, Values: 11" "13:48:28.4152459","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.4154152","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\Program Files" "13:48:28.4156536","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.4159412","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files" "13:48:28.4161412","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4161750","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4161887","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4162088","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4163839","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4164077","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.4164790","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.4166301","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Program Files (x86)" "13:48:28.4166895","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4167274","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.4168452","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)","SUCCESS","Type: REG_SZ, Length: 72, Data: C:\Program Files (x86)\Common Files" "13:48:28.4170713","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.4172534","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files" "13:48:28.4174126","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 5, Type: REG_EXPAND_SZ" "13:48:28.4176792","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 34, Data: %SystemRoot%\inf" "13:48:28.4178130","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 6, Type: REG_EXPAND_SZ" "13:48:28.4179072","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MediaPathUnexpanded","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %SystemRoot%\Media" "13:48:28.4179942","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 7, Type: REG_EXPAND_SZ" "13:48:28.4181129","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesPath","SUCCESS","Type: REG_EXPAND_SZ, Length: 30, Data: %ProgramFiles%" "13:48:28.4182246","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.4183162","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\Program Files" "13:48:28.4184081","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.4185178","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_ConfigureProgramsName","SUCCESS","Type: REG_SZ, Length: 64, Data: Set Program Access and Defaults" "13:48:28.4186417","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 10, Type: REG_SZ" "13:48:28.4187391","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_GamesName","SUCCESS","Type: REG_SZ, Length: 12, Data: Games" "13:48:28.4189601","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","" "13:48:28.4190797","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4191727","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Desired Access: Read" "13:48:28.4192705","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: Cached, SubKeys: 4, Values: 4" "13:48:28.4193577","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 0, Type: REG_EXPAND_SZ" "13:48:28.4194418","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A" "13:48:28.4194487","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","AllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.4195080","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.4197308","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’510’848, Length: 7’384, Priority: Normal" "13:48:28.4197999","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’506’752, Length: 4’096, Priority: Normal" "13:48:28.4200447","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 4’096, Length: 520’192, Priority: Normal" "13:48:28.4213650","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %SystemDrive%\Users\Default" "13:48:28.4214361","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 1, Type: REG_EXPAND_SZ" "13:48:28.4215221","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory","SUCCESS","Type: REG_EXPAND_SZ, Length: 40, Data: %SystemDrive%\Users" "13:48:28.4216075","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 2, Type: REG_EXPAND_SZ" "13:48:28.4216941","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData","SUCCESS","Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData" "13:48:28.4217760","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 3, Type: REG_EXPAND_SZ" "13:48:28.4218530","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public","SUCCESS","Type: REG_EXPAND_SZ, Length: 54, Data: %SystemDrive%\Users\Public" "13:48:28.4219514","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","" "13:48:28.4221313","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4222249","MsMpEng.exe","3220","RegCreateKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "13:48:28.4223180","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: Cached, SubKeys: 4, Values: 4" "13:48:28.4224012","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 0, Name: S-1-5-18" "13:48:28.4224820","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4225533","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","Desired Access: Read" "13:48:28.4226493","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile" "13:48:28.4228042","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4228791","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4229713","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4230427","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4230629","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\config\systemprofile","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4230704","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\config\systemprofile","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D, AllocationSize: 0, EndOfFile: 0" "13:48:28.4231071","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\config\systemprofile\ntuser.dat","NO SUCH FILE","FileInformationClass: FileIdFullDirectoryInformation, Filter: ntuser.dat" "13:48:28.4231256","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\config\systemprofile","SUCCESS","" "13:48:28.4232891","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4233149","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","" "13:48:28.4243416","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 524’288, Length: 524’288, Priority: Normal" "13:48:28.4244103","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 1, Name: S-1-5-19" "13:48:28.4249018","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4250263","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19","SUCCESS","Desired Access: Read" "13:48:28.4251111","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 84, Data: %systemroot%\ServiceProfiles\LocalService" "13:48:28.4253192","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4253529","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.4253621","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","" "13:48:28.4254391","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4254585","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A" "13:48:28.4254748","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","" "13:48:28.4256222","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4256454","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19","SUCCESS","" "13:48:28.4257623","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 2, Name: S-1-5-20" "13:48:28.4258432","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4259287","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20","SUCCESS","Desired Access: Read" "13:48:28.4260427","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 88, Data: %systemroot%\ServiceProfiles\NetworkService" "13:48:28.4263013","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4263369","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.4263451","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","" "13:48:28.4264220","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4264481","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A" "13:48:28.4264585","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","" "13:48:28.4265934","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4266165","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20","SUCCESS","" "13:48:28.4266730","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’048’576, Length: 524’288, Priority: Normal" "13:48:28.4268823","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 3, Name: S-1-5-21-4172013786-3171869251-2938521833-1000" "13:48:28.4269624","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4270477","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Desired Access: Read" "13:48:28.4271583","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 32, Data: C:\Users\hacker" "13:48:28.4273472","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4273808","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: HANCI" "13:48:28.4273875","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","" "13:48:28.4275274","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4275571","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, FileAttributes: HANCI" "13:48:28.4275853","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","" "13:48:28.4277164","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4277425","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS","CreationTime: 12.08.2025 19:42:01, LastAccessTime: 13.10.2025 13:32:41, LastWriteTime: 12.08.2025 19:42:01, ChangeTime: 12.08.2025 19:42:01, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: D" "13:48:28.4277490","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS","" "13:48:28.4278028","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","" "13:48:28.4278821","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","" "13:48:28.4279826","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4280614","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:28.4281164","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:28.4282185","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:28.4282944","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4283872","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:28.4285679","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:28.4286557","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4287260","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Read" "13:48:28.4287863","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 12" "13:48:28.4288690","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.4289558","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools","BUFFER OVERFLOW","Length: 144" "13:48:28.4290272","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools","SUCCESS","Type: REG_SZ, Length: 148, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools" "13:48:28.4290763","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.4291735","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData","SUCCESS","Type: REG_SZ, Length: 30, Data: C:\ProgramData" "13:48:28.4292670","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.4293966","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Desktop","SUCCESS","Type: REG_SZ, Length: 48, Data: C:\Users\Public\Desktop" "13:48:28.4295015","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.4295811","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Documents","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\Public\Documents" "13:48:28.4297692","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.4299565","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Programs","SUCCESS","Type: REG_SZ, Length: 106, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs" "13:48:28.4300556","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.4301819","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\ProgramData\Microsoft\Windows\Start Menu" "13:48:28.4302873","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 6, Type: REG_SZ" "13:48:28.4303502","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup" "13:48:28.4304065","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 7, Type: REG_SZ" "13:48:28.4304453","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Templates","SUCCESS","Type: REG_SZ, Length: 86, Data: C:\ProgramData\Microsoft\Windows\Templates" "13:48:28.4305291","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.4305746","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusic","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\Public\Music" "13:48:28.4306404","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.4306780","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPictures","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\Public\Pictures" "13:48:28.4307358","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 10, Type: REG_SZ" "13:48:28.4307971","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideo","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Users\Public\Videos" "13:48:28.4308607","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 11, Type: REG_SZ" "13:48:28.4309026","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\OEM Links","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\ProgramData\OEM\Links" "13:48:28.4309918","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "13:48:28.4310712","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.4311488","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read" "13:48:28.4312410","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Query: Cached, SubKeys: 1, Values: 11" "13:48:28.4313617","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 0, Type: REG_EXPAND_SZ" "13:48:28.4314059","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 28, Data: %ProgramData%" "13:48:28.4314964","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 1, Type: REG_EXPAND_SZ" "13:48:28.4315793","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Desktop","SUCCESS","Type: REG_EXPAND_SZ, Length: 34, Data: %PUBLIC%\Desktop" "13:48:28.4316446","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 2, Type: REG_EXPAND_SZ" "13:48:28.4316960","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Documents","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Documents" "13:48:28.4317255","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 3, Type: REG_EXPAND_SZ" "13:48:28.4317660","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs","SUCCESS","Type: REG_EXPAND_SZ, Length: 104, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs" "13:48:28.4318276","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 4, Type: REG_EXPAND_SZ" "13:48:28.4318622","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Start Menu","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %ProgramData%\Microsoft\Windows\Start Menu" "13:48:28.4319047","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 5, Type: REG_EXPAND_SZ" "13:48:28.4319574","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Startup","SUCCESS","Type: REG_EXPAND_SZ, Length: 120, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup" "13:48:28.4320504","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 6, Type: REG_EXPAND_SZ" "13:48:28.4321108","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Templates","SUCCESS","Type: REG_EXPAND_SZ, Length: 84, Data: %ProgramData%\Microsoft\Windows\Templates" "13:48:28.4321768","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 7, Type: REG_EXPAND_SZ" "13:48:28.4322428","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonMusic","SUCCESS","Type: REG_EXPAND_SZ, Length: 30, Data: %PUBLIC%\Music" "13:48:28.4323192","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 8, Type: REG_EXPAND_SZ" "13:48:28.4323704","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonPictures","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %PUBLIC%\Pictures" "13:48:28.4324145","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 9, Type: REG_EXPAND_SZ" "13:48:28.4324526","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonVideo","SUCCESS","Type: REG_EXPAND_SZ, Length: 32, Data: %PUBLIC%\Videos" "13:48:28.4325872","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 10, Type: REG_EXPAND_SZ" "13:48:28.4326543","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Downloads" "13:48:28.4327177","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","" "13:48:28.4329686","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4329878","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.4329947","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4330808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4331008","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4331079","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4331154","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4331211","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4331609","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4331753","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4332059","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4332784","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4332948","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.4333103","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4333380","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4333455","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4333560","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4333654","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4333878","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4334828","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4335090","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:28.4335188","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4335268","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.4335337","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.4335411","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4336662","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4336931","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4337882","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4338155","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.4338267","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4339536","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4339669","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.4339729","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.4341558","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4341883","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.4342808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4343140","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A" "13:48:28.4343208","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.4345916","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.4346264","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.4348375","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372’736, Length: 6’144, Priority: Normal" "13:48:28.4348629","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 376’832, Length: 2’048, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4383576","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’572’864, Length: 524’288, Priority: Normal" "13:48:28.4403465","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’097’152, Length: 421’080, Priority: Normal" "13:48:28.4424770","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.4425339","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4430154","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.4436904","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 4’096, Length: 262’144, Priority: Normal" "13:48:28.4445385","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 266’240, Length: 258’048, Priority: Normal" "13:48:28.4449553","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 524’288, Length: 4’096, Priority: Normal" "13:48:28.4462681","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 528’384, Length: 262’144, Priority: Normal" "13:48:28.4490840","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 790’528, Length: 258’048, Priority: Normal" "13:48:28.4494464","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’048’576, Length: 4’096, Priority: Normal" "13:48:28.4515156","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’052’672, Length: 262’144, Priority: Normal" "13:48:28.4534980","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’314’816, Length: 258’048, Priority: Normal" "13:48:28.4548680","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’572’864, Length: 4’096, Priority: Normal" "13:48:28.4712170","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’576’960, Length: 262’144, Priority: Normal" "13:48:28.4717004","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270’336, Length: 4’096, Priority: Normal" "13:48:28.4717113","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270’336, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4754079","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1’839’104, Length: 258’048, Priority: Normal" "13:48:28.4755787","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’097’152, Length: 4’096, Priority: Normal" "13:48:28.4756729","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274’432, Length: 4’096, Priority: Normal" "13:48:28.4757056","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274’432, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4782713","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81’920, Length: 4’096, Priority: Normal" "13:48:28.4782805","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81’920, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4799448","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299’008, Length: 4’096, Priority: Normal" "13:48:28.4800188","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266’240, Length: 8’192, Priority: Normal" "13:48:28.4800254","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266’240, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4803941","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184’320, Length: 8’192, Priority: Normal" "13:48:28.4805170","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184’320, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4811251","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86’016, Length: 4’096, Priority: Normal" "13:48:28.4811442","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86’016, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4814332","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’101’248, Length: 262’144, Priority: Normal" "13:48:28.4814413","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258’048, Length: 8’192, Priority: Normal" "13:48:28.4814503","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258’048, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4829081","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:28.4829172","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4’096, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4844314","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2’363’392, Length: 147’456, Priority: Normal" "13:48:28.4847561","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192’512, Length: 4’096, Priority: Normal" "13:48:28.4847635","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192’512, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4907578","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278’528, Length: 4’096, Priority: Normal" "13:48:28.4907659","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278’528, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4909934","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282’624, Length: 4’096, Priority: Normal" "13:48:28.4910086","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282’624, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4914409","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303’104, Length: 4’096, Priority: Normal" "13:48:28.4914889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307’200, Length: 8’192, Priority: Normal" "13:48:28.4914958","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 311’296, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.4917225","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.4997512","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5004346","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.5005107","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5005522","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","" "13:48:28.5005841","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:28.5005935","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL" "13:48:28.5006036","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:28.5006223","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:28.5010695","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286’720, Length: 12’288, Priority: Normal" "13:48:28.5010797","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286’720, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5011187","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5011355","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","NO EAS ON FILE","" "13:48:28.5012298","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5012525","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.5012596","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.5012676","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.5012816","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232" "13:48:28.5012920","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.5013032","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5014134","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5014255","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5015104","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5015555","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5015875","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","" "13:48:28.5023434","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90’112, Length: 16’384, Priority: Normal" "13:48:28.5023527","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90’112, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5050418","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180’224, Length: 4’096, Priority: Normal" "13:48:28.5050503","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180’224, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5154011","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122’880, Length: 8’192, Priority: Normal" "13:48:28.5154100","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122’880, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5157404","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131’072, Length: 4’096, Priority: Normal" "13:48:28.5157490","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131’072, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5216395","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151’552, Length: 8’192, Priority: Normal" "13:48:28.5216482","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151’552, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5220309","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159’744, Length: 4’096, Priority: Normal" "13:48:28.5220402","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159’744, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5224797","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118’784, Length: 8’192, Priority: Normal" "13:48:28.5224958","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118’784, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5229576","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135’168, Length: 8’192, Priority: Normal" "13:48:28.5229661","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135’168, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5233907","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196’608, Length: 4’096, Priority: Normal" "13:48:28.5233984","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196’608, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5816734","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147’456, Length: 8’192, Priority: Normal" "13:48:28.5817915","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147’456, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5859428","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.5859767","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.5861841","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5862274","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.5862526","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504" "13:48:28.5862732","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.5862836","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504" "13:48:28.5863043","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.5863134","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:28.5863462","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:28.5900437","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143’360, Length: 8’192, Priority: Normal" "13:48:28.5900552","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143’360, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5920450","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176’128, Length: 8’192, Priority: Normal" "13:48:28.5920547","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176’128, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.5947811","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5948617","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.5948958","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.5949062","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:28.5950322","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.5950735","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.5950857","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.5950943","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:28.5981343","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167’936, Length: 8’192, Priority: Normal" "13:48:28.5981508","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167’936, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.6070772","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6071160","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6071286","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6071369","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:28.6121278","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6122298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6122424","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6123531","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:28.6129480","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6129924","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6130017","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6130097","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:28.6132184","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6132582","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6132671","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6132841","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:28.6136157","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6136602","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6136698","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6136777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:28.6189603","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6189920","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6190007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6190193","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:28.6193094","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6193913","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6194041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6194224","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:28.6200416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6200739","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6200819","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6200891","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:28.6212853","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6213403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6213520","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6213599","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS","" "13:48:28.6218875","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8’192, Length: 4’096, Priority: Normal" "13:48:28.6219066","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8’192, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.6245301","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49’152, Length: 8’192, Priority: Normal" "13:48:28.6245410","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49’152, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.6250414","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12’288, Length: 16’384, Priority: Normal" "13:48:28.6250541","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12’288, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.6256793","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106’496, Length: 4’096, Priority: Normal" "13:48:28.6256954","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106’496, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.6300488","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6300824","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6300998","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6301108","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:28.6358922","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6359349","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6359469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6359549","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:28.6363891","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6364245","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6364335","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6364409","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:28.6366093","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6366539","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6366632","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6366716","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:28.6369623","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6370018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6370107","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6370179","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:28.6371212","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6371417","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6371494","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6371563","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:28.6413040","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6413435","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6413543","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6413623","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:28.6433909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6434593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6434799","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6435026","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:28.6563799","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\thumbcache.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6564041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6564125","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6564202","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\thumbcache.dll","SUCCESS","" "13:48:28.6566489","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.6566744","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.6567824","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\thumbcache.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6568138","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ" "13:48:28.6568215","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176" "13:48:28.6568301","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ" "13:48:28.6568355","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176" "13:48:28.6568436","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.6568586","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\thumbcache.dll","SUCCESS","" "13:48:28.6568792","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\thumbcache.dll","SUCCESS","" "13:48:28.6625567","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6626091","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6626200","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6626280","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS","" "13:48:28.6659004","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.6659286","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.6842378","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6842833","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6842958","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6843267","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.6844439","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6844901","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.6845007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.6866075","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:28.6898340","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.6898609","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.6909623","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.6909946","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.6910272","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.6910507","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 675’736, Length: 4’096" "13:48:28.6910773","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.6910890","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.6995947","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77’824, Length: 8’192, Priority: Normal" "13:48:28.6996076","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77’824, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.7001719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7002146","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7002287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7002369","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:28.7003416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7003644","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7003721","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7003787","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:28.7036676","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7037841","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7038049","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7038133","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:28.7075571","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7076064","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7076191","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7076271","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp140.dll","SUCCESS","" "13:48:28.7078366","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7078541","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7080516","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7080833","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7080951","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728" "13:48:28.7081031","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7081083","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728" "13:48:28.7081175","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7081348","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcp140.dll","SUCCESS","" "13:48:28.7081504","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp140.dll","SUCCESS","" "13:48:28.7084358","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7084673","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7084759","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7084831","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","" "13:48:28.7086279","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7086543","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7089639","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7089869","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7090026","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544" "13:48:28.7090163","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7090222","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544" "13:48:28.7090296","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7090383","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\vcruntime140.dll","SUCCESS","" "13:48:28.7090514","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","" "13:48:28.7093326","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7093662","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7093815","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7093894","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","" "13:48:28.7095300","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7095431","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7096549","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7097119","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7097224","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792" "13:48:28.7097395","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7097472","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792" "13:48:28.7097553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7097652","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","" "13:48:28.7097785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","" "13:48:28.7132480","MsMpEng.exe","3220","Thread Create","","SUCCESS","Thread ID: 7424" "13:48:28.7136831","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7137169","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","CreationTime: 10.10.2025 15:34:53, LastAccessTime: 13.10.2025 13:27:12, LastWriteTime: 13.10.2025 11:45:59, ChangeTime: 13.10.2025 11:45:59, FileAttributes: A" "13:48:28.7137235","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","" "13:48:28.7137960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7138149","MsMpEng.exe","3220","CreateFileMapping","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "13:48:28.7139295","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","" "13:48:28.7139676","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Offset: 46’080, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.7140155","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Offset: 153’088, Length: 45’056, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.7146151","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7146334","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:28.7146598","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7149542","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7149905","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7149994","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7150074","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7150132","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7150305","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7150408","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7150544","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7151310","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7151659","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7151768","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7151861","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7151914","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7151998","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7152173","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7152292","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7153061","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7153490","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7153616","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7153696","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:28.7153752","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7153961","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7154069","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7154236","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7155815","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7156119","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7156222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7156390","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","AllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.7156578","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)" "13:48:28.7156678","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.7161664","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","" "13:48:28.7163940","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7164226","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7164830","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7165135","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7165240","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:28.7165336","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7165420","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7166074","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:28.7193027","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:28.7193162","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7193270","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7194074","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7194339","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 222’536, Length: 4’096" "13:48:28.7194587","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 86’576, Length: 4’096" "13:48:28.7194836","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 700’456, Length: 4’096" "13:48:28.7195263","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7196113","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28’672, Length: 350’208, Priority: Normal" "13:48:28.7196377","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28’672, Length: 344’064, I/O Flags: Non-cached, Paging I/O, Priority: Normal" "13:48:28.7205235","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Setup","SUCCESS","Desired Access: Read" "13:48:28.7205392","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\MinimizeFootprint","NAME NOT FOUND","Length: 20" "13:48:28.7205696","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup","SUCCESS","" "13:48:28.7205905","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)" "13:48:28.7206014","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.7212630","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","AllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.7213481","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)" "13:48:28.7213990","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.7218911","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7218980","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","" "13:48:28.7230054","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)" "13:48:28.7230162","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.7238717","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","" "13:48:28.7239752","MsMpEng.exe","3220","Thread Exit","","SUCCESS","Thread ID: 7424, User Time: 0.0000000, Kernel Time: 0.0000000" "13:48:28.7241532","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7241967","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.7242057","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.7243988","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7244757","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.7244921","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.7247909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7248278","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.7250488","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7252960","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7253216","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.7253306","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.7254538","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7258632","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7258887","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.7258979","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7259076","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7259496","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7259638","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7259728","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:28.7260887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7261202","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7261376","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.7261461","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:28.7266267","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.7267873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7268679","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7268898","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.7268982","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.7270382","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7272135","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7272541","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.7272669","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7281850","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.7282154","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7283620","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7283798","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.7283967","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.7285158","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7285332","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.7285405","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.7286659","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7287031","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.7288092","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7289418","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7289649","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.7289830","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.7290740","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7294544","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7294795","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.7295194","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7297893","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.7299503","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7300319","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7300500","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.7300712","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.7302044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.7303356","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7303686","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.7303775","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7315119","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.7315303","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.7316001","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7317051","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7317283","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 45’376, Length: 4’096" "13:48:28.7317708","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7318043","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7318144","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 181’336, Length: 4’096" "13:48:28.7318359","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7318589","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7318657","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:28.7319331","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 856’992, Length: 24" "13:48:28.7319481","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 857’016, Length: 4’096" "13:48:28.7319793","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 861’112, Length: 24" "13:48:28.7319887","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 861’136, Length: 4’096" "13:48:28.7320071","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:28.7320148","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7323135","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7323495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7351906","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7352136","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NO EAS ON FILE","" "13:48:28.7357756","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7357981","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7359235","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:28.7360628","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\SET9BED.tmp","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.7361289","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7361395","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.7361504","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.7361645","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Query: Cached, SubKeys: 0, Values: 35" "13:48:28.7361817","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.7361917","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE","SUCCESS","Type: REG_SZ, Length: 2, Data: " "13:48:28.7362029","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.7362091","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE" "13:48:28.7362173","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.7362226","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM","SUCCESS","Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM" "13:48:28.7362296","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.7362428","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000","SUCCESS","Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD" "13:48:28.7362550","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.7362607","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT","SUCCESS","Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT" "13:48:28.7362782","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.7362838","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY" "13:48:28.7362914","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 6, Type: REG_SZ" "13:48:28.7363063","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM","SUCCESS","Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM" "13:48:28.7363142","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 7, Type: REG_SZ" "13:48:28.7363197","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","BUFFER OVERFLOW","Length: 144" "13:48:28.7363437","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","SUCCESS","Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT" "13:48:28.7363651","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.7363736","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","BUFFER OVERFLOW","Length: 144" "13:48:28.7363808","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","SUCCESS","Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT" "13:48:28.7363907","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.7363969","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:28.7364096","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7364235","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:28.7364379","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.7364664","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7364866","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read" "13:48:28.7365361","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local" "13:48:28.7365535","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","" "13:48:28.7365765","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7365866","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.7365964","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.7366071","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Query: Cached, SubKeys: 0, Values: 35" "13:48:28.7366182","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.7366435","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE","SUCCESS","Type: REG_SZ, Length: 2, Data: " "13:48:28.7366549","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.7366675","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE" "13:48:28.7366792","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.7366858","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM","SUCCESS","Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM" "13:48:28.7366926","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.7367133","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000","SUCCESS","Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD" "13:48:28.7367285","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.7367630","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT","SUCCESS","Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT" "13:48:28.7368103","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.7368282","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY" "13:48:28.7368407","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 6, Type: REG_SZ" "13:48:28.7368468","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM","SUCCESS","Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM" "13:48:28.7368549","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 7, Type: REG_SZ" "13:48:28.7368603","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","BUFFER OVERFLOW","Length: 144" "13:48:28.7368747","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","SUCCESS","Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT" "13:48:28.7368898","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.7368959","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","BUFFER OVERFLOW","Length: 144" "13:48:28.7369027","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","SUCCESS","Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT" "13:48:28.7369121","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.7369183","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:28.7369276","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","BUFFER OVERFLOW","Index: 10, Length: 144" "13:48:28.7369408","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 10, Type: REG_SZ" "13:48:28.7370464","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:28.7370642","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:28.7370973","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7371065","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:28.7371213","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.7371423","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7371523","MsMpEng.exe","3220","RegOpenKey","HKCU\Environment","SUCCESS","Desired Access: Read" "13:48:28.7371638","MsMpEng.exe","3220","RegQueryKey","HKCU\Environment","SUCCESS","Query: Cached, SubKeys: 0, Values: 4" "13:48:28.7371713","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 0, Type: REG_EXPAND_SZ" "13:48:28.7371785","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\Path","BUFFER OVERFLOW","Length: 144" "13:48:28.7371873","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\Path","SUCCESS","Type: REG_EXPAND_SZ, Length: 156, Data: " "13:48:28.7372078","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 1, Type: REG_EXPAND_SZ" "13:48:28.7372155","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\TEMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp" "13:48:28.7372286","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 2, Type: REG_EXPAND_SZ" "13:48:28.7372340","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\TMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp" "13:48:28.7372429","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 3, Type: REG_EXPAND_SZ" "13:48:28.7372484","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\OneDrive","SUCCESS","Type: REG_EXPAND_SZ, Length: 50, Data: C:\Users\hacker\OneDrive" "13:48:28.7372658","MsMpEng.exe","3220","RegCloseKey","HKCU\Environment","SUCCESS","" "13:48:28.7372761","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7372831","MsMpEng.exe","3220","RegOpenKey","HKCU\Volatile Environment","SUCCESS","Desired Access: Read" "13:48:28.7372942","MsMpEng.exe","3220","RegQueryKey","HKCU\Volatile Environment","SUCCESS","Query: Cached, SubKeys: 1, Values: 9" "13:48:28.7373007","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.7373073","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\LOGONSERVER","SUCCESS","Type: REG_SZ, Length: 24, Data: \\WINDOWS11" "13:48:28.7373233","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.7373304","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERDOMAIN","SUCCESS","Type: REG_SZ, Length: 20, Data: WINDOWS11" "13:48:28.7373403","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.7373459","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERNAME","SUCCESS","Type: REG_SZ, Length: 14, Data: hacker" "13:48:28.7373543","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.7373596","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERPROFILE","SUCCESS","Type: REG_SZ, Length: 32, Data: C:\Users\hacker" "13:48:28.7373675","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.7373729","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\HOMEPATH","SUCCESS","Type: REG_SZ, Length: 28, Data: \Users\hacker" "13:48:28.7373876","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.7373954","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\HOMEDRIVE","SUCCESS","Type: REG_SZ, Length: 6, Data: C:" "13:48:28.7374048","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 6, Type: REG_SZ" "13:48:28.7374602","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\APPDATA","SUCCESS","Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming" "13:48:28.7374867","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 7, Type: REG_SZ" "13:48:28.7374960","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\LOCALAPPDATA","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local" "13:48:28.7375067","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.7375128","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERDOMAIN_ROAMINGPROFILE","SUCCESS","Type: REG_SZ, Length: 20, Data: WINDOWS11" "13:48:28.7375255","MsMpEng.exe","3220","RegCloseKey","HKCU\Volatile Environment","SUCCESS","" "13:48:28.7375356","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7375514","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Read" "13:48:28.7375801","MsMpEng.exe","3220","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 31" "13:48:28.7375873","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 0, Type: REG_SZ" "13:48:28.7375941","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\!Do not use this registry key","SUCCESS","Type: REG_SZ, Length: 130, Data: Use the SHGetFolderPath or SHGetKnownFolderPath function instead" "13:48:28.7376117","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 1, Type: REG_SZ" "13:48:28.7376185","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData","SUCCESS","Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming" "13:48:28.7376286","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 2, Type: REG_SZ" "13:48:28.7376346","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Local AppData","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local" "13:48:28.7376426","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 3, Type: REG_SZ" "13:48:28.7376482","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CD Burning","SUCCESS","Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\Burn\Burn" "13:48:28.7376562","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 4, Type: REG_SZ" "13:48:28.7376682","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Libraries" "13:48:28.7376787","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 5, Type: REG_SZ" "13:48:28.7376842","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Video","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Users\hacker\Videos" "13:48:28.7376922","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 6, Type: REG_SZ" "13:48:28.7376975","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Pictures","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Pictures" "13:48:28.7377062","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 7, Type: REG_SZ" "13:48:28.7377114","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop","SUCCESS","Type: REG_SZ, Length: 48, Data: C:\Users\hacker\Desktop" "13:48:28.7377189","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 8, Type: REG_SZ" "13:48:28.7377296","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History","SUCCESS","Type: REG_SZ, Length: 112, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\History" "13:48:28.7377399","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 9, Type: REG_SZ" "13:48:28.7377453","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood","BUFFER OVERFLOW","Length: 144" "13:48:28.7377519","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood","SUCCESS","Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Network Shortcuts" "13:48:28.7377597","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 10, Type: REG_SZ" "13:48:28.7377654","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Contacts" "13:48:28.7377739","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 11, Type: REG_SZ" "13:48:28.7377795","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{00BCFC5A-ED94-4E48-96A1-3F6217F21990}","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\RoamingTiles" "13:48:28.7377938","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 12, Type: REG_SZ" "13:48:28.7378002","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCookies" "13:48:28.7378085","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 13, Type: REG_SZ" "13:48:28.7378138","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Favorites","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Favorites" "13:48:28.7378216","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 14, Type: REG_SZ" "13:48:28.7378268","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\SendTo","SUCCESS","Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\SendTo" "13:48:28.7378341","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 15, Type: REG_SZ" "13:48:28.7378394","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu" "13:48:28.7378543","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 16, Type: REG_SZ" "13:48:28.7378605","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Music","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Music" "13:48:28.7378687","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 17, Type: REG_SZ" "13:48:28.7378739","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs","BUFFER OVERFLOW","Length: 144" "13:48:28.7378805","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs","SUCCESS","Type: REG_SZ, Length: 140, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" "13:48:28.7378882","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 18, Type: REG_SZ" "13:48:28.7378936","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Recent","SUCCESS","Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Recent" "13:48:28.7379012","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 19, Type: REG_SZ" "13:48:28.7379117","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood","BUFFER OVERFLOW","Length: 144" "13:48:28.7379201","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood","SUCCESS","Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" "13:48:28.7379285","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 20, Type: REG_SZ" "13:48:28.7379342","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Searches" "13:48:28.7379433","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 21, Type: REG_SZ" "13:48:28.7379487","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Downloads" "13:48:28.7379572","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 22, Type: REG_SZ" "13:48:28.7379625","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{A520A1A4-1780-4FF6-BD18-167343C5AF16}","SUCCESS","Type: REG_SZ, Length: 66, Data: C:\Users\hacker\AppData\LocalLow" "13:48:28.7379771","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 23, Type: REG_SZ" "13:48:28.7379832","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup","BUFFER OVERFLOW","Length: 144" "13:48:28.7379912","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup","SUCCESS","Type: REG_SZ, Length: 156, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" "13:48:28.7379995","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 24, Type: REG_SZ" "13:48:28.7380049","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools","BUFFER OVERFLOW","Length: 144" "13:48:28.7380114","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools","SUCCESS","Type: REG_SZ, Length: 182, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools" "13:48:28.7380196","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 25, Type: REG_SZ" "13:48:28.7380250","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Documents" "13:48:28.7380396","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 26, Type: REG_SZ" "13:48:28.7380457","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Links" "13:48:28.7380544","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 27, Type: REG_SZ" "13:48:28.7380596","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCache" "13:48:28.7380692","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 28, Type: REG_SZ" "13:48:28.7380745","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Templates","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Templates" "13:48:28.7380821","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 29, Type: REG_SZ" "13:48:28.7380931","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}","SUCCESS","Type: REG_SZ, Length: 56, Data: C:\Users\hacker\Saved Games" "13:48:28.7381039","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 30, Type: REG_SZ" "13:48:28.7381096","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Fonts","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\WINDOWS\Fonts" "13:48:28.7381198","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "13:48:28.7381281","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7381357","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read" "13:48:28.7381460","MsMpEng.exe","3220","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 20" "13:48:28.7381591","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 0, Type: REG_EXPAND_SZ" "13:48:28.7381665","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming" "13:48:28.7381763","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 1, Type: REG_EXPAND_SZ" "13:48:28.7381819","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache","SUCCESS","Type: REG_EXPAND_SZ, Length: 112, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache" "13:48:28.7382524","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 2, Type: REG_EXPAND_SZ" "13:48:28.7382629","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies","SUCCESS","Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies" "13:48:28.7382839","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 3, Type: REG_EXPAND_SZ" "13:48:28.7382909","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop","SUCCESS","Type: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop" "13:48:28.7383003","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 4, Type: REG_EXPAND_SZ" "13:48:28.7383057","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Favorites" "13:48:28.7383137","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 5, Type: REG_EXPAND_SZ" "13:48:28.7383190","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\History","SUCCESS","Type: REG_EXPAND_SZ, Length: 108, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\History" "13:48:28.7383272","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 6, Type: REG_EXPAND_SZ" "13:48:28.7383395","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local" "13:48:28.7383514","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 7, Type: REG_EXPAND_SZ" "13:48:28.7383579","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music","SUCCESS","Type: REG_EXPAND_SZ, Length: 40, Data: %USERPROFILE%\Music" "13:48:28.7383658","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 8, Type: REG_EXPAND_SZ" "13:48:28.7383712","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: %USERPROFILE%\Pictures" "13:48:28.7383789","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 9, Type: REG_EXPAND_SZ" "13:48:28.7383841","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video","SUCCESS","Type: REG_EXPAND_SZ, Length: 42, Data: %USERPROFILE%\Videos" "13:48:28.7384017","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 10, Type: REG_EXPAND_SZ" "13:48:28.7384099","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\NetHood","SUCCESS","Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" "13:48:28.7384197","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 11, Type: REG_EXPAND_SZ" "13:48:28.7384259","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Documents" "13:48:28.7384359","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 12, Type: REG_EXPAND_SZ" "13:48:28.7384416","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\PrintHood","SUCCESS","Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" "13:48:28.7384642","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 13, Type: REG_EXPAND_SZ" "13:48:28.7384819","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs","BUFFER OVERFLOW","Length: 144" "13:48:28.7384906","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs","SUCCESS","Type: REG_EXPAND_SZ, Length: 136, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" "13:48:28.7384996","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 14, Type: REG_EXPAND_SZ" "13:48:28.7385051","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Recent","SUCCESS","Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" "13:48:28.7385153","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 15, Type: REG_EXPAND_SZ" "13:48:28.7385290","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\SendTo","SUCCESS","Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" "13:48:28.7385503","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 16, Type: REG_EXPAND_SZ" "13:48:28.7385676","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Start Menu","SUCCESS","Type: REG_EXPAND_SZ, Length: 118, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" "13:48:28.7385903","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 17, Type: REG_EXPAND_SZ" "13:48:28.7385996","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup","BUFFER OVERFLOW","Length: 144" "13:48:28.7386083","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup","SUCCESS","Type: REG_EXPAND_SZ, Length: 152, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" "13:48:28.7386167","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 18, Type: REG_EXPAND_SZ" "13:48:28.7386223","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Templates","SUCCESS","Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" "13:48:28.7386305","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 19, Type: REG_EXPAND_SZ" "13:48:28.7386527","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Downloads" "13:48:28.7386664","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","" "13:48:28.7386807","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:28.7387061","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:28.7387344","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7387561","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.7387762","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.7387889","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:28.7388415","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7388895","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:28.7389065","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.7389145","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7389211","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.7389293","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.7389381","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:28.7389843","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:28.7390375","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7390918","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:28.7391128","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.7393535","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7393842","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7394502","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7394850","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A" "13:48:28.7394935","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal" "13:48:28.7395081","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.7395335","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:28.7395904","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal" "13:48:28.7396358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.7397768","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7398065","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7399169","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7399524","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7400261","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7400669","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7400735","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7401629","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7402399","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7403014","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7403201","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7403289","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7404410","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7404587","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7406256","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7406784","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7406900","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7407828","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7408331","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7408465","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7409301","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7410086","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7411956","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7412144","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7413168","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7413549","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7414419","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7414673","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7414760","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7415551","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7416005","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7416211","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7417197","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7417880","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7418063","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7418250","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7418960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7419122","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7419790","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7420146","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7420344","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7421119","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7421403","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7421495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7422778","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7423534","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7423819","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7423912","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7424634","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7424789","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7425914","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7426246","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7426316","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7427065","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7427267","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7427491","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7428650","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7431174","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7431884","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7432054","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7432834","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7433079","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7434197","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7434633","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7434707","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7435491","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7435834","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7435928","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7436667","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7437296","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7437566","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7437655","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7438820","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7439112","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7439786","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7440009","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7440072","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7441213","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7441415","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7441503","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7442189","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7442821","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7443100","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7443190","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7443851","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7444010","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7444651","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7444979","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7445042","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7445867","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7446136","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7446228","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7446965","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7447232","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \" "13:48:28.7447412","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.7447503","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:28.7448286","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7448610","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7449587","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7449876","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7450919","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7451194","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7451909","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7452145","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7452207","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7452865","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7455915","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7457070","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7457267","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7457357","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7458159","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7458344","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7459025","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7459539","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7459874","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7460974","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7461214","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7461298","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.7462148","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7462754","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7463001","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7463091","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7463756","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7463986","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7464606","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7464834","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7464895","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7465545","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7465893","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7465975","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.7466621","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7467212","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7467361","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7467436","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7468348","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7468582","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7469527","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7469822","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7469907","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7473531","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7473887","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7474173","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.7475161","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7475951","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7476136","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7476230","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7476888","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7477161","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7478065","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7479147","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7479226","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7480143","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7480356","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7480442","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.7481137","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7481771","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7482053","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7482138","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7482801","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7482961","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7484759","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7485050","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7485120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7486166","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7486382","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7486567","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.7487301","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7487954","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7488132","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7488219","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7488854","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7491222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7492076","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7492327","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7492391","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7493034","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7493268","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7493377","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.7496489","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.7497192","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7497489","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7497581","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7498255","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7498500","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7499186","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7499437","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.7499503","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7500475","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7500661","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.7500749","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.7501453","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7501729","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512" "13:48:28.7501804","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:28.7502491","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7502770","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7503784","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7503877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7504024","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7504179","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 82’456, Length: 4’096" "13:48:28.7504428","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7506266","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.7506805","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:28.7507667","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:28.7511378","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7511747","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7511923","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7512035","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7512088","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7512164","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7512261","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7512435","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7513327","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7513516","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7513829","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7513945","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7513998","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7514115","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7514198","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7514434","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7515235","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7515468","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: WinÄ" "13:48:28.7515724","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7515815","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:28.7515869","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7515937","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7516014","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7516203","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7517666","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7517917","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7518120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7520298","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7520408","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:28.7520507","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:28.7520730","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:28.7520835","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.7520898","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:28.7520973","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:28.7522784","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7522935","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.7522999","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7525831","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7526318","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7526524","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7526619","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7526674","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7526749","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7526840","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7527038","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7527926","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7528107","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(돭噷ᦅ" "13:48:28.7528412","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7528523","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win譖ᐢ㰵" "13:48:28.7528583","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7528657","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7528894","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7529058","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7529833","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7530007","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:28.7530764","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7530870","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:28.7530926","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.7530999","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7531080","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7531201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7532132","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7532314","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.7532402","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7533782","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7533949","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:28.7534011","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.7535848","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7536109","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.7536825","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.7537077","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A" "13:48:28.7537137","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.7539135","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.7539514","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.7542573","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372’736, Length: 6’144, Priority: Normal" "13:48:28.7542599","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.7542866","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.7608054","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270’336, Length: 4’096, Priority: Normal" "13:48:28.7608648","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274’432, Length: 4’096, Priority: Normal" "13:48:28.7609497","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81’920, Length: 4’096, Priority: Normal" "13:48:28.7622318","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299’008, Length: 4’096, Priority: Normal" "13:48:28.7623118","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266’240, Length: 8’192, Priority: Normal" "13:48:28.7623358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184’320, Length: 8’192, Priority: Normal" "13:48:28.7626149","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86’016, Length: 4’096, Priority: Normal" "13:48:28.7626448","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258’048, Length: 8’192, Priority: Normal" "13:48:28.7639483","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:28.7640578","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192’512, Length: 4’096, Priority: Normal" "13:48:28.7640962","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278’528, Length: 4’096, Priority: Normal" "13:48:28.7641225","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282’624, Length: 4’096, Priority: Normal" "13:48:28.7643172","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303’104, Length: 4’096, Priority: Normal" "13:48:28.7643524","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307’200, Length: 8’192, Priority: Normal" "13:48:28.7661203","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286’720, Length: 12’288, Priority: Normal" "13:48:28.7661950","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90’112, Length: 16’384, Priority: Normal" "13:48:28.7668461","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180’224, Length: 4’096, Priority: Normal" "13:48:28.7673193","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122’880, Length: 8’192, Priority: Normal" "13:48:28.7673553","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131’072, Length: 4’096, Priority: Normal" "13:48:28.7673801","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151’552, Length: 8’192, Priority: Normal" "13:48:28.7674216","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159’744, Length: 4’096, Priority: Normal" "13:48:28.7675363","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118’784, Length: 8’192, Priority: Normal" "13:48:28.7678037","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135’168, Length: 8’192, Priority: Normal" "13:48:28.7679884","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196’608, Length: 4’096, Priority: Normal" "13:48:28.7701537","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147’456, Length: 8’192, Priority: Normal" "13:48:28.7702776","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143’360, Length: 8’192, Priority: Normal" "13:48:28.7708886","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176’128, Length: 8’192, Priority: Normal" "13:48:28.7712423","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167’936, Length: 8’192, Priority: Normal" "13:48:28.7751833","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8’192, Length: 4’096, Priority: Normal" "13:48:28.7757414","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49’152, Length: 8’192, Priority: Normal" "13:48:28.7758013","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12’288, Length: 16’384, Priority: Normal" "13:48:28.7759441","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106’496, Length: 4’096, Priority: Normal" "13:48:28.7947009","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77’824, Length: 8’192, Priority: Normal" "13:48:28.8019678","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:28.8019824","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880" "13:48:28.8019944","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:28.8021145","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28’672, Length: 350’208, Priority: Normal" "13:48:28.8033241","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8050546","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8050728","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.8050875","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8052086","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8052287","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.8052352","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8053105","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8053479","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.8054288","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8055297","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8055501","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8055668","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8057002","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8057993","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8058226","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8058323","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8060900","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.8061908","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8062616","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8063136","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8063248","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8064251","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8065450","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8065981","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8066108","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8068131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.8068462","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8069926","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8070099","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.8070252","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8071719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8071879","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.8071946","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8072870","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8073131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.8073979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8074904","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8075188","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8075351","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8077142","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8078991","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8079327","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8079418","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8081193","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.8082070","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8082939","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8083143","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8083224","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8083917","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8084795","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8084975","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8085052","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8087031","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.8087298","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8087751","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8088803","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.8089237","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.8089453","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.8089651","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.8089773","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.8089836","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:28.8090456","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 865’232, Length: 24" "13:48:28.8090628","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 865’256, Length: 4’096" "13:48:28.8090932","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 869’352, Length: 24" "13:48:28.8091013","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 869’376, Length: 4’096" "13:48:28.8091127","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:28.8091191","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.8093614","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8093919","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8099712","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8099857","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NO EAS ON FILE","" "13:48:28.8101865","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8102149","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8102721","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:28.8103364","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8103460","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.8103641","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.8103800","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:28.8104107","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8104250","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:28.8104378","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.8104455","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8104516","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.8104600","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.8104688","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:28.8104861","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:28.8105021","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8105139","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:28.8105567","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.8105749","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:28.8105819","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:28.8105905","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8106085","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.8106175","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.8106309","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:28.8106762","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8106881","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:28.8107139","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.8107257","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8107359","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:28.8107492","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:28.8107698","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:28.8107846","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:28.8108037","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:28.8108279","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:28.8108455","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:28.8111564","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8111955","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.8112789","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8113140","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A" "13:48:28.8113256","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal" "13:48:28.8113406","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.8113617","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:28.8113971","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal" "13:48:28.8114268","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.8116240","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8116538","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8117578","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8117819","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8118909","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8119480","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8119594","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8120731","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8121503","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8122157","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8122440","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8122752","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8126954","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8128304","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8129165","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8129541","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8129608","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8130901","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8131351","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8131571","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8132837","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8134002","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8134346","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8134523","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8136102","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8136296","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8136976","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8137767","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8138313","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8139300","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8139493","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8139669","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8140431","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8141061","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8141229","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8141312","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8141949","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8142216","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8142876","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8143363","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8143575","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8144305","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8144561","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8144667","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8145504","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8146128","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8146370","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8146473","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8147333","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8148568","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8152576","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8152904","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8155071","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8163254","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8166045","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8166945","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8172233","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8174941","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8176928","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8178614","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8185230","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8185761","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8186935","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8187261","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8187347","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8188053","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8188217","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8188319","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8190292","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8191393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8191806","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8191972","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8196727","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8197214","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8200443","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8200797","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8200873","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8201587","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8201755","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8201934","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8202615","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8204376","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8204730","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8204866","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8206106","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8207100","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8208104","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8209862","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8210067","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8214136","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8214582","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8214784","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8216139","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8216370","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \" "13:48:28.8216612","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:28.8216693","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:28.8217481","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8217663","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8218673","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8218864","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8219846","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8220007","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8220670","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8221000","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8221062","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8221752","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8222788","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8224230","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8224879","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8225343","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8226349","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8226570","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8227258","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8227636","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8227803","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8228516","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8228772","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8228882","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","" "13:48:28.8229563","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8230220","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8230399","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8230486","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8231350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8231512","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8232158","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8232475","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8232548","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8233216","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8233376","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8233462","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","" "13:48:28.8234088","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8234701","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8234962","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8235049","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8235816","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8236120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8236817","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8237087","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8237148","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8238503","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8238886","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8239029","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:28.8240090","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8240986","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8241388","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8241859","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8243048","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8243322","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8244700","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8245154","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8245262","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8246393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8246730","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8246882","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:28.8248014","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8249195","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8249374","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8249571","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8250271","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8250431","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8251234","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8251713","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8251825","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8252826","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8253074","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8253201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:28.8254578","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8255279","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8255457","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8255755","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8256490","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8256643","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8257268","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8257595","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8257659","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8258545","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8258624","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8258821","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8258908","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:28.8259352","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.8259559","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:28.8259661","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.8259780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:28.8260153","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8260313","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8260463","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8260996","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8261246","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8261847","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8262062","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:28.8262122","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8262786","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8263037","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:28.8263115","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:28.8263776","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8264000","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512" "13:48:28.8264152","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:28.8264583","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 65’536, Priority: Normal" "13:48:28.8265216","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 374’784, Length: 4’096, Priority: Normal" "13:48:28.8265831","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 378’880, Priority: Normal" "13:48:28.8275213","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8275502","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:28.8275730","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:28.8275840","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS","" "13:48:28.8297939","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\SystemTemp\UDDA014.tmp","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:28.8298641","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\SystemTemp\UDDA014.tmp","SUCCESS","AllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:28.8364461","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299’008, Length: 4’096, Priority: Normal" "13:48:28.8364704","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372’736, Length: 4’096, Priority: Normal" "13:48:28.8380345","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 1’024, Length: 185’856, Priority: Normal" "13:48:28.8383877","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 186’880, Length: 91’136, Priority: Normal" "13:48:28.8385765","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278’016, Length: 12’288, Priority: Normal" "13:48:28.8386189","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 290’304, Length: 9’216, Priority: Normal" "13:48:28.8386520","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 300’032, Length: 75’776, Priority: Normal" "13:48:28.8388074","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 376’832, Length: 2’048, Priority: Normal" "13:48:28.8388743","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303’104, Length: 4’096, Priority: Normal" "13:48:28.8389451","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307’200, Length: 4’096, Priority: Normal" "13:48:28.8389747","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 308’116, Length: 9’640, Priority: Normal" "13:48:28.8390322","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 317’756, Length: 4’264, Priority: Normal" "13:48:28.8390889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 319’488, Length: 4’096, Priority: Normal" "13:48:28.8391458","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 323’584, Length: 4’096, Priority: Normal" "13:48:28.8391870","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 326’080, Length: 48’399, Priority: Normal" "13:48:28.8393946","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81’920, Length: 4’096, Priority: Normal" "13:48:28.8394219","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:28.8395159","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe:Zone.Identifier","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.8395840","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "13:48:28.8396117","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:28.8396252","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal" "13:48:28.8396432","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:28.8396847","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 360, Priority: Normal" "13:48:28.8396996","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 364, Length: 76, Priority: Normal" "13:48:28.8397389","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 448, Length: 262’144, Priority: Normal" "13:48:28.8408915","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 262’592, Length: 116’288, Priority: Normal" "13:48:28.8414656","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8415061","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.8415153","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8417103","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8417461","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.8417587","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8419630","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8421908","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.8423050","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8425251","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8425513","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8426092","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8427205","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8428160","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8428546","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8428644","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8431183","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.8432411","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8433737","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8434051","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8435171","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8436279","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8439184","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8439499","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8439581","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8457377","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.8457580","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8459214","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8459474","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:28.8459566","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8460731","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8460888","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:28.8460947","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:28.8461672","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8462122","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:28.8462993","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8464220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8464530","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8464609","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8465328","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8466589","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8466891","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8466978","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8470210","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:28.8471403","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8472171","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8472352","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:28.8472529","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:28.8473335","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:28.8475024","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:28.8475198","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:28.8475374","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8477309","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:28.8477477","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:28.8477961","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A" "13:48:28.8478180","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8478525","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","" "13:48:28.8480475","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:28.8480966","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:28.8481063","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:28.8531914","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.8532131","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:28.8532523","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:28.8532824","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.0973827","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.0974296","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.0974977","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.0975385","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","" "13:48:29.0975558","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:29.0975795","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL" "13:48:29.0975961","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:29.0976160","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS","" "13:48:29.3525919","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3526166","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3526242","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3526313","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win" "13:48:29.3526362","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3526515","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3526615","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3526854","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3527586","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3527853","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win¨" "13:48:29.3527925","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3528062","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.3528114","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3528511","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3528629","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3528756","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3529467","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3529725","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3529792","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3529859","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3529910","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3529974","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3530044","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3530286","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3531009","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3531160","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3531482","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3533628","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3533735","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:29.3534152","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:29.3534365","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:29.3534471","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3534548","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:29.3534698","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:29.3536835","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3536990","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:29.3537158","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3538022","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3538210","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3538395","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3538489","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.3538650","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3538725","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3538983","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3539115","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3539893","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3540147","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3540227","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3540318","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.3540371","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3540441","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3540517","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3540877","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3542076","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3542580","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3542679","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3542869","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3542951","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3543054","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3543455","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3543636","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3544776","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3545138","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3545239","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3546574","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3546819","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:29.3547078","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3548991","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3549453","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.3550516","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3550993","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:29.3551088","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32’768, EndOfFile: 29’184, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:29.3553602","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:29.3553889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:29.3556064","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24’576, Length: 4’608, Priority: Normal" "13:48:29.3601209","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 20’480, Length: 4’096, Priority: Normal" "13:48:29.3601864","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8’192, Length: 8’192, Priority: Normal" "13:48:29.3619318","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 16’384, Length: 8’192, Priority: Normal" "13:48:29.3634192","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:29.3788111","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ" "13:48:29.3788219","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.3788564","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3789426","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3789760","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 721’056, Length: 4’096" "13:48:29.3790295","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3792572","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3795397","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3795575","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.3795803","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.3797052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3797231","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.3797307","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.3798061","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3798591","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.3799501","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3800198","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3800643","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.3800746","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.3801625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3803571","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3803780","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.3803861","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3806830","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.3807788","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3808553","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3808769","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.3808929","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.3809637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3811099","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3811302","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.3811385","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3897514","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.3897727","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3899420","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3899616","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.3899880","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.3901491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3901883","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.3901975","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.3902893","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3903196","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.3904165","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3904975","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3905261","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.3905383","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.3906454","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3907841","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3908161","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.3908259","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3910394","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.3911481","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3912293","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3912559","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.3912778","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.3913648","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.3914423","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3914752","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.3914916","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3929255","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.3929531","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.3929993","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3930897","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3931107","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3931421","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3931525","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3931623","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3931684","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:29.3932303","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 873’472, Length: 24" "13:48:29.3932562","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 873’496, Length: 4’096" "13:48:29.3932787","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 877’592, Length: 24" "13:48:29.3932859","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 877’616, Length: 4’096" "13:48:29.3933039","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:29.3933131","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3935393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3935834","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3940743","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3940885","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NO EAS ON FILE","" "13:48:29.3942617","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3942831","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3943330","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:29.3945156","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3945694","MsMpEng.exe","3220","FileSystemControl","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.3946488","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3946765","MsMpEng.exe","3220","QueryInformationVolume","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:29.3947024","MsMpEng.exe","3220","QueryAllInformationFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","BUFFER OVERFLOW","CreationTime: 18.09.2025 14:18:18, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 18.09.2025 14:18:13, ChangeTime: 11.10.2025 16:01:28, FileAttributes: ANCI, AllocationSize: 163’840, EndOfFile: 282’480" "13:48:29.3947118","MsMpEng.exe","3220","FileSystemControl","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.3947665","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3947750","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3947813","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.3947904","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.3948248","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 0, Length: 65’536, Priority: Normal" "13:48:29.3950293","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 65’536, Length: 65’536, Priority: Normal" "13:48:29.3952414","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 131’072, Length: 65’536, Priority: Normal" "13:48:29.3954416","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 196’608, Length: 65’536, Priority: Normal" "13:48:29.3956473","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 262’144, Length: 20’336, Priority: Normal" "13:48:29.3957298","MsMpEng.exe","3220","CloseFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","" "13:48:29.3957425","MsMpEng.exe","3220","CloseFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","" "13:48:29.3957875","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3958130","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.3958300","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.3958444","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:29.3958741","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3958822","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:29.3958939","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.3959039","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3959100","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.3959181","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.3959366","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:29.3959466","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:29.3959646","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3959716","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:29.3959893","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.3959996","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:29.3960058","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:29.3960136","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3960199","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.3960687","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.3961053","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:29.3961386","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3961510","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:29.3961665","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.3961832","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3961978","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.3962098","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.3962211","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:29.3962324","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:29.3962563","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.3962669","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:29.3962795","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.3965952","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3966370","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.3967185","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3967598","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:29.3967718","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal" "13:48:29.3968226","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32’768, EndOfFile: 29’184, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:29.3968601","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:29.3968781","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal" "13:48:29.3968961","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:29.3970133","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3970454","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3971212","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3971377","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3972155","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3972521","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.3972587","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.3973404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3974109","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3974722","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3974909","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3975001","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.3975852","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3976075","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.3976764","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3977107","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.3977178","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.3977875","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3978041","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3978125","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.3979066","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3979733","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3979902","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3980249","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.3981041","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3981302","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.3982057","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3982283","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.3982347","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.3983885","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3984145","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3984233","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.3985227","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3985960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3986218","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3986326","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.3987496","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3987839","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.3988681","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3989075","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.3989153","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.3989935","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3990238","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3990343","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.3991124","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3991803","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3992105","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3992195","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.3992910","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3993182","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.3994121","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3994391","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.3994454","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.3995464","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3995793","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3995964","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.3996826","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.3997762","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3998000","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.3998107","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.3999223","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.3999464","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4000361","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4000644","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4000817","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4001589","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4001774","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4001859","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4002494","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4003063","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4003308","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4003398","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4004167","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4004504","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4007179","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4007512","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4007591","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4008510","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4008714","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4008810","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4009645","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4010372","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4010572","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4010686","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4011487","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4011693","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4012418","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4012776","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4012858","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4013931","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4014136","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4014224","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4015155","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4015381","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \" "13:48:29.4015500","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:29.4015767","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:29.4016682","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4017000","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4017927","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4018230","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4019001","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4019171","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4020102","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4020352","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4020424","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4021313","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4022515","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4023288","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4023615","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4023744","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4024515","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4024815","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4025761","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4026172","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4026252","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4027145","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4027397","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4027495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4028364","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4029164","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4029360","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4029450","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4030341","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4030551","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4031328","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4031730","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4031803","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4032678","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4032980","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4033201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4033920","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4034508","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4034674","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4034751","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4035348","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4035493","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4036420","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4036638","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4036699","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4037322","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4037583","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4037659","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4038270","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4038830","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4038978","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4039050","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4039625","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4039765","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4040355","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4040647","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4040703","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4041321","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4041463","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4041533","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4042153","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4042730","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4042968","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4043053","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4043646","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4043797","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4044404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4044854","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4044912","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4045562","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4045837","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4045988","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4046606","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4047180","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4047354","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4047431","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4048051","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4048189","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4048780","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4049068","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4049134","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4049817","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4049961","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4050034","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4050619","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4051251","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4051497","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4051597","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4052761","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4053070","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4053828","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4054068","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4054254","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4055018","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4055201","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4055298","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4056385","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4056578","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512" "13:48:29.4056656","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:29.4057031","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4057208","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4057872","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.4057984","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.4059381","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:29.4059755","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:29.4059838","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:29.4062203","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4062460","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4062544","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4062620","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4062670","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4062748","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4062832","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4063114","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4063867","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4064016","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:29.4064081","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4064143","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4064262","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4064351","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4064422","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4064525","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4065351","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4065708","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4065796","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4065865","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4065913","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4065978","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4066119","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4066235","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4066941","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4067104","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4067474","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4069179","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4069304","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:29.4069421","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:29.4069694","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:29.4069804","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4069886","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "13:48:29.4069982","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "13:48:29.4072234","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4072409","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:29.4072484","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4073505","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4073707","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ" "13:48:29.4073915","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4074014","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4074081","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4074172","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4074270","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4074514","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4075382","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4075721","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4075833","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4075926","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4075989","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4076075","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4076166","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4076402","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4077249","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4077544","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4077641","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4077731","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4077794","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4077880","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4077969","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4078192","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4079036","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4079219","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4079437","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4080776","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4080926","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A" "13:48:29.4080998","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4082603","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4082864","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.4083658","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4083920","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:29.4083994","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32’768, EndOfFile: 29’184, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:29.4086275","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:29.4086716","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:29.4088486","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24’576, Length: 4’608, Priority: Normal" "13:48:29.4131604","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 20’480, Length: 4’096, Priority: Normal" "13:48:29.4132309","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8’192, Length: 8’192, Priority: Normal" "13:48:29.4147152","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 16’384, Length: 8’192, Priority: Normal" "13:48:29.4165019","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:29.4314285","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ" "13:48:29.4314414","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184" "13:48:29.4314627","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:29.4317210","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4321093","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4321449","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.4321533","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4322787","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4322941","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.4323093","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4323872","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4324131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.4325080","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4325994","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4326257","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4326341","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4327079","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4327713","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4327949","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4328044","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4330658","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.4332351","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4333486","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4333728","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4333944","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4334851","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4335792","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4336015","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4336102","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4338299","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.4338488","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4340233","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4340426","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.4340622","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4342041","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4342216","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.4342383","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4343268","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4343639","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.4344821","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4345460","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4345784","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4345868","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4347366","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4349193","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4349566","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4349669","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4351931","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.4353656","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4356250","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4356666","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4356904","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4359034","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4359956","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4360348","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4360441","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4362319","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.4362609","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4363004","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4364179","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.4364684","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.4365165","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.4365330","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.4365458","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:29.4365727","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:29.4366495","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 881’712, Length: 24" "13:48:29.4366779","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 881’736, Length: 4’096" "13:48:29.4367089","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 885’832, Length: 24" "13:48:29.4367178","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 885’856, Length: 4’096" "13:48:29.4367389","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:29.4367508","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:29.4369947","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4370211","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4375974","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4376234","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NO EAS ON FILE","" "13:48:29.4377792","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4378173","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4378827","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "13:48:29.4379453","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4379581","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.4379707","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.4379874","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:29.4380222","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4380309","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:29.4380463","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.4380623","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4380958","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.4381102","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.4381346","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:29.4381469","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:29.4381741","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4381919","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:29.4382069","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.4382166","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:29.4382257","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:29.4382347","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4382503","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.4382596","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.4382695","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT" "13:48:29.4382872","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4382945","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "13:48:29.4383198","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.4383277","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4383346","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read" "13:48:29.4383447","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read" "13:48:29.4383548","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144" "13:48:29.4383752","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat" "13:48:29.4383890","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:29.4383971","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read" "13:48:29.4384109","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","" "13:48:29.4386914","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4387221","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:29.4388105","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4388383","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:29.4388588","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal" "13:48:29.4388785","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32’768, EndOfFile: 29’184, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:29.4388981","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:29.4389226","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal" "13:48:29.4389593","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:29.4391100","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4391363","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4392149","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4392459","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4393245","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4393624","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4393707","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4394808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4395580","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4396404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4396714","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4396818","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4397540","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4397797","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4398544","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4398806","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4398880","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4399695","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4399910","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4400003","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4400858","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4401564","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4401759","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4401852","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4402553","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4402829","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4403549","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4403779","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4403944","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4404705","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4404886","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4404980","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4405911","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4406625","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4407075","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4407170","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4407913","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4408082","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4408925","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4409181","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4409251","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4410074","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4410277","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4410369","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4411078","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4411734","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4412040","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4412133","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4412818","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4413262","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4414493","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4414900","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4414985","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4416395","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4416702","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4416816","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4417666","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4418488","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4418712","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4418815","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4419572","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4419874","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4420656","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4421027","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4421105","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4421916","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4422210","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4422309","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4423462","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4424217","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4424409","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4424597","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4425385","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4425584","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4426561","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4426833","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4426902","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4427782","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4427976","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4428074","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4428972","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4429704","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4429902","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4430117","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4430900","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4431092","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4431892","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4432175","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4432247","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4433011","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4433316","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4433417","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4434672","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4435016","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \" "13:48:29.4435155","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS" "13:48:29.4435238","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:29.4436358","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4436556","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4437816","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4438142","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4439194","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4439374","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4440023","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4440340","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4440409","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4441070","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4441649","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4442194","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4442364","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4442442","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4443027","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4443169","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4443747","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4444101","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4444162","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4444785","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4444933","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4445005","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","" "13:48:29.4445751","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4446350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4446533","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4446672","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4447597","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4447857","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4448509","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4448723","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4448794","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4449446","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4449703","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4449782","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","" "13:48:29.4450798","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4451434","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4451630","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4451714","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4452350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4452512","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4453232","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4453476","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4453535","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4454176","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4454336","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4454502","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","" "13:48:29.4455115","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4455746","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4455930","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4456006","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4456639","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4456791","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4457418","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4457723","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4457780","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4458405","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4458564","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4458637","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS","" "13:48:29.4459357","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4459958","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4460134","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4460209","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4460878","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4461029","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4461656","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4461963","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4462021","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4462660","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4462829","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4462908","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS","" "13:48:29.4463617","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4464116","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4464570","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4464685","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4465355","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4465714","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4466367","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4466673","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4466749","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4467907","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4468170","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4468294","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS","" "13:48:29.4469257","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a" "13:48:29.4469910","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4470073","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4470162","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4470762","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4471002","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4471616","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4471889","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME" "13:48:29.4471994","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4473051","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4473225","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT" "13:48:29.4473380","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS","" "13:48:29.4474035","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4474219","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512" "13:48:29.4474305","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS","" "13:48:29.4474715","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 29’184, Priority: Normal" "13:48:29.4475075","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 25’088, Length: 4’096, Priority: Normal" "13:48:29.4475411","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 29’184, Priority: Normal" "13:48:29.4482383","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24’576, Length: 4’096, Priority: Normal" "13:48:29.4483058","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 1’024, Length: 14’336, Priority: Normal" "13:48:29.4483436","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 15’360, Length: 10’752, Priority: Normal" "13:48:29.4483876","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 28’672, Length: 512, Priority: Normal" "13:48:29.4484475","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8’192, Length: 4’096, Priority: Normal" "13:48:29.4484648","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4’096, Length: 4’096, Priority: Normal" "13:48:29.4485488","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe:Zone.Identifier","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:29.4486033","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "13:48:29.4486223","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal" "13:48:29.4486371","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal" "13:48:29.4486642","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4’096, Priority: Normal" "13:48:29.4487008","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 328, Priority: Normal" "13:48:29.4487358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 332, Length: 76, Priority: Normal" "13:48:29.4487532","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 416, Length: 28’768, Priority: Normal" "13:48:29.4490482","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4490700","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.4490780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4492289","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4492475","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.4492556","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4493469","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4493762","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.4495205","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4497401","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4497692","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4497777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4499175","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4500875","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4501106","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4501184","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4502898","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.4503771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4504535","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4504736","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4504810","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4505523","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4506625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4506801","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4506949","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4508520","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.4508675","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4510084","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4510256","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D" "13:48:29.4510329","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4511483","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4511842","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI" "13:48:29.4511991","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","" "13:48:29.4513072","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4513516","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}" "13:48:29.4515210","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4516133","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4516322","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4516396","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4517085","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4518843","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4519027","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4519192","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4520714","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}" "13:48:29.4521761","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4522443","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4522603","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL" "13:48:29.4522679","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS","" "13:48:29.4523699","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "13:48:29.4525379","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:29.4525557","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL" "13:48:29.4525754","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4527343","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "13:48:29.4527500","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS","" "13:48:29.4527908","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "13:48:29.4528084","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4528349","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "13:48:29.4530007","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:29.4530448","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS","" "13:48:29.4530555","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "13:48:30.7986656","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.7986864","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.7987084","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.7987327","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8104999","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.8105702","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.8105953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.8106101","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:30.8364951","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8365181","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:30.8365778","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:30.8365877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8366776","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8366992","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8369774","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8370024","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8391910","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8392049","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True" "13:48:30.8392298","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1" "13:48:30.8392358","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8393632","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\security\logs\scecomp.log","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "13:48:30.8393798","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\security\logs\scecomp.log","SUCCESS","AllocationSize: 240, EndOfFile: 236, NumberOfLinks: 1, DeletePending: False, Directory: False" "13:48:30.8531755","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8532743","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8672188","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\scecli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.8672668","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.8672772","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.8673189","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\scecli.dll","SUCCESS","" "13:48:30.8715156","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:30.8715738","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1" "13:48:30.8717361","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\scecli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.8717791","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჹ" "13:48:30.8717881","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:23, LastAccessTime: 13.10.2025 13:48:30, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 184’320, EndOfFile: 364’544" "13:48:30.8717990","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჹ" "13:48:30.8718043","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:23, LastAccessTime: 13.10.2025 13:48:30, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 184’320, EndOfFile: 364’544" "13:48:30.8718241","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA" "13:48:30.8718338","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\scecli.dll","SUCCESS","" "13:48:30.8718528","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\scecli.dll","SUCCESS","" "13:48:30.9122873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9124214","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9126245","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9127426","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9129335","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9132831","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9136280","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9152909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "13:48:30.9187134","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9187745","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9188134","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9188403","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:30.9189774","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9190202","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9190308","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9190395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS","" "13:48:30.9214070","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9214644","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9214772","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9214860","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:30.9216683","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9216915","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9216993","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9217159","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:30.9218138","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9218517","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9218601","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9218668","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:30.9230457","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9231075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9231171","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9231256","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:30.9233180","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9233643","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9233750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9233843","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:30.9235187","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9235778","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9235899","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9236050","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:30.9237107","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9237469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9237553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9237623","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:30.9238637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9238888","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9238966","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9239129","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:30.9243044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9244790","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9245040","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9245221","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:30.9249078","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9249660","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9249795","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9249880","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:30.9252550","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9252866","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9252947","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9253022","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:30.9255559","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9256002","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9256153","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9256250","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:30.9257158","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9257437","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9257524","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9257592","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:30.9258429","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9258782","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9258870","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9258935","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:30.9260707","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9261238","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9261327","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9261395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:30.9262770","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9263138","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9263218","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9263296","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:30.9295898","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9296506","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9296639","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9296740","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:30.9298719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9299131","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9299219","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9299292","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "13:48:30.9300912","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9301307","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9301390","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9301470","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:30.9304456","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9304790","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9304999","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9305080","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:30.9344746","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9344992","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9345084","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9345232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "13:48:30.9459680","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9460075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9460230","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9460340","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:30.9515084","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9515390","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9515575","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9515991","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:30.9527489","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9527930","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9528052","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9528149","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:30.9568145","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9568765","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9568955","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9569051","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "13:48:30.9598735","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9599440","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9599552","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9599639","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "13:48:30.9625887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9626290","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9626381","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9626463","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS","" "13:48:30.9635167","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9635548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9635773","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9635920","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS","" "13:48:30.9734589","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:30.9735224","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:30.9735371","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:30.9735467","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS","" "13:48:31.0005170","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0005526","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0005761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0005863","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","" "13:48:31.0150668","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0151125","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0151382","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0151492","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS","" "13:48:31.0161480","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0161966","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0162073","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0162260","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS","" "13:48:31.0167079","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0167943","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0168092","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0168187","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS","" "13:48:31.0176848","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0177147","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0177612","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0177710","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS","" "13:48:31.0180016","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0180339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0180512","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0180606","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS","" "13:48:31.0258140","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0258499","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0258604","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0258785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS","" "13:48:31.0324640","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0324934","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0325025","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0325204","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS","" "13:48:31.0356275","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0356568","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0356750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0356905","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS","" "13:48:31.0468194","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0469131","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0469345","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0469449","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS","" "13:48:31.0471220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0471638","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0471769","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0472014","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "13:48:31.0479763","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0480070","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0480273","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0480358","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "13:48:31.0481301","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0481611","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0481691","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0481846","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "13:48:31.0492913","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0493275","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0493484","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0493596","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "13:48:31.0494995","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0495432","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0495535","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0495754","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "13:48:31.0497236","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0497616","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0497738","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0497818","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "13:48:31.0499723","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0500066","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0500155","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0500232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "13:48:31.0503096","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0503512","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0503634","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0503714","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "13:48:31.0505378","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0506304","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0506530","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0506667","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "13:48:31.0508242","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0509204","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0509350","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0509436","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "13:48:31.0515799","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0516930","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0517046","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0517132","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "13:48:31.0524939","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0529073","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0529444","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0529566","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "13:48:31.0532928","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0533323","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0533408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0533478","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "13:48:31.0538887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0539255","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0539344","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0539414","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "13:48:31.0541248","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0541645","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0541767","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0541849","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS","" "13:48:31.0543637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0543925","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0544105","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0544201","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "13:48:31.0545098","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0545478","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0545560","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0545737","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","" "13:48:31.0547423","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0547810","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0547903","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0547974","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "13:48:31.0549277","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0549654","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0549738","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0549864","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "13:48:31.0592625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0592922","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0593032","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0593243","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "13:48:31.0595797","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0596176","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0596331","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0596423","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "13:48:31.0605226","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0605497","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0605593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0605818","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS","" "13:48:31.0624362","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "13:48:31.0624710","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "13:48:31.0624886","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "13:48:31.0624999","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "13:48:31.4224387","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:31.4226146","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels","NAME NOT FOUND","Desired Access: Query Value" "13:48:31.4277326","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:31.4279063","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","Desired Access: Read/Write" "13:48:31.4280570","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:31.4281314","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NAME NOT FOUND","Desired Access: Read" "13:48:31.4282197","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NO MORE ENTRIES","Index: 0, Length: 220" "13:48:31.4282891","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","" "13:48:31.4432988","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "13:48:31.4433787","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels","NAME NOT FOUND","Desired Access: Query Value" "13:48:31.5405742","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True" "13:48:31.5406424","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"