Files
2025-10-20 19:09:19 +02:00

4197 lines
844 KiB
CSV
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"13:48:27.5486279","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:27.5486430","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","Desired Access: Read/Write"
"13:48:27.5487033","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:27.5487114","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NAME NOT FOUND","Desired Access: Read"
"13:48:27.5487301","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NO MORE ENTRIES","Index: 0, Length: 220"
"13:48:27.5487496","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS",""
"13:48:27.5771694","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.5771900","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 144256, Length: 4096"
"13:48:27.5772238","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 403816, Length: 4096"
"13:48:27.5772477","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.5775423","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.5775761","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 399696, Length: 4096"
"13:48:27.5776013","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.5835398","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.5835887","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.5836207","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.5836339","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.5837392","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.5837908","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.5838018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.5838093","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:27.5846645","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.5846816","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 395576, Length: 4096"
"13:48:27.5847044","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.5854297","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.5854567","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.5854879","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.5854967","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 148376, Length: 4096"
"13:48:27.5855268","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 679856, Length: 4096"
"13:48:27.5855498","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.5855746","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.5860527","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.5860818","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.5860965","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1433600, EndOfFile: 2521976"
"13:48:27.5861087","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.5861142","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1433600, EndOfFile: 2521976"
"13:48:27.5861221","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.5861303","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:27.5861475","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:27.6098690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6099149","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6099290","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6099395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:27.6103226","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6103637","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6103722","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466944, EndOfFile: 836136"
"13:48:27.6103935","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6104073","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466944, EndOfFile: 836136"
"13:48:27.6104186","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6104270","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:27.6104488","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:27.6105220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6105433","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6105521","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6105714","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:27.6107812","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6108005","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6108165","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1785856, EndOfFile: 4150008"
"13:48:27.6108514","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6108570","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1785856, EndOfFile: 4150008"
"13:48:27.6108649","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6108817","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:27.6108948","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:27.6114914","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6115505","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6115761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6115853","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:27.6117397","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6117811","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6117915","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6117997","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:27.6118829","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6119405","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6119516","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393216, EndOfFile: 745192"
"13:48:27.6119609","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6119660","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393216, EndOfFile: 745192"
"13:48:27.6119745","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6119821","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:27.6120045","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:27.6120412","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6120716","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6120804","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6120876","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:27.6122052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6122414","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6122493","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6122567","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:27.6124017","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6126810","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6127107","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405504, EndOfFile: 699768"
"13:48:27.6127962","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6128189","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405504, EndOfFile: 699768"
"13:48:27.6128333","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6129082","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:27.6129750","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:27.6136426","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6137211","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6137333","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6137415","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS",""
"13:48:27.6144921","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6151458","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6152471","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385024, EndOfFile: 691520"
"13:48:27.6154232","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6154744","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385024, EndOfFile: 691520"
"13:48:27.6157337","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6157806","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:27.6158874","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:27.6159486","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6159879","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6159980","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6160061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS",""
"13:48:27.6164003","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\fltLib.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6164789","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6164907","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6165002","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\fltLib.dll","SUCCESS",""
"13:48:27.6171188","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\newdev.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6171656","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6171766","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6171848","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\newdev.dll","SUCCESS",""
"13:48:27.6177155","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6177819","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6177993","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708608, EndOfFile: 1162552"
"13:48:27.6178130","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(಼"
"13:48:27.6178193","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708608, EndOfFile: 1162552"
"13:48:27.6178282","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6178359","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:27.6178574","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:27.6178784","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6179311","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6179408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6179553","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:27.6180384","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6180593","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6186380","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msdelta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6187227","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6187581","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6187677","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msdelta.dll","SUCCESS",""
"13:48:27.6187807","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6188917","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6189036","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2146304, EndOfFile: 4794560"
"13:48:27.6189156","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6189222","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2146304, EndOfFile: 4794560"
"13:48:27.6189423","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\setupapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6189536","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\setupapi.dll","SUCCESS",""
"13:48:27.6189691","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS",""
"13:48:27.6192022","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptsp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6192430","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6192541","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6192616","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptsp.dll","SUCCESS",""
"13:48:27.6197451","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6198096","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6198174","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cabinet.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6198208","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90112, EndOfFile: 166736"
"13:48:27.6198313","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6198377","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90112, EndOfFile: 166736"
"13:48:27.6198567","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcrypt.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6198592","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6198679","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\bcrypt.dll","SUCCESS",""
"13:48:27.6198692","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6198769","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cabinet.dll","SUCCESS",""
"13:48:27.6198830","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS",""
"13:48:27.6200180","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6200461","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6202065","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\fltLib.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6202608","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6202686","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20480, EndOfFile: 59312"
"13:48:27.6202774","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6202827","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\fltLib.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20480, EndOfFile: 59312"
"13:48:27.6202905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\fltLib.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6203085","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\fltLib.dll","SUCCESS",""
"13:48:27.6203220","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\fltLib.dll","SUCCESS",""
"13:48:27.6204470","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6204602","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6205803","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\newdev.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6206222","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ"
"13:48:27.6206442","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188416, EndOfFile: 348160"
"13:48:27.6206728","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6206802","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\newdev.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188416, EndOfFile: 348160"
"13:48:27.6206893","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\newdev.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6206972","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\newdev.dll","SUCCESS",""
"13:48:27.6207095","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\newdev.dll","SUCCESS",""
"13:48:27.6210475","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6210988","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ"
"13:48:27.6211175","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802816, EndOfFile: 1373280"
"13:48:27.6211364","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6211895","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802816, EndOfFile: 1373280"
"13:48:27.6212124","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6212206","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:27.6212381","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:27.6213952","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6214089","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6215052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msdelta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6215325","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6215394","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278528, EndOfFile: 595360"
"13:48:27.6215468","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ"
"13:48:27.6215703","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msdelta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278528, EndOfFile: 595360"
"13:48:27.6215811","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msdelta.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6215885","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msdelta.dll","SUCCESS",""
"13:48:27.6216009","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msdelta.dll","SUCCESS",""
"13:48:27.6218401","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptsp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6235566","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6235764","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57344, EndOfFile: 121304"
"13:48:27.6235868","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6235995","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptsp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57344, EndOfFile: 121304"
"13:48:27.6236107","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptsp.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6236193","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cryptsp.dll","SUCCESS",""
"13:48:27.6236387","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptsp.dll","SUCCESS",""
"13:48:27.6239253","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cabinet.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6239720","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6239844","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98304, EndOfFile: 175024"
"13:48:27.6239953","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6240004","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cabinet.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98304, EndOfFile: 175024"
"13:48:27.6240092","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cabinet.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6240250","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cabinet.dll","SUCCESS",""
"13:48:27.6240748","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cabinet.dll","SUCCESS",""
"13:48:27.6309257","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6309663","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6309906","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6310005","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:27.6313950","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6314425","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6314543","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6314565","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6314787","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS",""
"13:48:27.6315075","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6315186","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1937408, EndOfFile: 3674784"
"13:48:27.6315301","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6315361","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1937408, EndOfFile: 3674784"
"13:48:27.6315561","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6315796","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:27.6315957","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:27.6323592","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6324402","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6324529","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512000, EndOfFile: 988984"
"13:48:27.6324633","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6324685","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512000, EndOfFile: 988984"
"13:48:27.6324762","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6324834","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\SHCore.dll","SUCCESS",""
"13:48:27.6325112","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS",""
"13:48:27.6333499","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6334200","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6334334","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6334407","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS",""
"13:48:27.6338266","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WofUtil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6338278","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6338615","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6338667","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6338749","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204800, EndOfFile: 365120"
"13:48:27.6338828","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6338840","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6338909","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204800, EndOfFile: 365120"
"13:48:27.6338935","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WofUtil.dll","SUCCESS",""
"13:48:27.6338988","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6339166","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cfgmgr32.dll","SUCCESS",""
"13:48:27.6339300","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS",""
"13:48:27.6340113","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\devrtl.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6340405","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6340633","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6340646","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6340742","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\devrtl.dll","SUCCESS",""
"13:48:27.6340789","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6341773","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WofUtil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6342017","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6342197","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24576, EndOfFile: 61440"
"13:48:27.6342285","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6342337","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WofUtil.dll","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24576, EndOfFile: 61440"
"13:48:27.6342409","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WofUtil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6342480","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\WofUtil.dll","SUCCESS",""
"13:48:27.6342597","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WofUtil.dll","SUCCESS",""
"13:48:27.6344055","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6344188","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6347807","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\devrtl.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6348444","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6348546","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45056, EndOfFile: 90112"
"13:48:27.6348643","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6348698","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\devrtl.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45056, EndOfFile: 90112"
"13:48:27.6348784","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\devrtl.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6348974","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\devrtl.dll","SUCCESS",""
"13:48:27.6349111","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\devrtl.dll","SUCCESS",""
"13:48:27.6405153","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6406282","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6406763","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6407083","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll","SUCCESS",""
"13:48:27.6409561","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6409824","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6571981","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rsaenh.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6572385","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6572487","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6572567","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rsaenh.dll","SUCCESS",""
"13:48:27.6575479","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rsaenh.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6575986","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6576073","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135168, EndOfFile: 253488"
"13:48:27.6576160","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6576210","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\rsaenh.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135168, EndOfFile: 253488"
"13:48:27.6576287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rsaenh.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6576365","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\rsaenh.dll","SUCCESS",""
"13:48:27.6576626","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rsaenh.dll","SUCCESS",""
"13:48:27.6586879","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6587335","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6587519","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6587624","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptbase.dll","SUCCESS",""
"13:48:27.6590178","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6590189","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cryptbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6590412","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.6590570","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20480, EndOfFile: 59320"
"13:48:27.6590572","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6590696","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6590731","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6590759","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20480, EndOfFile: 59320"
"13:48:27.6590839","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cryptbase.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6590922","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\cryptbase.dll","SUCCESS",""
"13:48:27.6591060","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cryptbase.dll","SUCCESS",""
"13:48:27.6591454","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:27.6594151","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6594423","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6594509","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368640, EndOfFile: 637800"
"13:48:27.6594942","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win怀"
"13:48:27.6595061","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368640, EndOfFile: 637800"
"13:48:27.6595293","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6595418","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:27.6595573","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:27.6786002","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spinf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6786532","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6786680","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6786777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spinf.dll","SUCCESS",""
"13:48:27.6788949","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6789179","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6790385","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spinf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6790818","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6790924","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69632, EndOfFile: 126976"
"13:48:27.6791032","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6791098","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spinf.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69632, EndOfFile: 126976"
"13:48:27.6791193","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spinf.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6791455","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\spinf.dll","SUCCESS",""
"13:48:27.6791616","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spinf.dll","SUCCESS",""
"13:48:27.6805104","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6805531","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6805817","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6805916","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:27.6807569","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6807755","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6807781","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6808022","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6808097","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6808255","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:27.6809834","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6810355","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6810497","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233472, EndOfFile: 422920"
"13:48:27.6810614","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6810677","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wldp.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233472, EndOfFile: 422920"
"13:48:27.6810773","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6810960","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:27.6811140","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:27.6813632","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6813990","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6814098","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278528, EndOfFile: 641920"
"13:48:27.6814212","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6814274","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278528, EndOfFile: 641920"
"13:48:27.6814375","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6814543","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:27.6814735","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:27.6829721","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spfileq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6830160","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6830251","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6830325","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spfileq.dll","SUCCESS",""
"13:48:27.6831971","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.6832126","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.6834129","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\spfileq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6834450","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6834522","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73728, EndOfFile: 139264"
"13:48:27.6834609","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6834747","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\spfileq.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73728, EndOfFile: 139264"
"13:48:27.6838485","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\spfileq.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6838604","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\spfileq.dll","SUCCESS",""
"13:48:27.6838849","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\spfileq.dll","SUCCESS",""
"13:48:27.6848873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6849423","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6849763","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6849972","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:27.6854787","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6855032","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6855119","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6855298","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:27.6855485","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6856346","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6856486","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53248, EndOfFile: 170872"
"13:48:27.6856698","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6856783","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53248, EndOfFile: 170872"
"13:48:27.6856905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6856996","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:27.6857118","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6857156","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:27.6857601","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6857694","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6857763","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:27.6861703","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6862206","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6862309","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6862462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6862549","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6862627","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:27.6862635","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659456, EndOfFile: 1236920"
"13:48:27.6862873","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6862941","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659456, EndOfFile: 1236920"
"13:48:27.6863041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6863129","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:27.6863269","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:27.6863551","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6863820","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6863916","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6864048","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:27.6867690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6867828","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6868059","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.6868146","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868352, EndOfFile: 1873232"
"13:48:27.6868211","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6868309","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6868373","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6868411","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:27.6868465","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868352, EndOfFile: 1873232"
"13:48:27.6868587","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6868677","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:27.6868933","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:27.6873265","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6873769","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6873885","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69632, EndOfFile: 187392"
"13:48:27.6873991","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.6874054","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69632, EndOfFile: 187392"
"13:48:27.6874145","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6874229","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:27.6874626","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:27.6877239","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6878021","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6878137","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102400, EndOfFile: 203904"
"13:48:27.6878227","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.6878280","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102400, EndOfFile: 203904"
"13:48:27.6878351","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6878421","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:27.6878620","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:27.6878666","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6879086","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.6879172","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.6879350","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:27.6886650","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.6887003","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.6887185","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360448, EndOfFile: 688128"
"13:48:27.6887310","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win?"
"13:48:27.6887372","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360448, EndOfFile: 688128"
"13:48:27.6887455","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.6887628","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:27.6887766","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:27.7030359","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7030753","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7030866","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7030966","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:27.7033874","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7034105","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7035319","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7035800","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7035890","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1576960, EndOfFile: 2696592"
"13:48:27.7036154","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7036233","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1576960, EndOfFile: 2696592"
"13:48:27.7036340","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7036431","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:27.7036586","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:27.7040260","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\WindowsShell.Manifest","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:27.7040408","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\WindowsShell.Manifest","SUCCESS","AllocationSize: 4096, EndOfFile: 670, NumberOfLinks: 4, DeletePending: False, Directory: False"
"13:48:27.7060038","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msctf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7060421","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7060525","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7060604","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msctf.dll","SUCCESS",""
"13:48:27.7063141","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msctf.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7063507","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7063594","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847872, EndOfFile: 1435240"
"13:48:27.7063681","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7063732","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847872, EndOfFile: 1435240"
"13:48:27.7063807","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msctf.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7063882","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msctf.dll","SUCCESS",""
"13:48:27.7064106","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msctf.dll","SUCCESS",""
"13:48:27.7140642","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7140893","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7140981","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7141145","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:27.7144992","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7145217","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.7145426","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53248, EndOfFile: 121280"
"13:48:27.7145548","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7145695","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53248, EndOfFile: 121280"
"13:48:27.7145813","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7145899","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:27.7146173","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:27.7148925","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7149479","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7149652","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7149770","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS",""
"13:48:27.7154325","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7154950","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.7155064","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483328, EndOfFile: 889816"
"13:48:27.7155574","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7158252","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483328, EndOfFile: 889816"
"13:48:27.7158815","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7159262","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\oleaut32.dll","SUCCESS",""
"13:48:27.7159673","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS",""
"13:48:27.7203923","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7204151","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7204234","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7204410","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS",""
"13:48:27.7207056","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7207283","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7208684","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7209567","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7210020","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774144, EndOfFile: 1369128"
"13:48:27.7210146","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7210210","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextInputFramework.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774144, EndOfFile: 1369128"
"13:48:27.7210291","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextInputFramework.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7210372","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\TextInputFramework.dll","SUCCESS",""
"13:48:27.7210644","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextInputFramework.dll","SUCCESS",""
"13:48:27.7324914","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\Fonts\StaticCache.dat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:27.7325032","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","AllocationSize: 9203712, EndOfFile: 20381696, NumberOfLinks: 2, DeletePending: False, Directory: False"
"13:48:27.7378599","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7378807","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7412452","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextShaping.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7412831","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7412953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7413214","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextShaping.dll","SUCCESS",""
"13:48:27.7416000","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7416304","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7418481","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\TextShaping.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7418847","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ"
"13:48:27.7418945","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270336, EndOfFile: 749328"
"13:48:27.7419051","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.7419218","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\TextShaping.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270336, EndOfFile: 749328"
"13:48:27.7419359","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\TextShaping.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7419493","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\TextShaping.dll","SUCCESS",""
"13:48:27.7419674","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\TextShaping.dll","SUCCESS",""
"13:48:27.7493089","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7493339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7493442","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7493517","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS",""
"13:48:27.7497009","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7497435","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.7497687","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4902912, EndOfFile: 8831584"
"13:48:27.7498270","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:27.7503231","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4902912, EndOfFile: 8831584"
"13:48:27.7503472","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7503602","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\windows.storage.dll","SUCCESS",""
"13:48:27.7503768","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS",""
"13:48:27.7507536","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7507905","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7507991","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7508065","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:27.7514323","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7527477","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:27.7527836","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200704, EndOfFile: 410504"
"13:48:27.7527960","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7528016","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200704, EndOfFile: 410504"
"13:48:27.7528098","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7528175","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:27.7528317","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:27.7560581","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7560947","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7561041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7561117","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS",""
"13:48:27.7565416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7566698","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.7566820","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118784, EndOfFile: 224632"
"13:48:27.7566929","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7566986","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ntmarta.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118784, EndOfFile: 224632"
"13:48:27.7567278","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7567514","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ntmarta.dll","SUCCESS",""
"13:48:27.7567694","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS",""
"13:48:27.7574225","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7574386","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:27.7574877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:27.7574994","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7575971","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\drivers\SET9BED.tmp","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:27.7576124","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\drivers\SET9BED.tmp","SUCCESS","AllocationSize: 2519040, EndOfFile: 2518232, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:27.7600356","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7600878","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7601007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7601089","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS",""
"13:48:27.7603229","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7603476","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7603550","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688128, EndOfFile: 1216272"
"13:48:27.7603631","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.7603904","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreMessaging.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688128, EndOfFile: 1216272"
"13:48:27.7604018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreMessaging.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7604099","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\CoreMessaging.dll","SUCCESS",""
"13:48:27.7604232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreMessaging.dll","SUCCESS",""
"13:48:27.7636945","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7637274","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7637908","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7637996","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS",""
"13:48:27.7651722","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7652114","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7653998","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7655395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:27.7865004","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7871100","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drvstore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7871462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7871706","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7871826","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drvstore.dll","SUCCESS",""
"13:48:27.7873186","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7876666","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7876940","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7877300","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1310720, EndOfFile: 3032976"
"13:48:27.7877437","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7877567","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CoreUIComponents.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1310720, EndOfFile: 3032976"
"13:48:27.7877682","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7877734","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CoreUIComponents.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7877824","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\CoreUIComponents.dll","SUCCESS",""
"13:48:27.7877996","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CoreUIComponents.dll","SUCCESS",""
"13:48:27.7878091","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.7878182","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.7878261","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:27.7880496","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7881130","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ"
"13:48:27.7881230","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593920, EndOfFile: 1505496"
"13:48:27.7881329","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7881460","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593920, EndOfFile: 1505496"
"13:48:27.7881849","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7881979","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:27.7882121","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:27.7883592","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7884133","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.7884272","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708608, EndOfFile: 1687288"
"13:48:27.7884391","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.7884529","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708608, EndOfFile: 1687288"
"13:48:27.7884661","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7884739","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:27.7885043","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:27.7887420","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.7887659","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.7889541","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drvstore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.7889922","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.7890003","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876544, EndOfFile: 1542672"
"13:48:27.7908322","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ"
"13:48:27.7908394","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drvstore.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876544, EndOfFile: 1542672"
"13:48:27.7908499","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drvstore.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.7908575","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drvstore.dll","SUCCESS",""
"13:48:27.7908806","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drvstore.dll","SUCCESS",""
"13:48:27.8065418","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8065827","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8216806","MsMpEng.exe","3220","Thread Create","","SUCCESS","Thread ID: 9140"
"13:48:27.8228289","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8228603","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8231013","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8231398","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8231492","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61440, EndOfFile: 122880"
"13:48:27.8231701","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8231760","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61440, EndOfFile: 122880"
"13:48:27.8231856","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8231951","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:27.8232278","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:27.8261304","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\services.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8261695","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\services.exe","SUCCESS","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A"
"13:48:27.8261780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\services.exe","SUCCESS",""
"13:48:27.8262905","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\services.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8263211","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\services.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ"
"13:48:27.8263406","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\services.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524288, EndOfFile: 906376"
"13:48:27.8263515","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\services.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8263580","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\services.exe","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524288, EndOfFile: 906376"
"13:48:27.8264144","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\services.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8264333","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\services.exe","SUCCESS",""
"13:48:27.8264628","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\services.exe","SUCCESS",""
"13:48:27.8346701","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8347249","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","CreationTime: 30.09.2025 13:54:23, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:23, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A"
"13:48:27.8347407","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wtsapi32.dll","SUCCESS",""
"13:48:27.8348586","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wtsapi32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8349088","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\wtsapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:27.8349357","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\wtsapi32.dll","SUCCESS","SyncType: SyncTypeOther"
"13:48:27.8350376","MsMpEng.exe","3220","Load Image","C:\Windows\System32\wtsapi32.dll","SUCCESS","Image Base: 0x7ff90e510000, Image Size: 0x2a000"
"13:48:27.8353968","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wtsapi32.dll","SUCCESS",""
"13:48:27.8368735","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\winsta.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8369175","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\winsta.dll","SUCCESS","CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A"
"13:48:27.8369271","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\winsta.dll","SUCCESS",""
"13:48:27.8371144","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\winsta.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8371670","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\winsta.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:27.8371865","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\winsta.dll","SUCCESS","SyncType: SyncTypeOther"
"13:48:27.8373002","MsMpEng.exe","3220","Load Image","C:\Windows\System32\winsta.dll","SUCCESS","Image Base: 0x7ff911100000, Image Size: 0x63000"
"13:48:27.8374034","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\winsta.dll","SUCCESS",""
"13:48:27.8383400","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8383833","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8383982","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8384067","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:27.8385942","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8386381","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8386472","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8386550","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:27.8398249","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8400229","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8403402","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8406491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8408413","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8411750","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8415556","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8418233","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:27.8466492","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8469234","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 263736, Length: 4096"
"13:48:27.8469672","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 119536, Length: 4096"
"13:48:27.8470610","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 255496, Length: 4096"
"13:48:27.8470954","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 848776, Length: 4096"
"13:48:27.8471154","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 115416, Length: 4096"
"13:48:27.8471325","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 832296, Length: 4096"
"13:48:27.8471641","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 852896, Length: 4096"
"13:48:27.8472315","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8473085","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8473288","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8474541","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8474933","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8475541","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8475783","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8476799","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8477274","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8478381","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8478497","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8479435","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8479546","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8480213","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8480298","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8481434","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8481550","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 251376, Length: 4096"
"13:48:27.8481846","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8517858","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8518503","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8518607","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8518700","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8518758","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8518842","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8518936","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8519222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8520017","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8520512","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.8520884","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8521704","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ"
"13:48:27.8521871","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8522002","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8522130","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8526818","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8533594","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8533782","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8533950","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8534191","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8534434","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8534532","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8534621","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8534902","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8535744","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8535936","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8536028","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8540513","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8540726","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8540812","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8540891","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ"
"13:48:27.8541025","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:27.8541126","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8541211","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8541921","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:27.8554461","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8554857","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.8555079","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8555210","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8555288","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:27.8556086","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 844656, Length: 4096"
"13:48:27.8556392","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8556488","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 836416, Length: 4096"
"13:48:27.8556589","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8556663","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8556725","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:27.8556966","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.8569509","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8570030","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8570165","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8570262","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:27.8577655","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8577965","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8578055","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8578135","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:27.8579274","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8579629","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8579715","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8579785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:27.8616801","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8617279","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8617403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8617611","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:27.8619105","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8619462","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8619568","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8619654","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:27.8671965","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8672557","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8672682","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8672772","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:27.8674147","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8674461","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8674548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8674709","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:27.8679100","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8679505","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8679593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8679666","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:27.8681926","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8682651","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8682750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8682917","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:27.8684329","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8684774","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.8684871","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4399104, EndOfFile: 7699432"
"13:48:27.8684978","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.8685157","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4399104, EndOfFile: 7699432"
"13:48:27.8685314","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.8685436","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:27.8685886","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:27.8688099","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8688415","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8688502","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8688575","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:27.8690106","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8690348","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8690430","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8690584","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:27.8692846","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8693516","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8693647","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8693727","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:27.8694757","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8694970","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8695150","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8695220","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:27.8696145","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8696529","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8696607","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8696671","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:27.8697570","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8697836","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8697910","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8697973","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:27.8704046","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8704420","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8704503","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8704817","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:27.8706575","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8706951","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8707031","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8707099","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS",""
"13:48:27.8721067","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8721459","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8721553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8721632","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:27.8848903","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8849237","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8849359","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8849542","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS",""
"13:48:27.8885109","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8885436","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8885548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8885763","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:27.8897427","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8897723","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8897814","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8897976","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:27.8908487","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8908783","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8908875","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8909061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:27.8972384","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8972850","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8972965","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8973129","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS",""
"13:48:27.8996849","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.8997979","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.8998169","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.8998279","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS",""
"13:48:27.9025718","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9026260","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9026375","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9026457","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS",""
"13:48:27.9028773","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9029077","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9029152","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565248, EndOfFile: 1079912"
"13:48:27.9029305","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9029375","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\propsys.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565248, EndOfFile: 1079912"
"13:48:27.9029476","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9029562","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\propsys.dll","SUCCESS",""
"13:48:27.9029773","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS",""
"13:48:27.9038224","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9038562","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9038752","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9038840","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS",""
"13:48:27.9040821","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9041178","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(찚㈀"
"13:48:27.9041312","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385024, EndOfFile: 724552"
"13:48:27.9041411","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.9041467","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\clbcatq.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385024, EndOfFile: 724552"
"13:48:27.9041557","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9041652","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\clbcatq.dll","SUCCESS",""
"13:48:27.9041902","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS",""
"13:48:27.9131771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9132194","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9132305","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9132381","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS",""
"13:48:27.9134907","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9135363","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ"
"13:48:27.9135771","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90112, EndOfFile: 179136"
"13:48:27.9135920","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9135976","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90112, EndOfFile: 179136"
"13:48:27.9136051","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9136123","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\profapi.dll","SUCCESS",""
"13:48:27.9136258","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS",""
"13:48:27.9393615","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9394573","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9394780","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9395134","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS",""
"13:48:27.9401344","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9401628","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9401721","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233472, EndOfFile: 819608"
"13:48:27.9401911","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9401970","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233472, EndOfFile: 819608"
"13:48:27.9402069","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9402162","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS",""
"13:48:27.9402454","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS",""
"13:48:27.9631334","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9632045","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9632372","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9632581","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS",""
"13:48:27.9638337","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9638741","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9638841","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81920, EndOfFile: 167936"
"13:48:27.9638934","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9638987","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\edputil.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81920, EndOfFile: 167936"
"13:48:27.9639075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9639165","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\edputil.dll","SUCCESS",""
"13:48:27.9639522","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS",""
"13:48:27.9646724","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9647356","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9647594","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9647744","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS",""
"13:48:27.9651470","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.9652157","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.9652887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9653151","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9653313","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9653412","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS",""
"13:48:27.9653771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9654258","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9654390","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1130496, EndOfFile: 1921024"
"13:48:27.9654648","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9654737","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1130496, EndOfFile: 1921024"
"13:48:27.9654872","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9654988","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\urlmon.dll","SUCCESS",""
"13:48:27.9655321","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS",""
"13:48:27.9660518","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9660945","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9661025","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1216512, EndOfFile: 2918640"
"13:48:27.9661107","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9661159","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1216512, EndOfFile: 2918640"
"13:48:27.9661339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9661469","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\iertutil.dll","SUCCESS",""
"13:48:27.9661615","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS",""
"13:48:27.9665746","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9666171","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9666408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9666551","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS",""
"13:48:27.9669618","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9670101","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:27.9670230","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65536, EndOfFile: 146080"
"13:48:27.9670369","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.9670462","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\srvcli.dll","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65536, EndOfFile: 146080"
"13:48:27.9670673","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9670824","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\srvcli.dll","SUCCESS",""
"13:48:27.9671031","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS",""
"13:48:27.9672008","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9672298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9672395","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9672469","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS",""
"13:48:27.9676479","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9677081","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ"
"13:48:27.9677225","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28672, EndOfFile: 63336"
"13:48:27.9677380","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:27.9677582","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\netutils.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28672, EndOfFile: 63336"
"13:48:27.9677731","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9677868","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\netutils.dll","SUCCESS",""
"13:48:27.9678439","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS",""
"13:48:27.9721593","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9722298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9722412","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9722509","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS",""
"13:48:27.9725350","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9725959","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ"
"13:48:27.9726070","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151552, EndOfFile: 307200"
"13:48:27.9726182","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ"
"13:48:27.9726320","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\sspicli.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151552, EndOfFile: 307200"
"13:48:27.9726448","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9726542","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\sspicli.dll","SUCCESS",""
"13:48:27.9726707","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS",""
"13:48:27.9800473","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9800961","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9801095","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9801200","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS",""
"13:48:27.9803349","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.9803580","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.9805848","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9806591","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ"
"13:48:27.9807015","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49152, EndOfFile: 103832"
"13:48:27.9807171","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9807323","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\virtdisk.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49152, EndOfFile: 103832"
"13:48:27.9807481","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9807586","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\virtdisk.dll","SUCCESS",""
"13:48:27.9807769","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS",""
"13:48:27.9826642","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9827308","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:27.9827539","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:27.9827648","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:27.9880251","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:27.9880560","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:27.9883606","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:27.9884272","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9884388","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12288, EndOfFile: 45056"
"13:48:27.9884499","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:27.9884644","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12288, EndOfFile: 45056"
"13:48:27.9884780","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:27.9884881","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:27.9885044","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:28.0042802","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\en-US\grpconv.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:28.0042927","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","AllocationSize: 4096, EndOfFile: 3072, NumberOfLinks: 2, DeletePending: False, Directory: False"
"13:48:28.0048210","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0048550","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0048650","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0048969","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:28.0050482","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0050860","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0051060","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0051174","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:28.0055984","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0056270","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.0056356","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.0057689","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0057844","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.0058009","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.0058804","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0059048","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.0059990","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.0060720","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0060890","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.0061069","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.0061960","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.0063817","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0064082","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.0064189","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.0068237","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.0092005","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.0096665","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0096864","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.0096950","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.0097856","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.0098965","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0099148","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.0099340","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.0110987","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0111248","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0111327","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS",""
"13:48:28.0112696","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0112923","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0113004","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS",""
"13:48:28.0114297","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0114588","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0114663","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS",""
"13:48:28.0114915","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.0115170","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.0116491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0116657","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0116729","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS",""
"13:48:28.0117447","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0117768","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32768, EndOfFile: 68167, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0117855","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:28.0117934","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32768, EndOfFile: 68167, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0118056","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4曘;","SUCCESS","SyncType: SyncTypeOther"
"13:48:28.0119523","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.0119611","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A, AllocationSize: 32768, EndOfFile: 68167"
"13:48:28.0120931","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0121091","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0121241","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS",""
"13:48:28.0121690","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0121961","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0122012","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0122189","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0122329","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:28.0122461","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","AllocationSize: 32768, EndOfFile: 68180, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0122561","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:28.0122637","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS","AllocationSize: 32768, EndOfFile: 68180, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0122760","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4ꗔ","SUCCESS","SyncType: SyncTypeOther"
"13:48:28.0123650","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.0123759","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","BUFFER OVERFLOW","CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, FileAttributes: A, AllocationSize: 32768, EndOfFile: 68180"
"13:48:28.0123909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0124182","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0124275","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0124364","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:28.0125050","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0125239","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.0125304","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS",""
"13:48:28.0126349","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0126563","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","AllocationSize: 40960, EndOfFile: 87970, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0126721","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:28.0126812","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS","AllocationSize: 40960, EndOfFile: 87970, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0126940","MsMpEng.exe","3220","CreateFileMapping","\Device\HarddiskVolume4뎨","SUCCESS","SyncType: SyncTypeOther"
"13:48:28.0128182","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.0128270","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, FileAttributes: A, AllocationSize: 40960, EndOfFile: 87970"
"13:48:28.0128677","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS",""
"13:48:28.0129061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat","SUCCESS",""
"13:48:28.0129452","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat","SUCCESS",""
"13:48:28.0130287","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0130647","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0131316","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: RH, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0131620","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","AllocationSize: 32768, EndOfFile: 68167, NumberOfLinks: 3, DeletePending: False, Directory: False"
"13:48:28.0131707","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A"
"13:48:28.0131824","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS","Offset: 0, Length: 68167, Priority: Normal"
"13:48:28.0136797","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0137181","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0137288","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0137374","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:28.0138794","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0139273","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0139403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0139707","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:28.0141277","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0141774","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0141871","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0142081","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:28.0143059","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0144061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS",""
"13:48:28.0144222","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat","SUCCESS",""
"13:48:28.0144848","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0144973","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0145070","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:28.0147675","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0147962","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0148143","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0148169","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0148217","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:28.0148382","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.0148497","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS",""
"13:48:28.0148752","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\en-US\grpconv.exe.mui","SUCCESS",""
"13:48:28.0149734","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0150797","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0150940","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0151036","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:28.0154734","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0155249","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0155353","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0155443","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:28.0156942","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0157157","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0157231","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0157306","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:28.0158285","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0158469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0158535","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0158597","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:28.0160074","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0160319","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0160399","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0168866","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:28.0174862","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0176858","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0177148","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0177265","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:28.0182979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0183767","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0183953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0184058","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:28.0198161","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0198546","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0198636","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0198712","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:28.0199743","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0199956","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0200038","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0200194","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:28.0201140","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0202701","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0202843","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0203061","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:28.0204664","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0205163","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0205283","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0205483","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:28.0254379","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0254602","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0254695","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0254771","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:28.0257540","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0257761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0258005","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0258105","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:28.0270441","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0270816","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0270936","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0271013","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:28.0286892","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.0287268","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.0287378","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.0287457","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:28.0340751","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.0341071","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.0346317","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.0346543","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.3342979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3344175","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.3345044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3345523","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\runonce.exe","BUFFER OVERFLOW",""
"13:48:28.3345903","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:28.3346020","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL"
"13:48:28.3346147","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:28.3346358","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:28.3563838","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.3564103","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.3898769","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3899185","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.3899397","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3899493","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.3900002","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3900367","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.3900483","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3900732","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3901603","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3901784","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.3901853","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3902050","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.3902102","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3902190","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.3902267","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3902383","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3903599","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3903847","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.3903918","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3903994","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.3904205","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.3904454","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.3904563","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3904729","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3905725","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3905983","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.3906072","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.3907981","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wintrust.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3908339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.3908549","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.3909303","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wintrust.dll","SUCCESS",""
"13:48:28.3910627","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3910981","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.3911167","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.3911292","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS",""
"13:48:28.3912624","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3912986","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.3913117","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.3913213","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS",""
"13:48:28.3914343","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.3914514","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.3914587","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.3914651","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4062534","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wintrust.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4063170","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.4063250","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299008, EndOfFile: 530344"
"13:48:28.4063657","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win,"
"13:48:28.4063736","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\wintrust.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299008, EndOfFile: 530344"
"13:48:28.4064095","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wintrust.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4064335","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\wintrust.dll","SUCCESS",""
"13:48:28.4065552","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wintrust.dll","SUCCESS",""
"13:48:28.4070978","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4071431","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ"
"13:48:28.4071665","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909312, EndOfFile: 1534408"
"13:48:28.4071832","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.4071900","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909312, EndOfFile: 1534408"
"13:48:28.4072064","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\crypt32.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4072169","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\crypt32.dll","SUCCESS",""
"13:48:28.4072333","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS",""
"13:48:28.4073460","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4074062","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4074363","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4074449","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40960, EndOfFile: 88248"
"13:48:28.4074530","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ"
"13:48:28.4074658","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40960, EndOfFile: 88248"
"13:48:28.4074768","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msasn1.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4074841","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msasn1.dll","SUCCESS",""
"13:48:28.4074966","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS",""
"13:48:28.4075532","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment","REPARSE","Desired Access: Read"
"13:48:28.4076521","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4076751","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:28.4076830","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4076908","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4076964","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4077111","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4077213","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Desired Access: Read"
"13:48:28.4077252","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4077370","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4078235","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Query: Cached, SubKeys: 0, Values: 15"
"13:48:28.4078596","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4078989","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ"
"13:48:28.4079086","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4079167","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4079216","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4079287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4079379","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4079578","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4079653","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 0, Type: REG_EXPAND_SZ"
"13:48:28.4080685","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4081275","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4081348","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4081438","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.4081492","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.4081565","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4081602","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\ComSpec","SUCCESS","Type: REG_EXPAND_SZ, Length: 60, Data: %SystemRoot%\system32\cmd.exe"
"13:48:28.4081655","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4081871","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4082884","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4083152","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4083252","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4084074","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4084385","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.4085031","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4085268","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4085447","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4086514","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4087427","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.4089002","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\DriverData","SUCCESS","Type: REG_SZ, Length: 78, Data: C:\Windows\System32\Drivers\DriverData"
"13:48:28.4090547","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.4091814","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\OS","SUCCESS","Type: REG_SZ, Length: 22, Data: Windows_NT"
"13:48:28.4093401","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 3, Type: REG_EXPAND_SZ"
"13:48:28.4095410","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path","BUFFER OVERFLOW","Length: 144"
"13:48:28.4095466","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4096645","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path","SUCCESS","Type: REG_EXPAND_SZ, Length: 514, Data: "
"13:48:28.4097914","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.4099007","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PATHEXT","SUCCESS","Type: REG_SZ, Length: 108, Data: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC"
"13:48:28.4099163","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.4100824","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.4101942","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_ARCHITECTURE","SUCCESS","Type: REG_SZ, Length: 12, Data: AMD64"
"13:48:28.4103225","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 6, Type: REG_EXPAND_SZ"
"13:48:28.4104192","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath","BUFFER OVERFLOW","Length: 144"
"13:48:28.4106832","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 188, Data: "
"13:48:28.4108727","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 7, Type: REG_EXPAND_SZ"
"13:48:28.4111180","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TEMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP"
"13:48:28.4114699","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 8, Type: REG_EXPAND_SZ"
"13:48:28.4119680","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP"
"13:48:28.4121491","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.4122589","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\USERNAME","SUCCESS","Type: REG_SZ, Length: 14, Data: SYSTEM"
"13:48:28.4123776","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 10, Type: REG_EXPAND_SZ"
"13:48:28.4124750","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\windir","SUCCESS","Type: REG_EXPAND_SZ, Length: 26, Data: %SystemRoot%"
"13:48:28.4126314","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 11, Type: REG_SZ"
"13:48:28.4127466","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\NUMBER_OF_PROCESSORS","SUCCESS","Type: REG_SZ, Length: 4, Data: 4"
"13:48:28.4129272","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 12, Type: REG_SZ"
"13:48:28.4130339","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_LEVEL","SUCCESS","Type: REG_SZ, Length: 6, Data: 25"
"13:48:28.4131439","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 13, Type: REG_SZ"
"13:48:28.4132525","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_IDENTIFIER","SUCCESS","Type: REG_SZ, Length: 100, Data: AMD64 Family 25 Model 33 Stepping 0, AuthenticAMD"
"13:48:28.4133289","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS","Index: 14, Type: REG_SZ"
"13:48:28.4134232","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_REVISION","SUCCESS","Type: REG_SZ, Length: 10, Data: 2100"
"13:48:28.4135187","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager\Environment","SUCCESS",""
"13:48:28.4136168","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4144746","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SFC","REPARSE","Desired Access: Read"
"13:48:28.4145954","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\SFC","NAME NOT FOUND","Desired Access: Read"
"13:48:28.4147199","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4148243","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion","SUCCESS","Desired Access: Read"
"13:48:28.4149953","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Query: Cached, SubKeys: 167, Values: 11"
"13:48:28.4152459","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.4154152","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\Program Files"
"13:48:28.4156536","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.4159412","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files"
"13:48:28.4161412","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4161750","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4161887","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4162088","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4163839","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4164077","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.4164790","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.4166301","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Program Files (x86)"
"13:48:28.4166895","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4167274","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.4168452","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)","SUCCESS","Type: REG_SZ, Length: 72, Data: C:\Program Files (x86)\Common Files"
"13:48:28.4170713","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.4172534","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files"
"13:48:28.4174126","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 5, Type: REG_EXPAND_SZ"
"13:48:28.4176792","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 34, Data: %SystemRoot%\inf"
"13:48:28.4178130","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 6, Type: REG_EXPAND_SZ"
"13:48:28.4179072","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MediaPathUnexpanded","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %SystemRoot%\Media"
"13:48:28.4179942","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 7, Type: REG_EXPAND_SZ"
"13:48:28.4181129","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesPath","SUCCESS","Type: REG_EXPAND_SZ, Length: 30, Data: %ProgramFiles%"
"13:48:28.4182246","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.4183162","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\Program Files"
"13:48:28.4184081","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.4185178","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_ConfigureProgramsName","SUCCESS","Type: REG_SZ, Length: 64, Data: Set Program Access and Defaults"
"13:48:28.4186417","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS","Index: 10, Type: REG_SZ"
"13:48:28.4187391","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_GamesName","SUCCESS","Type: REG_SZ, Length: 12, Data: Games"
"13:48:28.4189601","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion","SUCCESS",""
"13:48:28.4190797","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4191727","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Desired Access: Read"
"13:48:28.4192705","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: Cached, SubKeys: 4, Values: 4"
"13:48:28.4193577","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 0, Type: REG_EXPAND_SZ"
"13:48:28.4194418","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A"
"13:48:28.4194487","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","AllocationSize: 2519040, EndOfFile: 2518232, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.4195080","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.4197308","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2510848, Length: 7384, Priority: Normal"
"13:48:28.4197999","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2506752, Length: 4096, Priority: Normal"
"13:48:28.4200447","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 4096, Length: 520192, Priority: Normal"
"13:48:28.4213650","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %SystemDrive%\Users\Default"
"13:48:28.4214361","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 1, Type: REG_EXPAND_SZ"
"13:48:28.4215221","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory","SUCCESS","Type: REG_EXPAND_SZ, Length: 40, Data: %SystemDrive%\Users"
"13:48:28.4216075","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 2, Type: REG_EXPAND_SZ"
"13:48:28.4216941","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData","SUCCESS","Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData"
"13:48:28.4217760","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 3, Type: REG_EXPAND_SZ"
"13:48:28.4218530","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public","SUCCESS","Type: REG_EXPAND_SZ, Length: 54, Data: %SystemDrive%\Users\Public"
"13:48:28.4219514","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS",""
"13:48:28.4221313","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4222249","MsMpEng.exe","3220","RegCreateKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY"
"13:48:28.4223180","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: Cached, SubKeys: 4, Values: 4"
"13:48:28.4224012","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 0, Name: S-1-5-18"
"13:48:28.4224820","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4225533","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","Desired Access: Read"
"13:48:28.4226493","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile"
"13:48:28.4228042","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4228791","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4229713","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\ntuser.dat","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4230427","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4230629","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\config\systemprofile","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4230704","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\config\systemprofile","BUFFER OVERFLOW","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D, AllocationSize: 0, EndOfFile: 0"
"13:48:28.4231071","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\config\systemprofile\ntuser.dat","NO SUCH FILE","FileInformationClass: FileIdFullDirectoryInformation, Filter: ntuser.dat"
"13:48:28.4231256","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\config\systemprofile","SUCCESS",""
"13:48:28.4232891","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4233149","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS",""
"13:48:28.4243416","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 524288, Length: 524288, Priority: Normal"
"13:48:28.4244103","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 1, Name: S-1-5-19"
"13:48:28.4249018","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4250263","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19","SUCCESS","Desired Access: Read"
"13:48:28.4251111","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 84, Data: %systemroot%\ServiceProfiles\LocalService"
"13:48:28.4253192","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4253529","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.4253621","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS",""
"13:48:28.4254391","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4254585","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A"
"13:48:28.4254748","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT","SUCCESS",""
"13:48:28.4256222","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\LocalService\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4256454","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19","SUCCESS",""
"13:48:28.4257623","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 2, Name: S-1-5-20"
"13:48:28.4258432","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4259287","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20","SUCCESS","Desired Access: Read"
"13:48:28.4260427","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 88, Data: %systemroot%\ServiceProfiles\NetworkService"
"13:48:28.4263013","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4263369","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.4263451","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS",""
"13:48:28.4264220","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4264481","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A"
"13:48:28.4264585","MsMpEng.exe","3220","CloseFile","C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT","SUCCESS",""
"13:48:28.4265934","MsMpEng.exe","3220","CreateFile","C:\Windows\ServiceProfiles\NetworkService\AppData\Local\VirtualStore","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4266165","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20","SUCCESS",""
"13:48:28.4266730","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1048576, Length: 524288, Priority: Normal"
"13:48:28.4268823","MsMpEng.exe","3220","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Index: 3, Name: S-1-5-21-4172013786-3171869251-2938521833-1000"
"13:48:28.4269624","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4270477","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Desired Access: Read"
"13:48:28.4271583","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 32, Data: C:\Users\hacker"
"13:48:28.4273472","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4273808","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: HANCI"
"13:48:28.4273875","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\NTUSER.DAT","SUCCESS",""
"13:48:28.4275274","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4275571","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\NTUSER.DAT","SUCCESS","CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, FileAttributes: HANCI"
"13:48:28.4275853","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\NTUSER.DAT","SUCCESS",""
"13:48:28.4277164","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4277425","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS","CreationTime: 12.08.2025 19:42:01, LastAccessTime: 13.10.2025 13:32:41, LastWriteTime: 12.08.2025 19:42:01, ChangeTime: 12.08.2025 19:42:01, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: D"
"13:48:28.4277490","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\AppData\Local\VirtualStore","SUCCESS",""
"13:48:28.4278028","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS",""
"13:48:28.4278821","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList","SUCCESS",""
"13:48:28.4279826","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4280614","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:28.4281164","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:28.4282185","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:28.4282944","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4283872","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:28.4285679","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:28.4286557","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4287260","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Read"
"13:48:28.4287863","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 12"
"13:48:28.4288690","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.4289558","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools","BUFFER OVERFLOW","Length: 144"
"13:48:28.4290272","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools","SUCCESS","Type: REG_SZ, Length: 148, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools"
"13:48:28.4290763","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.4291735","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData","SUCCESS","Type: REG_SZ, Length: 30, Data: C:\ProgramData"
"13:48:28.4292670","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.4293966","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Desktop","SUCCESS","Type: REG_SZ, Length: 48, Data: C:\Users\Public\Desktop"
"13:48:28.4295015","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.4295811","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Documents","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\Public\Documents"
"13:48:28.4297692","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.4299565","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Programs","SUCCESS","Type: REG_SZ, Length: 106, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs"
"13:48:28.4300556","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.4301819","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\ProgramData\Microsoft\Windows\Start Menu"
"13:48:28.4302873","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 6, Type: REG_SZ"
"13:48:28.4303502","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup"
"13:48:28.4304065","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 7, Type: REG_SZ"
"13:48:28.4304453","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Templates","SUCCESS","Type: REG_SZ, Length: 86, Data: C:\ProgramData\Microsoft\Windows\Templates"
"13:48:28.4305291","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.4305746","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusic","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\Public\Music"
"13:48:28.4306404","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.4306780","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPictures","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\Public\Pictures"
"13:48:28.4307358","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 10, Type: REG_SZ"
"13:48:28.4307971","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideo","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Users\Public\Videos"
"13:48:28.4308607","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 11, Type: REG_SZ"
"13:48:28.4309026","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\OEM Links","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\ProgramData\OEM\Links"
"13:48:28.4309918","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS",""
"13:48:28.4310712","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.4311488","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read"
"13:48:28.4312410","MsMpEng.exe","3220","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Query: Cached, SubKeys: 1, Values: 11"
"13:48:28.4313617","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 0, Type: REG_EXPAND_SZ"
"13:48:28.4314059","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 28, Data: %ProgramData%"
"13:48:28.4314964","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 1, Type: REG_EXPAND_SZ"
"13:48:28.4315793","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Desktop","SUCCESS","Type: REG_EXPAND_SZ, Length: 34, Data: %PUBLIC%\Desktop"
"13:48:28.4316446","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 2, Type: REG_EXPAND_SZ"
"13:48:28.4316960","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Documents","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Documents"
"13:48:28.4317255","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 3, Type: REG_EXPAND_SZ"
"13:48:28.4317660","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs","SUCCESS","Type: REG_EXPAND_SZ, Length: 104, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs"
"13:48:28.4318276","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 4, Type: REG_EXPAND_SZ"
"13:48:28.4318622","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Start Menu","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %ProgramData%\Microsoft\Windows\Start Menu"
"13:48:28.4319047","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 5, Type: REG_EXPAND_SZ"
"13:48:28.4319574","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Startup","SUCCESS","Type: REG_EXPAND_SZ, Length: 120, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup"
"13:48:28.4320504","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 6, Type: REG_EXPAND_SZ"
"13:48:28.4321108","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Templates","SUCCESS","Type: REG_EXPAND_SZ, Length: 84, Data: %ProgramData%\Microsoft\Windows\Templates"
"13:48:28.4321768","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 7, Type: REG_EXPAND_SZ"
"13:48:28.4322428","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonMusic","SUCCESS","Type: REG_EXPAND_SZ, Length: 30, Data: %PUBLIC%\Music"
"13:48:28.4323192","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 8, Type: REG_EXPAND_SZ"
"13:48:28.4323704","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonPictures","SUCCESS","Type: REG_EXPAND_SZ, Length: 36, Data: %PUBLIC%\Pictures"
"13:48:28.4324145","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 9, Type: REG_EXPAND_SZ"
"13:48:28.4324526","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonVideo","SUCCESS","Type: REG_EXPAND_SZ, Length: 32, Data: %PUBLIC%\Videos"
"13:48:28.4325872","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 10, Type: REG_EXPAND_SZ"
"13:48:28.4326543","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}","SUCCESS","Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Downloads"
"13:48:28.4327177","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS",""
"13:48:28.4329686","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4329878","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.4329947","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4330808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4331008","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4331079","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4331154","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4331211","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4331609","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4331753","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4332059","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4332784","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4332948","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.4333103","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4333380","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4333455","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4333560","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4333654","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4333878","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4334828","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4335090","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:28.4335188","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4335268","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.4335337","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.4335411","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4336662","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4336931","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4337882","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4338155","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.4338267","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4339536","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4339669","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.4339729","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.4341558","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4341883","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.4342808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4343140","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A"
"13:48:28.4343208","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380928, EndOfFile: 378880, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.4345916","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.4346264","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.4348375","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372736, Length: 6144, Priority: Normal"
"13:48:28.4348629","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 376832, Length: 2048, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4383576","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1572864, Length: 524288, Priority: Normal"
"13:48:28.4403465","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2097152, Length: 421080, Priority: Normal"
"13:48:28.4424770","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.4425339","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4430154","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.4436904","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 4096, Length: 262144, Priority: Normal"
"13:48:28.4445385","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 266240, Length: 258048, Priority: Normal"
"13:48:28.4449553","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 524288, Length: 4096, Priority: Normal"
"13:48:28.4462681","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 528384, Length: 262144, Priority: Normal"
"13:48:28.4490840","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 790528, Length: 258048, Priority: Normal"
"13:48:28.4494464","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1048576, Length: 4096, Priority: Normal"
"13:48:28.4515156","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1052672, Length: 262144, Priority: Normal"
"13:48:28.4534980","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1314816, Length: 258048, Priority: Normal"
"13:48:28.4548680","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1572864, Length: 4096, Priority: Normal"
"13:48:28.4712170","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1576960, Length: 262144, Priority: Normal"
"13:48:28.4717004","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270336, Length: 4096, Priority: Normal"
"13:48:28.4717113","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270336, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4754079","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 1839104, Length: 258048, Priority: Normal"
"13:48:28.4755787","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2097152, Length: 4096, Priority: Normal"
"13:48:28.4756729","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274432, Length: 4096, Priority: Normal"
"13:48:28.4757056","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274432, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4782713","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81920, Length: 4096, Priority: Normal"
"13:48:28.4782805","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81920, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4799448","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299008, Length: 4096, Priority: Normal"
"13:48:28.4800188","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266240, Length: 8192, Priority: Normal"
"13:48:28.4800254","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266240, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4803941","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184320, Length: 8192, Priority: Normal"
"13:48:28.4805170","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184320, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4811251","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86016, Length: 4096, Priority: Normal"
"13:48:28.4811442","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86016, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4814332","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2101248, Length: 262144, Priority: Normal"
"13:48:28.4814413","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258048, Length: 8192, Priority: Normal"
"13:48:28.4814503","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258048, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4829081","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:28.4829172","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4096, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4844314","MsMpEng.exe","3220","ReadFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Offset: 2363392, Length: 147456, Priority: Normal"
"13:48:28.4847561","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192512, Length: 4096, Priority: Normal"
"13:48:28.4847635","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192512, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4907578","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278528, Length: 4096, Priority: Normal"
"13:48:28.4907659","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278528, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4909934","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282624, Length: 4096, Priority: Normal"
"13:48:28.4910086","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282624, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4914409","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303104, Length: 4096, Priority: Normal"
"13:48:28.4914889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307200, Length: 8192, Priority: Normal"
"13:48:28.4914958","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 311296, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.4917225","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.4997512","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5004346","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.5005107","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5005522","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\grpconv.exe","BUFFER OVERFLOW",""
"13:48:28.5005841","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:28.5005935","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL"
"13:48:28.5006036","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:28.5006223","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:28.5010695","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286720, Length: 12288, Priority: Normal"
"13:48:28.5010797","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286720, Length: 12288, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5011187","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5011355","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\drivers\NeacSafe64.sys","NO EAS ON FILE",""
"13:48:28.5012298","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5012525","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.5012596","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.5012676","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.5012816","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","BUFFER OVERFLOW","CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2519040, EndOfFile: 2518232"
"13:48:28.5012920","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.5013032","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5014134","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5014255","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5015104","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5015555","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5015875","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\drivers\NeacSafe64.sys","SUCCESS",""
"13:48:28.5023434","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90112, Length: 16384, Priority: Normal"
"13:48:28.5023527","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90112, Length: 16384, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5050418","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180224, Length: 4096, Priority: Normal"
"13:48:28.5050503","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180224, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5154011","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122880, Length: 8192, Priority: Normal"
"13:48:28.5154100","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122880, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5157404","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131072, Length: 4096, Priority: Normal"
"13:48:28.5157490","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131072, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5216395","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151552, Length: 8192, Priority: Normal"
"13:48:28.5216482","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151552, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5220309","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159744, Length: 4096, Priority: Normal"
"13:48:28.5220402","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159744, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5224797","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118784, Length: 8192, Priority: Normal"
"13:48:28.5224958","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118784, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5229576","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135168, Length: 8192, Priority: Normal"
"13:48:28.5229661","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135168, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5233907","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196608, Length: 4096, Priority: Normal"
"13:48:28.5233984","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196608, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5816734","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147456, Length: 8192, Priority: Normal"
"13:48:28.5817915","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147456, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5859428","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.5859767","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.5861841","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5862274","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.5862526","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16384, EndOfFile: 50504"
"13:48:28.5862732","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.5862836","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW","CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16384, EndOfFile: 50504"
"13:48:28.5863043","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.5863134","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:28.5863462","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:28.5900437","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143360, Length: 8192, Priority: Normal"
"13:48:28.5900552","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143360, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5920450","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176128, Length: 8192, Priority: Normal"
"13:48:28.5920547","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176128, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.5947811","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5948617","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.5948958","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.5949062","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:28.5950322","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.5950735","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.5950857","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.5950943","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:28.5981343","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167936, Length: 8192, Priority: Normal"
"13:48:28.5981508","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167936, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.6070772","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6071160","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6071286","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6071369","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:28.6121278","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6122298","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6122424","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6123531","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:28.6129480","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6129924","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6130017","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6130097","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:28.6132184","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6132582","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6132671","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6132841","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:28.6136157","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6136602","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6136698","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6136777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:28.6189603","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6189920","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6190007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6190193","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:28.6193094","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6193913","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6194041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6194224","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:28.6200416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6200739","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6200819","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6200891","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:28.6212853","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6213403","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6213520","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6213599","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS",""
"13:48:28.6218875","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8192, Length: 4096, Priority: Normal"
"13:48:28.6219066","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8192, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.6245301","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49152, Length: 8192, Priority: Normal"
"13:48:28.6245410","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49152, Length: 8192, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.6250414","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12288, Length: 16384, Priority: Normal"
"13:48:28.6250541","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12288, Length: 16384, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.6256793","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106496, Length: 4096, Priority: Normal"
"13:48:28.6256954","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106496, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.6300488","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6300824","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6300998","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6301108","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:28.6358922","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6359349","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6359469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6359549","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:28.6363891","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6364245","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6364335","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6364409","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:28.6366093","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6366539","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6366632","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6366716","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:28.6369623","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6370018","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6370107","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6370179","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:28.6371212","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6371417","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6371494","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6371563","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:28.6413040","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6413435","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6413543","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6413623","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:28.6433909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6434593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6434799","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6435026","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:28.6563799","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\thumbcache.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6564041","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6564125","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6564202","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\thumbcache.dll","SUCCESS",""
"13:48:28.6566489","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.6566744","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.6567824","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\thumbcache.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6568138","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ"
"13:48:28.6568215","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249856, EndOfFile: 460176"
"13:48:28.6568301","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ"
"13:48:28.6568355","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\thumbcache.dll","BUFFER OVERFLOW","CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249856, EndOfFile: 460176"
"13:48:28.6568436","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\thumbcache.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.6568586","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\thumbcache.dll","SUCCESS",""
"13:48:28.6568792","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\thumbcache.dll","SUCCESS",""
"13:48:28.6625567","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6626091","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6626200","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6626280","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS",""
"13:48:28.6659004","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.6659286","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.6842378","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6842833","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6842958","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6843267","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.6844439","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6844901","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.6845007","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.6866075","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:28.6898340","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.6898609","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.6909623","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.6909946","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.6910272","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.6910507","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 675736, Length: 4096"
"13:48:28.6910773","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.6910890","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.6995947","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77824, Length: 8192, Priority: Normal"
"13:48:28.6996076","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77824, Length: 4096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.7001719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7002146","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7002287","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7002369","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:28.7003416","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7003644","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7003721","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7003787","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:28.7036676","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7037841","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7038049","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7038133","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:28.7075571","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7076064","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7076191","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7076271","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp140.dll","SUCCESS",""
"13:48:28.7078366","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7078541","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7080516","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7080833","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7080951","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561152, EndOfFile: 557728"
"13:48:28.7081031","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7081083","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\msvcp140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561152, EndOfFile: 557728"
"13:48:28.7081175","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp140.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7081348","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\msvcp140.dll","SUCCESS",""
"13:48:28.7081504","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp140.dll","SUCCESS",""
"13:48:28.7084358","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7084673","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7084759","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7084831","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140.dll","SUCCESS",""
"13:48:28.7086279","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7086543","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7089639","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7089869","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7090026","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126976, EndOfFile: 124544"
"13:48:28.7090163","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7090222","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126976, EndOfFile: 124544"
"13:48:28.7090296","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7090383","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\vcruntime140.dll","SUCCESS",""
"13:48:28.7090514","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140.dll","SUCCESS",""
"13:48:28.7093326","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7093662","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7093815","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7093894","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS",""
"13:48:28.7095300","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7095431","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7096549","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7097119","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7097224","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53248, EndOfFile: 49792"
"13:48:28.7097395","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7097472","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\vcruntime140_1.dll","BUFFER OVERFLOW","CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53248, EndOfFile: 49792"
"13:48:28.7097553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\vcruntime140_1.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7097652","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\vcruntime140_1.dll","SUCCESS",""
"13:48:28.7097785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\vcruntime140_1.dll","SUCCESS",""
"13:48:28.7132480","MsMpEng.exe","3220","Thread Create","","SUCCESS","Thread ID: 7424"
"13:48:28.7136831","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7137169","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","CreationTime: 10.10.2025 15:34:53, LastAccessTime: 13.10.2025 13:27:12, LastWriteTime: 13.10.2025 11:45:59, ChangeTime: 13.10.2025 11:45:59, FileAttributes: A"
"13:48:28.7137235","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS",""
"13:48:28.7137960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7138149","MsMpEng.exe","3220","CreateFileMapping","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE"
"13:48:28.7139295","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS",""
"13:48:28.7139676","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Offset: 46080, Length: 12288, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.7140155","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","Offset: 153088, Length: 45056, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.7146151","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7146334","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:28.7146598","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7149542","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7149905","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7149994","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7150074","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7150132","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7150305","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7150408","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7150544","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7151310","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7151659","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7151768","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7151861","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7151914","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7151998","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7152173","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7152292","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7153061","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7153490","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7153616","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7153696","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:28.7153752","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7153961","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7154069","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7154236","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7155815","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7156119","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7156222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7156390","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","AllocationSize: 241664, EndOfFile: 240128, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.7156578","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)"
"13:48:28.7156678","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.7161664","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS",""
"13:48:28.7163940","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7164226","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7164830","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7165135","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7165240","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:28.7165336","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7165420","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7166074","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:28.7193027","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:28.7193162","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7193270","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7194074","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7194339","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 222536, Length: 4096"
"13:48:28.7194587","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 86576, Length: 4096"
"13:48:28.7194836","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 700456, Length: 4096"
"13:48:28.7195263","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7196113","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28672, Length: 350208, Priority: Normal"
"13:48:28.7196377","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28672, Length: 344064, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
"13:48:28.7205235","MsMpEng.exe","3220","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Setup","SUCCESS","Desired Access: Read"
"13:48:28.7205392","MsMpEng.exe","3220","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\MinimizeFootprint","NAME NOT FOUND","Length: 20"
"13:48:28.7205696","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup","SUCCESS",""
"13:48:28.7205905","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)"
"13:48:28.7206014","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.7212630","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","AllocationSize: 241664, EndOfFile: 240128, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.7213481","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)"
"13:48:28.7213990","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.7218911","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7218980","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS",""
"13:48:28.7230054","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","INVALID DEVICE REQUEST","Control: 0x90390 (Device:0x9 Function:228 Method: 0)"
"13:48:28.7230162","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.7238717","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll","SUCCESS",""
"13:48:28.7239752","MsMpEng.exe","3220","Thread Exit","","SUCCESS","Thread ID: 7424, User Time: 0.0000000, Kernel Time: 0.0000000"
"13:48:28.7241532","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7241967","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.7242057","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.7243988","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7244757","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.7244921","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.7247909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7248278","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.7250488","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7252960","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7253216","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.7253306","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.7254538","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7258632","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7258887","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.7258979","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7259076","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7259496","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7259638","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7259728","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:28.7260887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7261202","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7261376","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.7261461","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:28.7266267","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.7267873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7268679","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7268898","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.7268982","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.7270382","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7272135","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7272541","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.7272669","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7281850","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.7282154","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7283620","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7283798","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.7283967","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.7285158","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7285332","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.7285405","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.7286659","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7287031","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.7288092","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7289418","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7289649","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.7289830","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.7290740","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7294544","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7294795","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.7295194","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7297893","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.7299503","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7300319","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7300500","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.7300712","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.7302044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.7303356","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7303686","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.7303775","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7315119","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.7315303","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.7316001","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7317051","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7317283","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 45376, Length: 4096"
"13:48:28.7317708","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7318043","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7318144","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 181336, Length: 4096"
"13:48:28.7318359","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7318589","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7318657","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:28.7319331","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 856992, Length: 24"
"13:48:28.7319481","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 857016, Length: 4096"
"13:48:28.7319793","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 861112, Length: 24"
"13:48:28.7319887","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 861136, Length: 4096"
"13:48:28.7320071","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:28.7320148","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7323135","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7323495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7351906","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7352136","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NO EAS ON FILE",""
"13:48:28.7357756","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7357981","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7359235","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:28.7360628","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\drivers\SET9BED.tmp","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.7361289","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7361395","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.7361504","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.7361645","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Query: Cached, SubKeys: 0, Values: 35"
"13:48:28.7361817","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.7361917","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"13:48:28.7362029","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.7362091","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE"
"13:48:28.7362173","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.7362226","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM","SUCCESS","Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM"
"13:48:28.7362296","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.7362428","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000","SUCCESS","Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD"
"13:48:28.7362550","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.7362607","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT","SUCCESS","Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT"
"13:48:28.7362782","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.7362838","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY"
"13:48:28.7362914","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 6, Type: REG_SZ"
"13:48:28.7363063","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM","SUCCESS","Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM"
"13:48:28.7363142","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 7, Type: REG_SZ"
"13:48:28.7363197","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","BUFFER OVERFLOW","Length: 144"
"13:48:28.7363437","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","SUCCESS","Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT"
"13:48:28.7363651","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.7363736","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","BUFFER OVERFLOW","Length: 144"
"13:48:28.7363808","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","SUCCESS","Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT"
"13:48:28.7363907","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.7363969","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:28.7364096","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7364235","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:28.7364379","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.7364664","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7364866","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read"
"13:48:28.7365361","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local"
"13:48:28.7365535","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS",""
"13:48:28.7365765","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7365866","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.7365964","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.7366071","MsMpEng.exe","3220","RegQueryKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Query: Cached, SubKeys: 0, Values: 35"
"13:48:28.7366182","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.7366435","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"13:48:28.7366549","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.7366675","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE"
"13:48:28.7366792","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.7366858","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM","SUCCESS","Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM"
"13:48:28.7366926","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.7367133","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000","SUCCESS","Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD"
"13:48:28.7367285","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.7367630","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT","SUCCESS","Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT"
"13:48:28.7368103","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.7368282","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY","SUCCESS","Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY"
"13:48:28.7368407","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 6, Type: REG_SZ"
"13:48:28.7368468","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM","SUCCESS","Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM"
"13:48:28.7368549","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 7, Type: REG_SZ"
"13:48:28.7368603","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","BUFFER OVERFLOW","Length: 144"
"13:48:28.7368747","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20","SUCCESS","Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT"
"13:48:28.7368898","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.7368959","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","BUFFER OVERFLOW","Length: 144"
"13:48:28.7369027","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19","SUCCESS","Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT"
"13:48:28.7369121","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.7369183","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:28.7369276","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","BUFFER OVERFLOW","Index: 10, Length: 144"
"13:48:28.7369408","MsMpEng.exe","3220","RegEnumValue","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Index: 10, Type: REG_SZ"
"13:48:28.7370464","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:28.7370642","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:28.7370973","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7371065","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:28.7371213","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.7371423","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7371523","MsMpEng.exe","3220","RegOpenKey","HKCU\Environment","SUCCESS","Desired Access: Read"
"13:48:28.7371638","MsMpEng.exe","3220","RegQueryKey","HKCU\Environment","SUCCESS","Query: Cached, SubKeys: 0, Values: 4"
"13:48:28.7371713","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 0, Type: REG_EXPAND_SZ"
"13:48:28.7371785","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\Path","BUFFER OVERFLOW","Length: 144"
"13:48:28.7371873","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\Path","SUCCESS","Type: REG_EXPAND_SZ, Length: 156, Data: "
"13:48:28.7372078","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 1, Type: REG_EXPAND_SZ"
"13:48:28.7372155","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\TEMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp"
"13:48:28.7372286","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 2, Type: REG_EXPAND_SZ"
"13:48:28.7372340","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\TMP","SUCCESS","Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp"
"13:48:28.7372429","MsMpEng.exe","3220","RegEnumValue","HKCU\Environment","SUCCESS","Index: 3, Type: REG_EXPAND_SZ"
"13:48:28.7372484","MsMpEng.exe","3220","RegQueryValue","HKCU\Environment\OneDrive","SUCCESS","Type: REG_EXPAND_SZ, Length: 50, Data: C:\Users\hacker\OneDrive"
"13:48:28.7372658","MsMpEng.exe","3220","RegCloseKey","HKCU\Environment","SUCCESS",""
"13:48:28.7372761","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7372831","MsMpEng.exe","3220","RegOpenKey","HKCU\Volatile Environment","SUCCESS","Desired Access: Read"
"13:48:28.7372942","MsMpEng.exe","3220","RegQueryKey","HKCU\Volatile Environment","SUCCESS","Query: Cached, SubKeys: 1, Values: 9"
"13:48:28.7373007","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.7373073","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\LOGONSERVER","SUCCESS","Type: REG_SZ, Length: 24, Data: \\WINDOWS11"
"13:48:28.7373233","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.7373304","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERDOMAIN","SUCCESS","Type: REG_SZ, Length: 20, Data: WINDOWS11"
"13:48:28.7373403","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.7373459","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERNAME","SUCCESS","Type: REG_SZ, Length: 14, Data: hacker"
"13:48:28.7373543","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.7373596","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERPROFILE","SUCCESS","Type: REG_SZ, Length: 32, Data: C:\Users\hacker"
"13:48:28.7373675","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.7373729","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\HOMEPATH","SUCCESS","Type: REG_SZ, Length: 28, Data: \Users\hacker"
"13:48:28.7373876","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.7373954","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\HOMEDRIVE","SUCCESS","Type: REG_SZ, Length: 6, Data: C:"
"13:48:28.7374048","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 6, Type: REG_SZ"
"13:48:28.7374602","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\APPDATA","SUCCESS","Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming"
"13:48:28.7374867","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 7, Type: REG_SZ"
"13:48:28.7374960","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\LOCALAPPDATA","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local"
"13:48:28.7375067","MsMpEng.exe","3220","RegEnumValue","HKCU\Volatile Environment","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.7375128","MsMpEng.exe","3220","RegQueryValue","HKCU\Volatile Environment\USERDOMAIN_ROAMINGPROFILE","SUCCESS","Type: REG_SZ, Length: 20, Data: WINDOWS11"
"13:48:28.7375255","MsMpEng.exe","3220","RegCloseKey","HKCU\Volatile Environment","SUCCESS",""
"13:48:28.7375356","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7375514","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Read"
"13:48:28.7375801","MsMpEng.exe","3220","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 31"
"13:48:28.7375873","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 0, Type: REG_SZ"
"13:48:28.7375941","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\!Do not use this registry key","SUCCESS","Type: REG_SZ, Length: 130, Data: Use the SHGetFolderPath or SHGetKnownFolderPath function instead"
"13:48:28.7376117","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 1, Type: REG_SZ"
"13:48:28.7376185","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData","SUCCESS","Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming"
"13:48:28.7376286","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 2, Type: REG_SZ"
"13:48:28.7376346","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Local AppData","SUCCESS","Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local"
"13:48:28.7376426","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 3, Type: REG_SZ"
"13:48:28.7376482","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CD Burning","SUCCESS","Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\Burn\Burn"
"13:48:28.7376562","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 4, Type: REG_SZ"
"13:48:28.7376682","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Libraries"
"13:48:28.7376787","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 5, Type: REG_SZ"
"13:48:28.7376842","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Video","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Users\hacker\Videos"
"13:48:28.7376922","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 6, Type: REG_SZ"
"13:48:28.7376975","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Pictures","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Pictures"
"13:48:28.7377062","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 7, Type: REG_SZ"
"13:48:28.7377114","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop","SUCCESS","Type: REG_SZ, Length: 48, Data: C:\Users\hacker\Desktop"
"13:48:28.7377189","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 8, Type: REG_SZ"
"13:48:28.7377296","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History","SUCCESS","Type: REG_SZ, Length: 112, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\History"
"13:48:28.7377399","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 9, Type: REG_SZ"
"13:48:28.7377453","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood","BUFFER OVERFLOW","Length: 144"
"13:48:28.7377519","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood","SUCCESS","Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
"13:48:28.7377597","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 10, Type: REG_SZ"
"13:48:28.7377654","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Contacts"
"13:48:28.7377739","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 11, Type: REG_SZ"
"13:48:28.7377795","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{00BCFC5A-ED94-4E48-96A1-3F6217F21990}","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\RoamingTiles"
"13:48:28.7377938","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 12, Type: REG_SZ"
"13:48:28.7378002","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCookies"
"13:48:28.7378085","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 13, Type: REG_SZ"
"13:48:28.7378138","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Favorites","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Favorites"
"13:48:28.7378216","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 14, Type: REG_SZ"
"13:48:28.7378268","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\SendTo","SUCCESS","Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\SendTo"
"13:48:28.7378341","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 15, Type: REG_SZ"
"13:48:28.7378394","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu","SUCCESS","Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu"
"13:48:28.7378543","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 16, Type: REG_SZ"
"13:48:28.7378605","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Music","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Music"
"13:48:28.7378687","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 17, Type: REG_SZ"
"13:48:28.7378739","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs","BUFFER OVERFLOW","Length: 144"
"13:48:28.7378805","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs","SUCCESS","Type: REG_SZ, Length: 140, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs"
"13:48:28.7378882","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 18, Type: REG_SZ"
"13:48:28.7378936","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Recent","SUCCESS","Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Recent"
"13:48:28.7379012","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 19, Type: REG_SZ"
"13:48:28.7379117","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood","BUFFER OVERFLOW","Length: 144"
"13:48:28.7379201","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood","SUCCESS","Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
"13:48:28.7379285","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 20, Type: REG_SZ"
"13:48:28.7379342","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}","SUCCESS","Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Searches"
"13:48:28.7379433","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 21, Type: REG_SZ"
"13:48:28.7379487","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Downloads"
"13:48:28.7379572","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 22, Type: REG_SZ"
"13:48:28.7379625","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{A520A1A4-1780-4FF6-BD18-167343C5AF16}","SUCCESS","Type: REG_SZ, Length: 66, Data: C:\Users\hacker\AppData\LocalLow"
"13:48:28.7379771","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 23, Type: REG_SZ"
"13:48:28.7379832","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup","BUFFER OVERFLOW","Length: 144"
"13:48:28.7379912","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup","SUCCESS","Type: REG_SZ, Length: 156, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"
"13:48:28.7379995","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 24, Type: REG_SZ"
"13:48:28.7380049","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools","BUFFER OVERFLOW","Length: 144"
"13:48:28.7380114","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools","SUCCESS","Type: REG_SZ, Length: 182, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools"
"13:48:28.7380196","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 25, Type: REG_SZ"
"13:48:28.7380250","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal","SUCCESS","Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Documents"
"13:48:28.7380396","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 26, Type: REG_SZ"
"13:48:28.7380457","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}","SUCCESS","Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Links"
"13:48:28.7380544","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 27, Type: REG_SZ"
"13:48:28.7380596","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCache"
"13:48:28.7380692","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 28, Type: REG_SZ"
"13:48:28.7380745","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Templates","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Templates"
"13:48:28.7380821","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 29, Type: REG_SZ"
"13:48:28.7380931","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}","SUCCESS","Type: REG_SZ, Length: 56, Data: C:\Users\hacker\Saved Games"
"13:48:28.7381039","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Index: 30, Type: REG_SZ"
"13:48:28.7381096","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Fonts","SUCCESS","Type: REG_SZ, Length: 34, Data: C:\WINDOWS\Fonts"
"13:48:28.7381198","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS",""
"13:48:28.7381281","MsMpEng.exe","3220","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7381357","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read"
"13:48:28.7381460","MsMpEng.exe","3220","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Query: Cached, SubKeys: 0, Values: 20"
"13:48:28.7381591","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 0, Type: REG_EXPAND_SZ"
"13:48:28.7381665","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming"
"13:48:28.7381763","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 1, Type: REG_EXPAND_SZ"
"13:48:28.7381819","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache","SUCCESS","Type: REG_EXPAND_SZ, Length: 112, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache"
"13:48:28.7382524","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 2, Type: REG_EXPAND_SZ"
"13:48:28.7382629","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies","SUCCESS","Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies"
"13:48:28.7382839","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 3, Type: REG_EXPAND_SZ"
"13:48:28.7382909","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop","SUCCESS","Type: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop"
"13:48:28.7383003","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 4, Type: REG_EXPAND_SZ"
"13:48:28.7383057","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Favorites"
"13:48:28.7383137","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 5, Type: REG_EXPAND_SZ"
"13:48:28.7383190","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\History","SUCCESS","Type: REG_EXPAND_SZ, Length: 108, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\History"
"13:48:28.7383272","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 6, Type: REG_EXPAND_SZ"
"13:48:28.7383395","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local"
"13:48:28.7383514","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 7, Type: REG_EXPAND_SZ"
"13:48:28.7383579","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music","SUCCESS","Type: REG_EXPAND_SZ, Length: 40, Data: %USERPROFILE%\Music"
"13:48:28.7383658","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 8, Type: REG_EXPAND_SZ"
"13:48:28.7383712","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: %USERPROFILE%\Pictures"
"13:48:28.7383789","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 9, Type: REG_EXPAND_SZ"
"13:48:28.7383841","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video","SUCCESS","Type: REG_EXPAND_SZ, Length: 42, Data: %USERPROFILE%\Videos"
"13:48:28.7384017","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 10, Type: REG_EXPAND_SZ"
"13:48:28.7384099","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\NetHood","SUCCESS","Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
"13:48:28.7384197","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 11, Type: REG_EXPAND_SZ"
"13:48:28.7384259","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Documents"
"13:48:28.7384359","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 12, Type: REG_EXPAND_SZ"
"13:48:28.7384416","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\PrintHood","SUCCESS","Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
"13:48:28.7384642","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 13, Type: REG_EXPAND_SZ"
"13:48:28.7384819","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs","BUFFER OVERFLOW","Length: 144"
"13:48:28.7384906","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs","SUCCESS","Type: REG_EXPAND_SZ, Length: 136, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs"
"13:48:28.7384996","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 14, Type: REG_EXPAND_SZ"
"13:48:28.7385051","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Recent","SUCCESS","Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent"
"13:48:28.7385153","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 15, Type: REG_EXPAND_SZ"
"13:48:28.7385290","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\SendTo","SUCCESS","Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo"
"13:48:28.7385503","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 16, Type: REG_EXPAND_SZ"
"13:48:28.7385676","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Start Menu","SUCCESS","Type: REG_EXPAND_SZ, Length: 118, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu"
"13:48:28.7385903","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 17, Type: REG_EXPAND_SZ"
"13:48:28.7385996","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup","BUFFER OVERFLOW","Length: 144"
"13:48:28.7386083","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup","SUCCESS","Type: REG_EXPAND_SZ, Length: 152, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"
"13:48:28.7386167","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 18, Type: REG_EXPAND_SZ"
"13:48:28.7386223","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Templates","SUCCESS","Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates"
"13:48:28.7386305","MsMpEng.exe","3220","RegEnumValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Index: 19, Type: REG_EXPAND_SZ"
"13:48:28.7386527","MsMpEng.exe","3220","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}","SUCCESS","Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Downloads"
"13:48:28.7386664","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS",""
"13:48:28.7386807","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:28.7387061","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:28.7387344","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7387561","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.7387762","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.7387889","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:28.7388415","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7388895","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:28.7389065","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.7389145","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7389211","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.7389293","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.7389381","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:28.7389843","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:28.7390375","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7390918","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:28.7391128","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.7393535","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7393842","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7394502","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7394850","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A"
"13:48:28.7394935","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal"
"13:48:28.7395081","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380928, EndOfFile: 378880, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.7395335","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:28.7395904","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal"
"13:48:28.7396358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.7397768","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7398065","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7399169","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7399524","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7400261","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7400669","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7400735","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7401629","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7402399","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7403014","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7403201","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7403289","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7404410","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7404587","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7406256","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7406784","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7406900","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7407828","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7408331","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7408465","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7409301","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7410086","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7411956","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7412144","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7413168","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7413549","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7414419","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7414673","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7414760","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7415551","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7416005","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7416211","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7417197","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7417880","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7418063","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7418250","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7418960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7419122","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7419790","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7420146","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7420344","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7421119","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7421403","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7421495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7422778","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7423534","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7423819","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7423912","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7424634","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7424789","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7425914","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7426246","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7426316","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7427065","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7427267","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7427491","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7428650","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7431174","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7431884","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7432054","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7432834","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7433079","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7434197","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7434633","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7434707","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7435491","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7435834","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7435928","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7436667","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7437296","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7437566","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7437655","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7438820","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7439112","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7439786","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7440009","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7440072","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7441213","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7441415","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7441503","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7442189","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7442821","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7443100","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7443190","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7443851","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7444010","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7444651","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7444979","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7445042","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7445867","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7446136","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7446228","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7446965","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7447232","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \"
"13:48:28.7447412","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.7447503","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:28.7448286","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7448610","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7449587","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7449876","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7450919","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7451194","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7451909","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7452145","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7452207","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7452865","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7455915","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7457070","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7457267","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7457357","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7458159","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7458344","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7459025","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7459539","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7459874","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7460974","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7461214","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7461298","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.7462148","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7462754","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7463001","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7463091","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7463756","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7463986","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7464606","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7464834","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7464895","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7465545","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7465893","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7465975","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.7466621","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7467212","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7467361","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7467436","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7468348","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7468582","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7469527","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7469822","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7469907","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7473531","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7473887","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7474173","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.7475161","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7475951","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7476136","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7476230","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7476888","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7477161","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7478065","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7479147","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7479226","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7480143","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7480356","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7480442","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.7481137","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7481771","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7482053","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7482138","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7482801","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7482961","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7484759","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7485050","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7485120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7486166","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7486382","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7486567","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.7487301","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7487954","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7488132","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7488219","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7488854","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7491222","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7492076","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7492327","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7492391","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7493034","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7493268","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7493377","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.7496489","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.7497192","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7497489","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7497581","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7498255","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7498500","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7499186","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7499437","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.7499503","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7500475","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7500661","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.7500749","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.7501453","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7501729","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20646655, AvailableAllocationUnits: 5331773, SectorsPerAllocationUnit: 8, BytesPerSector: 512"
"13:48:28.7501804","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:28.7502491","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7502770","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7503784","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7503877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7504024","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7504179","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 82456, Length: 4096"
"13:48:28.7504428","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7506266","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.7506805","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:28.7507667","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:28.7511378","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7511747","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7511923","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7512035","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7512088","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7512164","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7512261","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7512435","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7513327","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7513516","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7513829","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7513945","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7513998","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7514115","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7514198","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7514434","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7515235","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7515468","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: WinÄ"
"13:48:28.7515724","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7515815","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:28.7515869","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7515937","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7516014","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7516203","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7517666","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7517917","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7518120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7520298","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7520408","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:28.7520507","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:28.7520730","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:28.7520835","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.7520898","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:28.7520973","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:28.7522784","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7522935","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.7522999","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7525831","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7526318","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7526524","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7526619","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7526674","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7526749","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7526840","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7527038","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7527926","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7528107","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(돭噷ᦅ"
"13:48:28.7528412","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7528523","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win譖ᐢ㰵"
"13:48:28.7528583","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7528657","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7528894","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7529058","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7529833","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7530007","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:28.7530764","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7530870","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:28.7530926","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.7530999","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7531080","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7531201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7532132","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7532314","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.7532402","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7533782","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7533949","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:28.7534011","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.7535848","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7536109","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.7536825","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.7537077","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A"
"13:48:28.7537137","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380928, EndOfFile: 378880, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.7539135","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.7539514","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.7542573","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372736, Length: 6144, Priority: Normal"
"13:48:28.7542599","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.7542866","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.7608054","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 270336, Length: 4096, Priority: Normal"
"13:48:28.7608648","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 274432, Length: 4096, Priority: Normal"
"13:48:28.7609497","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81920, Length: 4096, Priority: Normal"
"13:48:28.7622318","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299008, Length: 4096, Priority: Normal"
"13:48:28.7623118","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 266240, Length: 8192, Priority: Normal"
"13:48:28.7623358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 184320, Length: 8192, Priority: Normal"
"13:48:28.7626149","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 86016, Length: 4096, Priority: Normal"
"13:48:28.7626448","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 258048, Length: 8192, Priority: Normal"
"13:48:28.7639483","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:28.7640578","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 192512, Length: 4096, Priority: Normal"
"13:48:28.7640962","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278528, Length: 4096, Priority: Normal"
"13:48:28.7641225","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 282624, Length: 4096, Priority: Normal"
"13:48:28.7643172","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303104, Length: 4096, Priority: Normal"
"13:48:28.7643524","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307200, Length: 8192, Priority: Normal"
"13:48:28.7661203","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 286720, Length: 12288, Priority: Normal"
"13:48:28.7661950","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 90112, Length: 16384, Priority: Normal"
"13:48:28.7668461","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 180224, Length: 4096, Priority: Normal"
"13:48:28.7673193","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 122880, Length: 8192, Priority: Normal"
"13:48:28.7673553","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 131072, Length: 4096, Priority: Normal"
"13:48:28.7673801","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 151552, Length: 8192, Priority: Normal"
"13:48:28.7674216","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 159744, Length: 4096, Priority: Normal"
"13:48:28.7675363","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 118784, Length: 8192, Priority: Normal"
"13:48:28.7678037","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 135168, Length: 8192, Priority: Normal"
"13:48:28.7679884","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 196608, Length: 4096, Priority: Normal"
"13:48:28.7701537","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 147456, Length: 8192, Priority: Normal"
"13:48:28.7702776","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 143360, Length: 8192, Priority: Normal"
"13:48:28.7708886","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 176128, Length: 8192, Priority: Normal"
"13:48:28.7712423","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 167936, Length: 8192, Priority: Normal"
"13:48:28.7751833","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 8192, Length: 4096, Priority: Normal"
"13:48:28.7757414","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 49152, Length: 8192, Priority: Normal"
"13:48:28.7758013","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 12288, Length: 16384, Priority: Normal"
"13:48:28.7759441","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 106496, Length: 4096, Priority: Normal"
"13:48:28.7947009","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 77824, Length: 8192, Priority: Normal"
"13:48:28.8019678","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:28.8019824","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","BUFFER OVERFLOW","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380928, EndOfFile: 378880"
"13:48:28.8019944","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:28.8021145","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 28672, Length: 350208, Priority: Normal"
"13:48:28.8033241","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8050546","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8050728","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.8050875","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8052086","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8052287","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.8052352","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8053105","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8053479","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.8054288","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8055297","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8055501","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8055668","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8057002","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8057993","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8058226","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8058323","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8060900","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.8061908","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8062616","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8063136","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8063248","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8064251","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8065450","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8065981","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8066108","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8068131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.8068462","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8069926","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8070099","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.8070252","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8071719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8071879","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.8071946","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8072870","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8073131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.8073979","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8074904","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8075188","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8075351","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8077142","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8078991","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8079327","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8079418","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8081193","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.8082070","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8082939","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8083143","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8083224","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8083917","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8084795","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8084975","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8085052","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8087031","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.8087298","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8087751","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8088803","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.8089237","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.8089453","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.8089651","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.8089773","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.8089836","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:28.8090456","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 865232, Length: 24"
"13:48:28.8090628","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 865256, Length: 4096"
"13:48:28.8090932","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 869352, Length: 24"
"13:48:28.8091013","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 869376, Length: 4096"
"13:48:28.8091127","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:28.8091191","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.8093614","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8093919","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8099712","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8099857","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NO EAS ON FILE",""
"13:48:28.8101865","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8102149","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8102721","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:28.8103364","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8103460","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.8103641","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.8103800","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:28.8104107","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8104250","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:28.8104378","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.8104455","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8104516","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.8104600","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.8104688","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:28.8104861","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:28.8105021","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8105139","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:28.8105567","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.8105749","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:28.8105819","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:28.8105905","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8106085","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.8106175","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.8106309","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:28.8106762","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8106881","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:28.8107139","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.8107257","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8107359","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:28.8107492","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:28.8107698","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:28.8107846","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:28.8108037","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:28.8108279","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:28.8108455","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:28.8111564","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8111955","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.8112789","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8113140","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A"
"13:48:28.8113256","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal"
"13:48:28.8113406","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","AllocationSize: 380928, EndOfFile: 378880, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.8113617","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:28.8113971","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal"
"13:48:28.8114268","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.8116240","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8116538","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8117578","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8117819","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8118909","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8119480","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8119594","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8120731","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8121503","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8122157","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8122440","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8122752","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8126954","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8128304","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8129165","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8129541","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8129608","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8130901","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8131351","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8131571","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8132837","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8134002","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8134346","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8134523","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8136102","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8136296","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8136976","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8137767","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8138313","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8139300","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8139493","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8139669","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8140431","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8141061","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8141229","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8141312","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8141949","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8142216","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8142876","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8143363","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8143575","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8144305","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8144561","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8144667","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8145504","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8146128","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8146370","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8146473","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8147333","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8148568","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8152576","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8152904","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8155071","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8163254","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8166045","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8166945","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8172233","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8174941","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8176928","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8178614","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8185230","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8185761","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8186935","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8187261","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8187347","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8188053","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8188217","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8188319","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8190292","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8191393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8191806","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8191972","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8196727","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8197214","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8200443","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8200797","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8200873","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8201587","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8201755","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8201934","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8202615","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8204376","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8204730","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8204866","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8206106","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8207100","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8208104","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8209862","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8210067","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8214136","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8214582","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8214784","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8216139","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8216370","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \"
"13:48:28.8216612","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:28.8216693","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:28.8217481","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8217663","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8218673","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8218864","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8219846","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8220007","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8220670","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8221000","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8221062","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8221752","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8222788","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8224230","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8224879","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8225343","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8226349","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8226570","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8227258","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8227636","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8227803","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8228516","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8228772","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8228882","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU","SUCCESS",""
"13:48:28.8229563","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8230220","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8230399","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8230486","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8231350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8231512","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8232158","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8232475","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8232548","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8233216","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8233376","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\helpers","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8233462","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers","SUCCESS",""
"13:48:28.8234088","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8234701","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8234962","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8235049","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8235816","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8236120","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8236817","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8237087","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8237148","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8238503","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8238886","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8239029","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:28.8240090","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8240986","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8241388","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8241859","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8243048","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8243322","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8244700","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8245154","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8245262","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8246393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8246730","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8246882","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:28.8248014","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8249195","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8249374","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8249571","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8250271","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8250431","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8251234","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8251713","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8251825","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8252826","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8253074","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8253201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:28.8254578","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8255279","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8255457","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8255755","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8256490","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8256643","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8257268","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8257595","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8257659","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8258545","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8258624","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8258821","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8258908","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:28.8259352","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.8259559","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:28.8259661","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.8259780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:28.8260153","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8260313","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8260463","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8260996","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8261246","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8261847","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8262062","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:28.8262122","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8262786","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8263037","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:28.8263115","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:28.8263776","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8264000","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20646655, AvailableAllocationUnits: 5331773, SectorsPerAllocationUnit: 8, BytesPerSector: 512"
"13:48:28.8264152","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:28.8264583","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 65536, Priority: Normal"
"13:48:28.8265216","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 374784, Length: 4096, Priority: Normal"
"13:48:28.8265831","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 378880, Priority: Normal"
"13:48:28.8275213","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntmarta.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8275502","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:28.8275730","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntmarta.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:28.8275840","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntmarta.dll","SUCCESS",""
"13:48:28.8297939","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\SystemTemp\UDDA014.tmp","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:28.8298641","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\SystemTemp\UDDA014.tmp","SUCCESS","AllocationSize: 2519040, EndOfFile: 2518232, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:28.8364461","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 299008, Length: 4096, Priority: Normal"
"13:48:28.8364704","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 372736, Length: 4096, Priority: Normal"
"13:48:28.8380345","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 1024, Length: 185856, Priority: Normal"
"13:48:28.8383877","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 186880, Length: 91136, Priority: Normal"
"13:48:28.8385765","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 278016, Length: 12288, Priority: Normal"
"13:48:28.8386189","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 290304, Length: 9216, Priority: Normal"
"13:48:28.8386520","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 300032, Length: 75776, Priority: Normal"
"13:48:28.8388074","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 376832, Length: 2048, Priority: Normal"
"13:48:28.8388743","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 303104, Length: 4096, Priority: Normal"
"13:48:28.8389451","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 307200, Length: 4096, Priority: Normal"
"13:48:28.8389747","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 308116, Length: 9640, Priority: Normal"
"13:48:28.8390322","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 317756, Length: 4264, Priority: Normal"
"13:48:28.8390889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 319488, Length: 4096, Priority: Normal"
"13:48:28.8391458","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 323584, Length: 4096, Priority: Normal"
"13:48:28.8391870","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 326080, Length: 48399, Priority: Normal"
"13:48:28.8393946","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 81920, Length: 4096, Priority: Normal"
"13:48:28.8394219","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:28.8395159","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe:Zone.Identifier","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.8395840","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 2, Priority: Normal"
"13:48:28.8396117","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:28.8396252","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 272, Length: 28, Priority: Normal"
"13:48:28.8396432","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:28.8396847","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 0, Length: 360, Priority: Normal"
"13:48:28.8396996","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 364, Length: 76, Priority: Normal"
"13:48:28.8397389","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 448, Length: 262144, Priority: Normal"
"13:48:28.8408915","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","Offset: 262592, Length: 116288, Priority: Normal"
"13:48:28.8414656","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8415061","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.8415153","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8417103","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8417461","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.8417587","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8419630","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8421908","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.8423050","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8425251","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8425513","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8426092","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8427205","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8428160","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8428546","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8428644","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8431183","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.8432411","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8433737","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8434051","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8435171","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8436279","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8439184","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8439499","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8439581","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8457377","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.8457580","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8459214","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8459474","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:28.8459566","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8460731","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8460888","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:28.8460947","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:28.8461672","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8462122","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:28.8462993","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8464220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8464530","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8464609","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8465328","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8466589","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8466891","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8466978","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8470210","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:28.8471403","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8472171","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8472352","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:28.8472529","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:28.8473335","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:28.8475024","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:28.8475198","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:28.8475374","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8477309","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:28.8477477","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:28.8477961","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS","CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A"
"13:48:28.8478180","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8478525","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe","SUCCESS",""
"13:48:28.8480475","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:28.8480966","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:28.8481063","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:28.8531914","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.8532131","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:28.8532523","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:28.8532824","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.0973827","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.0974296","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.0974977","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\dllhost.exe","SUCCESS","Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.0975385","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\dllhost.exe","BUFFER OVERFLOW",""
"13:48:29.0975558","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:29.0975795","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\dllhost.exe","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL"
"13:48:29.0975961","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:29.0976160","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\dllhost.exe","SUCCESS",""
"13:48:29.3525919","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3526166","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3526242","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3526313","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win"
"13:48:29.3526362","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3526515","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3526615","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3526854","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3527586","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3527853","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win¨"
"13:48:29.3527925","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3528062","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.3528114","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3528511","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3528629","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3528756","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3529467","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3529725","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3529792","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3529859","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3529910","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3529974","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3530044","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3530286","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3531009","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3531160","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3531482","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3533628","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3533735","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:29.3534152","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:29.3534365","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:29.3534471","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3534548","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:29.3534698","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:29.3536835","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3536990","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:29.3537158","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3538022","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3538210","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3538395","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3538489","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.3538650","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3538725","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3538983","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3539115","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3539893","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3540147","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3540227","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3540318","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.3540371","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3540441","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3540517","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3540877","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3542076","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3542580","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3542679","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3542869","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3542951","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3543054","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3543455","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3543636","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3544776","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3545138","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3545239","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3546574","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3546819","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:29.3547078","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3548991","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3549453","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.3550516","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3550993","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:29.3551088","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32768, EndOfFile: 29184, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:29.3553602","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:29.3553889","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:29.3556064","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24576, Length: 4608, Priority: Normal"
"13:48:29.3601209","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 20480, Length: 4096, Priority: Normal"
"13:48:29.3601864","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8192, Length: 8192, Priority: Normal"
"13:48:29.3619318","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 16384, Length: 8192, Priority: Normal"
"13:48:29.3634192","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:29.3788111","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ"
"13:48:29.3788219","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.3788564","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3789426","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3789760","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 721056, Length: 4096"
"13:48:29.3790295","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3792572","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3795397","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3795575","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.3795803","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.3797052","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3797231","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.3797307","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.3798061","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3798591","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.3799501","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3800198","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3800643","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.3800746","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.3801625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3803571","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3803780","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.3803861","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3806830","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.3807788","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3808553","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3808769","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.3808929","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.3809637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3811099","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3811302","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.3811385","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3897514","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.3897727","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3899420","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3899616","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.3899880","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.3901491","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3901883","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.3901975","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.3902893","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3903196","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.3904165","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3904975","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3905261","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.3905383","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.3906454","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3907841","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3908161","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.3908259","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3910394","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.3911481","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3912293","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3912559","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.3912778","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.3913648","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.3914423","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3914752","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.3914916","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3929255","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.3929531","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.3929993","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3930897","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3931107","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3931421","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3931525","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3931623","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3931684","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:29.3932303","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 873472, Length: 24"
"13:48:29.3932562","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 873496, Length: 4096"
"13:48:29.3932787","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 877592, Length: 24"
"13:48:29.3932859","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 877616, Length: 4096"
"13:48:29.3933039","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:29.3933131","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3935393","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3935834","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3940743","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3940885","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NO EAS ON FILE",""
"13:48:29.3942617","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3942831","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3943330","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:29.3945156","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3945694","MsMpEng.exe","3220","FileSystemControl","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.3946488","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3946765","MsMpEng.exe","3220","QueryInformationVolume","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:29.3947024","MsMpEng.exe","3220","QueryAllInformationFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","BUFFER OVERFLOW","CreationTime: 18.09.2025 14:18:18, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 18.09.2025 14:18:13, ChangeTime: 11.10.2025 16:01:28, FileAttributes: ANCI, AllocationSize: 163840, EndOfFile: 282480"
"13:48:29.3947118","MsMpEng.exe","3220","FileSystemControl","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.3947665","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3947750","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3947813","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.3947904","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.3948248","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 0, Length: 65536, Priority: Normal"
"13:48:29.3950293","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 65536, Length: 65536, Priority: Normal"
"13:48:29.3952414","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 131072, Length: 65536, Priority: Normal"
"13:48:29.3954416","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 196608, Length: 65536, Priority: Normal"
"13:48:29.3956473","MsMpEng.exe","3220","ReadFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS","Offset: 262144, Length: 20336, Priority: Normal"
"13:48:29.3957298","MsMpEng.exe","3220","CloseFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS",""
"13:48:29.3957425","MsMpEng.exe","3220","CloseFile","C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe","SUCCESS",""
"13:48:29.3957875","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3958130","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.3958300","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.3958444","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:29.3958741","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3958822","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:29.3958939","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.3959039","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3959100","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.3959181","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.3959366","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:29.3959466","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:29.3959646","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3959716","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:29.3959893","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.3959996","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:29.3960058","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:29.3960136","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3960199","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.3960687","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.3961053","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:29.3961386","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3961510","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:29.3961665","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.3961832","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3961978","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.3962098","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.3962211","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:29.3962324","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:29.3962563","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.3962669","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:29.3962795","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.3965952","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3966370","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.3967185","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3967598","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:29.3967718","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal"
"13:48:29.3968226","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32768, EndOfFile: 29184, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:29.3968601","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:29.3968781","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal"
"13:48:29.3968961","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:29.3970133","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3970454","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3971212","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3971377","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3972155","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3972521","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.3972587","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.3973404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3974109","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3974722","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3974909","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3975001","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.3975852","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3976075","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.3976764","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3977107","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.3977178","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.3977875","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3978041","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3978125","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.3979066","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3979733","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3979902","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3980249","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.3981041","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3981302","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.3982057","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3982283","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.3982347","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.3983885","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3984145","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3984233","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.3985227","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3985960","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3986218","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3986326","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.3987496","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3987839","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.3988681","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3989075","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.3989153","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.3989935","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3990238","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3990343","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.3991124","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3991803","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3992105","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3992195","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.3992910","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3993182","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.3994121","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3994391","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.3994454","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.3995464","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3995793","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3995964","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.3996826","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.3997762","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3998000","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.3998107","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.3999223","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.3999464","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4000361","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4000644","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4000817","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4001589","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4001774","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4001859","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4002494","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4003063","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4003308","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4003398","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4004167","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4004504","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4007179","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4007512","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4007591","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4008510","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4008714","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4008810","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4009645","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4010372","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4010572","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4010686","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4011487","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4011693","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4012418","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4012776","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4012858","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4013931","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4014136","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4014224","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4015155","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4015381","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \"
"13:48:29.4015500","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:29.4015767","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:29.4016682","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4017000","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4017927","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4018230","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4019001","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4019171","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4020102","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4020352","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4020424","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4021313","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4022515","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4023288","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4023615","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4023744","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4024515","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4024815","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4025761","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4026172","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4026252","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4027145","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4027397","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4027495","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4028364","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4029164","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4029360","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4029450","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4030341","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4030551","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4031328","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4031730","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4031803","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4032678","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4032980","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4033201","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4033920","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4034508","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4034674","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4034751","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4035348","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4035493","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4036420","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4036638","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4036699","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4037322","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4037583","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4037659","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4038270","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4038830","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4038978","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4039050","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4039625","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4039765","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4040355","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4040647","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4040703","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4041321","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4041463","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4041533","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4042153","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4042730","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4042968","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4043053","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4043646","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4043797","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4044404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4044854","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4044912","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4045562","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4045837","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4045988","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4046606","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4047180","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4047354","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4047431","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4048051","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4048189","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4048780","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4049068","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4049134","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4049817","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4049961","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4050034","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4050619","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4051251","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4051497","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4051597","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4052761","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4053070","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4053828","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4054068","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4054254","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4055018","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4055201","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4055298","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4056385","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4056578","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20646655, AvailableAllocationUnits: 5331773, SectorsPerAllocationUnit: 8, BytesPerSector: 512"
"13:48:29.4056656","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:29.4057031","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4057208","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4057872","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.4057984","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.4059381","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:29.4059755","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:29.4059838","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:29.4062203","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4062460","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4062544","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4062620","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4062670","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4062748","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4062832","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4063114","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4063867","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4064016","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:29.4064081","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4064143","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4064262","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4064351","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4064422","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4064525","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4065351","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4065708","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4065796","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4065865","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4065913","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4065978","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4066119","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4066235","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4066941","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4067104","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4067474","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4069179","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4069304","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:29.4069421","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:29.4069694","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:29.4069804","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4069886","MsMpEng.exe","3220","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read"
"13:48:29.4069982","MsMpEng.exe","3220","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read"
"13:48:29.4072234","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4072409","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:29.4072484","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4073505","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4073707","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ"
"13:48:29.4073915","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4074014","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4074081","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4074172","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4074270","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4074514","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4075382","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4075721","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4075833","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4075926","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4075989","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4076075","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4076166","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4076402","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4077249","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4077544","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4077641","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4077731","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4077794","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4077880","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4077969","MsMpEng.exe","3220","QueryIdInformation","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4078192","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4079036","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4079219","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4079437","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4080776","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4080926","MsMpEng.exe","3220","QueryNetworkOpenInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A"
"13:48:29.4080998","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4082603","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4082864","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.4083658","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4083920","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:29.4083994","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32768, EndOfFile: 29184, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:29.4086275","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:29.4086716","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:29.4088486","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24576, Length: 4608, Priority: Normal"
"13:48:29.4131604","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 20480, Length: 4096, Priority: Normal"
"13:48:29.4132309","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8192, Length: 8192, Priority: Normal"
"13:48:29.4147152","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 16384, Length: 8192, Priority: Normal"
"13:48:29.4165019","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:29.4314285","MsMpEng.exe","3220","QueryInformationVolume","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ"
"13:48:29.4314414","MsMpEng.exe","3220","QueryAllInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","BUFFER OVERFLOW","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32768, EndOfFile: 29184"
"13:48:29.4314627","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:29.4317210","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4321093","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4321449","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.4321533","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4322787","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4322941","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.4323093","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4323872","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4324131","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.4325080","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4325994","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4326257","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4326341","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4327079","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4327713","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4327949","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4328044","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4330658","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.4332351","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4333486","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4333728","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4333944","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4334851","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4335792","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4336015","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4336102","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4338299","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.4338488","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4340233","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4340426","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.4340622","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4342041","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4342216","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.4342383","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4343268","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4343639","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.4344821","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4345460","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4345784","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4345868","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4347366","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4349193","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4349566","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4349669","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4351931","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.4353656","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4356250","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4356666","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4356904","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4359034","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4359956","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4360348","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4360441","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4362319","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.4362609","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4363004","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4364179","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.4364684","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.4365165","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.4365330","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.4365458","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:29.4365727","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:29.4366495","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 881712, Length: 24"
"13:48:29.4366779","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 881736, Length: 4096"
"13:48:29.4367089","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 885832, Length: 24"
"13:48:29.4367178","MsMpEng.exe","3220","WriteFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal","SUCCESS","Offset: 885856, Length: 4096"
"13:48:29.4367389","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:29.4367508","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:29.4369947","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4370211","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4375974","MsMpEng.exe","3220","QueryStreamInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4376234","MsMpEng.exe","3220","QueryEAFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NO EAS ON FILE",""
"13:48:29.4377792","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4378173","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4378827","MsMpEng.exe","3220","RegCloseKey","HKU\.DEFAULT","SUCCESS",""
"13:48:29.4379453","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4379581","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.4379707","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.4379874","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:29.4380222","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4380309","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:29.4380463","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.4380623","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4380958","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.4381102","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.4381346","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:29.4381469","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:29.4381741","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4381919","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:29.4382069","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.4382166","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:29.4382257","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:29.4382347","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4382503","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.4382596","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.4382695","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000","SUCCESS","Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT"
"13:48:29.4382872","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4382945","MsMpEng.exe","3220","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"13:48:29.4383198","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.4383277","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4383346","MsMpEng.exe","3220","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\hivelist","REPARSE","Desired Access: Read"
"13:48:29.4383447","MsMpEng.exe","3220","RegOpenKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS","Desired Access: Read"
"13:48:29.4383548","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","BUFFER OVERFLOW","Length: 144"
"13:48:29.4383752","MsMpEng.exe","3220","RegQueryValue","HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes","SUCCESS","Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat"
"13:48:29.4383890","MsMpEng.exe","3220","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:29.4383971","MsMpEng.exe","3220","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Read"
"13:48:29.4384109","MsMpEng.exe","3220","RegCloseKey","HKLM\System\CurrentControlSet\Control\hivelist","SUCCESS",""
"13:48:29.4386914","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4387221","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:29.4388105","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4388383","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:29.4388588","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 512, Priority: Normal"
"13:48:29.4388785","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","AllocationSize: 32768, EndOfFile: 29184, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:29.4388981","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:29.4389226","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal"
"13:48:29.4389593","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:29.4391100","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4391363","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4392149","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4392459","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4393245","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4393624","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4393707","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4394808","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4395580","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4396404","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4396714","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4396818","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4397540","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4397797","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4398544","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4398806","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4398880","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4399695","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4399910","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4400003","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4400858","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4401564","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4401759","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4401852","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4402553","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4402829","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4403549","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4403779","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4403944","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4404705","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4404886","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4404980","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4405911","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4406625","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4407075","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4407170","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4407913","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4408082","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4408925","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4409181","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4409251","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4410074","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4410277","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4410369","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4411078","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4411734","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4412040","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4412133","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4412818","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4413262","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4414493","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4414900","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4414985","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4416395","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4416702","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4416816","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4417666","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4418488","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4418712","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4418815","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4419572","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4419874","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4420656","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4421027","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4421105","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4421916","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4422210","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4422309","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4423462","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4424217","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4424409","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4424597","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4425385","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4425584","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4426561","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4426833","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4426902","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4427782","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4427976","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4428074","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4428972","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4429704","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4429902","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4430117","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4430900","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4431092","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4431892","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4432175","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4432247","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4433011","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4433316","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4433417","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4434672","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4435016","MsMpEng.exe","3220","QueryNameInformationFile","C:\","SUCCESS","Name: \"
"13:48:29.4435155","MsMpEng.exe","3220","QueryAttributeInformationVolume","C:\","SUCCESS","FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS"
"13:48:29.4435238","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:29.4436358","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4436556","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4437816","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4438142","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4439194","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4439374","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4440023","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4440340","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4440409","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4441070","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","NOT A DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4441649","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4442194","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4442364","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4442442","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4443027","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4443169","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4443747","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4444101","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4444162","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4444785","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4444933","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4445005","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release","SUCCESS",""
"13:48:29.4445751","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4446350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4446533","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4446672","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4447597","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4447857","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4448509","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4448723","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4448794","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4449446","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4449703","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection\x64","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4449782","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64","SUCCESS",""
"13:48:29.4450798","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4451434","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4451630","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4451714","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4452350","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4452512","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4453232","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4453476","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos\EDR-Introspection","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4453535","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4454176","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4454336","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos\EDR-Introspection","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4454502","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection","SUCCESS",""
"13:48:29.4455115","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4455746","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4455930","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4456006","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4456639","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4456791","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4457418","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4457723","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source\repos","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4457780","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4458405","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4458564","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source\repos","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4458637","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos","SUCCESS",""
"13:48:29.4459357","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4459958","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4460134","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4460209","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4460878","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4461029","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4461656","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4461963","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker\source","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4462021","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4462660","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4462829","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker\source","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4462908","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source","SUCCESS",""
"13:48:29.4463617","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4464116","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4464570","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4464685","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4465355","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4465714","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4466367","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4466673","MsMpEng.exe","3220","DeviceIoControl","C:\Users\hacker","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4466749","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4467907","MsMpEng.exe","3220","CreateFile","C:\Users\hacker","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4468170","MsMpEng.exe","3220","FileSystemControl","C:\Users\hacker","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4468294","MsMpEng.exe","3220","CloseFile","C:\Users\hacker","SUCCESS",""
"13:48:29.4469257","MsMpEng.exe","3220","CreateFile","C:\Users","IS DIRECTORY","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a"
"13:48:29.4469910","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4470073","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4470162","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4470762","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4471002","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4471616","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4471889","MsMpEng.exe","3220","DeviceIoControl","C:\Users","INVALID PARAMETER","Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME"
"13:48:29.4471994","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4473051","MsMpEng.exe","3220","CreateFile","C:\Users","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4473225","MsMpEng.exe","3220","FileSystemControl","C:\Users","NOT REPARSE POINT","Control: FSCTL_GET_REPARSE_POINT"
"13:48:29.4473380","MsMpEng.exe","3220","CloseFile","C:\Users","SUCCESS",""
"13:48:29.4474035","MsMpEng.exe","3220","CreateFile","C:\","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4474219","MsMpEng.exe","3220","QuerySizeInformationVolume","C:\","SUCCESS","TotalAllocationUnits: 20646655, AvailableAllocationUnits: 5331773, SectorsPerAllocationUnit: 8, BytesPerSector: 512"
"13:48:29.4474305","MsMpEng.exe","3220","CloseFile","C:\","SUCCESS",""
"13:48:29.4474715","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 29184, Priority: Normal"
"13:48:29.4475075","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 25088, Length: 4096, Priority: Normal"
"13:48:29.4475411","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 29184, Priority: Normal"
"13:48:29.4482383","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 24576, Length: 4096, Priority: Normal"
"13:48:29.4483058","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 1024, Length: 14336, Priority: Normal"
"13:48:29.4483436","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 15360, Length: 10752, Priority: Normal"
"13:48:29.4483876","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 28672, Length: 512, Priority: Normal"
"13:48:29.4484475","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 8192, Length: 4096, Priority: Normal"
"13:48:29.4484648","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 4096, Length: 4096, Priority: Normal"
"13:48:29.4485488","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe:Zone.Identifier","NAME NOT FOUND","Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:29.4486033","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 2, Priority: Normal"
"13:48:29.4486223","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 64, Priority: Normal"
"13:48:29.4486371","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 240, Length: 28, Priority: Normal"
"13:48:29.4486642","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 4096, Priority: Normal"
"13:48:29.4487008","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 0, Length: 328, Priority: Normal"
"13:48:29.4487358","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 332, Length: 76, Priority: Normal"
"13:48:29.4487532","MsMpEng.exe","3220","ReadFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Offset: 416, Length: 28768, Priority: Normal"
"13:48:29.4490482","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4490700","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.4490780","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4492289","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4492475","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.4492556","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4493469","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4493762","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.4495205","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4497401","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4497692","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4497777","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4499175","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4500875","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4501106","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4501184","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4502898","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.4503771","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4504535","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4504736","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4504810","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4505523","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4506625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4506801","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4506949","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4508520","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.4508675","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4510084","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4510256","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D"
"13:48:29.4510329","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4511483","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4511842","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS","CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI"
"13:48:29.4511991","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}","SUCCESS",""
"13:48:29.4513072","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4513516","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2\{????????????????????????????????????}","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE}"
"13:48:29.4515210","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4516133","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4516322","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4516396","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4517085","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4518843","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4519027","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4519192","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4520714","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
"13:48:29.4521761","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4522443","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\CatRoot","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4522603","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\CatRoot","SUCCESS","Information: DACL"
"13:48:29.4522679","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\CatRoot","SUCCESS",""
"13:48:29.4523699","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
"13:48:29.4525379","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\catroot2","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:29.4525557","MsMpEng.exe","3220","QuerySecurityFile","C:\Windows\System32\catroot2","SUCCESS","Information: DACL"
"13:48:29.4525754","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4527343","MsMpEng.exe","3220","QueryDirectory","C:\Windows\System32\catroot2","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation"
"13:48:29.4527500","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\catroot2","SUCCESS",""
"13:48:29.4527908","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:29, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A"
"13:48:29.4528084","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4528349","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS",""
"13:48:29.4530007","MsMpEng.exe","3220","CreateFile","C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\998F15D801113A42F317A677646B63B6","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:29.4530448","MsMpEng.exe","3220","RegCloseKey","HKCU","SUCCESS",""
"13:48:29.4530555","MsMpEng.exe","3220","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"13:48:30.7986656","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.7986864","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.7987084","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.7987327","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8104999","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.8105702","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.8105953","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.8106101","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:30.8364951","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8365181","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:30.8365778","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:30.8365877","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8366776","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8366992","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8369774","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8370024","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8391910","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8392049","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True"
"13:48:30.8392298","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 120, Length: 1"
"13:48:30.8392358","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8393632","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\security\logs\scecomp.log","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ"
"13:48:30.8393798","MsMpEng.exe","3220","QueryStandardInformationFile","C:\Windows\security\logs\scecomp.log","SUCCESS","AllocationSize: 240, EndOfFile: 236, NumberOfLinks: 1, DeletePending: False, Directory: False"
"13:48:30.8531755","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8532743","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8672188","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\scecli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.8672668","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.8672772","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.8673189","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\scecli.dll","SUCCESS",""
"13:48:30.8715156","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:30.8715738","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"
"13:48:30.8717361","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\scecli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.8717791","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჹ"
"13:48:30.8717881","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:23, LastAccessTime: 13.10.2025 13:48:30, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 184320, EndOfFile: 364544"
"13:48:30.8717990","MsMpEng.exe","3220","QueryInformationVolume","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჹ"
"13:48:30.8718043","MsMpEng.exe","3220","QueryAllInformationFile","C:\Windows\System32\scecli.dll","BUFFER OVERFLOW","CreationTime: 12.08.2025 20:16:23, LastAccessTime: 13.10.2025 13:48:30, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 184320, EndOfFile: 364544"
"13:48:30.8718241","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\scecli.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"13:48:30.8718338","MsMpEng.exe","3220","QueryIdInformation","C:\Windows\System32\scecli.dll","SUCCESS",""
"13:48:30.8718528","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\scecli.dll","SUCCESS",""
"13:48:30.9122873","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9124214","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9126245","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9127426","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9129335","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9132831","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9136280","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9152909","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv -o","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:48:30.9187134","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9187745","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9188134","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9188403","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:30.9189774","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\runonce.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9190202","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9190308","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\runonce.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9190395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\runonce.exe","SUCCESS",""
"13:48:30.9214070","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9214644","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9214772","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9214860","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:30.9216683","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9216915","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9216993","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9217159","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:30.9218138","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9218517","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9218601","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9218668","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:30.9230457","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9231075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9231171","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9231256","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:30.9233180","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9233643","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9233750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9233843","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:30.9235187","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9235778","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9235899","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9236050","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:30.9237107","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9237469","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9237553","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9237623","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:30.9238637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9238888","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9238966","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9239129","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:30.9243044","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9244790","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9245040","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9245221","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:30.9249078","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9249660","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9249795","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9249880","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:30.9252550","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9252866","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9252947","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9253022","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:30.9255559","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9256002","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9256153","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9256250","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:30.9257158","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9257437","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9257524","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9257592","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:30.9258429","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9258782","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9258870","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9258935","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:30.9260707","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9261238","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9261327","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9261395","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:30.9262770","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9263138","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9263218","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9263296","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:30.9295898","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9296506","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9296639","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9296740","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:30.9298719","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9299131","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9299219","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\SHCore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9299292","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS",""
"13:48:30.9300912","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9301307","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9301390","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9301470","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:30.9304456","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9304790","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9304999","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9305080","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:30.9344746","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9344992","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9345084","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\windows.storage.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9345232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS",""
"13:48:30.9459680","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9460075","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9460230","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9460340","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:30.9515084","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9515390","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9515575","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9515991","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:30.9527489","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9527930","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9528052","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9528149","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:30.9568145","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9568765","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9568955","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\oleaut32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9569051","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS",""
"13:48:30.9598735","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9599440","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9599552","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9599639","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS",""
"13:48:30.9625887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\propsys.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9626290","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9626381","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\propsys.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9626463","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\propsys.dll","SUCCESS",""
"13:48:30.9635167","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9635548","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9635773","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9635920","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS",""
"13:48:30.9734589","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:30.9735224","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:30.9735371","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\profapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:30.9735467","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS",""
"13:48:31.0005170","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0005526","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0005761","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0005863","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\Windows.StateRepositoryPS.dll","SUCCESS",""
"13:48:31.0150668","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\edputil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0151125","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0151382","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\edputil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0151492","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\edputil.dll","SUCCESS",""
"13:48:31.0161480","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\urlmon.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0161966","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0162073","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\urlmon.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0162260","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\urlmon.dll","SUCCESS",""
"13:48:31.0167079","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\iertutil.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0167943","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0168092","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\iertutil.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0168187","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\iertutil.dll","SUCCESS",""
"13:48:31.0176848","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\srvcli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0177147","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0177612","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\srvcli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0177710","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\srvcli.dll","SUCCESS",""
"13:48:31.0180016","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\netutils.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0180339","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0180512","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\netutils.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0180606","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\netutils.dll","SUCCESS",""
"13:48:31.0258140","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sspicli.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0258499","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0258604","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sspicli.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0258785","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sspicli.dll","SUCCESS",""
"13:48:31.0324640","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\virtdisk.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0324934","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0325025","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\virtdisk.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0325204","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\virtdisk.dll","SUCCESS",""
"13:48:31.0356275","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\wldp.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0356568","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0356750","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\wldp.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0356905","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\wldp.dll","SUCCESS",""
"13:48:31.0468194","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\grpconv.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0469131","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0469345","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\grpconv.exe","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0469449","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\grpconv.exe","SUCCESS",""
"13:48:31.0471220","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0471638","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0471769","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ntdll.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0472014","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS",""
"13:48:31.0479763","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0480070","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0480273","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0480358","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS",""
"13:48:31.0481301","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0481611","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0481691","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\KernelBase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0481846","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS",""
"13:48:31.0492913","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0493275","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0493484","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\advapi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0493596","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS",""
"13:48:31.0494995","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0495432","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0495535","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0495754","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS",""
"13:48:31.0497236","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0497616","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0497738","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\sechost.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0497818","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS",""
"13:48:31.0499723","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0500066","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0500155","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\rpcrt4.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0500232","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS",""
"13:48:31.0503096","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0503512","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0503634","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\user32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0503714","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\user32.dll","SUCCESS",""
"13:48:31.0505378","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0506304","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0506530","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\win32u.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0506667","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS",""
"13:48:31.0508242","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0509204","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0509350","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0509436","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS",""
"13:48:31.0515799","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0516930","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0517046","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\gdi32full.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0517132","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS",""
"13:48:31.0524939","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0529073","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0529444","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcp_win.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0529566","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS",""
"13:48:31.0532928","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0533323","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0533408","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ucrtbase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0533478","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS",""
"13:48:31.0538887","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0539255","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0539344","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shell32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0539414","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS",""
"13:48:31.0541248","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\WinTypes.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0541645","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0541767","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\WinTypes.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0541849","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\WinTypes.dll","SUCCESS",""
"13:48:31.0543637","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0543925","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0544105","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\imm32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0544201","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS",""
"13:48:31.0545098","MsMpEng.exe","3220","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0545478","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0545560","MsMpEng.exe","3220","FileSystemControl","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0545737","MsMpEng.exe","3220","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll","SUCCESS",""
"13:48:31.0547423","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0547810","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0547903","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\combase.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0547974","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\combase.dll","SUCCESS",""
"13:48:31.0549277","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0549654","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0549738","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\shlwapi.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0549864","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS",""
"13:48:31.0592625","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0592922","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0593032","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0593243","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS",""
"13:48:31.0595797","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0596176","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0596331","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0596423","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS",""
"13:48:31.0605226","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\uxtheme.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0605497","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0605593","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\uxtheme.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0605818","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\uxtheme.dll","SUCCESS",""
"13:48:31.0624362","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"13:48:31.0624710","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK"
"13:48:31.0624886","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\ole32.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)"
"13:48:31.0624999","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS",""
"13:48:31.4224387","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:31.4226146","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels","NAME NOT FOUND","Desired Access: Query Value"
"13:48:31.4277326","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:31.4279063","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS","Desired Access: Read/Write"
"13:48:31.4280570","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:31.4281314","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NAME NOT FOUND","Desired Access: Read"
"13:48:31.4282197","MsMpEng.exe","3220","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","NO MORE ENTRIES","Index: 0, Length: 220"
"13:48:31.4282891","MsMpEng.exe","3220","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction","SUCCESS",""
"13:48:31.4432988","MsMpEng.exe","3220","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"13:48:31.4433787","MsMpEng.exe","3220","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels","NAME NOT FOUND","Desired Access: Query Value"
"13:48:31.5405742","MsMpEng.exe","3220","LockFile","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True"
"13:48:31.5406424","MsMpEng.exe","3220","UnlockFileSingle","C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm","SUCCESS","Offset: 124, Length: 1"