"Time of Day","Process Name","PID","Operation","Path","Result","Detail" "14:33:35.2458968","MsMpEng.exe","3220","Thread Create","","SUCCESS","Thread ID: 3276" "14:33:35.2546059","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2546630","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "14:33:35.2546769","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "14:33:35.2546868","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "14:33:35.2548323","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2548641","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "14:33:35.2548719","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\msvcrt.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "14:33:35.2548895","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "14:33:35.2549829","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2550157","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "14:33:35.2550235","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "14:33:35.2550301","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "14:33:35.2551498","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\clbcatq.dll","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2551772","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","OPLOCK HANDLE CLOSED","Control: FSCTL_REQUEST_OPLOCK" "14:33:35.2551952","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\clbcatq.dll","SUCCESS","Control: 0x902eb (Device:0x9 Function:186 Method: 3)" "14:33:35.2552020","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\clbcatq.dll","SUCCESS","" "14:33:35.2561196","MsMpEng.exe","3220","CreateFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2561420","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 14:33:35, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A" "14:33:35.2561502","MsMpEng.exe","3220","CloseFile","C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe","SUCCESS","" "14:33:35.2571028","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\AcGenral.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2571661","MsMpEng.exe","3220","QueryBasicInformationFile","C:\Windows\System32\AcGenral.dll","SUCCESS","CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 14:32:58, LastWriteTime: 30.09.2025 13:53:26, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A" "14:33:35.2571736","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\AcGenral.dll","SUCCESS","" "14:33:35.2572550","MsMpEng.exe","3220","CreateFile","C:\Windows\System32\AcGenral.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "14:33:35.2572941","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\AcGenral.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "14:33:35.2574456","MsMpEng.exe","3220","QueryEAFile","C:\Windows\System32\AcGenral.dll","SUCCESS","" "14:33:35.2574591","MsMpEng.exe","3220","FileSystemControl","C:\Windows\System32\AcGenral.dll","SUCCESS","Control: FSCTL_QUERY_USN_JOURNAL" "14:33:35.2574874","MsMpEng.exe","3220","CreateFileMapping","C:\Windows\System32\AcGenral.dll","SUCCESS","SyncType: SyncTypeOther" "14:33:35.2575800","MsMpEng.exe","3220","Load Image","C:\Windows\System32\AcGenral.dll","SUCCESS","Image Base: 0x7ff8d0870000, Image Size: 0x71000" "14:33:35.2583354","MsMpEng.exe","3220","CloseFile","C:\Windows\System32\AcGenral.dll","SUCCESS",""