Files
cailllev-EDR-Introspection/docs/LoadLibrary-Tests/MsMpEng-LoadLibrary-MsSignedDLL-ProcMonLog.CSV
2025-10-20 19:09:19 +02:00

5.7 KiB

1Time of DayProcess NamePIDOperationPathResultDetail
214:33:35.2458968MsMpEng.exe3220Thread CreateSUCCESSThread ID: 3276
314:33:35.2546059MsMpEng.exe3220CreateFileC:\Windows\System32\kernel.appcore.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
414:33:35.2546630MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
514:33:35.2546769MsMpEng.exe3220FileSystemControlC:\Windows\System32\kernel.appcore.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
614:33:35.2546868MsMpEng.exe3220CloseFileC:\Windows\System32\kernel.appcore.dllSUCCESS
714:33:35.2548323MsMpEng.exe3220CreateFileC:\Windows\System32\msvcrt.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
814:33:35.2548641MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
914:33:35.2548719MsMpEng.exe3220FileSystemControlC:\Windows\System32\msvcrt.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
1014:33:35.2548895MsMpEng.exe3220CloseFileC:\Windows\System32\msvcrt.dllSUCCESS
1114:33:35.2549829MsMpEng.exe3220CreateFileC:\Windows\System32\bcryptprimitives.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
1214:33:35.2550157MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
1314:33:35.2550235MsMpEng.exe3220FileSystemControlC:\Windows\System32\bcryptprimitives.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
1414:33:35.2550301MsMpEng.exe3220CloseFileC:\Windows\System32\bcryptprimitives.dllSUCCESS
1514:33:35.2551498MsMpEng.exe3220CreateFileC:\Windows\System32\clbcatq.dllSUCCESSDesired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
1614:33:35.2551772MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllOPLOCK HANDLE CLOSEDControl: FSCTL_REQUEST_OPLOCK
1714:33:35.2551952MsMpEng.exe3220FileSystemControlC:\Windows\System32\clbcatq.dllSUCCESSControl: 0x902eb (Device:0x9 Function:186 Method: 3)
1814:33:35.2552020MsMpEng.exe3220CloseFileC:\Windows\System32\clbcatq.dllSUCCESS
1914:33:35.2561196MsMpEng.exe3220CreateFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
2014:33:35.2561420MsMpEng.exe3220QueryBasicInformationFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESSCreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 14:33:35, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A
2114:33:35.2561502MsMpEng.exe3220CloseFileC:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exeSUCCESS
2214:33:35.2571028MsMpEng.exe3220CreateFileC:\Windows\System32\AcGenral.dllSUCCESSDesired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
2314:33:35.2571661MsMpEng.exe3220QueryBasicInformationFileC:\Windows\System32\AcGenral.dllSUCCESSCreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 14:32:58, LastWriteTime: 30.09.2025 13:53:26, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A
2414:33:35.2571736MsMpEng.exe3220CloseFileC:\Windows\System32\AcGenral.dllSUCCESS
2514:33:35.2572550MsMpEng.exe3220CreateFileC:\Windows\System32\AcGenral.dllSUCCESSDesired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
2614:33:35.2572941MsMpEng.exe3220CreateFileMappingC:\Windows\System32\AcGenral.dllFILE LOCKED WITH ONLY READERSSyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
2714:33:35.2574456MsMpEng.exe3220QueryEAFileC:\Windows\System32\AcGenral.dllSUCCESS
2814:33:35.2574591MsMpEng.exe3220FileSystemControlC:\Windows\System32\AcGenral.dllSUCCESSControl: FSCTL_QUERY_USN_JOURNAL
2914:33:35.2574874MsMpEng.exe3220CreateFileMappingC:\Windows\System32\AcGenral.dllSUCCESSSyncType: SyncTypeOther
3014:33:35.2575800MsMpEng.exe3220Load ImageC:\Windows\System32\AcGenral.dllSUCCESSImage Base: 0x7ff8d0870000, Image Size: 0x71000
3114:33:35.2583354MsMpEng.exe3220CloseFileC:\Windows\System32\AcGenral.dllSUCCESS