mirror of
https://github.com/evilele/EDR-Introspection
synced 2026-06-09 08:11:09 +00:00
844 KiB
844 KiB
| 1 | Time of Day | Process Name | PID | Operation | Path | Result | Detail |
|---|---|---|---|---|---|---|---|
| 2 | 13:48:27.5486279 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 3 | 13:48:27.5486430 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction | SUCCESS | Desired Access: Read/Write |
| 4 | 13:48:27.5487033 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 5 | 13:48:27.5487114 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction | NAME NOT FOUND | Desired Access: Read |
| 6 | 13:48:27.5487301 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction | NO MORE ENTRIES | Index: 0, Length: 220 |
| 7 | 13:48:27.5487496 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction | SUCCESS | |
| 8 | 13:48:27.5771694 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 9 | 13:48:27.5771900 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 144’256, Length: 4’096 |
| 10 | 13:48:27.5772238 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 403’816, Length: 4’096 |
| 11 | 13:48:27.5772477 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 12 | 13:48:27.5775423 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 13 | 13:48:27.5775761 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 399’696, Length: 4’096 |
| 14 | 13:48:27.5776013 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 15 | 13:48:27.5835398 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 16 | 13:48:27.5835887 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 17 | 13:48:27.5836207 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 18 | 13:48:27.5836339 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 19 | 13:48:27.5837392 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 20 | 13:48:27.5837908 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 21 | 13:48:27.5838018 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 22 | 13:48:27.5838093 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 23 | 13:48:27.5846645 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 24 | 13:48:27.5846816 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 395’576, Length: 4’096 |
| 25 | 13:48:27.5847044 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 26 | 13:48:27.5854297 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 27 | 13:48:27.5854567 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 28 | 13:48:27.5854879 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 29 | 13:48:27.5854967 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 148’376, Length: 4’096 |
| 30 | 13:48:27.5855268 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 679’856, Length: 4’096 |
| 31 | 13:48:27.5855498 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 32 | 13:48:27.5855746 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 33 | 13:48:27.5860527 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 34 | 13:48:27.5860818 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ntdll.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 35 | 13:48:27.5860965 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ntdll.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976 |
| 36 | 13:48:27.5861087 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ntdll.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 37 | 13:48:27.5861142 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ntdll.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:42:55, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 1’433’600, EndOfFile: 2’521’976 |
| 38 | 13:48:27.5861221 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 39 | 13:48:27.5861303 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 40 | 13:48:27.5861475 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 41 | 13:48:27.6098690 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 42 | 13:48:27.6099149 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 43 | 13:48:27.6099290 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 44 | 13:48:27.6099395 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 45 | 13:48:27.6103226 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 46 | 13:48:27.6103637 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\kernel32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 47 | 13:48:27.6103722 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\kernel32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136 |
| 48 | 13:48:27.6103935 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\kernel32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 49 | 13:48:27.6104073 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\kernel32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 466’944, EndOfFile: 836’136 |
| 50 | 13:48:27.6104186 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 51 | 13:48:27.6104270 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 52 | 13:48:27.6104488 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 53 | 13:48:27.6105220 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 54 | 13:48:27.6105433 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 55 | 13:48:27.6105521 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 56 | 13:48:27.6105714 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 57 | 13:48:27.6107812 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 58 | 13:48:27.6108005 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\KernelBase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 59 | 13:48:27.6108165 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\KernelBase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008 |
| 60 | 13:48:27.6108514 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\KernelBase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 61 | 13:48:27.6108570 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\KernelBase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 1’785’856, EndOfFile: 4’150’008 |
| 62 | 13:48:27.6108649 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 63 | 13:48:27.6108817 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 64 | 13:48:27.6108948 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 65 | 13:48:27.6114914 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\advapi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 66 | 13:48:27.6115505 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 67 | 13:48:27.6115761 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 68 | 13:48:27.6115853 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\advapi32.dll | SUCCESS | |
| 69 | 13:48:27.6117397 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 70 | 13:48:27.6117811 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 71 | 13:48:27.6117915 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 72 | 13:48:27.6117997 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 73 | 13:48:27.6118829 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\advapi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 74 | 13:48:27.6119405 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\advapi32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 75 | 13:48:27.6119516 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\advapi32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192 |
| 76 | 13:48:27.6119609 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\advapi32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 77 | 13:48:27.6119660 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\advapi32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:25, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:25, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 393’216, EndOfFile: 745’192 |
| 78 | 13:48:27.6119745 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 79 | 13:48:27.6119821 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\advapi32.dll | SUCCESS | |
| 80 | 13:48:27.6120045 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\advapi32.dll | SUCCESS | |
| 81 | 13:48:27.6120412 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sechost.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 82 | 13:48:27.6120716 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 83 | 13:48:27.6120804 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 84 | 13:48:27.6120876 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sechost.dll | SUCCESS | |
| 85 | 13:48:27.6122052 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 86 | 13:48:27.6122414 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 87 | 13:48:27.6122493 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 88 | 13:48:27.6122567 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 89 | 13:48:27.6124017 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 90 | 13:48:27.6126810 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcrt.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 91 | 13:48:27.6127107 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcrt.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768 |
| 92 | 13:48:27.6127962 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcrt.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 93 | 13:48:27.6128189 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcrt.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:58, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 405’504, EndOfFile: 699’768 |
| 94 | 13:48:27.6128333 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 95 | 13:48:27.6129082 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 96 | 13:48:27.6129750 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 97 | 13:48:27.6136426 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\setupapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 98 | 13:48:27.6137211 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\setupapi.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 99 | 13:48:27.6137333 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\setupapi.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 100 | 13:48:27.6137415 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\setupapi.dll | SUCCESS | |
| 101 | 13:48:27.6144921 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sechost.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 102 | 13:48:27.6151458 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\sechost.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 103 | 13:48:27.6152471 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\sechost.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520 |
| 104 | 13:48:27.6154232 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\sechost.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 105 | 13:48:27.6154744 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\sechost.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:09, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:09, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 691’520 |
| 106 | 13:48:27.6157337 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 107 | 13:48:27.6157806 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\sechost.dll | SUCCESS | |
| 108 | 13:48:27.6158874 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sechost.dll | SUCCESS | |
| 109 | 13:48:27.6159486 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcrypt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 110 | 13:48:27.6159879 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcrypt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 111 | 13:48:27.6159980 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcrypt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 112 | 13:48:27.6160061 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcrypt.dll | SUCCESS | |
| 113 | 13:48:27.6164003 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\fltLib.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 114 | 13:48:27.6164789 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\fltLib.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 115 | 13:48:27.6164907 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\fltLib.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 116 | 13:48:27.6165002 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\fltLib.dll | SUCCESS | |
| 117 | 13:48:27.6171188 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\newdev.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 118 | 13:48:27.6171656 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\newdev.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 119 | 13:48:27.6171766 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\newdev.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 120 | 13:48:27.6171848 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\newdev.dll | SUCCESS | |
| 121 | 13:48:27.6177155 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 122 | 13:48:27.6177819 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\rpcrt4.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 123 | 13:48:27.6177993 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\rpcrt4.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552 |
| 124 | 13:48:27.6178130 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\rpcrt4.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(಼�㈀ |
| 125 | 13:48:27.6178193 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\rpcrt4.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’162’552 |
| 126 | 13:48:27.6178282 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 127 | 13:48:27.6178359 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 128 | 13:48:27.6178574 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 129 | 13:48:27.6178784 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 130 | 13:48:27.6179311 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 131 | 13:48:27.6179408 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 132 | 13:48:27.6179553 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 133 | 13:48:27.6180384 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 134 | 13:48:27.6180593 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 135 | 13:48:27.6186380 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msdelta.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 136 | 13:48:27.6187227 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msdelta.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 137 | 13:48:27.6187581 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msdelta.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 138 | 13:48:27.6187677 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msdelta.dll | SUCCESS | |
| 139 | 13:48:27.6187807 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\setupapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 140 | 13:48:27.6188917 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\setupapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 141 | 13:48:27.6189036 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\setupapi.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560 |
| 142 | 13:48:27.6189156 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\setupapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 143 | 13:48:27.6189222 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\setupapi.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 2’146’304, EndOfFile: 4’794’560 |
| 144 | 13:48:27.6189423 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\setupapi.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 145 | 13:48:27.6189536 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\setupapi.dll | SUCCESS | |
| 146 | 13:48:27.6189691 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\setupapi.dll | SUCCESS | |
| 147 | 13:48:27.6192022 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cryptsp.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 148 | 13:48:27.6192430 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptsp.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 149 | 13:48:27.6192541 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptsp.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 150 | 13:48:27.6192616 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cryptsp.dll | SUCCESS | |
| 151 | 13:48:27.6197451 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcrypt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 152 | 13:48:27.6198096 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\bcrypt.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 153 | 13:48:27.6198174 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cabinet.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 154 | 13:48:27.6198208 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\bcrypt.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736 |
| 155 | 13:48:27.6198313 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\bcrypt.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 156 | 13:48:27.6198377 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\bcrypt.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 166’736 |
| 157 | 13:48:27.6198567 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcrypt.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 158 | 13:48:27.6198592 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cabinet.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 159 | 13:48:27.6198679 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\bcrypt.dll | SUCCESS | |
| 160 | 13:48:27.6198692 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cabinet.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 161 | 13:48:27.6198769 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cabinet.dll | SUCCESS | |
| 162 | 13:48:27.6198830 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcrypt.dll | SUCCESS | |
| 163 | 13:48:27.6200180 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 164 | 13:48:27.6200461 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 165 | 13:48:27.6202065 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\fltLib.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 166 | 13:48:27.6202608 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\fltLib.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 167 | 13:48:27.6202686 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\fltLib.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312 |
| 168 | 13:48:27.6202774 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\fltLib.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 169 | 13:48:27.6202827 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\fltLib.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:10, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’312 |
| 170 | 13:48:27.6202905 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\fltLib.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 171 | 13:48:27.6203085 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\fltLib.dll | SUCCESS | |
| 172 | 13:48:27.6203220 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\fltLib.dll | SUCCESS | |
| 173 | 13:48:27.6204470 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 174 | 13:48:27.6204602 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 175 | 13:48:27.6205803 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\newdev.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 176 | 13:48:27.6206222 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\newdev.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ |
| 177 | 13:48:27.6206442 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\newdev.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160 |
| 178 | 13:48:27.6206728 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\newdev.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 179 | 13:48:27.6206802 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\newdev.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:59, LastAccessTime: 13.10.2025 13:29:14, LastWriteTime: 30.09.2025 13:53:59, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 188’416, EndOfFile: 348’160 |
| 180 | 13:48:27.6206893 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\newdev.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 181 | 13:48:27.6206972 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\newdev.dll | SUCCESS | |
| 182 | 13:48:27.6207095 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\newdev.dll | SUCCESS | |
| 183 | 13:48:27.6210475 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 184 | 13:48:27.6210988 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ucrtbase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ |
| 185 | 13:48:27.6211175 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ucrtbase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280 |
| 186 | 13:48:27.6211364 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ucrtbase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 187 | 13:48:27.6211895 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ucrtbase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 802’816, EndOfFile: 1’373’280 |
| 188 | 13:48:27.6212124 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 189 | 13:48:27.6212206 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 190 | 13:48:27.6212381 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 191 | 13:48:27.6213952 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 192 | 13:48:27.6214089 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 193 | 13:48:27.6215052 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msdelta.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 194 | 13:48:27.6215325 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msdelta.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 195 | 13:48:27.6215394 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msdelta.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360 |
| 196 | 13:48:27.6215468 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msdelta.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ |
| 197 | 13:48:27.6215703 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msdelta.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:05, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 595’360 |
| 198 | 13:48:27.6215811 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msdelta.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 199 | 13:48:27.6215885 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msdelta.dll | SUCCESS | |
| 200 | 13:48:27.6216009 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msdelta.dll | SUCCESS | |
| 201 | 13:48:27.6218401 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cryptsp.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 202 | 13:48:27.6235566 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cryptsp.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 203 | 13:48:27.6235764 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cryptsp.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304 |
| 204 | 13:48:27.6235868 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cryptsp.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 205 | 13:48:27.6235995 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cryptsp.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 57’344, EndOfFile: 121’304 |
| 206 | 13:48:27.6236107 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptsp.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 207 | 13:48:27.6236193 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\cryptsp.dll | SUCCESS | |
| 208 | 13:48:27.6236387 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cryptsp.dll | SUCCESS | |
| 209 | 13:48:27.6239253 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cabinet.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 210 | 13:48:27.6239720 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cabinet.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 211 | 13:48:27.6239844 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cabinet.dll | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024 |
| 212 | 13:48:27.6239953 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cabinet.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 213 | 13:48:27.6240004 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cabinet.dll | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:11, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 98’304, EndOfFile: 175’024 |
| 214 | 13:48:27.6240092 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cabinet.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 215 | 13:48:27.6240250 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\cabinet.dll | SUCCESS | |
| 216 | 13:48:27.6240748 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cabinet.dll | SUCCESS | |
| 217 | 13:48:27.6309257 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\combase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 218 | 13:48:27.6309663 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 219 | 13:48:27.6309906 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 220 | 13:48:27.6310005 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\combase.dll | SUCCESS | |
| 221 | 13:48:27.6313950 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\SHCore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 222 | 13:48:27.6314425 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\SHCore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 223 | 13:48:27.6314543 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\combase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 224 | 13:48:27.6314565 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\SHCore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 225 | 13:48:27.6314787 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\SHCore.dll | SUCCESS | |
| 226 | 13:48:27.6315075 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\combase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 227 | 13:48:27.6315186 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\combase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784 |
| 228 | 13:48:27.6315301 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\combase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 229 | 13:48:27.6315361 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\combase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 1’937’408, EndOfFile: 3’674’784 |
| 230 | 13:48:27.6315561 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 231 | 13:48:27.6315796 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\combase.dll | SUCCESS | |
| 232 | 13:48:27.6315957 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\combase.dll | SUCCESS | |
| 233 | 13:48:27.6323592 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\SHCore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 234 | 13:48:27.6324402 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\SHCore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 235 | 13:48:27.6324529 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\SHCore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984 |
| 236 | 13:48:27.6324633 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\SHCore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 237 | 13:48:27.6324685 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\SHCore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:14, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:14, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 512’000, EndOfFile: 988’984 |
| 238 | 13:48:27.6324762 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\SHCore.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 239 | 13:48:27.6324834 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\SHCore.dll | SUCCESS | |
| 240 | 13:48:27.6325112 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\SHCore.dll | SUCCESS | |
| 241 | 13:48:27.6333499 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 242 | 13:48:27.6334200 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cfgmgr32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 243 | 13:48:27.6334334 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 244 | 13:48:27.6334407 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | |
| 245 | 13:48:27.6338266 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WofUtil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 246 | 13:48:27.6338278 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 247 | 13:48:27.6338615 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WofUtil.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 248 | 13:48:27.6338667 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cfgmgr32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 249 | 13:48:27.6338749 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cfgmgr32.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120 |
| 250 | 13:48:27.6338828 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cfgmgr32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 251 | 13:48:27.6338840 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WofUtil.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 252 | 13:48:27.6338909 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cfgmgr32.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:29, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:29, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 204’800, EndOfFile: 365’120 |
| 253 | 13:48:27.6338935 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WofUtil.dll | SUCCESS | |
| 254 | 13:48:27.6338988 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 255 | 13:48:27.6339166 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\cfgmgr32.dll | SUCCESS | |
| 256 | 13:48:27.6339300 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | |
| 257 | 13:48:27.6340113 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\devrtl.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 258 | 13:48:27.6340405 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\devrtl.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 259 | 13:48:27.6340633 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 260 | 13:48:27.6340646 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\devrtl.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 261 | 13:48:27.6340742 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\devrtl.dll | SUCCESS | |
| 262 | 13:48:27.6340789 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 263 | 13:48:27.6341773 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WofUtil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 264 | 13:48:27.6342017 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\WofUtil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 265 | 13:48:27.6342197 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\WofUtil.dll | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440 |
| 266 | 13:48:27.6342285 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\WofUtil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 267 | 13:48:27.6342337 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\WofUtil.dll | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:10, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 01.04.2024 09:22:10, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 24’576, EndOfFile: 61’440 |
| 268 | 13:48:27.6342409 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WofUtil.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 269 | 13:48:27.6342480 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\WofUtil.dll | SUCCESS | |
| 270 | 13:48:27.6342597 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WofUtil.dll | SUCCESS | |
| 271 | 13:48:27.6344055 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 272 | 13:48:27.6344188 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 273 | 13:48:27.6347807 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\devrtl.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 274 | 13:48:27.6348444 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\devrtl.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 275 | 13:48:27.6348546 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\devrtl.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112 |
| 276 | 13:48:27.6348643 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\devrtl.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 277 | 13:48:27.6348698 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\devrtl.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:30, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 45’056, EndOfFile: 90’112 |
| 278 | 13:48:27.6348784 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\devrtl.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 279 | 13:48:27.6348974 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\devrtl.dll | SUCCESS | |
| 280 | 13:48:27.6349111 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\devrtl.dll | SUCCESS | |
| 281 | 13:48:27.6405153 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 282 | 13:48:27.6406282 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 283 | 13:48:27.6406763 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 284 | 13:48:27.6407083 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\drv64.dll | SUCCESS | |
| 285 | 13:48:27.6409561 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 286 | 13:48:27.6409824 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 287 | 13:48:27.6571981 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rsaenh.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 288 | 13:48:27.6572385 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rsaenh.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 289 | 13:48:27.6572487 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rsaenh.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 290 | 13:48:27.6572567 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rsaenh.dll | SUCCESS | |
| 291 | 13:48:27.6575479 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rsaenh.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 292 | 13:48:27.6575986 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\rsaenh.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 293 | 13:48:27.6576073 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\rsaenh.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488 |
| 294 | 13:48:27.6576160 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\rsaenh.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 295 | 13:48:27.6576210 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\rsaenh.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 135’168, EndOfFile: 253’488 |
| 296 | 13:48:27.6576287 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rsaenh.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 297 | 13:48:27.6576365 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\rsaenh.dll | SUCCESS | |
| 298 | 13:48:27.6576626 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rsaenh.dll | SUCCESS | |
| 299 | 13:48:27.6586879 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cryptbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 300 | 13:48:27.6587335 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 301 | 13:48:27.6587519 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 302 | 13:48:27.6587624 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cryptbase.dll | SUCCESS | |
| 303 | 13:48:27.6590178 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 304 | 13:48:27.6590189 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cryptbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 305 | 13:48:27.6590412 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cryptbase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 306 | 13:48:27.6590570 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cryptbase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320 |
| 307 | 13:48:27.6590572 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 308 | 13:48:27.6590696 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\cryptbase.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 309 | 13:48:27.6590731 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 310 | 13:48:27.6590759 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\cryptbase.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:33, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 20’480, EndOfFile: 59’320 |
| 311 | 13:48:27.6590839 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cryptbase.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 312 | 13:48:27.6590922 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\cryptbase.dll | SUCCESS | |
| 313 | 13:48:27.6591060 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cryptbase.dll | SUCCESS | |
| 314 | 13:48:27.6591454 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 315 | 13:48:27.6594151 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 316 | 13:48:27.6594423 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\bcryptprimitives.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 317 | 13:48:27.6594509 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\bcryptprimitives.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800 |
| 318 | 13:48:27.6594942 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\bcryptprimitives.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win怀 |
| 319 | 13:48:27.6595061 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\bcryptprimitives.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:27, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:27, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 368’640, EndOfFile: 637’800 |
| 320 | 13:48:27.6595293 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 321 | 13:48:27.6595418 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 322 | 13:48:27.6595573 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 323 | 13:48:27.6786002 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\spinf.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 324 | 13:48:27.6786532 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spinf.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 325 | 13:48:27.6786680 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spinf.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 326 | 13:48:27.6786777 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\spinf.dll | SUCCESS | |
| 327 | 13:48:27.6788949 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 328 | 13:48:27.6789179 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 329 | 13:48:27.6790385 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\spinf.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 330 | 13:48:27.6790818 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\spinf.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 331 | 13:48:27.6790924 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\spinf.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976 |
| 332 | 13:48:27.6791032 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\spinf.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 333 | 13:48:27.6791098 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\spinf.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 126’976 |
| 334 | 13:48:27.6791193 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spinf.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 335 | 13:48:27.6791455 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\spinf.dll | SUCCESS | |
| 336 | 13:48:27.6791616 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\spinf.dll | SUCCESS | |
| 337 | 13:48:27.6805104 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wldp.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 338 | 13:48:27.6805531 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wldp.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 339 | 13:48:27.6805817 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wldp.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 340 | 13:48:27.6805916 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wldp.dll | SUCCESS | |
| 341 | 13:48:27.6807569 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 342 | 13:48:27.6807755 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 343 | 13:48:27.6807781 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 344 | 13:48:27.6808022 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 345 | 13:48:27.6808097 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 346 | 13:48:27.6808255 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 347 | 13:48:27.6809834 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wldp.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 348 | 13:48:27.6810355 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\wldp.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 349 | 13:48:27.6810497 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\wldp.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920 |
| 350 | 13:48:27.6810614 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\wldp.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 351 | 13:48:27.6810677 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\wldp.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 422’920 |
| 352 | 13:48:27.6810773 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wldp.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 353 | 13:48:27.6810960 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\wldp.dll | SUCCESS | |
| 354 | 13:48:27.6811140 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wldp.dll | SUCCESS | |
| 355 | 13:48:27.6813632 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 356 | 13:48:27.6813990 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcp_win.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 357 | 13:48:27.6814098 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcp_win.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920 |
| 358 | 13:48:27.6814212 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcp_win.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 359 | 13:48:27.6814274 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcp_win.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:28, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:28, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 278’528, EndOfFile: 641’920 |
| 360 | 13:48:27.6814375 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 361 | 13:48:27.6814543 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 362 | 13:48:27.6814735 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 363 | 13:48:27.6829721 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\spfileq.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 364 | 13:48:27.6830160 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spfileq.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 365 | 13:48:27.6830251 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spfileq.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 366 | 13:48:27.6830325 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\spfileq.dll | SUCCESS | |
| 367 | 13:48:27.6831971 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 368 | 13:48:27.6832126 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 369 | 13:48:27.6834129 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\spfileq.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 370 | 13:48:27.6834450 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\spfileq.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 371 | 13:48:27.6834522 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\spfileq.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264 |
| 372 | 13:48:27.6834609 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\spfileq.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 373 | 13:48:27.6834747 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\spfileq.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:40, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 73’728, EndOfFile: 139’264 |
| 374 | 13:48:27.6838485 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\spfileq.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 375 | 13:48:27.6838604 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\spfileq.dll | SUCCESS | |
| 376 | 13:48:27.6838849 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\spfileq.dll | SUCCESS | |
| 377 | 13:48:27.6848873 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\win32u.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 378 | 13:48:27.6849423 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 379 | 13:48:27.6849763 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 380 | 13:48:27.6849972 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\win32u.dll | SUCCESS | |
| 381 | 13:48:27.6854787 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32full.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 382 | 13:48:27.6855032 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 383 | 13:48:27.6855119 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 384 | 13:48:27.6855298 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 385 | 13:48:27.6855485 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\win32u.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 386 | 13:48:27.6856346 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\win32u.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 387 | 13:48:27.6856486 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\win32u.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872 |
| 388 | 13:48:27.6856698 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\win32u.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 389 | 13:48:27.6856783 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\win32u.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:35, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:35, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 170’872 |
| 390 | 13:48:27.6856905 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 391 | 13:48:27.6856996 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\win32u.dll | SUCCESS | |
| 392 | 13:48:27.6857118 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\user32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 393 | 13:48:27.6857156 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\win32u.dll | SUCCESS | |
| 394 | 13:48:27.6857601 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 395 | 13:48:27.6857694 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 396 | 13:48:27.6857763 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\user32.dll | SUCCESS | |
| 397 | 13:48:27.6861703 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 398 | 13:48:27.6862206 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32full.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 399 | 13:48:27.6862309 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 400 | 13:48:27.6862462 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 401 | 13:48:27.6862549 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\gdi32full.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 402 | 13:48:27.6862627 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 403 | 13:48:27.6862635 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\gdi32full.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920 |
| 404 | 13:48:27.6862873 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\gdi32full.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 405 | 13:48:27.6862941 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\gdi32full.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 659’456, EndOfFile: 1’236’920 |
| 406 | 13:48:27.6863041 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 407 | 13:48:27.6863129 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 408 | 13:48:27.6863269 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 409 | 13:48:27.6863551 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 410 | 13:48:27.6863820 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 411 | 13:48:27.6863916 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 412 | 13:48:27.6864048 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 413 | 13:48:27.6867690 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\user32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 414 | 13:48:27.6867828 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\imm32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 415 | 13:48:27.6868059 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\user32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 416 | 13:48:27.6868146 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\user32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232 |
| 417 | 13:48:27.6868211 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 418 | 13:48:27.6868309 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 419 | 13:48:27.6868373 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\user32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 420 | 13:48:27.6868411 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\imm32.dll | SUCCESS | |
| 421 | 13:48:27.6868465 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\user32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:32, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:32, ChangeTime: 01.10.2025 17:29:45, FileAttributes: A, AllocationSize: 868’352, EndOfFile: 1’873’232 |
| 422 | 13:48:27.6868587 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 423 | 13:48:27.6868677 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\user32.dll | SUCCESS | |
| 424 | 13:48:27.6868933 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\user32.dll | SUCCESS | |
| 425 | 13:48:27.6873265 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 426 | 13:48:27.6873769 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\gdi32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 427 | 13:48:27.6873885 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\gdi32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392 |
| 428 | 13:48:27.6873991 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\gdi32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 429 | 13:48:27.6874054 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\gdi32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:42, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:42, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 69’632, EndOfFile: 187’392 |
| 430 | 13:48:27.6874145 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 431 | 13:48:27.6874229 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 432 | 13:48:27.6874626 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 433 | 13:48:27.6877239 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\imm32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 434 | 13:48:27.6878021 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\imm32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 435 | 13:48:27.6878137 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\imm32.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904 |
| 436 | 13:48:27.6878227 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\imm32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 437 | 13:48:27.6878280 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\imm32.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:39, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 102’400, EndOfFile: 203’904 |
| 438 | 13:48:27.6878351 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 439 | 13:48:27.6878421 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\imm32.dll | SUCCESS | |
| 440 | 13:48:27.6878620 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\imm32.dll | SUCCESS | |
| 441 | 13:48:27.6878666 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\uxtheme.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 442 | 13:48:27.6879086 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 443 | 13:48:27.6879172 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 444 | 13:48:27.6879350 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 445 | 13:48:27.6886650 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\uxtheme.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 446 | 13:48:27.6887003 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\uxtheme.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 447 | 13:48:27.6887185 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\uxtheme.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128 |
| 448 | 13:48:27.6887310 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\uxtheme.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win? |
| 449 | 13:48:27.6887372 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\uxtheme.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:33, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:33, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 360’448, EndOfFile: 688’128 |
| 450 | 13:48:27.6887455 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 451 | 13:48:27.6887628 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 452 | 13:48:27.6887766 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 453 | 13:48:27.7030359 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 454 | 13:48:27.7030753 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 455 | 13:48:27.7030866 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 456 | 13:48:27.7030966 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | |
| 457 | 13:48:27.7033874 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 458 | 13:48:27.7034105 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 459 | 13:48:27.7035319 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 460 | 13:48:27.7035800 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 461 | 13:48:27.7035890 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592 |
| 462 | 13:48:27.7036154 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 463 | 13:48:27.7036233 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:06, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 26.09.2025 09:40:09, ChangeTime: 01.10.2025 17:35:48, FileAttributes: A, AllocationSize: 1’576’960, EndOfFile: 2’696’592 |
| 464 | 13:48:27.7036340 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 465 | 13:48:27.7036431 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | |
| 466 | 13:48:27.7036586 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | |
| 467 | 13:48:27.7040260 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\WindowsShell.Manifest | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ |
| 468 | 13:48:27.7040408 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\WindowsShell.Manifest | SUCCESS | AllocationSize: 4’096, EndOfFile: 670, NumberOfLinks: 4, DeletePending: False, Directory: False |
| 469 | 13:48:27.7060038 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msctf.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 470 | 13:48:27.7060421 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msctf.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 471 | 13:48:27.7060525 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msctf.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 472 | 13:48:27.7060604 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msctf.dll | SUCCESS | |
| 473 | 13:48:27.7063141 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msctf.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 474 | 13:48:27.7063507 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msctf.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 475 | 13:48:27.7063594 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msctf.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240 |
| 476 | 13:48:27.7063681 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msctf.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 477 | 13:48:27.7063732 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msctf.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:43:00, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 847’872, EndOfFile: 1’435’240 |
| 478 | 13:48:27.7063807 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msctf.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 479 | 13:48:27.7063882 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msctf.dll | SUCCESS | |
| 480 | 13:48:27.7064106 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msctf.dll | SUCCESS | |
| 481 | 13:48:27.7140642 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 482 | 13:48:27.7140893 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 483 | 13:48:27.7140981 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 484 | 13:48:27.7141145 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 485 | 13:48:27.7144992 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 486 | 13:48:27.7145217 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\kernel.appcore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 487 | 13:48:27.7145426 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\kernel.appcore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280 |
| 488 | 13:48:27.7145548 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\kernel.appcore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 489 | 13:48:27.7145695 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\kernel.appcore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 121’280 |
| 490 | 13:48:27.7145813 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 491 | 13:48:27.7145899 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 492 | 13:48:27.7146173 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 493 | 13:48:27.7148925 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\oleaut32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 494 | 13:48:27.7149479 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\oleaut32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 495 | 13:48:27.7149652 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\oleaut32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 496 | 13:48:27.7149770 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\oleaut32.dll | SUCCESS | |
| 497 | 13:48:27.7154325 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\oleaut32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 498 | 13:48:27.7154950 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\oleaut32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 499 | 13:48:27.7155064 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\oleaut32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816 |
| 500 | 13:48:27.7155574 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\oleaut32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 501 | 13:48:27.7158252 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\oleaut32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:00, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:54:00, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 483’328, EndOfFile: 889’816 |
| 502 | 13:48:27.7158815 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\oleaut32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 503 | 13:48:27.7159262 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\oleaut32.dll | SUCCESS | |
| 504 | 13:48:27.7159673 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\oleaut32.dll | SUCCESS | |
| 505 | 13:48:27.7203923 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\TextInputFramework.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 506 | 13:48:27.7204151 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextInputFramework.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 507 | 13:48:27.7204234 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextInputFramework.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 508 | 13:48:27.7204410 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\TextInputFramework.dll | SUCCESS | |
| 509 | 13:48:27.7207056 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 510 | 13:48:27.7207283 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 511 | 13:48:27.7208684 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\TextInputFramework.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 512 | 13:48:27.7209567 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\TextInputFramework.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 513 | 13:48:27.7210020 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\TextInputFramework.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128 |
| 514 | 13:48:27.7210146 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\TextInputFramework.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 515 | 13:48:27.7210210 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\TextInputFramework.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:43, FileAttributes: A, AllocationSize: 774’144, EndOfFile: 1’369’128 |
| 516 | 13:48:27.7210291 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextInputFramework.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 517 | 13:48:27.7210372 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\TextInputFramework.dll | SUCCESS | |
| 518 | 13:48:27.7210644 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\TextInputFramework.dll | SUCCESS | |
| 519 | 13:48:27.7324914 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\Fonts\StaticCache.dat | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ |
| 520 | 13:48:27.7325032 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\Fonts\StaticCache.dat | SUCCESS | AllocationSize: 9’203’712, EndOfFile: 20’381’696, NumberOfLinks: 2, DeletePending: False, Directory: False |
| 521 | 13:48:27.7378599 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 522 | 13:48:27.7378807 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 523 | 13:48:27.7412452 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\TextShaping.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 524 | 13:48:27.7412831 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextShaping.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 525 | 13:48:27.7412953 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextShaping.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 526 | 13:48:27.7413214 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\TextShaping.dll | SUCCESS | |
| 527 | 13:48:27.7416000 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 528 | 13:48:27.7416304 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 529 | 13:48:27.7418481 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\TextShaping.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 530 | 13:48:27.7418847 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\TextShaping.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅻ |
| 531 | 13:48:27.7418945 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\TextShaping.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328 |
| 532 | 13:48:27.7419051 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\TextShaping.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 533 | 13:48:27.7419218 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\TextShaping.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:37, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:37, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 270’336, EndOfFile: 749’328 |
| 534 | 13:48:27.7419359 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\TextShaping.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 535 | 13:48:27.7419493 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\TextShaping.dll | SUCCESS | |
| 536 | 13:48:27.7419674 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\TextShaping.dll | SUCCESS | |
| 537 | 13:48:27.7493089 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\windows.storage.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 538 | 13:48:27.7493339 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\windows.storage.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 539 | 13:48:27.7493442 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\windows.storage.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 540 | 13:48:27.7493517 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\windows.storage.dll | SUCCESS | |
| 541 | 13:48:27.7497009 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\windows.storage.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 542 | 13:48:27.7497435 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\windows.storage.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 543 | 13:48:27.7497687 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\windows.storage.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584 |
| 544 | 13:48:27.7498270 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\windows.storage.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 545 | 13:48:27.7503231 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\windows.storage.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:01, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:01, ChangeTime: 01.10.2025 17:29:41, FileAttributes: A, AllocationSize: 4’902’912, EndOfFile: 8’831’584 |
| 546 | 13:48:27.7503472 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\windows.storage.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 547 | 13:48:27.7503602 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\windows.storage.dll | SUCCESS | |
| 548 | 13:48:27.7503768 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\windows.storage.dll | SUCCESS | |
| 549 | 13:48:27.7507536 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shlwapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 550 | 13:48:27.7507905 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 551 | 13:48:27.7507991 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 552 | 13:48:27.7508065 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shlwapi.dll | SUCCESS | |
| 553 | 13:48:27.7514323 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shlwapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 554 | 13:48:27.7527477 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\shlwapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 555 | 13:48:27.7527836 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\shlwapi.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504 |
| 556 | 13:48:27.7527960 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\shlwapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 557 | 13:48:27.7528016 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\shlwapi.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:16, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:54:16, ChangeTime: 01.10.2025 17:29:40, FileAttributes: A, AllocationSize: 200’704, EndOfFile: 410’504 |
| 558 | 13:48:27.7528098 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 559 | 13:48:27.7528175 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\shlwapi.dll | SUCCESS | |
| 560 | 13:48:27.7528317 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shlwapi.dll | SUCCESS | |
| 561 | 13:48:27.7560581 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntmarta.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 562 | 13:48:27.7560947 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntmarta.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 563 | 13:48:27.7561041 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntmarta.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 564 | 13:48:27.7561117 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntmarta.dll | SUCCESS | |
| 565 | 13:48:27.7565416 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntmarta.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 566 | 13:48:27.7566698 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ntmarta.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 567 | 13:48:27.7566820 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ntmarta.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632 |
| 568 | 13:48:27.7566929 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ntmarta.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 569 | 13:48:27.7566986 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ntmarta.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:22, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:23, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 118’784, EndOfFile: 224’632 |
| 570 | 13:48:27.7567278 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntmarta.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 571 | 13:48:27.7567514 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\ntmarta.dll | SUCCESS | |
| 572 | 13:48:27.7567694 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntmarta.dll | SUCCESS | |
| 573 | 13:48:27.7574225 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 574 | 13:48:27.7574386 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True |
| 575 | 13:48:27.7574877 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 120, Length: 1 |
| 576 | 13:48:27.7574994 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 577 | 13:48:27.7575971 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\drivers\SET9BED.tmp | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ |
| 578 | 13:48:27.7576124 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\drivers\SET9BED.tmp | SUCCESS | AllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 579 | 13:48:27.7600356 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CoreMessaging.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 580 | 13:48:27.7600878 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreMessaging.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 581 | 13:48:27.7601007 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreMessaging.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 582 | 13:48:27.7601089 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CoreMessaging.dll | SUCCESS | |
| 583 | 13:48:27.7603229 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CoreMessaging.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 584 | 13:48:27.7603476 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CoreMessaging.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 585 | 13:48:27.7603550 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CoreMessaging.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272 |
| 586 | 13:48:27.7603631 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CoreMessaging.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 587 | 13:48:27.7603904 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CoreMessaging.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:14:25, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:14:25, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 688’128, EndOfFile: 1’216’272 |
| 588 | 13:48:27.7604018 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreMessaging.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 589 | 13:48:27.7604099 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\CoreMessaging.dll | SUCCESS | |
| 590 | 13:48:27.7604232 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CoreMessaging.dll | SUCCESS | |
| 591 | 13:48:27.7636945 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 592 | 13:48:27.7637274 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreUIComponents.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 593 | 13:48:27.7637908 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 594 | 13:48:27.7637996 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | |
| 595 | 13:48:27.7651722 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WinTypes.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 596 | 13:48:27.7652114 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 597 | 13:48:27.7653998 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 598 | 13:48:27.7655395 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WinTypes.dll | SUCCESS | |
| 599 | 13:48:27.7865004 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 600 | 13:48:27.7871100 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drvstore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 601 | 13:48:27.7871462 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drvstore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 602 | 13:48:27.7871706 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drvstore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 603 | 13:48:27.7871826 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drvstore.dll | SUCCESS | |
| 604 | 13:48:27.7873186 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 605 | 13:48:27.7876666 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 606 | 13:48:27.7876940 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CoreUIComponents.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 607 | 13:48:27.7877300 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CoreUIComponents.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976 |
| 608 | 13:48:27.7877437 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CoreUIComponents.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 609 | 13:48:27.7877567 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CoreUIComponents.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:09:11, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:09:11, ChangeTime: 30.09.2025 17:02:32, FileAttributes: A, AllocationSize: 1’310’720, EndOfFile: 3’032’976 |
| 610 | 13:48:27.7877682 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ole32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 611 | 13:48:27.7877734 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 612 | 13:48:27.7877824 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | |
| 613 | 13:48:27.7877996 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CoreUIComponents.dll | SUCCESS | |
| 614 | 13:48:27.7878091 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 615 | 13:48:27.7878182 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 616 | 13:48:27.7878261 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ole32.dll | SUCCESS | |
| 617 | 13:48:27.7880496 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WinTypes.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 618 | 13:48:27.7881130 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\WinTypes.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ |
| 619 | 13:48:27.7881230 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\WinTypes.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496 |
| 620 | 13:48:27.7881329 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\WinTypes.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 621 | 13:48:27.7881460 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\WinTypes.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:30, LastAccessTime: 13.10.2025 13:47:37, LastWriteTime: 30.09.2025 13:53:30, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 593’920, EndOfFile: 1’505’496 |
| 622 | 13:48:27.7881849 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 623 | 13:48:27.7881979 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\WinTypes.dll | SUCCESS | |
| 624 | 13:48:27.7882121 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WinTypes.dll | SUCCESS | |
| 625 | 13:48:27.7883592 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ole32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 626 | 13:48:27.7884133 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ole32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 627 | 13:48:27.7884272 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ole32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288 |
| 628 | 13:48:27.7884391 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\ole32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 629 | 13:48:27.7884529 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\ole32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 708’608, EndOfFile: 1’687’288 |
| 630 | 13:48:27.7884661 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 631 | 13:48:27.7884739 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\ole32.dll | SUCCESS | |
| 632 | 13:48:27.7885043 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ole32.dll | SUCCESS | |
| 633 | 13:48:27.7887420 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 634 | 13:48:27.7887659 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 635 | 13:48:27.7889541 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drvstore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 636 | 13:48:27.7889922 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drvstore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 637 | 13:48:27.7890003 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drvstore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672 |
| 638 | 13:48:27.7908322 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drvstore.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅍ |
| 639 | 13:48:27.7908394 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drvstore.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:40, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:40, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A, AllocationSize: 876’544, EndOfFile: 1’542’672 |
| 640 | 13:48:27.7908499 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drvstore.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 641 | 13:48:27.7908575 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drvstore.dll | SUCCESS | |
| 642 | 13:48:27.7908806 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drvstore.dll | SUCCESS | |
| 643 | 13:48:27.8065418 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 644 | 13:48:27.8065827 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 645 | 13:48:27.8216806 | MsMpEng.exe | 3220 | Thread Create | SUCCESS | Thread ID: 9140 | |
| 646 | 13:48:27.8228289 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 647 | 13:48:27.8228603 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 648 | 13:48:27.8231013 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\runonce.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 649 | 13:48:27.8231398 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\runonce.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 650 | 13:48:27.8231492 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\runonce.exe | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880 |
| 651 | 13:48:27.8231701 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\runonce.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 652 | 13:48:27.8231760 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\runonce.exe | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:06, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 30.09.2025 13:54:06, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 61’440, EndOfFile: 122’880 |
| 653 | 13:48:27.8231856 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\runonce.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 654 | 13:48:27.8231951 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\runonce.exe | SUCCESS | |
| 655 | 13:48:27.8232278 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\runonce.exe | SUCCESS | |
| 656 | 13:48:27.8261304 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\services.exe | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 657 | 13:48:27.8261695 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\services.exe | SUCCESS | CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A |
| 658 | 13:48:27.8261780 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\services.exe | SUCCESS | |
| 659 | 13:48:27.8262905 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\services.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 660 | 13:48:27.8263211 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\services.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჶ |
| 661 | 13:48:27.8263406 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\services.exe | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376 |
| 662 | 13:48:27.8263515 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\services.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 663 | 13:48:27.8263580 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\services.exe | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:13, LastAccessTime: 13.10.2025 13:48:26, LastWriteTime: 30.09.2025 13:54:13, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 524’288, EndOfFile: 906’376 |
| 664 | 13:48:27.8264144 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\services.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 665 | 13:48:27.8264333 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\services.exe | SUCCESS | |
| 666 | 13:48:27.8264628 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\services.exe | SUCCESS | |
| 667 | 13:48:27.8346701 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wtsapi32.dll | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 668 | 13:48:27.8347249 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\wtsapi32.dll | SUCCESS | CreationTime: 30.09.2025 13:54:23, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:23, ChangeTime: 01.10.2025 17:29:47, FileAttributes: A |
| 669 | 13:48:27.8347407 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wtsapi32.dll | SUCCESS | |
| 670 | 13:48:27.8348586 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wtsapi32.dll | SUCCESS | Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 671 | 13:48:27.8349088 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\wtsapi32.dll | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 672 | 13:48:27.8349357 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\wtsapi32.dll | SUCCESS | SyncType: SyncTypeOther |
| 673 | 13:48:27.8350376 | MsMpEng.exe | 3220 | Load Image | C:\Windows\System32\wtsapi32.dll | SUCCESS | Image Base: 0x7ff90e510000, Image Size: 0x2a000 |
| 674 | 13:48:27.8353968 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wtsapi32.dll | SUCCESS | |
| 675 | 13:48:27.8368735 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\winsta.dll | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 676 | 13:48:27.8369175 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\winsta.dll | SUCCESS | CreationTime: 30.09.2025 13:54:24, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:24, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A |
| 677 | 13:48:27.8369271 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\winsta.dll | SUCCESS | |
| 678 | 13:48:27.8371144 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\winsta.dll | SUCCESS | Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 679 | 13:48:27.8371670 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\winsta.dll | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 680 | 13:48:27.8371865 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\winsta.dll | SUCCESS | SyncType: SyncTypeOther |
| 681 | 13:48:27.8373002 | MsMpEng.exe | 3220 | Load Image | C:\Windows\System32\winsta.dll | SUCCESS | Image Base: 0x7ff911100000, Image Size: 0x63000 |
| 682 | 13:48:27.8374034 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\winsta.dll | SUCCESS | |
| 683 | 13:48:27.8383400 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\runonce.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 684 | 13:48:27.8383833 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\runonce.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 685 | 13:48:27.8383982 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\runonce.exe | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 686 | 13:48:27.8384067 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\runonce.exe | SUCCESS | |
| 687 | 13:48:27.8385942 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 688 | 13:48:27.8386381 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 689 | 13:48:27.8386472 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 690 | 13:48:27.8386550 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 691 | 13:48:27.8398249 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 692 | 13:48:27.8400229 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv -o | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 693 | 13:48:27.8403402 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 694 | 13:48:27.8406491 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv -o | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 695 | 13:48:27.8408413 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 696 | 13:48:27.8411750 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv -o | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 697 | 13:48:27.8415556 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 698 | 13:48:27.8418233 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv -o | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 699 | 13:48:27.8466492 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 700 | 13:48:27.8469234 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 263’736, Length: 4’096 |
| 701 | 13:48:27.8469672 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 119’536, Length: 4’096 |
| 702 | 13:48:27.8470610 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 255’496, Length: 4’096 |
| 703 | 13:48:27.8470954 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 848’776, Length: 4’096 |
| 704 | 13:48:27.8471154 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 115’416, Length: 4’096 |
| 705 | 13:48:27.8471325 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 832’296, Length: 4’096 |
| 706 | 13:48:27.8471641 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 852’896, Length: 4’096 |
| 707 | 13:48:27.8472315 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 708 | 13:48:27.8473085 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 709 | 13:48:27.8473288 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 710 | 13:48:27.8474541 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 711 | 13:48:27.8474933 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 712 | 13:48:27.8475541 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 713 | 13:48:27.8475783 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 714 | 13:48:27.8476799 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 715 | 13:48:27.8477274 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 716 | 13:48:27.8478381 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 717 | 13:48:27.8478497 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 718 | 13:48:27.8479435 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 719 | 13:48:27.8479546 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 720 | 13:48:27.8480213 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 721 | 13:48:27.8480298 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 722 | 13:48:27.8481434 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 723 | 13:48:27.8481550 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 251’376, Length: 4’096 |
| 724 | 13:48:27.8481846 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 725 | 13:48:27.8517858 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 726 | 13:48:27.8518503 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 727 | 13:48:27.8518607 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 728 | 13:48:27.8518700 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 729 | 13:48:27.8518758 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 730 | 13:48:27.8518842 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 731 | 13:48:27.8518936 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 732 | 13:48:27.8519222 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 733 | 13:48:27.8520017 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 734 | 13:48:27.8520512 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 735 | 13:48:27.8520884 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 736 | 13:48:27.8521704 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ |
| 737 | 13:48:27.8521871 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 738 | 13:48:27.8522002 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 739 | 13:48:27.8522130 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 740 | 13:48:27.8526818 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 741 | 13:48:27.8533594 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 742 | 13:48:27.8533782 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 743 | 13:48:27.8533950 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 744 | 13:48:27.8534191 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 745 | 13:48:27.8534434 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 746 | 13:48:27.8534532 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 747 | 13:48:27.8534621 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 748 | 13:48:27.8534902 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 749 | 13:48:27.8535744 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 750 | 13:48:27.8535936 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 751 | 13:48:27.8536028 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 752 | 13:48:27.8540513 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 753 | 13:48:27.8540726 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 754 | 13:48:27.8540812 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 755 | 13:48:27.8540891 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winჱ |
| 756 | 13:48:27.8541025 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 757 | 13:48:27.8541126 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 758 | 13:48:27.8541211 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 759 | 13:48:27.8541921 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 760 | 13:48:27.8554461 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 761 | 13:48:27.8554857 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 762 | 13:48:27.8555079 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 763 | 13:48:27.8555210 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 764 | 13:48:27.8555288 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 765 | 13:48:27.8556086 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 844’656, Length: 4’096 |
| 766 | 13:48:27.8556392 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 767 | 13:48:27.8556488 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 836’416, Length: 4’096 |
| 768 | 13:48:27.8556589 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 769 | 13:48:27.8556663 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 770 | 13:48:27.8556725 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 771 | 13:48:27.8556966 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 772 | 13:48:27.8569509 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\advapi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 773 | 13:48:27.8570030 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 774 | 13:48:27.8570165 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 775 | 13:48:27.8570262 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\advapi32.dll | SUCCESS | |
| 776 | 13:48:27.8577655 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 777 | 13:48:27.8577965 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 778 | 13:48:27.8578055 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 779 | 13:48:27.8578135 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 780 | 13:48:27.8579274 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sechost.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 781 | 13:48:27.8579629 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 782 | 13:48:27.8579715 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 783 | 13:48:27.8579785 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sechost.dll | SUCCESS | |
| 784 | 13:48:27.8616801 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 785 | 13:48:27.8617279 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 786 | 13:48:27.8617403 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 787 | 13:48:27.8617611 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 788 | 13:48:27.8619105 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 789 | 13:48:27.8619462 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 790 | 13:48:27.8619568 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 791 | 13:48:27.8619654 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 792 | 13:48:27.8671965 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 793 | 13:48:27.8672557 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 794 | 13:48:27.8672682 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 795 | 13:48:27.8672772 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 796 | 13:48:27.8674147 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\user32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 797 | 13:48:27.8674461 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 798 | 13:48:27.8674548 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 799 | 13:48:27.8674709 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\user32.dll | SUCCESS | |
| 800 | 13:48:27.8679100 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shell32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 801 | 13:48:27.8679505 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shell32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 802 | 13:48:27.8679593 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shell32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 803 | 13:48:27.8679666 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shell32.dll | SUCCESS | |
| 804 | 13:48:27.8681926 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 805 | 13:48:27.8682651 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 806 | 13:48:27.8682750 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 807 | 13:48:27.8682917 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 808 | 13:48:27.8684329 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shell32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 809 | 13:48:27.8684774 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\shell32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 810 | 13:48:27.8684871 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\shell32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432 |
| 811 | 13:48:27.8684978 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\shell32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 812 | 13:48:27.8685157 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\shell32.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:15, LastAccessTime: 13.10.2025 13:46:06, LastWriteTime: 30.09.2025 13:54:15, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 4’399’104, EndOfFile: 7’699’432 |
| 813 | 13:48:27.8685314 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shell32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 814 | 13:48:27.8685436 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\shell32.dll | SUCCESS | |
| 815 | 13:48:27.8685886 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shell32.dll | SUCCESS | |
| 816 | 13:48:27.8688099 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\win32u.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 817 | 13:48:27.8688415 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 818 | 13:48:27.8688502 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 819 | 13:48:27.8688575 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\win32u.dll | SUCCESS | |
| 820 | 13:48:27.8690106 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32full.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 821 | 13:48:27.8690348 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 822 | 13:48:27.8690430 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 823 | 13:48:27.8690584 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 824 | 13:48:27.8692846 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WinTypes.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 825 | 13:48:27.8693516 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 826 | 13:48:27.8693647 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 827 | 13:48:27.8693727 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WinTypes.dll | SUCCESS | |
| 828 | 13:48:27.8694757 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 829 | 13:48:27.8694970 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 830 | 13:48:27.8695150 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 831 | 13:48:27.8695220 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | |
| 832 | 13:48:27.8696145 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\combase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 833 | 13:48:27.8696529 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 834 | 13:48:27.8696607 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 835 | 13:48:27.8696671 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\combase.dll | SUCCESS | |
| 836 | 13:48:27.8697570 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shlwapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 837 | 13:48:27.8697836 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 838 | 13:48:27.8697910 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 839 | 13:48:27.8697973 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shlwapi.dll | SUCCESS | |
| 840 | 13:48:27.8704046 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ole32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 841 | 13:48:27.8704420 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 842 | 13:48:27.8704503 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 843 | 13:48:27.8704817 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ole32.dll | SUCCESS | |
| 844 | 13:48:27.8706575 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\SHCore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 845 | 13:48:27.8706951 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\SHCore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 846 | 13:48:27.8707031 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\SHCore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 847 | 13:48:27.8707099 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\SHCore.dll | SUCCESS | |
| 848 | 13:48:27.8721067 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\imm32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 849 | 13:48:27.8721459 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 850 | 13:48:27.8721553 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 851 | 13:48:27.8721632 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\imm32.dll | SUCCESS | |
| 852 | 13:48:27.8848903 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\windows.storage.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 853 | 13:48:27.8849237 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\windows.storage.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 854 | 13:48:27.8849359 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\windows.storage.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 855 | 13:48:27.8849542 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\windows.storage.dll | SUCCESS | |
| 856 | 13:48:27.8885109 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 857 | 13:48:27.8885436 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 858 | 13:48:27.8885548 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 859 | 13:48:27.8885763 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 860 | 13:48:27.8897427 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 861 | 13:48:27.8897723 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 862 | 13:48:27.8897814 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 863 | 13:48:27.8897976 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 864 | 13:48:27.8908487 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\uxtheme.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 865 | 13:48:27.8908783 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 866 | 13:48:27.8908875 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 867 | 13:48:27.8909061 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 868 | 13:48:27.8972384 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\oleaut32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 869 | 13:48:27.8972850 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\oleaut32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 870 | 13:48:27.8972965 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\oleaut32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 871 | 13:48:27.8973129 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\oleaut32.dll | SUCCESS | |
| 872 | 13:48:27.8996849 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 873 | 13:48:27.8997979 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cfgmgr32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 874 | 13:48:27.8998169 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\cfgmgr32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 875 | 13:48:27.8998279 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\cfgmgr32.dll | SUCCESS | |
| 876 | 13:48:27.9025718 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\propsys.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 877 | 13:48:27.9026260 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\propsys.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 878 | 13:48:27.9026375 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\propsys.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 879 | 13:48:27.9026457 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\propsys.dll | SUCCESS | |
| 880 | 13:48:27.9028773 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\propsys.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 881 | 13:48:27.9029077 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\propsys.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 882 | 13:48:27.9029152 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\propsys.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912 |
| 883 | 13:48:27.9029305 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\propsys.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 884 | 13:48:27.9029375 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\propsys.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:05, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:54:05, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 565’248, EndOfFile: 1’079’912 |
| 885 | 13:48:27.9029476 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\propsys.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 886 | 13:48:27.9029562 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\propsys.dll | SUCCESS | |
| 887 | 13:48:27.9029773 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\propsys.dll | SUCCESS | |
| 888 | 13:48:27.9038224 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\clbcatq.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 889 | 13:48:27.9038562 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\clbcatq.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 890 | 13:48:27.9038752 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\clbcatq.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 891 | 13:48:27.9038840 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\clbcatq.dll | SUCCESS | |
| 892 | 13:48:27.9040821 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\clbcatq.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 893 | 13:48:27.9041178 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\clbcatq.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win(찚㈀ |
| 894 | 13:48:27.9041312 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\clbcatq.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552 |
| 895 | 13:48:27.9041411 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\clbcatq.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 896 | 13:48:27.9041467 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\clbcatq.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:31, LastAccessTime: 13.10.2025 13:47:36, LastWriteTime: 30.09.2025 13:53:31, ChangeTime: 01.10.2025 17:29:46, FileAttributes: A, AllocationSize: 385’024, EndOfFile: 724’552 |
| 897 | 13:48:27.9041557 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\clbcatq.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 898 | 13:48:27.9041652 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\clbcatq.dll | SUCCESS | |
| 899 | 13:48:27.9041902 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\clbcatq.dll | SUCCESS | |
| 900 | 13:48:27.9131771 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\profapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 901 | 13:48:27.9132194 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\profapi.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 902 | 13:48:27.9132305 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\profapi.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 903 | 13:48:27.9132381 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\profapi.dll | SUCCESS | |
| 904 | 13:48:27.9134907 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\profapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 905 | 13:48:27.9135363 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\profapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ |
| 906 | 13:48:27.9135771 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\profapi.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136 |
| 907 | 13:48:27.9135920 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\profapi.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 908 | 13:48:27.9135976 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\profapi.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:15, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:15, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 90’112, EndOfFile: 179’136 |
| 909 | 13:48:27.9136051 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\profapi.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 910 | 13:48:27.9136123 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\profapi.dll | SUCCESS | |
| 911 | 13:48:27.9136258 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\profapi.dll | SUCCESS | |
| 912 | 13:48:27.9393615 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 913 | 13:48:27.9394573 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\Windows.StateRepositoryPS.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 914 | 13:48:27.9394780 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 915 | 13:48:27.9395134 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | |
| 916 | 13:48:27.9401344 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 917 | 13:48:27.9401628 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\Windows.StateRepositoryPS.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 918 | 13:48:27.9401721 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608 |
| 919 | 13:48:27.9401911 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\Windows.StateRepositoryPS.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 920 | 13:48:27.9401970 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:11:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:11:03, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 233’472, EndOfFile: 819’608 |
| 921 | 13:48:27.9402069 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 922 | 13:48:27.9402162 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | |
| 923 | 13:48:27.9402454 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\Windows.StateRepositoryPS.dll | SUCCESS | |
| 924 | 13:48:27.9631334 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\edputil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 925 | 13:48:27.9632045 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\edputil.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 926 | 13:48:27.9632372 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\edputil.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 927 | 13:48:27.9632581 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\edputil.dll | SUCCESS | |
| 928 | 13:48:27.9638337 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\edputil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 929 | 13:48:27.9638741 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\edputil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 930 | 13:48:27.9638841 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\edputil.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936 |
| 931 | 13:48:27.9638934 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\edputil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 932 | 13:48:27.9638987 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\edputil.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:15:17, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:15:17, ChangeTime: 30.09.2025 17:02:24, FileAttributes: A, AllocationSize: 81’920, EndOfFile: 167’936 |
| 933 | 13:48:27.9639075 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\edputil.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 934 | 13:48:27.9639165 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\edputil.dll | SUCCESS | |
| 935 | 13:48:27.9639522 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\edputil.dll | SUCCESS | |
| 936 | 13:48:27.9646724 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\urlmon.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 937 | 13:48:27.9647356 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\urlmon.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 938 | 13:48:27.9647594 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\urlmon.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 939 | 13:48:27.9647744 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\urlmon.dll | SUCCESS | |
| 940 | 13:48:27.9651470 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 941 | 13:48:27.9652157 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 942 | 13:48:27.9652887 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\iertutil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 943 | 13:48:27.9653151 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\iertutil.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 944 | 13:48:27.9653313 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\iertutil.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 945 | 13:48:27.9653412 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\iertutil.dll | SUCCESS | |
| 946 | 13:48:27.9653771 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\urlmon.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 947 | 13:48:27.9654258 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\urlmon.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 948 | 13:48:27.9654390 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\urlmon.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024 |
| 949 | 13:48:27.9654648 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\urlmon.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 950 | 13:48:27.9654737 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\urlmon.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:47, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:47, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 1’130’496, EndOfFile: 1’921’024 |
| 951 | 13:48:27.9654872 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\urlmon.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 952 | 13:48:27.9654988 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\urlmon.dll | SUCCESS | |
| 953 | 13:48:27.9655321 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\urlmon.dll | SUCCESS | |
| 954 | 13:48:27.9660518 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\iertutil.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 955 | 13:48:27.9660945 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\iertutil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 956 | 13:48:27.9661025 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\iertutil.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640 |
| 957 | 13:48:27.9661107 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\iertutil.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 958 | 13:48:27.9661159 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\iertutil.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:48, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:48, ChangeTime: 01.10.2025 17:29:44, FileAttributes: A, AllocationSize: 1’216’512, EndOfFile: 2’918’640 |
| 959 | 13:48:27.9661339 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\iertutil.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 960 | 13:48:27.9661469 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\iertutil.dll | SUCCESS | |
| 961 | 13:48:27.9661615 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\iertutil.dll | SUCCESS | |
| 962 | 13:48:27.9665746 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\srvcli.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 963 | 13:48:27.9666171 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\srvcli.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 964 | 13:48:27.9666408 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\srvcli.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 965 | 13:48:27.9666551 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\srvcli.dll | SUCCESS | |
| 966 | 13:48:27.9669618 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\srvcli.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 967 | 13:48:27.9670101 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\srvcli.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win |
| 968 | 13:48:27.9670230 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\srvcli.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080 |
| 969 | 13:48:27.9670369 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\srvcli.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 970 | 13:48:27.9670462 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\srvcli.dll | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:44, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 06.09.2024 06:02:44, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 65’536, EndOfFile: 146’080 |
| 971 | 13:48:27.9670673 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\srvcli.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 972 | 13:48:27.9670824 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\srvcli.dll | SUCCESS | |
| 973 | 13:48:27.9671031 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\srvcli.dll | SUCCESS | |
| 974 | 13:48:27.9672008 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\netutils.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 975 | 13:48:27.9672298 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\netutils.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 976 | 13:48:27.9672395 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\netutils.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 977 | 13:48:27.9672469 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\netutils.dll | SUCCESS | |
| 978 | 13:48:27.9676479 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\netutils.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 979 | 13:48:27.9677081 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\netutils.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ |
| 980 | 13:48:27.9677225 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\netutils.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336 |
| 981 | 13:48:27.9677380 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\netutils.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 982 | 13:48:27.9677582 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\netutils.dll | BUFFER OVERFLOW | CreationTime: 12.08.2025 20:16:04, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 12.08.2025 20:16:04, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 28’672, EndOfFile: 63’336 |
| 983 | 13:48:27.9677731 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\netutils.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 984 | 13:48:27.9677868 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\netutils.dll | SUCCESS | |
| 985 | 13:48:27.9678439 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\netutils.dll | SUCCESS | |
| 986 | 13:48:27.9721593 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sspicli.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 987 | 13:48:27.9722298 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sspicli.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 988 | 13:48:27.9722412 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sspicli.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 989 | 13:48:27.9722509 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sspicli.dll | SUCCESS | |
| 990 | 13:48:27.9725350 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sspicli.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 991 | 13:48:27.9725959 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\sspicli.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ |
| 992 | 13:48:27.9726070 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\sspicli.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200 |
| 993 | 13:48:27.9726182 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\sspicli.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ |
| 994 | 13:48:27.9726320 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\sspicli.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:52, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.09.2025 13:53:52, ChangeTime: 01.10.2025 17:29:48, FileAttributes: A, AllocationSize: 151’552, EndOfFile: 307’200 |
| 995 | 13:48:27.9726448 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sspicli.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 996 | 13:48:27.9726542 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\sspicli.dll | SUCCESS | |
| 997 | 13:48:27.9726707 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sspicli.dll | SUCCESS | |
| 998 | 13:48:27.9800473 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\virtdisk.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 999 | 13:48:27.9800961 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\virtdisk.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1000 | 13:48:27.9801095 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\virtdisk.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1001 | 13:48:27.9801200 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\virtdisk.dll | SUCCESS | |
| 1002 | 13:48:27.9803349 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1003 | 13:48:27.9803580 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1004 | 13:48:27.9805848 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\virtdisk.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1005 | 13:48:27.9806591 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\virtdisk.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅼ |
| 1006 | 13:48:27.9807015 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\virtdisk.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832 |
| 1007 | 13:48:27.9807171 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\virtdisk.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1008 | 13:48:27.9807323 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\virtdisk.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:10:39, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 30.08.2025 10:10:39, ChangeTime: 30.09.2025 17:02:21, FileAttributes: A, AllocationSize: 49’152, EndOfFile: 103’832 |
| 1009 | 13:48:27.9807481 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\virtdisk.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1010 | 13:48:27.9807586 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\virtdisk.dll | SUCCESS | |
| 1011 | 13:48:27.9807769 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\virtdisk.dll | SUCCESS | |
| 1012 | 13:48:27.9826642 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wldp.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1013 | 13:48:27.9827308 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wldp.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1014 | 13:48:27.9827539 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wldp.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1015 | 13:48:27.9827648 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wldp.dll | SUCCESS | |
| 1016 | 13:48:27.9880251 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1017 | 13:48:27.9880560 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1018 | 13:48:27.9883606 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1019 | 13:48:27.9884272 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\grpconv.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1020 | 13:48:27.9884388 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\grpconv.exe | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056 |
| 1021 | 13:48:27.9884499 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\grpconv.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1022 | 13:48:27.9884644 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\grpconv.exe | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:22:17, LastAccessTime: 13.10.2025 13:29:21, LastWriteTime: 01.04.2024 09:22:17, ChangeTime: 30.09.2025 17:02:35, FileAttributes: A, AllocationSize: 12’288, EndOfFile: 45’056 |
| 1023 | 13:48:27.9884780 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\grpconv.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1024 | 13:48:27.9884881 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1025 | 13:48:27.9885044 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1026 | 13:48:28.0042802 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\en-US\grpconv.exe.mui | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ |
| 1027 | 13:48:28.0042927 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\en-US\grpconv.exe.mui | SUCCESS | AllocationSize: 4’096, EndOfFile: 3’072, NumberOfLinks: 2, DeletePending: False, Directory: False |
| 1028 | 13:48:28.0048210 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1029 | 13:48:28.0048550 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\grpconv.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1030 | 13:48:28.0048650 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\grpconv.exe | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1031 | 13:48:28.0048969 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1032 | 13:48:28.0050482 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1033 | 13:48:28.0050860 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1034 | 13:48:28.0051060 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1035 | 13:48:28.0051174 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 1036 | 13:48:28.0055984 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1037 | 13:48:28.0056270 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D |
| 1038 | 13:48:28.0056356 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1039 | 13:48:28.0057689 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1040 | 13:48:28.0057844 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI |
| 1041 | 13:48:28.0058009 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1042 | 13:48:28.0058804 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1043 | 13:48:28.0059048 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2\{????????????????????????????????????} | SUCCESS | FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE} |
| 1044 | 13:48:28.0059990 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1045 | 13:48:28.0060720 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1046 | 13:48:28.0060890 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1047 | 13:48:28.0061069 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1048 | 13:48:28.0061960 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1049 | 13:48:28.0063817 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1050 | 13:48:28.0064082 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1051 | 13:48:28.0064189 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1052 | 13:48:28.0068237 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | SUCCESS | FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE} |
| 1053 | 13:48:28.0092005 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1054 | 13:48:28.0096665 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1055 | 13:48:28.0096864 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1056 | 13:48:28.0096950 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1057 | 13:48:28.0097856 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1058 | 13:48:28.0098965 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1059 | 13:48:28.0099148 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1060 | 13:48:28.0099340 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1061 | 13:48:28.0110987 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1062 | 13:48:28.0111248 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1063 | 13:48:28.0111327 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | |
| 1064 | 13:48:28.0112696 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1065 | 13:48:28.0112923 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1066 | 13:48:28.0113004 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | |
| 1067 | 13:48:28.0114297 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1068 | 13:48:28.0114588 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1069 | 13:48:28.0114663 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | |
| 1070 | 13:48:28.0114915 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | NO MORE FILES | FileInformationClass: FileBothDirectoryInformation |
| 1071 | 13:48:28.0115170 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1072 | 13:48:28.0116491 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1073 | 13:48:28.0116657 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1074 | 13:48:28.0116729 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | |
| 1075 | 13:48:28.0117447 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1076 | 13:48:28.0117768 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1077 | 13:48:28.0117855 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 1078 | 13:48:28.0117934 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1079 | 13:48:28.0118056 | MsMpEng.exe | 3220 | CreateFileMapping | \Device\HarddiskVolume4曘; | SUCCESS | SyncType: SyncTypeOther |
| 1080 | 13:48:28.0119523 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1081 | 13:48:28.0119611 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’167 |
| 1082 | 13:48:28.0120931 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1083 | 13:48:28.0121091 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1084 | 13:48:28.0121241 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | |
| 1085 | 13:48:28.0121690 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1086 | 13:48:28.0121961 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1087 | 13:48:28.0122012 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1088 | 13:48:28.0122189 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1089 | 13:48:28.0122329 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 1090 | 13:48:28.0122461 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | AllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1091 | 13:48:28.0122561 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 1092 | 13:48:28.0122637 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | AllocationSize: 32’768, EndOfFile: 68’180, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1093 | 13:48:28.0122760 | MsMpEng.exe | 3220 | CreateFileMapping | \Device\HarddiskVolume4ꗔ | SUCCESS | SyncType: SyncTypeOther |
| 1094 | 13:48:28.0123650 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1095 | 13:48:28.0123759 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | BUFFER OVERFLOW | CreationTime: 30.09.2025 16:57:54, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 30.09.2025 16:45:09, ChangeTime: 30.09.2025 17:06:31, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 68’180 |
| 1096 | 13:48:28.0123909 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1097 | 13:48:28.0124182 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1098 | 13:48:28.0124275 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1099 | 13:48:28.0124364 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 1100 | 13:48:28.0125050 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1101 | 13:48:28.0125239 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1102 | 13:48:28.0125304 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | |
| 1103 | 13:48:28.0126349 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1104 | 13:48:28.0126563 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | AllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1105 | 13:48:28.0126721 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 1106 | 13:48:28.0126812 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | AllocationSize: 40’960, EndOfFile: 87’970, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1107 | 13:48:28.0126940 | MsMpEng.exe | 3220 | CreateFileMapping | \Device\HarddiskVolume4뎨 | SUCCESS | SyncType: SyncTypeOther |
| 1108 | 13:48:28.0128182 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1109 | 13:48:28.0128270 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:05:08, LastAccessTime: 13.10.2025 13:44:11, LastWriteTime: 06.09.2024 05:59:20, ChangeTime: 12.08.2025 21:30:48, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 87’970 |
| 1110 | 13:48:28.0128677 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | |
| 1111 | 13:48:28.0129061 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.6725.cat | SUCCESS | |
| 1112 | 13:48:28.0129452 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~en-GB~10.0.26100.1591.cat | SUCCESS | |
| 1113 | 13:48:28.0130287 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1114 | 13:48:28.0130647 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1115 | 13:48:28.0131316 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: RH, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1116 | 13:48:28.0131620 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | AllocationSize: 32’768, EndOfFile: 68’167, NumberOfLinks: 3, DeletePending: False, Directory: False |
| 1117 | 13:48:28.0131707 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | CreationTime: 30.08.2025 10:16:17, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:04:47, ChangeTime: 30.08.2025 10:21:59, FileAttributes: A |
| 1118 | 13:48:28.0131824 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | Offset: 0, Length: 68’167, Priority: Normal |
| 1119 | 13:48:28.0136797 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\advapi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1120 | 13:48:28.0137181 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1121 | 13:48:28.0137288 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\advapi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1122 | 13:48:28.0137374 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\advapi32.dll | SUCCESS | |
| 1123 | 13:48:28.0138794 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1124 | 13:48:28.0139273 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1125 | 13:48:28.0139403 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1126 | 13:48:28.0139707 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 1127 | 13:48:28.0141277 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sechost.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1128 | 13:48:28.0141774 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1129 | 13:48:28.0141871 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1130 | 13:48:28.0142081 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sechost.dll | SUCCESS | |
| 1131 | 13:48:28.0143059 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1132 | 13:48:28.0144061 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | |
| 1133 | 13:48:28.0144222 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0111~31bf3856ad364e35~amd64~en-GB~10.0.26100.5074.cat | SUCCESS | |
| 1134 | 13:48:28.0144848 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1135 | 13:48:28.0144973 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1136 | 13:48:28.0145070 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 1137 | 13:48:28.0147675 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\user32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1138 | 13:48:28.0147962 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1139 | 13:48:28.0148143 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1140 | 13:48:28.0148169 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\en-US\grpconv.exe.mui | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1141 | 13:48:28.0148217 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\user32.dll | SUCCESS | |
| 1142 | 13:48:28.0148382 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\en-US\grpconv.exe.mui | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1143 | 13:48:28.0148497 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\en-US\grpconv.exe.mui | SUCCESS | |
| 1144 | 13:48:28.0148752 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\en-US\grpconv.exe.mui | SUCCESS | |
| 1145 | 13:48:28.0149734 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\win32u.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1146 | 13:48:28.0150797 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1147 | 13:48:28.0150940 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1148 | 13:48:28.0151036 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\win32u.dll | SUCCESS | |
| 1149 | 13:48:28.0154734 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1150 | 13:48:28.0155249 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1151 | 13:48:28.0155353 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1152 | 13:48:28.0155443 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 1153 | 13:48:28.0156942 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32full.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1154 | 13:48:28.0157157 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1155 | 13:48:28.0157231 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1156 | 13:48:28.0157306 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 1157 | 13:48:28.0158285 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1158 | 13:48:28.0158469 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1159 | 13:48:28.0158535 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1160 | 13:48:28.0158597 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 1161 | 13:48:28.0160074 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1162 | 13:48:28.0160319 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1163 | 13:48:28.0160399 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1164 | 13:48:28.0168866 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 1165 | 13:48:28.0174862 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shell32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1166 | 13:48:28.0176858 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shell32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1167 | 13:48:28.0177148 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shell32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1168 | 13:48:28.0177265 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shell32.dll | SUCCESS | |
| 1169 | 13:48:28.0182979 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\WinTypes.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1170 | 13:48:28.0183767 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1171 | 13:48:28.0183953 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\WinTypes.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1172 | 13:48:28.0184058 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\WinTypes.dll | SUCCESS | |
| 1173 | 13:48:28.0198161 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\imm32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1174 | 13:48:28.0198546 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1175 | 13:48:28.0198636 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1176 | 13:48:28.0198712 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\imm32.dll | SUCCESS | |
| 1177 | 13:48:28.0199743 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1178 | 13:48:28.0199956 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1179 | 13:48:28.0200038 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1180 | 13:48:28.0200194 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.26100.6725_none_3e085828e334708b\comctl32.dll | SUCCESS | |
| 1181 | 13:48:28.0201140 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\combase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1182 | 13:48:28.0202701 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1183 | 13:48:28.0202843 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1184 | 13:48:28.0203061 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\combase.dll | SUCCESS | |
| 1185 | 13:48:28.0204664 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\shlwapi.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1186 | 13:48:28.0205163 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1187 | 13:48:28.0205283 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\shlwapi.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1188 | 13:48:28.0205483 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\shlwapi.dll | SUCCESS | |
| 1189 | 13:48:28.0254379 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1190 | 13:48:28.0254602 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1191 | 13:48:28.0254695 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1192 | 13:48:28.0254771 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 1193 | 13:48:28.0257540 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1194 | 13:48:28.0257761 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1195 | 13:48:28.0258005 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1196 | 13:48:28.0258105 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 1197 | 13:48:28.0270441 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\uxtheme.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1198 | 13:48:28.0270816 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1199 | 13:48:28.0270936 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1200 | 13:48:28.0271013 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 1201 | 13:48:28.0286892 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ole32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1202 | 13:48:28.0287268 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1203 | 13:48:28.0287378 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ole32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1204 | 13:48:28.0287457 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ole32.dll | SUCCESS | |
| 1205 | 13:48:28.0340751 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1206 | 13:48:28.0341071 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1207 | 13:48:28.0346317 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1208 | 13:48:28.0346543 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1209 | 13:48:28.3342979 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\runonce.exe | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1210 | 13:48:28.3344175 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\runonce.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1211 | 13:48:28.3345044 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\runonce.exe | SUCCESS | Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1212 | 13:48:28.3345523 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\runonce.exe | BUFFER OVERFLOW | |
| 1213 | 13:48:28.3345903 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\runonce.exe | SUCCESS | |
| 1214 | 13:48:28.3346020 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\runonce.exe | SUCCESS | Control: FSCTL_QUERY_USN_JOURNAL |
| 1215 | 13:48:28.3346147 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\runonce.exe | SUCCESS | |
| 1216 | 13:48:28.3346358 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\runonce.exe | SUCCESS | |
| 1217 | 13:48:28.3563838 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1218 | 13:48:28.3564103 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1219 | 13:48:28.3898769 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1220 | 13:48:28.3899185 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1221 | 13:48:28.3899397 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1222 | 13:48:28.3899493 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1223 | 13:48:28.3900002 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1224 | 13:48:28.3900367 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1225 | 13:48:28.3900483 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1226 | 13:48:28.3900732 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1227 | 13:48:28.3901603 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1228 | 13:48:28.3901784 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1229 | 13:48:28.3901853 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1230 | 13:48:28.3902050 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1231 | 13:48:28.3902102 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1232 | 13:48:28.3902190 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1233 | 13:48:28.3902267 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1234 | 13:48:28.3902383 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1235 | 13:48:28.3903599 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1236 | 13:48:28.3903847 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1237 | 13:48:28.3903918 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1238 | 13:48:28.3903994 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1239 | 13:48:28.3904205 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1240 | 13:48:28.3904454 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1241 | 13:48:28.3904563 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1242 | 13:48:28.3904729 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1243 | 13:48:28.3905725 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1244 | 13:48:28.3905983 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1245 | 13:48:28.3906072 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1246 | 13:48:28.3907981 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wintrust.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1247 | 13:48:28.3908339 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wintrust.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1248 | 13:48:28.3908549 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wintrust.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1249 | 13:48:28.3909303 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wintrust.dll | SUCCESS | |
| 1250 | 13:48:28.3910627 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\crypt32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1251 | 13:48:28.3910981 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\crypt32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1252 | 13:48:28.3911167 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\crypt32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1253 | 13:48:28.3911292 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\crypt32.dll | SUCCESS | |
| 1254 | 13:48:28.3912624 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msasn1.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1255 | 13:48:28.3912986 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msasn1.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1256 | 13:48:28.3913117 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msasn1.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1257 | 13:48:28.3913213 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msasn1.dll | SUCCESS | |
| 1258 | 13:48:28.3914343 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1259 | 13:48:28.3914514 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1260 | 13:48:28.3914587 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1261 | 13:48:28.3914651 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1262 | 13:48:28.4062534 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\wintrust.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1263 | 13:48:28.4063170 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\wintrust.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1264 | 13:48:28.4063250 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\wintrust.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344 |
| 1265 | 13:48:28.4063657 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\wintrust.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Win, |
| 1266 | 13:48:28.4063736 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\wintrust.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:40, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:40, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 299’008, EndOfFile: 530’344 |
| 1267 | 13:48:28.4064095 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\wintrust.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1268 | 13:48:28.4064335 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\wintrust.dll | SUCCESS | |
| 1269 | 13:48:28.4065552 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\wintrust.dll | SUCCESS | |
| 1270 | 13:48:28.4070978 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\crypt32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1271 | 13:48:28.4071431 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\crypt32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ |
| 1272 | 13:48:28.4071665 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\crypt32.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408 |
| 1273 | 13:48:28.4071832 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\crypt32.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1274 | 13:48:28.4071900 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\crypt32.dll | BUFFER OVERFLOW | CreationTime: 30.08.2025 10:09:13, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.08.2025 10:09:13, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 909’312, EndOfFile: 1’534’408 |
| 1275 | 13:48:28.4072064 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\crypt32.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1276 | 13:48:28.4072169 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\crypt32.dll | SUCCESS | |
| 1277 | 13:48:28.4072333 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\crypt32.dll | SUCCESS | |
| 1278 | 13:48:28.4073460 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1279 | 13:48:28.4074062 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msasn1.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1280 | 13:48:28.4074363 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msasn1.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1281 | 13:48:28.4074449 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msasn1.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248 |
| 1282 | 13:48:28.4074530 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msasn1.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ |
| 1283 | 13:48:28.4074658 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msasn1.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:53:57, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:53:57, ChangeTime: 01.10.2025 17:29:49, FileAttributes: A, AllocationSize: 40’960, EndOfFile: 88’248 |
| 1284 | 13:48:28.4074768 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msasn1.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1285 | 13:48:28.4074841 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msasn1.dll | SUCCESS | |
| 1286 | 13:48:28.4074966 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msasn1.dll | SUCCESS | |
| 1287 | 13:48:28.4075532 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment | REPARSE | Desired Access: Read |
| 1288 | 13:48:28.4076521 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1289 | 13:48:28.4076751 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 1290 | 13:48:28.4076830 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1291 | 13:48:28.4076908 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1292 | 13:48:28.4076964 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1293 | 13:48:28.4077111 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1294 | 13:48:28.4077213 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Desired Access: Read |
| 1295 | 13:48:28.4077252 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1296 | 13:48:28.4077370 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1297 | 13:48:28.4078235 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Query: Cached, SubKeys: 0, Values: 15 |
| 1298 | 13:48:28.4078596 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1299 | 13:48:28.4078989 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅄ |
| 1300 | 13:48:28.4079086 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1301 | 13:48:28.4079167 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1302 | 13:48:28.4079216 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1303 | 13:48:28.4079287 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1304 | 13:48:28.4079379 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1305 | 13:48:28.4079578 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1306 | 13:48:28.4079653 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 0, Type: REG_EXPAND_SZ |
| 1307 | 13:48:28.4080685 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1308 | 13:48:28.4081275 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1309 | 13:48:28.4081348 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1310 | 13:48:28.4081438 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1311 | 13:48:28.4081492 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1312 | 13:48:28.4081565 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1313 | 13:48:28.4081602 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\ComSpec | SUCCESS | Type: REG_EXPAND_SZ, Length: 60, Data: %SystemRoot%\system32\cmd.exe |
| 1314 | 13:48:28.4081655 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1315 | 13:48:28.4081871 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1316 | 13:48:28.4082884 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1317 | 13:48:28.4083152 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1318 | 13:48:28.4083252 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1319 | 13:48:28.4084074 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1320 | 13:48:28.4084385 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1321 | 13:48:28.4085031 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1322 | 13:48:28.4085268 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1323 | 13:48:28.4085447 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1324 | 13:48:28.4086514 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1325 | 13:48:28.4087427 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 1, Type: REG_SZ |
| 1326 | 13:48:28.4089002 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\DriverData | SUCCESS | Type: REG_SZ, Length: 78, Data: C:\Windows\System32\Drivers\DriverData |
| 1327 | 13:48:28.4090547 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 2, Type: REG_SZ |
| 1328 | 13:48:28.4091814 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\OS | SUCCESS | Type: REG_SZ, Length: 22, Data: Windows_NT |
| 1329 | 13:48:28.4093401 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 3, Type: REG_EXPAND_SZ |
| 1330 | 13:48:28.4095410 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path | BUFFER OVERFLOW | Length: 144 |
| 1331 | 13:48:28.4095466 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1332 | 13:48:28.4096645 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\Path | SUCCESS | Type: REG_EXPAND_SZ, Length: 514, Data: |
| 1333 | 13:48:28.4097914 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 4, Type: REG_SZ |
| 1334 | 13:48:28.4099007 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PATHEXT | SUCCESS | Type: REG_SZ, Length: 108, Data: .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC |
| 1335 | 13:48:28.4099163 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1336 | 13:48:28.4100824 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 5, Type: REG_SZ |
| 1337 | 13:48:28.4101942 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_ARCHITECTURE | SUCCESS | Type: REG_SZ, Length: 12, Data: AMD64 |
| 1338 | 13:48:28.4103225 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 6, Type: REG_EXPAND_SZ |
| 1339 | 13:48:28.4104192 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath | BUFFER OVERFLOW | Length: 144 |
| 1340 | 13:48:28.4106832 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PSModulePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 188, Data: |
| 1341 | 13:48:28.4108727 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 7, Type: REG_EXPAND_SZ |
| 1342 | 13:48:28.4111180 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TEMP | SUCCESS | Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP |
| 1343 | 13:48:28.4114699 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 8, Type: REG_EXPAND_SZ |
| 1344 | 13:48:28.4119680 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\TMP | SUCCESS | Type: REG_EXPAND_SZ, Length: 36, Data: %SystemRoot%\TEMP |
| 1345 | 13:48:28.4121491 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 9, Type: REG_SZ |
| 1346 | 13:48:28.4122589 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\USERNAME | SUCCESS | Type: REG_SZ, Length: 14, Data: SYSTEM |
| 1347 | 13:48:28.4123776 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 10, Type: REG_EXPAND_SZ |
| 1348 | 13:48:28.4124750 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\windir | SUCCESS | Type: REG_EXPAND_SZ, Length: 26, Data: %SystemRoot% |
| 1349 | 13:48:28.4126314 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 11, Type: REG_SZ |
| 1350 | 13:48:28.4127466 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\NUMBER_OF_PROCESSORS | SUCCESS | Type: REG_SZ, Length: 4, Data: 4 |
| 1351 | 13:48:28.4129272 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 12, Type: REG_SZ |
| 1352 | 13:48:28.4130339 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_LEVEL | SUCCESS | Type: REG_SZ, Length: 6, Data: 25 |
| 1353 | 13:48:28.4131439 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 13, Type: REG_SZ |
| 1354 | 13:48:28.4132525 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_IDENTIFIER | SUCCESS | Type: REG_SZ, Length: 100, Data: AMD64 Family 25 Model 33 Stepping 0, AuthenticAMD |
| 1355 | 13:48:28.4133289 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | Index: 14, Type: REG_SZ |
| 1356 | 13:48:28.4134232 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\Session Manager\Environment\PROCESSOR_REVISION | SUCCESS | Type: REG_SZ, Length: 10, Data: 2100 |
| 1357 | 13:48:28.4135187 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\System\CurrentControlSet\Control\Session Manager\Environment | SUCCESS | |
| 1358 | 13:48:28.4136168 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1359 | 13:48:28.4144746 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SFC | REPARSE | Desired Access: Read |
| 1360 | 13:48:28.4145954 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\SFC | NAME NOT FOUND | Desired Access: Read |
| 1361 | 13:48:28.4147199 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1362 | 13:48:28.4148243 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion | SUCCESS | Desired Access: Read |
| 1363 | 13:48:28.4149953 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Query: Cached, SubKeys: 167, Values: 11 |
| 1364 | 13:48:28.4152459 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 0, Type: REG_SZ |
| 1365 | 13:48:28.4154152 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir | SUCCESS | Type: REG_SZ, Length: 34, Data: C:\Program Files |
| 1366 | 13:48:28.4156536 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 1, Type: REG_SZ |
| 1367 | 13:48:28.4159412 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir | SUCCESS | Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files |
| 1368 | 13:48:28.4161412 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1369 | 13:48:28.4161750 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1370 | 13:48:28.4161887 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1371 | 13:48:28.4162088 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1372 | 13:48:28.4163839 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1373 | 13:48:28.4164077 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1374 | 13:48:28.4164790 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 2, Type: REG_SZ |
| 1375 | 13:48:28.4166301 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) | SUCCESS | Type: REG_SZ, Length: 46, Data: C:\Program Files (x86) |
| 1376 | 13:48:28.4166895 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1377 | 13:48:28.4167274 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 3, Type: REG_SZ |
| 1378 | 13:48:28.4168452 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) | SUCCESS | Type: REG_SZ, Length: 72, Data: C:\Program Files (x86)\Common Files |
| 1379 | 13:48:28.4170713 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 4, Type: REG_SZ |
| 1380 | 13:48:28.4172534 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir | SUCCESS | Type: REG_SZ, Length: 60, Data: C:\Program Files\Common Files |
| 1381 | 13:48:28.4174126 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 5, Type: REG_EXPAND_SZ |
| 1382 | 13:48:28.4176792 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 34, Data: %SystemRoot%\inf |
| 1383 | 13:48:28.4178130 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 6, Type: REG_EXPAND_SZ |
| 1384 | 13:48:28.4179072 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MediaPathUnexpanded | SUCCESS | Type: REG_EXPAND_SZ, Length: 38, Data: %SystemRoot%\Media |
| 1385 | 13:48:28.4179942 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 7, Type: REG_EXPAND_SZ |
| 1386 | 13:48:28.4181129 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesPath | SUCCESS | Type: REG_EXPAND_SZ, Length: 30, Data: %ProgramFiles% |
| 1387 | 13:48:28.4182246 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 8, Type: REG_SZ |
| 1388 | 13:48:28.4183162 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir | SUCCESS | Type: REG_SZ, Length: 34, Data: C:\Program Files |
| 1389 | 13:48:28.4184081 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 9, Type: REG_SZ |
| 1390 | 13:48:28.4185178 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_ConfigureProgramsName | SUCCESS | Type: REG_SZ, Length: 64, Data: Set Program Access and Defaults |
| 1391 | 13:48:28.4186417 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | Index: 10, Type: REG_SZ |
| 1392 | 13:48:28.4187391 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SM_GamesName | SUCCESS | Type: REG_SZ, Length: 12, Data: Games |
| 1393 | 13:48:28.4189601 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion | SUCCESS | |
| 1394 | 13:48:28.4190797 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1395 | 13:48:28.4191727 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Desired Access: Read |
| 1396 | 13:48:28.4192705 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: Cached, SubKeys: 4, Values: 4 |
| 1397 | 13:48:28.4193577 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 0, Type: REG_EXPAND_SZ |
| 1398 | 13:48:28.4194418 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A |
| 1399 | 13:48:28.4194487 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | AllocationSize: 2’519’040, EndOfFile: 2’518’232, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 1400 | 13:48:28.4195080 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 0, Length: 4’096, Priority: Normal |
| 1401 | 13:48:28.4197308 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’510’848, Length: 7’384, Priority: Normal |
| 1402 | 13:48:28.4197999 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’506’752, Length: 4’096, Priority: Normal |
| 1403 | 13:48:28.4200447 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 4’096, Length: 520’192, Priority: Normal |
| 1404 | 13:48:28.4213650 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default | SUCCESS | Type: REG_EXPAND_SZ, Length: 56, Data: %SystemDrive%\Users\Default |
| 1405 | 13:48:28.4214361 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 1, Type: REG_EXPAND_SZ |
| 1406 | 13:48:28.4215221 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory | SUCCESS | Type: REG_EXPAND_SZ, Length: 40, Data: %SystemDrive%\Users |
| 1407 | 13:48:28.4216075 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 2, Type: REG_EXPAND_SZ |
| 1408 | 13:48:28.4216941 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData | SUCCESS | Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData |
| 1409 | 13:48:28.4217760 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 3, Type: REG_EXPAND_SZ |
| 1410 | 13:48:28.4218530 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public | SUCCESS | Type: REG_EXPAND_SZ, Length: 54, Data: %SystemDrive%\Users\Public |
| 1411 | 13:48:28.4219514 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | |
| 1412 | 13:48:28.4221313 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1413 | 13:48:28.4222249 | MsMpEng.exe | 3220 | RegCreateKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY |
| 1414 | 13:48:28.4223180 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: Cached, SubKeys: 4, Values: 4 |
| 1415 | 13:48:28.4224012 | MsMpEng.exe | 3220 | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 0, Name: S-1-5-18 |
| 1416 | 13:48:28.4224820 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1417 | 13:48:28.4225533 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 | SUCCESS | Desired Access: Read |
| 1418 | 13:48:28.4226493 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile |
| 1419 | 13:48:28.4228042 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\config\systemprofile\ntuser.dat | NAME NOT FOUND | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1420 | 13:48:28.4228791 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\config\systemprofile\ntuser.dat | NAME NOT FOUND | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1421 | 13:48:28.4229713 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\config\systemprofile\ntuser.dat | NAME NOT FOUND | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1422 | 13:48:28.4230427 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\config\systemprofile | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1423 | 13:48:28.4230629 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\config\systemprofile | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1424 | 13:48:28.4230704 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\config\systemprofile | BUFFER OVERFLOW | CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D, AllocationSize: 0, EndOfFile: 0 |
| 1425 | 13:48:28.4231071 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\config\systemprofile\ntuser.dat | NO SUCH FILE | FileInformationClass: FileIdFullDirectoryInformation, Filter: ntuser.dat |
| 1426 | 13:48:28.4231256 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\config\systemprofile | SUCCESS | |
| 1427 | 13:48:28.4232891 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\config\systemprofile\AppData\Local\VirtualStore | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1428 | 13:48:28.4233149 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 | SUCCESS | |
| 1429 | 13:48:28.4243416 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 524’288, Length: 524’288, Priority: Normal |
| 1430 | 13:48:28.4244103 | MsMpEng.exe | 3220 | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 1, Name: S-1-5-19 |
| 1431 | 13:48:28.4249018 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1432 | 13:48:28.4250263 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 | SUCCESS | Desired Access: Read |
| 1433 | 13:48:28.4251111 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 84, Data: %systemroot%\ServiceProfiles\LocalService |
| 1434 | 13:48:28.4253192 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1435 | 13:48:28.4253529 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1436 | 13:48:28.4253621 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | |
| 1437 | 13:48:28.4254391 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1438 | 13:48:28.4254585 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A |
| 1439 | 13:48:28.4254748 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT | SUCCESS | |
| 1440 | 13:48:28.4256222 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\LocalService\AppData\Local\VirtualStore | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1441 | 13:48:28.4256454 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 | SUCCESS | |
| 1442 | 13:48:28.4257623 | MsMpEng.exe | 3220 | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 2, Name: S-1-5-20 |
| 1443 | 13:48:28.4258432 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1444 | 13:48:28.4259287 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20 | SUCCESS | Desired Access: Read |
| 1445 | 13:48:28.4260427 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 88, Data: %systemroot%\ServiceProfiles\NetworkService |
| 1446 | 13:48:28.4263013 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1447 | 13:48:28.4263369 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1448 | 13:48:28.4263451 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | |
| 1449 | 13:48:28.4264220 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1450 | 13:48:28.4264481 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 20:37:21, LastAccessTime: 13.10.2025 13:30:48, LastWriteTime: 13.10.2025 13:30:48, ChangeTime: 12.08.2025 20:37:21, FileAttributes: A |
| 1451 | 13:48:28.4264585 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT | SUCCESS | |
| 1452 | 13:48:28.4265934 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\VirtualStore | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1453 | 13:48:28.4266165 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20 | SUCCESS | |
| 1454 | 13:48:28.4266730 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’048’576, Length: 524’288, Priority: Normal |
| 1455 | 13:48:28.4268823 | MsMpEng.exe | 3220 | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Index: 3, Name: S-1-5-21-4172013786-3171869251-2938521833-1000 |
| 1456 | 13:48:28.4269624 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1457 | 13:48:28.4270477 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000 | SUCCESS | Desired Access: Read |
| 1458 | 13:48:28.4271583 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000\ProfileImagePath | SUCCESS | Type: REG_EXPAND_SZ, Length: 32, Data: C:\Users\hacker |
| 1459 | 13:48:28.4273472 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1460 | 13:48:28.4273808 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: HANCI |
| 1461 | 13:48:28.4273875 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | |
| 1462 | 13:48:28.4275274 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1463 | 13:48:28.4275571 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | CreationTime: 12.08.2025 19:41:55, LastAccessTime: 13.10.2025 13:30:45, LastWriteTime: 13.10.2025 13:30:45, ChangeTime: 12.08.2025 19:41:55, FileAttributes: HANCI |
| 1464 | 13:48:28.4275853 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\NTUSER.DAT | SUCCESS | |
| 1465 | 13:48:28.4277164 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\AppData\Local\VirtualStore | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1466 | 13:48:28.4277425 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Users\hacker\AppData\Local\VirtualStore | SUCCESS | CreationTime: 12.08.2025 19:42:01, LastAccessTime: 13.10.2025 13:32:41, LastWriteTime: 12.08.2025 19:42:01, ChangeTime: 12.08.2025 19:42:01, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: D |
| 1467 | 13:48:28.4277490 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\AppData\Local\VirtualStore | SUCCESS | |
| 1468 | 13:48:28.4278028 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-4172013786-3171869251-2938521833-1000 | SUCCESS | |
| 1469 | 13:48:28.4278821 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList | SUCCESS | |
| 1470 | 13:48:28.4279826 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1471 | 13:48:28.4280614 | MsMpEng.exe | 3220 | RegOpenKey | HKU\S-1-5-18 | REPARSE | Desired Access: Read |
| 1472 | 13:48:28.4281164 | MsMpEng.exe | 3220 | RegOpenKey | HKU\.DEFAULT | SUCCESS | Desired Access: Read |
| 1473 | 13:48:28.4282185 | MsMpEng.exe | 3220 | RegCloseKey | HKU\.DEFAULT | SUCCESS | |
| 1474 | 13:48:28.4282944 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1475 | 13:48:28.4283872 | MsMpEng.exe | 3220 | RegOpenKey | HKU\S-1-5-18 | REPARSE | Desired Access: Read |
| 1476 | 13:48:28.4285679 | MsMpEng.exe | 3220 | RegOpenKey | HKU\.DEFAULT | SUCCESS | Desired Access: Read |
| 1477 | 13:48:28.4286557 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1478 | 13:48:28.4287260 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Desired Access: Read |
| 1479 | 13:48:28.4287863 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Query: Cached, SubKeys: 0, Values: 12 |
| 1480 | 13:48:28.4288690 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 0, Type: REG_SZ |
| 1481 | 13:48:28.4289558 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools | BUFFER OVERFLOW | Length: 144 |
| 1482 | 13:48:28.4290272 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Administrative Tools | SUCCESS | Type: REG_SZ, Length: 148, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools |
| 1483 | 13:48:28.4290763 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 1, Type: REG_SZ |
| 1484 | 13:48:28.4291735 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData | SUCCESS | Type: REG_SZ, Length: 30, Data: C:\ProgramData |
| 1485 | 13:48:28.4292670 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 2, Type: REG_SZ |
| 1486 | 13:48:28.4293966 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Desktop | SUCCESS | Type: REG_SZ, Length: 48, Data: C:\Users\Public\Desktop |
| 1487 | 13:48:28.4295015 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 3, Type: REG_SZ |
| 1488 | 13:48:28.4295811 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Documents | SUCCESS | Type: REG_SZ, Length: 52, Data: C:\Users\Public\Documents |
| 1489 | 13:48:28.4297692 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 4, Type: REG_SZ |
| 1490 | 13:48:28.4299565 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Programs | SUCCESS | Type: REG_SZ, Length: 106, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs |
| 1491 | 13:48:28.4300556 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 5, Type: REG_SZ |
| 1492 | 13:48:28.4301819 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu | SUCCESS | Type: REG_SZ, Length: 88, Data: C:\ProgramData\Microsoft\Windows\Start Menu |
| 1493 | 13:48:28.4302873 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 6, Type: REG_SZ |
| 1494 | 13:48:28.4303502 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup | SUCCESS | Type: REG_SZ, Length: 122, Data: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup |
| 1495 | 13:48:28.4304065 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 7, Type: REG_SZ |
| 1496 | 13:48:28.4304453 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Templates | SUCCESS | Type: REG_SZ, Length: 86, Data: C:\ProgramData\Microsoft\Windows\Templates |
| 1497 | 13:48:28.4305291 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 8, Type: REG_SZ |
| 1498 | 13:48:28.4305746 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusic | SUCCESS | Type: REG_SZ, Length: 44, Data: C:\Users\Public\Music |
| 1499 | 13:48:28.4306404 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 9, Type: REG_SZ |
| 1500 | 13:48:28.4306780 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPictures | SUCCESS | Type: REG_SZ, Length: 50, Data: C:\Users\Public\Pictures |
| 1501 | 13:48:28.4307358 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 10, Type: REG_SZ |
| 1502 | 13:48:28.4307971 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideo | SUCCESS | Type: REG_SZ, Length: 46, Data: C:\Users\Public\Videos |
| 1503 | 13:48:28.4308607 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 11, Type: REG_SZ |
| 1504 | 13:48:28.4309026 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\OEM Links | SUCCESS | Type: REG_SZ, Length: 50, Data: C:\ProgramData\OEM\Links |
| 1505 | 13:48:28.4309918 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | |
| 1506 | 13:48:28.4310712 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 1507 | 13:48:28.4311488 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Desired Access: Read |
| 1508 | 13:48:28.4312410 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Query: Cached, SubKeys: 1, Values: 11 |
| 1509 | 13:48:28.4313617 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 0, Type: REG_EXPAND_SZ |
| 1510 | 13:48:28.4314059 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common AppData | SUCCESS | Type: REG_EXPAND_SZ, Length: 28, Data: %ProgramData% |
| 1511 | 13:48:28.4314964 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 1, Type: REG_EXPAND_SZ |
| 1512 | 13:48:28.4315793 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Desktop | SUCCESS | Type: REG_EXPAND_SZ, Length: 34, Data: %PUBLIC%\Desktop |
| 1513 | 13:48:28.4316446 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 2, Type: REG_EXPAND_SZ |
| 1514 | 13:48:28.4316960 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Documents | SUCCESS | Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Documents |
| 1515 | 13:48:28.4317255 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 3, Type: REG_EXPAND_SZ |
| 1516 | 13:48:28.4317660 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs | SUCCESS | Type: REG_EXPAND_SZ, Length: 104, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs |
| 1517 | 13:48:28.4318276 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 4, Type: REG_EXPAND_SZ |
| 1518 | 13:48:28.4318622 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Start Menu | SUCCESS | Type: REG_EXPAND_SZ, Length: 86, Data: %ProgramData%\Microsoft\Windows\Start Menu |
| 1519 | 13:48:28.4319047 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 5, Type: REG_EXPAND_SZ |
| 1520 | 13:48:28.4319574 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Startup | SUCCESS | Type: REG_EXPAND_SZ, Length: 120, Data: %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup |
| 1521 | 13:48:28.4320504 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 6, Type: REG_EXPAND_SZ |
| 1522 | 13:48:28.4321108 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Templates | SUCCESS | Type: REG_EXPAND_SZ, Length: 84, Data: %ProgramData%\Microsoft\Windows\Templates |
| 1523 | 13:48:28.4321768 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 7, Type: REG_EXPAND_SZ |
| 1524 | 13:48:28.4322428 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonMusic | SUCCESS | Type: REG_EXPAND_SZ, Length: 30, Data: %PUBLIC%\Music |
| 1525 | 13:48:28.4323192 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 8, Type: REG_EXPAND_SZ |
| 1526 | 13:48:28.4323704 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonPictures | SUCCESS | Type: REG_EXPAND_SZ, Length: 36, Data: %PUBLIC%\Pictures |
| 1527 | 13:48:28.4324145 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 9, Type: REG_EXPAND_SZ |
| 1528 | 13:48:28.4324526 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonVideo | SUCCESS | Type: REG_EXPAND_SZ, Length: 32, Data: %PUBLIC%\Videos |
| 1529 | 13:48:28.4325872 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 10, Type: REG_EXPAND_SZ |
| 1530 | 13:48:28.4326543 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{3D644C9B-1FB8-4f30-9B45-F670235F79C0} | SUCCESS | Type: REG_EXPAND_SZ, Length: 38, Data: %PUBLIC%\Downloads |
| 1531 | 13:48:28.4327177 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | |
| 1532 | 13:48:28.4329686 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1533 | 13:48:28.4329878 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1534 | 13:48:28.4329947 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1535 | 13:48:28.4330808 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1536 | 13:48:28.4331008 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1537 | 13:48:28.4331079 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1538 | 13:48:28.4331154 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1539 | 13:48:28.4331211 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1540 | 13:48:28.4331609 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1541 | 13:48:28.4331753 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1542 | 13:48:28.4332059 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1543 | 13:48:28.4332784 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1544 | 13:48:28.4332948 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1545 | 13:48:28.4333103 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1546 | 13:48:28.4333380 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1547 | 13:48:28.4333455 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1548 | 13:48:28.4333560 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1549 | 13:48:28.4333654 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1550 | 13:48:28.4333878 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1551 | 13:48:28.4334828 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1552 | 13:48:28.4335090 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 1553 | 13:48:28.4335188 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1554 | 13:48:28.4335268 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1555 | 13:48:28.4335337 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1556 | 13:48:28.4335411 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1557 | 13:48:28.4336662 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1558 | 13:48:28.4336931 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1559 | 13:48:28.4337882 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1560 | 13:48:28.4338155 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1561 | 13:48:28.4338267 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1562 | 13:48:28.4339536 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1563 | 13:48:28.4339669 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 1564 | 13:48:28.4339729 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1565 | 13:48:28.4341558 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1566 | 13:48:28.4341883 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1567 | 13:48:28.4342808 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1568 | 13:48:28.4343140 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:27, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A |
| 1569 | 13:48:28.4343208 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 1570 | 13:48:28.4345916 | MsMpEng.exe | 3220 | CreateFile | C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9 | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 1571 | 13:48:28.4346264 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 0, Length: 4’096, Priority: Normal |
| 1572 | 13:48:28.4348375 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 372’736, Length: 6’144, Priority: Normal |
| 1573 | 13:48:28.4348629 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 376’832, Length: 2’048, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1574 | 13:48:28.4383576 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’572’864, Length: 524’288, Priority: Normal |
| 1575 | 13:48:28.4403465 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’097’152, Length: 421’080, Priority: Normal |
| 1576 | 13:48:28.4424770 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1577 | 13:48:28.4425339 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1578 | 13:48:28.4430154 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 0, Length: 4’096, Priority: Normal |
| 1579 | 13:48:28.4436904 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 4’096, Length: 262’144, Priority: Normal |
| 1580 | 13:48:28.4445385 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 266’240, Length: 258’048, Priority: Normal |
| 1581 | 13:48:28.4449553 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 524’288, Length: 4’096, Priority: Normal |
| 1582 | 13:48:28.4462681 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 528’384, Length: 262’144, Priority: Normal |
| 1583 | 13:48:28.4490840 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 790’528, Length: 258’048, Priority: Normal |
| 1584 | 13:48:28.4494464 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’048’576, Length: 4’096, Priority: Normal |
| 1585 | 13:48:28.4515156 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’052’672, Length: 262’144, Priority: Normal |
| 1586 | 13:48:28.4534980 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’314’816, Length: 258’048, Priority: Normal |
| 1587 | 13:48:28.4548680 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’572’864, Length: 4’096, Priority: Normal |
| 1588 | 13:48:28.4712170 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’576’960, Length: 262’144, Priority: Normal |
| 1589 | 13:48:28.4717004 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 270’336, Length: 4’096, Priority: Normal |
| 1590 | 13:48:28.4717113 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 270’336, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1591 | 13:48:28.4754079 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 1’839’104, Length: 258’048, Priority: Normal |
| 1592 | 13:48:28.4755787 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’097’152, Length: 4’096, Priority: Normal |
| 1593 | 13:48:28.4756729 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 274’432, Length: 4’096, Priority: Normal |
| 1594 | 13:48:28.4757056 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 274’432, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1595 | 13:48:28.4782713 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 81’920, Length: 4’096, Priority: Normal |
| 1596 | 13:48:28.4782805 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 81’920, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1597 | 13:48:28.4799448 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 299’008, Length: 4’096, Priority: Normal |
| 1598 | 13:48:28.4800188 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 266’240, Length: 8’192, Priority: Normal |
| 1599 | 13:48:28.4800254 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 266’240, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1600 | 13:48:28.4803941 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 184’320, Length: 8’192, Priority: Normal |
| 1601 | 13:48:28.4805170 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 184’320, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1602 | 13:48:28.4811251 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 86’016, Length: 4’096, Priority: Normal |
| 1603 | 13:48:28.4811442 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 86’016, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1604 | 13:48:28.4814332 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’101’248, Length: 262’144, Priority: Normal |
| 1605 | 13:48:28.4814413 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 258’048, Length: 8’192, Priority: Normal |
| 1606 | 13:48:28.4814503 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 258’048, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1607 | 13:48:28.4829081 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 4’096, Length: 4’096, Priority: Normal |
| 1608 | 13:48:28.4829172 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 4’096, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1609 | 13:48:28.4844314 | MsMpEng.exe | 3220 | ReadFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Offset: 2’363’392, Length: 147’456, Priority: Normal |
| 1610 | 13:48:28.4847561 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 192’512, Length: 4’096, Priority: Normal |
| 1611 | 13:48:28.4847635 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 192’512, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1612 | 13:48:28.4907578 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 278’528, Length: 4’096, Priority: Normal |
| 1613 | 13:48:28.4907659 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 278’528, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1614 | 13:48:28.4909934 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 282’624, Length: 4’096, Priority: Normal |
| 1615 | 13:48:28.4910086 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 282’624, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1616 | 13:48:28.4914409 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 303’104, Length: 4’096, Priority: Normal |
| 1617 | 13:48:28.4914889 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 307’200, Length: 8’192, Priority: Normal |
| 1618 | 13:48:28.4914958 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 311’296, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1619 | 13:48:28.4917225 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1620 | 13:48:28.4997512 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv.exe | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1621 | 13:48:28.5004346 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\grpconv.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1622 | 13:48:28.5005107 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\grpconv.exe | SUCCESS | Desired Access: Read Data/List Directory, Read EA, Read Attributes, Synchronize, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1623 | 13:48:28.5005522 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\grpconv.exe | BUFFER OVERFLOW | |
| 1624 | 13:48:28.5005841 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1625 | 13:48:28.5005935 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\grpconv.exe | SUCCESS | Control: FSCTL_QUERY_USN_JOURNAL |
| 1626 | 13:48:28.5006036 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1627 | 13:48:28.5006223 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\grpconv.exe | SUCCESS | |
| 1628 | 13:48:28.5010695 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 286’720, Length: 12’288, Priority: Normal |
| 1629 | 13:48:28.5010797 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 286’720, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1630 | 13:48:28.5011187 | MsMpEng.exe | 3220 | QueryStreamInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1631 | 13:48:28.5011355 | MsMpEng.exe | 3220 | QueryEAFile | C:\Windows\System32\drivers\NeacSafe64.sys | NO EAS ON FILE | |
| 1632 | 13:48:28.5012298 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1633 | 13:48:28.5012525 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1634 | 13:48:28.5012596 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1635 | 13:48:28.5012676 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1636 | 13:48:28.5012816 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | BUFFER OVERFLOW | CreationTime: 10.10.2025 23:07:07, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 13:48:27, ChangeTime: 13.10.2025 13:48:27, FileAttributes: A, AllocationSize: 2’519’040, EndOfFile: 2’518’232 |
| 1637 | 13:48:28.5012920 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1638 | 13:48:28.5013032 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1639 | 13:48:28.5014134 | MsMpEng.exe | 3220 | QueryStreamInformationFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1640 | 13:48:28.5014255 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1641 | 13:48:28.5015104 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1642 | 13:48:28.5015555 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1643 | 13:48:28.5015875 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\drivers\NeacSafe64.sys | SUCCESS | |
| 1644 | 13:48:28.5023434 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 90’112, Length: 16’384, Priority: Normal |
| 1645 | 13:48:28.5023527 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 90’112, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1646 | 13:48:28.5050418 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 180’224, Length: 4’096, Priority: Normal |
| 1647 | 13:48:28.5050503 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 180’224, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1648 | 13:48:28.5154011 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 122’880, Length: 8’192, Priority: Normal |
| 1649 | 13:48:28.5154100 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 122’880, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1650 | 13:48:28.5157404 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 131’072, Length: 4’096, Priority: Normal |
| 1651 | 13:48:28.5157490 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 131’072, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1652 | 13:48:28.5216395 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 151’552, Length: 8’192, Priority: Normal |
| 1653 | 13:48:28.5216482 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 151’552, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1654 | 13:48:28.5220309 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 159’744, Length: 4’096, Priority: Normal |
| 1655 | 13:48:28.5220402 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 159’744, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1656 | 13:48:28.5224797 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 118’784, Length: 8’192, Priority: Normal |
| 1657 | 13:48:28.5224958 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 118’784, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1658 | 13:48:28.5229576 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 135’168, Length: 8’192, Priority: Normal |
| 1659 | 13:48:28.5229661 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 135’168, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1660 | 13:48:28.5233907 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 196’608, Length: 4’096, Priority: Normal |
| 1661 | 13:48:28.5233984 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 196’608, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1662 | 13:48:28.5816734 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 147’456, Length: 8’192, Priority: Normal |
| 1663 | 13:48:28.5817915 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 147’456, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1664 | 13:48:28.5859428 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1665 | 13:48:28.5859767 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1666 | 13:48:28.5861841 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\dllhost.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1667 | 13:48:28.5862274 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\dllhost.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1668 | 13:48:28.5862526 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\dllhost.exe | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504 |
| 1669 | 13:48:28.5862732 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\dllhost.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1670 | 13:48:28.5862836 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\dllhost.exe | BUFFER OVERFLOW | CreationTime: 06.09.2024 06:02:01, LastAccessTime: 13.10.2025 13:47:55, LastWriteTime: 06.09.2024 06:02:01, ChangeTime: 30.09.2025 17:02:31, FileAttributes: A, AllocationSize: 16’384, EndOfFile: 50’504 |
| 1671 | 13:48:28.5863043 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\dllhost.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1672 | 13:48:28.5863134 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\dllhost.exe | SUCCESS | |
| 1673 | 13:48:28.5863462 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\dllhost.exe | SUCCESS | |
| 1674 | 13:48:28.5900437 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 143’360, Length: 8’192, Priority: Normal |
| 1675 | 13:48:28.5900552 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 143’360, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1676 | 13:48:28.5920450 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 176’128, Length: 8’192, Priority: Normal |
| 1677 | 13:48:28.5920547 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 176’128, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1678 | 13:48:28.5947811 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\dllhost.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1679 | 13:48:28.5948617 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\dllhost.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1680 | 13:48:28.5948958 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\dllhost.exe | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1681 | 13:48:28.5949062 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\dllhost.exe | SUCCESS | |
| 1682 | 13:48:28.5950322 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1683 | 13:48:28.5950735 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1684 | 13:48:28.5950857 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1685 | 13:48:28.5950943 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 1686 | 13:48:28.5981343 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 167’936, Length: 8’192, Priority: Normal |
| 1687 | 13:48:28.5981508 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 167’936, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1688 | 13:48:28.6070772 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1689 | 13:48:28.6071160 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1690 | 13:48:28.6071286 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1691 | 13:48:28.6071369 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 1692 | 13:48:28.6121278 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1693 | 13:48:28.6122298 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1694 | 13:48:28.6122424 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1695 | 13:48:28.6123531 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 1696 | 13:48:28.6129480 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1697 | 13:48:28.6129924 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1698 | 13:48:28.6130017 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1699 | 13:48:28.6130097 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 1700 | 13:48:28.6132184 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\combase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1701 | 13:48:28.6132582 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1702 | 13:48:28.6132671 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\combase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1703 | 13:48:28.6132841 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\combase.dll | SUCCESS | |
| 1704 | 13:48:28.6136157 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1705 | 13:48:28.6136602 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1706 | 13:48:28.6136698 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\rpcrt4.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1707 | 13:48:28.6136777 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\rpcrt4.dll | SUCCESS | |
| 1708 | 13:48:28.6189603 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1709 | 13:48:28.6189920 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1710 | 13:48:28.6190007 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1711 | 13:48:28.6190193 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 1712 | 13:48:28.6193094 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1713 | 13:48:28.6193913 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1714 | 13:48:28.6194041 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1715 | 13:48:28.6194224 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 1716 | 13:48:28.6200416 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1717 | 13:48:28.6200739 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1718 | 13:48:28.6200819 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1719 | 13:48:28.6200891 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\bcryptprimitives.dll | SUCCESS | |
| 1720 | 13:48:28.6212853 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\clbcatq.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1721 | 13:48:28.6213403 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\clbcatq.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1722 | 13:48:28.6213520 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\clbcatq.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1723 | 13:48:28.6213599 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\clbcatq.dll | SUCCESS | |
| 1724 | 13:48:28.6218875 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 8’192, Length: 4’096, Priority: Normal |
| 1725 | 13:48:28.6219066 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 8’192, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1726 | 13:48:28.6245301 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 49’152, Length: 8’192, Priority: Normal |
| 1727 | 13:48:28.6245410 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 49’152, Length: 8’192, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1728 | 13:48:28.6250414 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 12’288, Length: 16’384, Priority: Normal |
| 1729 | 13:48:28.6250541 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 12’288, Length: 16’384, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1730 | 13:48:28.6256793 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 106’496, Length: 4’096, Priority: Normal |
| 1731 | 13:48:28.6256954 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 106’496, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1732 | 13:48:28.6300488 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\sechost.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1733 | 13:48:28.6300824 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1734 | 13:48:28.6300998 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\sechost.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1735 | 13:48:28.6301108 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\sechost.dll | SUCCESS | |
| 1736 | 13:48:28.6358922 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\user32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1737 | 13:48:28.6359349 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1738 | 13:48:28.6359469 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\user32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1739 | 13:48:28.6359549 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\user32.dll | SUCCESS | |
| 1740 | 13:48:28.6363891 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1741 | 13:48:28.6364245 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1742 | 13:48:28.6364335 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp_win.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1743 | 13:48:28.6364409 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp_win.dll | SUCCESS | |
| 1744 | 13:48:28.6366093 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\win32u.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1745 | 13:48:28.6366539 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1746 | 13:48:28.6366632 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\win32u.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1747 | 13:48:28.6366716 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\win32u.dll | SUCCESS | |
| 1748 | 13:48:28.6369623 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1749 | 13:48:28.6370018 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1750 | 13:48:28.6370107 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1751 | 13:48:28.6370179 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32.dll | SUCCESS | |
| 1752 | 13:48:28.6371212 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\gdi32full.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1753 | 13:48:28.6371417 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1754 | 13:48:28.6371494 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\gdi32full.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1755 | 13:48:28.6371563 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\gdi32full.dll | SUCCESS | |
| 1756 | 13:48:28.6413040 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\imm32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1757 | 13:48:28.6413435 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1758 | 13:48:28.6413543 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\imm32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1759 | 13:48:28.6413623 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\imm32.dll | SUCCESS | |
| 1760 | 13:48:28.6433909 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\uxtheme.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1761 | 13:48:28.6434593 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1762 | 13:48:28.6434799 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\uxtheme.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1763 | 13:48:28.6435026 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\uxtheme.dll | SUCCESS | |
| 1764 | 13:48:28.6563799 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\thumbcache.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1765 | 13:48:28.6564041 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\thumbcache.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1766 | 13:48:28.6564125 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\thumbcache.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1767 | 13:48:28.6564202 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\thumbcache.dll | SUCCESS | |
| 1768 | 13:48:28.6566489 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1769 | 13:48:28.6566744 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1770 | 13:48:28.6567824 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\thumbcache.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1771 | 13:48:28.6568138 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\thumbcache.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ |
| 1772 | 13:48:28.6568215 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\thumbcache.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176 |
| 1773 | 13:48:28.6568301 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\thumbcache.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᅾ |
| 1774 | 13:48:28.6568355 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\thumbcache.dll | BUFFER OVERFLOW | CreationTime: 30.09.2025 13:54:26, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 30.09.2025 13:54:26, ChangeTime: 01.10.2025 17:29:42, FileAttributes: A, AllocationSize: 249’856, EndOfFile: 460’176 |
| 1775 | 13:48:28.6568436 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\thumbcache.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1776 | 13:48:28.6568586 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\thumbcache.dll | SUCCESS | |
| 1777 | 13:48:28.6568792 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\thumbcache.dll | SUCCESS | |
| 1778 | 13:48:28.6625567 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\propsys.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1779 | 13:48:28.6626091 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\propsys.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1780 | 13:48:28.6626200 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\propsys.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1781 | 13:48:28.6626280 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\propsys.dll | SUCCESS | |
| 1782 | 13:48:28.6659004 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1783 | 13:48:28.6659286 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1784 | 13:48:28.6842378 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1785 | 13:48:28.6842833 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1786 | 13:48:28.6842958 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1787 | 13:48:28.6843267 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1788 | 13:48:28.6844439 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ntdll.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1789 | 13:48:28.6844901 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1790 | 13:48:28.6845007 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ntdll.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1791 | 13:48:28.6866075 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ntdll.dll | SUCCESS | |
| 1792 | 13:48:28.6898340 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1793 | 13:48:28.6898609 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1794 | 13:48:28.6909623 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1795 | 13:48:28.6909946 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1796 | 13:48:28.6910272 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1797 | 13:48:28.6910507 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 675’736, Length: 4’096 |
| 1798 | 13:48:28.6910773 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1799 | 13:48:28.6910890 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1800 | 13:48:28.6995947 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 77’824, Length: 8’192, Priority: Normal |
| 1801 | 13:48:28.6996076 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 77’824, Length: 4’096, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1802 | 13:48:28.7001719 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel32.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1803 | 13:48:28.7002146 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1804 | 13:48:28.7002287 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel32.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1805 | 13:48:28.7002369 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel32.dll | SUCCESS | |
| 1806 | 13:48:28.7003416 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\KernelBase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1807 | 13:48:28.7003644 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1808 | 13:48:28.7003721 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\KernelBase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1809 | 13:48:28.7003787 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\KernelBase.dll | SUCCESS | |
| 1810 | 13:48:28.7036676 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1811 | 13:48:28.7037841 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1812 | 13:48:28.7038049 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\ucrtbase.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1813 | 13:48:28.7038133 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\ucrtbase.dll | SUCCESS | |
| 1814 | 13:48:28.7075571 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp140.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1815 | 13:48:28.7076064 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp140.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1816 | 13:48:28.7076191 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp140.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1817 | 13:48:28.7076271 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp140.dll | SUCCESS | |
| 1818 | 13:48:28.7078366 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1819 | 13:48:28.7078541 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1820 | 13:48:28.7080516 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcp140.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1821 | 13:48:28.7080833 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcp140.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1822 | 13:48:28.7080951 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcp140.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728 |
| 1823 | 13:48:28.7081031 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\msvcp140.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1824 | 13:48:28.7081083 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\msvcp140.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:56, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:56, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 561’152, EndOfFile: 557’728 |
| 1825 | 13:48:28.7081175 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcp140.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1826 | 13:48:28.7081348 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\msvcp140.dll | SUCCESS | |
| 1827 | 13:48:28.7081504 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcp140.dll | SUCCESS | |
| 1828 | 13:48:28.7084358 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\vcruntime140.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1829 | 13:48:28.7084673 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1830 | 13:48:28.7084759 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1831 | 13:48:28.7084831 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\vcruntime140.dll | SUCCESS | |
| 1832 | 13:48:28.7086279 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1833 | 13:48:28.7086543 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1834 | 13:48:28.7089639 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\vcruntime140.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1835 | 13:48:28.7089869 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\vcruntime140.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1836 | 13:48:28.7090026 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\vcruntime140.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544 |
| 1837 | 13:48:28.7090163 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\vcruntime140.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1838 | 13:48:28.7090222 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\vcruntime140.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:04:34, FileAttributes: A, AllocationSize: 126’976, EndOfFile: 124’544 |
| 1839 | 13:48:28.7090296 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1840 | 13:48:28.7090383 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\vcruntime140.dll | SUCCESS | |
| 1841 | 13:48:28.7090514 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\vcruntime140.dll | SUCCESS | |
| 1842 | 13:48:28.7093326 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1843 | 13:48:28.7093662 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140_1.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1844 | 13:48:28.7093815 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1845 | 13:48:28.7093894 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | |
| 1846 | 13:48:28.7095300 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1847 | 13:48:28.7095431 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1848 | 13:48:28.7096549 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1849 | 13:48:28.7097119 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\vcruntime140_1.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1850 | 13:48:28.7097224 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\vcruntime140_1.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792 |
| 1851 | 13:48:28.7097395 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Windows\System32\vcruntime140_1.dll | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1852 | 13:48:28.7097472 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Windows\System32\vcruntime140_1.dll | BUFFER OVERFLOW | CreationTime: 11.06.2025 05:21:58, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 11.06.2025 05:21:58, ChangeTime: 12.08.2025 21:24:20, FileAttributes: A, AllocationSize: 53’248, EndOfFile: 49’792 |
| 1853 | 13:48:28.7097553 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1854 | 13:48:28.7097652 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | |
| 1855 | 13:48:28.7097785 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\vcruntime140_1.dll | SUCCESS | |
| 1856 | 13:48:28.7132480 | MsMpEng.exe | 3220 | Thread Create | SUCCESS | Thread ID: 7424 | |
| 1857 | 13:48:28.7136831 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1858 | 13:48:28.7137169 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | CreationTime: 10.10.2025 15:34:53, LastAccessTime: 13.10.2025 13:27:12, LastWriteTime: 13.10.2025 11:45:59, ChangeTime: 13.10.2025 11:45:59, FileAttributes: A |
| 1859 | 13:48:28.7137235 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | |
| 1860 | 13:48:28.7137960 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1861 | 13:48:28.7138149 | MsMpEng.exe | 3220 | CreateFileMapping | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | FILE LOCKED WITH ONLY READERS | SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE |
| 1862 | 13:48:28.7139295 | MsMpEng.exe | 3220 | QueryEAFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | |
| 1863 | 13:48:28.7139676 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | Offset: 46’080, Length: 12’288, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1864 | 13:48:28.7140155 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | Offset: 153’088, Length: 45’056, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1865 | 13:48:28.7146151 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1866 | 13:48:28.7146334 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A |
| 1867 | 13:48:28.7146598 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1868 | 13:48:28.7149542 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1869 | 13:48:28.7149905 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1870 | 13:48:28.7149994 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1871 | 13:48:28.7150074 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1872 | 13:48:28.7150132 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1873 | 13:48:28.7150305 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1874 | 13:48:28.7150408 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1875 | 13:48:28.7150544 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1876 | 13:48:28.7151310 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1877 | 13:48:28.7151659 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1878 | 13:48:28.7151768 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1879 | 13:48:28.7151861 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1880 | 13:48:28.7151914 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1881 | 13:48:28.7151998 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1882 | 13:48:28.7152173 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1883 | 13:48:28.7152292 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1884 | 13:48:28.7153061 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1885 | 13:48:28.7153490 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1886 | 13:48:28.7153616 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1887 | 13:48:28.7153696 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 1888 | 13:48:28.7153752 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1889 | 13:48:28.7153961 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1890 | 13:48:28.7154069 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1891 | 13:48:28.7154236 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1892 | 13:48:28.7155815 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1893 | 13:48:28.7156119 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1894 | 13:48:28.7156222 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1895 | 13:48:28.7156390 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | AllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 1896 | 13:48:28.7156578 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | INVALID DEVICE REQUEST | Control: 0x90390 (Device:0x9 Function:228 Method: 0) |
| 1897 | 13:48:28.7156678 | MsMpEng.exe | 3220 | QueryAttributeInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS |
| 1898 | 13:48:28.7161664 | MsMpEng.exe | 3220 | QueryEAFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | |
| 1899 | 13:48:28.7163940 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1900 | 13:48:28.7164226 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 1901 | 13:48:28.7164830 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1902 | 13:48:28.7165135 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1903 | 13:48:28.7165240 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | BUFFER OVERFLOW | CreationTime: 12.10.2025 21:49:19, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 13.10.2025 11:46:00, ChangeTime: 13.10.2025 11:46:00, FileAttributes: A, AllocationSize: 32’768, EndOfFile: 29’184 |
| 1904 | 13:48:28.7165336 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1905 | 13:48:28.7165420 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1906 | 13:48:28.7166074 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\HookTester.exe | SUCCESS | |
| 1907 | 13:48:28.7193027 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄩ |
| 1908 | 13:48:28.7193162 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 1909 | 13:48:28.7193270 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 1910 | 13:48:28.7194074 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1911 | 13:48:28.7194339 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 222’536, Length: 4’096 |
| 1912 | 13:48:28.7194587 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 86’576, Length: 4’096 |
| 1913 | 13:48:28.7194836 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 700’456, Length: 4’096 |
| 1914 | 13:48:28.7195263 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1915 | 13:48:28.7196113 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 28’672, Length: 350’208, Priority: Normal |
| 1916 | 13:48:28.7196377 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 28’672, Length: 344’064, I/O Flags: Non-cached, Paging I/O, Priority: Normal |
| 1917 | 13:48:28.7205235 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Setup | SUCCESS | Desired Access: Read |
| 1918 | 13:48:28.7205392 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\MinimizeFootprint | NAME NOT FOUND | Length: 20 |
| 1919 | 13:48:28.7205696 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup | SUCCESS | |
| 1920 | 13:48:28.7205905 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | INVALID DEVICE REQUEST | Control: 0x90390 (Device:0x9 Function:228 Method: 0) |
| 1921 | 13:48:28.7206014 | MsMpEng.exe | 3220 | QueryAttributeInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS |
| 1922 | 13:48:28.7212630 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | AllocationSize: 241’664, EndOfFile: 240’128, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 1923 | 13:48:28.7213481 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | INVALID DEVICE REQUEST | Control: 0x90390 (Device:0x9 Function:228 Method: 0) |
| 1924 | 13:48:28.7213990 | MsMpEng.exe | 3220 | QueryAttributeInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS |
| 1925 | 13:48:28.7218911 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1926 | 13:48:28.7218980 | MsMpEng.exe | 3220 | QueryEAFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | |
| 1927 | 13:48:28.7230054 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | INVALID DEVICE REQUEST | Control: 0x90390 (Device:0x9 Function:228 Method: 0) |
| 1928 | 13:48:28.7230162 | MsMpEng.exe | 3220 | QueryAttributeInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS |
| 1929 | 13:48:28.7238717 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\EDRHooker.dll | SUCCESS | |
| 1930 | 13:48:28.7239752 | MsMpEng.exe | 3220 | Thread Exit | SUCCESS | Thread ID: 7424, User Time: 0.0000000, Kernel Time: 0.0000000 | |
| 1931 | 13:48:28.7241532 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1932 | 13:48:28.7241967 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D |
| 1933 | 13:48:28.7242057 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1934 | 13:48:28.7243988 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1935 | 13:48:28.7244757 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI |
| 1936 | 13:48:28.7244921 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1937 | 13:48:28.7247909 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1938 | 13:48:28.7248278 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2\{????????????????????????????????????} | SUCCESS | FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE} |
| 1939 | 13:48:28.7250488 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1940 | 13:48:28.7252960 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1941 | 13:48:28.7253216 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1942 | 13:48:28.7253306 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1943 | 13:48:28.7254538 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1944 | 13:48:28.7258632 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1945 | 13:48:28.7258887 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1946 | 13:48:28.7258979 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1947 | 13:48:28.7259076 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1948 | 13:48:28.7259496 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1949 | 13:48:28.7259638 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\kernel.appcore.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1950 | 13:48:28.7259728 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\kernel.appcore.dll | SUCCESS | |
| 1951 | 13:48:28.7260887 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\msvcrt.dll | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Non-Directory File, Open For Backup, Open Reparse Point, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1952 | 13:48:28.7261202 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 1953 | 13:48:28.7261376 | MsMpEng.exe | 3220 | FileSystemControl | C:\Windows\System32\msvcrt.dll | SUCCESS | Control: 0x902eb (Device:0x9 Function:186 Method: 3) |
| 1954 | 13:48:28.7261461 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\msvcrt.dll | SUCCESS | |
| 1955 | 13:48:28.7266267 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | SUCCESS | FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE} |
| 1956 | 13:48:28.7267873 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1957 | 13:48:28.7268679 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1958 | 13:48:28.7268898 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1959 | 13:48:28.7268982 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1960 | 13:48:28.7270382 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1961 | 13:48:28.7272135 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1962 | 13:48:28.7272541 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1963 | 13:48:28.7272669 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1964 | 13:48:28.7281850 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | NO MORE FILES | FileInformationClass: FileBothDirectoryInformation |
| 1965 | 13:48:28.7282154 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1966 | 13:48:28.7283620 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1967 | 13:48:28.7283798 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 09:26:07, LastAccessTime: 13.08.2025 20:52:27, LastWriteTime: 01.04.2024 09:26:07, ChangeTime: 12.08.2025 21:35:30, FileAttributes: D |
| 1968 | 13:48:28.7283967 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1969 | 13:48:28.7285158 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1970 | 13:48:28.7285332 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | CreationTime: 01.04.2024 18:17:28, LastAccessTime: 13.10.2025 13:32:53, LastWriteTime: 12.08.2025 20:38:19, ChangeTime: 12.08.2025 20:38:19, FileAttributes: DNCI |
| 1971 | 13:48:28.7285405 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | SUCCESS | |
| 1972 | 13:48:28.7286659 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1973 | 13:48:28.7287031 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2\{????????????????????????????????????} | SUCCESS | FileInformationClass: FileBothDirectoryInformation, Filter: {????????????????????????????????????}, 2: {127D0A1D-4EF2-11D1-8608-00C04FC295EE} |
| 1974 | 13:48:28.7288092 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1975 | 13:48:28.7289418 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1976 | 13:48:28.7289649 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1977 | 13:48:28.7289830 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1978 | 13:48:28.7290740 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1979 | 13:48:28.7294544 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1980 | 13:48:28.7294795 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1981 | 13:48:28.7295194 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1982 | 13:48:28.7297893 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | SUCCESS | FileInformationClass: FileBothDirectoryInformation, 1: {F750E6C3-38EE-11D1-85E5-00C04FC295EE} |
| 1983 | 13:48:28.7299503 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1984 | 13:48:28.7300319 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\CatRoot | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1985 | 13:48:28.7300500 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\CatRoot | SUCCESS | Information: DACL |
| 1986 | 13:48:28.7300712 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\CatRoot | SUCCESS | |
| 1987 | 13:48:28.7302044 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | NAME COLLISION | Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0 |
| 1988 | 13:48:28.7303356 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\catroot2 | SUCCESS | Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 1989 | 13:48:28.7303686 | MsMpEng.exe | 3220 | QuerySecurityFile | C:\Windows\System32\catroot2 | SUCCESS | Information: DACL |
| 1990 | 13:48:28.7303775 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1991 | 13:48:28.7315119 | MsMpEng.exe | 3220 | QueryDirectory | C:\Windows\System32\catroot2 | NO MORE FILES | FileInformationClass: FileBothDirectoryInformation |
| 1992 | 13:48:28.7315303 | MsMpEng.exe | 3220 | CloseFile | C:\Windows\System32\catroot2 | SUCCESS | |
| 1993 | 13:48:28.7316001 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 1994 | 13:48:28.7317051 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1995 | 13:48:28.7317283 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 45’376, Length: 4’096 |
| 1996 | 13:48:28.7317708 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 1997 | 13:48:28.7318043 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 1998 | 13:48:28.7318144 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 181’336, Length: 4’096 |
| 1999 | 13:48:28.7318359 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 2000 | 13:48:28.7318589 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 2001 | 13:48:28.7318657 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: True, Offset: 120, Length: 1, Fail Immediately: True |
| 2002 | 13:48:28.7319331 | MsMpEng.exe | 3220 | WriteFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 856’992, Length: 24 |
| 2003 | 13:48:28.7319481 | MsMpEng.exe | 3220 | WriteFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 857’016, Length: 4’096 |
| 2004 | 13:48:28.7319793 | MsMpEng.exe | 3220 | WriteFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 861’112, Length: 24 |
| 2005 | 13:48:28.7319887 | MsMpEng.exe | 3220 | WriteFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 861’136, Length: 4’096 |
| 2006 | 13:48:28.7320071 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 120, Length: 1 |
| 2007 | 13:48:28.7320148 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 2008 | 13:48:28.7323135 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2009 | 13:48:28.7323495 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2010 | 13:48:28.7351906 | MsMpEng.exe | 3220 | QueryStreamInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2011 | 13:48:28.7352136 | MsMpEng.exe | 3220 | QueryEAFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | NO EAS ON FILE | |
| 2012 | 13:48:28.7357756 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2013 | 13:48:28.7357981 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2014 | 13:48:28.7359235 | MsMpEng.exe | 3220 | RegCloseKey | HKU\.DEFAULT | SUCCESS | |
| 2015 | 13:48:28.7360628 | MsMpEng.exe | 3220 | CreateFile | C:\Windows\System32\drivers\SET9BED.tmp | NAME NOT FOUND | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 2016 | 13:48:28.7361289 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2017 | 13:48:28.7361395 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\hivelist | REPARSE | Desired Access: Read |
| 2018 | 13:48:28.7361504 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Desired Access: Read |
| 2019 | 13:48:28.7361645 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Query: Cached, SubKeys: 0, Values: 35 |
| 2020 | 13:48:28.7361817 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 0, Type: REG_SZ |
| 2021 | 13:48:28.7361917 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE | SUCCESS | Type: REG_SZ, Length: 2, Data: |
| 2022 | 13:48:28.7362029 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 1, Type: REG_SZ |
| 2023 | 13:48:28.7362091 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE | SUCCESS | Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE |
| 2024 | 13:48:28.7362173 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 2, Type: REG_SZ |
| 2025 | 13:48:28.7362226 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM | SUCCESS | Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM |
| 2026 | 13:48:28.7362296 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 3, Type: REG_SZ |
| 2027 | 13:48:28.7362428 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000 | SUCCESS | Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD |
| 2028 | 13:48:28.7362550 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 4, Type: REG_SZ |
| 2029 | 13:48:28.7362607 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT | SUCCESS | Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT |
| 2030 | 13:48:28.7362782 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 5, Type: REG_SZ |
| 2031 | 13:48:28.7362838 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY | SUCCESS | Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY |
| 2032 | 13:48:28.7362914 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 6, Type: REG_SZ |
| 2033 | 13:48:28.7363063 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM | SUCCESS | Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM |
| 2034 | 13:48:28.7363142 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 7, Type: REG_SZ |
| 2035 | 13:48:28.7363197 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20 | BUFFER OVERFLOW | Length: 144 |
| 2036 | 13:48:28.7363437 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20 | SUCCESS | Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT |
| 2037 | 13:48:28.7363651 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 8, Type: REG_SZ |
| 2038 | 13:48:28.7363736 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19 | BUFFER OVERFLOW | Length: 144 |
| 2039 | 13:48:28.7363808 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19 | SUCCESS | Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT |
| 2040 | 13:48:28.7363907 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 9, Type: REG_SZ |
| 2041 | 13:48:28.7363969 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000 | SUCCESS | Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT |
| 2042 | 13:48:28.7364096 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2043 | 13:48:28.7364235 | MsMpEng.exe | 3220 | RegOpenKey | HKCU | SUCCESS | Desired Access: Read |
| 2044 | 13:48:28.7364379 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | |
| 2045 | 13:48:28.7364664 | MsMpEng.exe | 3220 | RegQueryKey | HKCU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2046 | 13:48:28.7364866 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Desired Access: Read |
| 2047 | 13:48:28.7365361 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData | SUCCESS | Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local |
| 2048 | 13:48:28.7365535 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | |
| 2049 | 13:48:28.7365765 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2050 | 13:48:28.7365866 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\hivelist | REPARSE | Desired Access: Read |
| 2051 | 13:48:28.7365964 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Desired Access: Read |
| 2052 | 13:48:28.7366071 | MsMpEng.exe | 3220 | RegQueryKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Query: Cached, SubKeys: 0, Values: 35 |
| 2053 | 13:48:28.7366182 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 0, Type: REG_SZ |
| 2054 | 13:48:28.7366435 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\HARDWARE | SUCCESS | Type: REG_SZ, Length: 2, Data: |
| 2055 | 13:48:28.7366549 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 1, Type: REG_SZ |
| 2056 | 13:48:28.7366675 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SOFTWARE | SUCCESS | Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SOFTWARE |
| 2057 | 13:48:28.7366792 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 2, Type: REG_SZ |
| 2058 | 13:48:28.7366858 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SYSTEM | SUCCESS | Type: REG_SZ, Length: 112, Data: \Device\HarddiskVolume4\Windows\System32\config\SYSTEM |
| 2059 | 13:48:28.7366926 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 3, Type: REG_SZ |
| 2060 | 13:48:28.7367133 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\BCD00000000 | SUCCESS | Type: REG_SZ, Length: 96, Data: \Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD |
| 2061 | 13:48:28.7367285 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 4, Type: REG_SZ |
| 2062 | 13:48:28.7367630 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\.DEFAULT | SUCCESS | Type: REG_SZ, Length: 114, Data: \Device\HarddiskVolume4\Windows\System32\config\DEFAULT |
| 2063 | 13:48:28.7368103 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 5, Type: REG_SZ |
| 2064 | 13:48:28.7368282 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SECURITY | SUCCESS | Type: REG_SZ, Length: 116, Data: \Device\HarddiskVolume4\Windows\System32\config\SECURITY |
| 2065 | 13:48:28.7368407 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 6, Type: REG_SZ |
| 2066 | 13:48:28.7368468 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\MACHINE\SAM | SUCCESS | Type: REG_SZ, Length: 106, Data: \Device\HarddiskVolume4\Windows\System32\config\SAM |
| 2067 | 13:48:28.7368549 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 7, Type: REG_SZ |
| 2068 | 13:48:28.7368603 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20 | BUFFER OVERFLOW | Length: 144 |
| 2069 | 13:48:28.7368747 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-20 | SUCCESS | Type: REG_SZ, Length: 150, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\NetworkService\NTUSER.DAT |
| 2070 | 13:48:28.7368898 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 8, Type: REG_SZ |
| 2071 | 13:48:28.7368959 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19 | BUFFER OVERFLOW | Length: 144 |
| 2072 | 13:48:28.7369027 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-19 | SUCCESS | Type: REG_SZ, Length: 146, Data: \Device\HarddiskVolume4\Windows\ServiceProfiles\LocalService\NTUSER.DAT |
| 2073 | 13:48:28.7369121 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 9, Type: REG_SZ |
| 2074 | 13:48:28.7369183 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000 | SUCCESS | Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT |
| 2075 | 13:48:28.7369276 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | BUFFER OVERFLOW | Index: 10, Length: 144 |
| 2076 | 13:48:28.7369408 | MsMpEng.exe | 3220 | RegEnumValue | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Index: 10, Type: REG_SZ |
| 2077 | 13:48:28.7370464 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes | BUFFER OVERFLOW | Length: 144 |
| 2078 | 13:48:28.7370642 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes | SUCCESS | Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat |
| 2079 | 13:48:28.7370973 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2080 | 13:48:28.7371065 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Software\Classes | SUCCESS | Desired Access: Read |
| 2081 | 13:48:28.7371213 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | |
| 2082 | 13:48:28.7371423 | MsMpEng.exe | 3220 | RegQueryKey | HKCU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2083 | 13:48:28.7371523 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Environment | SUCCESS | Desired Access: Read |
| 2084 | 13:48:28.7371638 | MsMpEng.exe | 3220 | RegQueryKey | HKCU\Environment | SUCCESS | Query: Cached, SubKeys: 0, Values: 4 |
| 2085 | 13:48:28.7371713 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Environment | SUCCESS | Index: 0, Type: REG_EXPAND_SZ |
| 2086 | 13:48:28.7371785 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Environment\Path | BUFFER OVERFLOW | Length: 144 |
| 2087 | 13:48:28.7371873 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Environment\Path | SUCCESS | Type: REG_EXPAND_SZ, Length: 156, Data: |
| 2088 | 13:48:28.7372078 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Environment | SUCCESS | Index: 1, Type: REG_EXPAND_SZ |
| 2089 | 13:48:28.7372155 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Environment\TEMP | SUCCESS | Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp |
| 2090 | 13:48:28.7372286 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Environment | SUCCESS | Index: 2, Type: REG_EXPAND_SZ |
| 2091 | 13:48:28.7372340 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Environment\TMP | SUCCESS | Type: REG_EXPAND_SZ, Length: 66, Data: %USERPROFILE%\AppData\Local\Temp |
| 2092 | 13:48:28.7372429 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Environment | SUCCESS | Index: 3, Type: REG_EXPAND_SZ |
| 2093 | 13:48:28.7372484 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Environment\OneDrive | SUCCESS | Type: REG_EXPAND_SZ, Length: 50, Data: C:\Users\hacker\OneDrive |
| 2094 | 13:48:28.7372658 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Environment | SUCCESS | |
| 2095 | 13:48:28.7372761 | MsMpEng.exe | 3220 | RegQueryKey | HKCU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2096 | 13:48:28.7372831 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Volatile Environment | SUCCESS | Desired Access: Read |
| 2097 | 13:48:28.7372942 | MsMpEng.exe | 3220 | RegQueryKey | HKCU\Volatile Environment | SUCCESS | Query: Cached, SubKeys: 1, Values: 9 |
| 2098 | 13:48:28.7373007 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 0, Type: REG_SZ |
| 2099 | 13:48:28.7373073 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\LOGONSERVER | SUCCESS | Type: REG_SZ, Length: 24, Data: \\WINDOWS11 |
| 2100 | 13:48:28.7373233 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 1, Type: REG_SZ |
| 2101 | 13:48:28.7373304 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\USERDOMAIN | SUCCESS | Type: REG_SZ, Length: 20, Data: WINDOWS11 |
| 2102 | 13:48:28.7373403 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 2, Type: REG_SZ |
| 2103 | 13:48:28.7373459 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\USERNAME | SUCCESS | Type: REG_SZ, Length: 14, Data: hacker |
| 2104 | 13:48:28.7373543 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 3, Type: REG_SZ |
| 2105 | 13:48:28.7373596 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\USERPROFILE | SUCCESS | Type: REG_SZ, Length: 32, Data: C:\Users\hacker |
| 2106 | 13:48:28.7373675 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 4, Type: REG_SZ |
| 2107 | 13:48:28.7373729 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\HOMEPATH | SUCCESS | Type: REG_SZ, Length: 28, Data: \Users\hacker |
| 2108 | 13:48:28.7373876 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 5, Type: REG_SZ |
| 2109 | 13:48:28.7373954 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\HOMEDRIVE | SUCCESS | Type: REG_SZ, Length: 6, Data: C: |
| 2110 | 13:48:28.7374048 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 6, Type: REG_SZ |
| 2111 | 13:48:28.7374602 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\APPDATA | SUCCESS | Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming |
| 2112 | 13:48:28.7374867 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 7, Type: REG_SZ |
| 2113 | 13:48:28.7374960 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\LOCALAPPDATA | SUCCESS | Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local |
| 2114 | 13:48:28.7375067 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Volatile Environment | SUCCESS | Index: 8, Type: REG_SZ |
| 2115 | 13:48:28.7375128 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Volatile Environment\USERDOMAIN_ROAMINGPROFILE | SUCCESS | Type: REG_SZ, Length: 20, Data: WINDOWS11 |
| 2116 | 13:48:28.7375255 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Volatile Environment | SUCCESS | |
| 2117 | 13:48:28.7375356 | MsMpEng.exe | 3220 | RegQueryKey | HKCU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2118 | 13:48:28.7375514 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Desired Access: Read |
| 2119 | 13:48:28.7375801 | MsMpEng.exe | 3220 | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Query: Cached, SubKeys: 0, Values: 31 |
| 2120 | 13:48:28.7375873 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 0, Type: REG_SZ |
| 2121 | 13:48:28.7375941 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\!Do not use this registry key | SUCCESS | Type: REG_SZ, Length: 130, Data: Use the SHGetFolderPath or SHGetKnownFolderPath function instead |
| 2122 | 13:48:28.7376117 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 1, Type: REG_SZ |
| 2123 | 13:48:28.7376185 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData | SUCCESS | Type: REG_SZ, Length: 64, Data: C:\Users\hacker\AppData\Roaming |
| 2124 | 13:48:28.7376286 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 2, Type: REG_SZ |
| 2125 | 13:48:28.7376346 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Local AppData | SUCCESS | Type: REG_SZ, Length: 60, Data: C:\Users\hacker\AppData\Local |
| 2126 | 13:48:28.7376426 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 3, Type: REG_SZ |
| 2127 | 13:48:28.7376482 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CD Burning | SUCCESS | Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\Burn\Burn |
| 2128 | 13:48:28.7376562 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 4, Type: REG_SZ |
| 2129 | 13:48:28.7376682 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} | SUCCESS | Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Libraries |
| 2130 | 13:48:28.7376787 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 5, Type: REG_SZ |
| 2131 | 13:48:28.7376842 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Video | SUCCESS | Type: REG_SZ, Length: 46, Data: C:\Users\hacker\Videos |
| 2132 | 13:48:28.7376922 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 6, Type: REG_SZ |
| 2133 | 13:48:28.7376975 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Pictures | SUCCESS | Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Pictures |
| 2134 | 13:48:28.7377062 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 7, Type: REG_SZ |
| 2135 | 13:48:28.7377114 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop | SUCCESS | Type: REG_SZ, Length: 48, Data: C:\Users\hacker\Desktop |
| 2136 | 13:48:28.7377189 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 8, Type: REG_SZ |
| 2137 | 13:48:28.7377296 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History | SUCCESS | Type: REG_SZ, Length: 112, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\History |
| 2138 | 13:48:28.7377399 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 9, Type: REG_SZ |
| 2139 | 13:48:28.7377453 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood | BUFFER OVERFLOW | Length: 144 |
| 2140 | 13:48:28.7377519 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\NetHood | SUCCESS | Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Network Shortcuts |
| 2141 | 13:48:28.7377597 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 10, Type: REG_SZ |
| 2142 | 13:48:28.7377654 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882} | SUCCESS | Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Contacts |
| 2143 | 13:48:28.7377739 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 11, Type: REG_SZ |
| 2144 | 13:48:28.7377795 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{00BCFC5A-ED94-4E48-96A1-3F6217F21990} | SUCCESS | Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\RoamingTiles |
| 2145 | 13:48:28.7377938 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 12, Type: REG_SZ |
| 2146 | 13:48:28.7378002 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies | SUCCESS | Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCookies |
| 2147 | 13:48:28.7378085 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 13, Type: REG_SZ |
| 2148 | 13:48:28.7378138 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Favorites | SUCCESS | Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Favorites |
| 2149 | 13:48:28.7378216 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 14, Type: REG_SZ |
| 2150 | 13:48:28.7378268 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\SendTo | SUCCESS | Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\SendTo |
| 2151 | 13:48:28.7378341 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 15, Type: REG_SZ |
| 2152 | 13:48:28.7378394 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu | SUCCESS | Type: REG_SZ, Length: 122, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu |
| 2153 | 13:48:28.7378543 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 16, Type: REG_SZ |
| 2154 | 13:48:28.7378605 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Music | SUCCESS | Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Music |
| 2155 | 13:48:28.7378687 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 17, Type: REG_SZ |
| 2156 | 13:48:28.7378739 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs | BUFFER OVERFLOW | Length: 144 |
| 2157 | 13:48:28.7378805 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Programs | SUCCESS | Type: REG_SZ, Length: 140, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs |
| 2158 | 13:48:28.7378882 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 18, Type: REG_SZ |
| 2159 | 13:48:28.7378936 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Recent | SUCCESS | Type: REG_SZ, Length: 114, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Recent |
| 2160 | 13:48:28.7379012 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 19, Type: REG_SZ |
| 2161 | 13:48:28.7379117 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood | BUFFER OVERFLOW | Length: 144 |
| 2162 | 13:48:28.7379201 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\PrintHood | SUCCESS | Type: REG_SZ, Length: 136, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Printer Shortcuts |
| 2163 | 13:48:28.7379285 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 20, Type: REG_SZ |
| 2164 | 13:48:28.7379342 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA} | SUCCESS | Type: REG_SZ, Length: 50, Data: C:\Users\hacker\Searches |
| 2165 | 13:48:28.7379433 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 21, Type: REG_SZ |
| 2166 | 13:48:28.7379487 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{374DE290-123F-4565-9164-39C4925E467B} | SUCCESS | Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Downloads |
| 2167 | 13:48:28.7379572 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 22, Type: REG_SZ |
| 2168 | 13:48:28.7379625 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{A520A1A4-1780-4FF6-BD18-167343C5AF16} | SUCCESS | Type: REG_SZ, Length: 66, Data: C:\Users\hacker\AppData\LocalLow |
| 2169 | 13:48:28.7379771 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 23, Type: REG_SZ |
| 2170 | 13:48:28.7379832 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup | BUFFER OVERFLOW | Length: 144 |
| 2171 | 13:48:28.7379912 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup | SUCCESS | Type: REG_SZ, Length: 156, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
| 2172 | 13:48:28.7379995 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 24, Type: REG_SZ |
| 2173 | 13:48:28.7380049 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools | BUFFER OVERFLOW | Length: 144 |
| 2174 | 13:48:28.7380114 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Administrative Tools | SUCCESS | Type: REG_SZ, Length: 182, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools |
| 2175 | 13:48:28.7380196 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 25, Type: REG_SZ |
| 2176 | 13:48:28.7380250 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal | SUCCESS | Type: REG_SZ, Length: 52, Data: C:\Users\hacker\Documents |
| 2177 | 13:48:28.7380396 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 26, Type: REG_SZ |
| 2178 | 13:48:28.7380457 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968} | SUCCESS | Type: REG_SZ, Length: 44, Data: C:\Users\hacker\Links |
| 2179 | 13:48:28.7380544 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 27, Type: REG_SZ |
| 2180 | 13:48:28.7380596 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache | SUCCESS | Type: REG_SZ, Length: 116, Data: C:\Users\hacker\AppData\Local\Microsoft\Windows\INetCache |
| 2181 | 13:48:28.7380692 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 28, Type: REG_SZ |
| 2182 | 13:48:28.7380745 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Templates | SUCCESS | Type: REG_SZ, Length: 120, Data: C:\Users\hacker\AppData\Roaming\Microsoft\Windows\Templates |
| 2183 | 13:48:28.7380821 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 29, Type: REG_SZ |
| 2184 | 13:48:28.7380931 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4} | SUCCESS | Type: REG_SZ, Length: 56, Data: C:\Users\hacker\Saved Games |
| 2185 | 13:48:28.7381039 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | Index: 30, Type: REG_SZ |
| 2186 | 13:48:28.7381096 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Fonts | SUCCESS | Type: REG_SZ, Length: 34, Data: C:\WINDOWS\Fonts |
| 2187 | 13:48:28.7381198 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | SUCCESS | |
| 2188 | 13:48:28.7381281 | MsMpEng.exe | 3220 | RegQueryKey | HKCU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2189 | 13:48:28.7381357 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Desired Access: Read |
| 2190 | 13:48:28.7381460 | MsMpEng.exe | 3220 | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Query: Cached, SubKeys: 0, Values: 20 |
| 2191 | 13:48:28.7381591 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 0, Type: REG_EXPAND_SZ |
| 2192 | 13:48:28.7381665 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData | SUCCESS | Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming |
| 2193 | 13:48:28.7381763 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 1, Type: REG_EXPAND_SZ |
| 2194 | 13:48:28.7381819 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache | SUCCESS | Type: REG_EXPAND_SZ, Length: 112, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache |
| 2195 | 13:48:28.7382524 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 2, Type: REG_EXPAND_SZ |
| 2196 | 13:48:28.7382629 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies | SUCCESS | Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies |
| 2197 | 13:48:28.7382839 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 3, Type: REG_EXPAND_SZ |
| 2198 | 13:48:28.7382909 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop | SUCCESS | Type: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop |
| 2199 | 13:48:28.7383003 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 4, Type: REG_EXPAND_SZ |
| 2200 | 13:48:28.7383057 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites | SUCCESS | Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Favorites |
| 2201 | 13:48:28.7383137 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 5, Type: REG_EXPAND_SZ |
| 2202 | 13:48:28.7383190 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\History | SUCCESS | Type: REG_EXPAND_SZ, Length: 108, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\History |
| 2203 | 13:48:28.7383272 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 6, Type: REG_EXPAND_SZ |
| 2204 | 13:48:28.7383395 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData | SUCCESS | Type: REG_EXPAND_SZ, Length: 56, Data: %USERPROFILE%\AppData\Local |
| 2205 | 13:48:28.7383514 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 7, Type: REG_EXPAND_SZ |
| 2206 | 13:48:28.7383579 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music | SUCCESS | Type: REG_EXPAND_SZ, Length: 40, Data: %USERPROFILE%\Music |
| 2207 | 13:48:28.7383658 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 8, Type: REG_EXPAND_SZ |
| 2208 | 13:48:28.7383712 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures | SUCCESS | Type: REG_EXPAND_SZ, Length: 46, Data: %USERPROFILE%\Pictures |
| 2209 | 13:48:28.7383789 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 9, Type: REG_EXPAND_SZ |
| 2210 | 13:48:28.7383841 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video | SUCCESS | Type: REG_EXPAND_SZ, Length: 42, Data: %USERPROFILE%\Videos |
| 2211 | 13:48:28.7384017 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 10, Type: REG_EXPAND_SZ |
| 2212 | 13:48:28.7384099 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\NetHood | SUCCESS | Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts |
| 2213 | 13:48:28.7384197 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 11, Type: REG_EXPAND_SZ |
| 2214 | 13:48:28.7384259 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal | SUCCESS | Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Documents |
| 2215 | 13:48:28.7384359 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 12, Type: REG_EXPAND_SZ |
| 2216 | 13:48:28.7384416 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\PrintHood | SUCCESS | Type: REG_EXPAND_SZ, Length: 132, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts |
| 2217 | 13:48:28.7384642 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 13, Type: REG_EXPAND_SZ |
| 2218 | 13:48:28.7384819 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs | BUFFER OVERFLOW | Length: 144 |
| 2219 | 13:48:28.7384906 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs | SUCCESS | Type: REG_EXPAND_SZ, Length: 136, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs |
| 2220 | 13:48:28.7384996 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 14, Type: REG_EXPAND_SZ |
| 2221 | 13:48:28.7385051 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Recent | SUCCESS | Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent |
| 2222 | 13:48:28.7385153 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 15, Type: REG_EXPAND_SZ |
| 2223 | 13:48:28.7385290 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\SendTo | SUCCESS | Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo |
| 2224 | 13:48:28.7385503 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 16, Type: REG_EXPAND_SZ |
| 2225 | 13:48:28.7385676 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Start Menu | SUCCESS | Type: REG_EXPAND_SZ, Length: 118, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu |
| 2226 | 13:48:28.7385903 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 17, Type: REG_EXPAND_SZ |
| 2227 | 13:48:28.7385996 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup | BUFFER OVERFLOW | Length: 144 |
| 2228 | 13:48:28.7386083 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup | SUCCESS | Type: REG_EXPAND_SZ, Length: 152, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
| 2229 | 13:48:28.7386167 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 18, Type: REG_EXPAND_SZ |
| 2230 | 13:48:28.7386223 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Templates | SUCCESS | Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates |
| 2231 | 13:48:28.7386305 | MsMpEng.exe | 3220 | RegEnumValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | Index: 19, Type: REG_EXPAND_SZ |
| 2232 | 13:48:28.7386527 | MsMpEng.exe | 3220 | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B} | SUCCESS | Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Downloads |
| 2233 | 13:48:28.7386664 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SUCCESS | |
| 2234 | 13:48:28.7386807 | MsMpEng.exe | 3220 | RegCloseKey | HKCU | SUCCESS | |
| 2235 | 13:48:28.7387061 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Software\Classes | SUCCESS | |
| 2236 | 13:48:28.7387344 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2237 | 13:48:28.7387561 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\hivelist | REPARSE | Desired Access: Read |
| 2238 | 13:48:28.7387762 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Desired Access: Read |
| 2239 | 13:48:28.7387889 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000 | SUCCESS | Type: REG_SZ, Length: 98, Data: \Device\HarddiskVolume4\Users\hacker\NTUSER.DAT |
| 2240 | 13:48:28.7388415 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2241 | 13:48:28.7388895 | MsMpEng.exe | 3220 | RegOpenKey | HKCU | SUCCESS | Desired Access: Read |
| 2242 | 13:48:28.7389065 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | |
| 2243 | 13:48:28.7389145 | MsMpEng.exe | 3220 | RegQueryKey | HKLM | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2244 | 13:48:28.7389211 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\hivelist | REPARSE | Desired Access: Read |
| 2245 | 13:48:28.7389293 | MsMpEng.exe | 3220 | RegOpenKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | Desired Access: Read |
| 2246 | 13:48:28.7389381 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes | BUFFER OVERFLOW | Length: 144 |
| 2247 | 13:48:28.7389843 | MsMpEng.exe | 3220 | RegQueryValue | HKLM\System\CurrentControlSet\Control\hivelist\\REGISTRY\USER\S-1-5-21-4172013786-3171869251-2938521833-1000_Classes | SUCCESS | Type: REG_SZ, Length: 166, Data: \Device\HarddiskVolume4\Users\hacker\AppData\Local\Microsoft\Windows\UsrClass.dat |
| 2248 | 13:48:28.7390375 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2249 | 13:48:28.7390918 | MsMpEng.exe | 3220 | RegOpenKey | HKCU\Software\Classes | SUCCESS | Desired Access: Read |
| 2250 | 13:48:28.7391128 | MsMpEng.exe | 3220 | RegCloseKey | HKLM\System\CurrentControlSet\Control\hivelist | SUCCESS | |
| 2251 | 13:48:28.7393535 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Data/List Directory, Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Open For Backup, Open Requiring Oplock, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2252 | 13:48:28.7393842 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | OPLOCK HANDLE CLOSED | Control: FSCTL_REQUEST_OPLOCK |
| 2253 | 13:48:28.7394502 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2254 | 13:48:28.7394850 | MsMpEng.exe | 3220 | QueryBasicInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A |
| 2255 | 13:48:28.7394935 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 0, Length: 512, Priority: Normal |
| 2256 | 13:48:28.7395081 | MsMpEng.exe | 3220 | QueryStandardInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | AllocationSize: 380’928, EndOfFile: 378’880, NumberOfLinks: 1, DeletePending: False, Directory: False |
| 2257 | 13:48:28.7395335 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 0, Length: 64, Priority: Normal |
| 2258 | 13:48:28.7395904 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 272, Length: 28, Priority: Normal |
| 2259 | 13:48:28.7396358 | MsMpEng.exe | 3220 | ReadFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Offset: 0, Length: 4’096, Priority: Normal |
| 2260 | 13:48:28.7397768 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2261 | 13:48:28.7398065 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2262 | 13:48:28.7399169 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2263 | 13:48:28.7399524 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2264 | 13:48:28.7400261 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2265 | 13:48:28.7400669 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2266 | 13:48:28.7400735 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2267 | 13:48:28.7401629 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | NOT A DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a |
| 2268 | 13:48:28.7402399 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2269 | 13:48:28.7403014 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2270 | 13:48:28.7403201 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2271 | 13:48:28.7403289 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2272 | 13:48:28.7404410 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2273 | 13:48:28.7404587 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2274 | 13:48:28.7406256 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2275 | 13:48:28.7406784 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2276 | 13:48:28.7406900 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2277 | 13:48:28.7407828 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2278 | 13:48:28.7408331 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2279 | 13:48:28.7408465 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2280 | 13:48:28.7409301 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2281 | 13:48:28.7410086 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2282 | 13:48:28.7411956 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2283 | 13:48:28.7412144 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2284 | 13:48:28.7413168 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2285 | 13:48:28.7413549 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2286 | 13:48:28.7414419 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2287 | 13:48:28.7414673 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2288 | 13:48:28.7414760 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2289 | 13:48:28.7415551 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2290 | 13:48:28.7416005 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2291 | 13:48:28.7416211 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2292 | 13:48:28.7417197 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2293 | 13:48:28.7417880 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2294 | 13:48:28.7418063 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2295 | 13:48:28.7418250 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2296 | 13:48:28.7418960 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2297 | 13:48:28.7419122 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2298 | 13:48:28.7419790 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2299 | 13:48:28.7420146 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2300 | 13:48:28.7420344 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2301 | 13:48:28.7421119 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2302 | 13:48:28.7421403 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2303 | 13:48:28.7421495 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2304 | 13:48:28.7422778 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2305 | 13:48:28.7423534 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2306 | 13:48:28.7423819 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2307 | 13:48:28.7423912 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2308 | 13:48:28.7424634 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2309 | 13:48:28.7424789 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2310 | 13:48:28.7425914 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2311 | 13:48:28.7426246 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2312 | 13:48:28.7426316 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2313 | 13:48:28.7427065 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2314 | 13:48:28.7427267 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2315 | 13:48:28.7427491 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2316 | 13:48:28.7428650 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2317 | 13:48:28.7431174 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2318 | 13:48:28.7431884 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2319 | 13:48:28.7432054 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2320 | 13:48:28.7432834 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2321 | 13:48:28.7433079 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2322 | 13:48:28.7434197 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2323 | 13:48:28.7434633 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2324 | 13:48:28.7434707 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2325 | 13:48:28.7435491 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2326 | 13:48:28.7435834 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2327 | 13:48:28.7435928 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2328 | 13:48:28.7436667 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2329 | 13:48:28.7437296 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2330 | 13:48:28.7437566 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2331 | 13:48:28.7437655 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2332 | 13:48:28.7438820 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2333 | 13:48:28.7439112 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2334 | 13:48:28.7439786 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2335 | 13:48:28.7440009 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2336 | 13:48:28.7440072 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2337 | 13:48:28.7441213 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2338 | 13:48:28.7441415 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2339 | 13:48:28.7441503 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2340 | 13:48:28.7442189 | MsMpEng.exe | 3220 | CreateFile | C:\Users | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2341 | 13:48:28.7442821 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2342 | 13:48:28.7443100 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2343 | 13:48:28.7443190 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2344 | 13:48:28.7443851 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2345 | 13:48:28.7444010 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2346 | 13:48:28.7444651 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2347 | 13:48:28.7444979 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2348 | 13:48:28.7445042 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2349 | 13:48:28.7445867 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2350 | 13:48:28.7446136 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2351 | 13:48:28.7446228 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2352 | 13:48:28.7446965 | MsMpEng.exe | 3220 | CreateFile | C:\ | SUCCESS | Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2353 | 13:48:28.7447232 | MsMpEng.exe | 3220 | QueryNameInformationFile | C:\ | SUCCESS | Name: \ |
| 2354 | 13:48:28.7447412 | MsMpEng.exe | 3220 | QueryAttributeInformationVolume | C:\ | SUCCESS | FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c02e00, MaximumComponentNameLength: 255, FileSystemName: NTFS |
| 2355 | 13:48:28.7447503 | MsMpEng.exe | 3220 | CloseFile | C:\ | SUCCESS | |
| 2356 | 13:48:28.7448286 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2357 | 13:48:28.7448610 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2358 | 13:48:28.7449587 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2359 | 13:48:28.7449876 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2360 | 13:48:28.7450919 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2361 | 13:48:28.7451194 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2362 | 13:48:28.7451909 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2363 | 13:48:28.7452145 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2364 | 13:48:28.7452207 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2365 | 13:48:28.7452865 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | NOT A DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a |
| 2366 | 13:48:28.7455915 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2367 | 13:48:28.7457070 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2368 | 13:48:28.7457267 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2369 | 13:48:28.7457357 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2370 | 13:48:28.7458159 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2371 | 13:48:28.7458344 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2372 | 13:48:28.7459025 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2373 | 13:48:28.7459539 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2374 | 13:48:28.7459874 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2375 | 13:48:28.7460974 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2376 | 13:48:28.7461214 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2377 | 13:48:28.7461298 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU | SUCCESS | |
| 2378 | 13:48:28.7462148 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2379 | 13:48:28.7462754 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2380 | 13:48:28.7463001 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2381 | 13:48:28.7463091 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2382 | 13:48:28.7463756 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2383 | 13:48:28.7463986 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2384 | 13:48:28.7464606 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2385 | 13:48:28.7464834 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2386 | 13:48:28.7464895 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2387 | 13:48:28.7465545 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2388 | 13:48:28.7465893 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2389 | 13:48:28.7465975 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers | SUCCESS | |
| 2390 | 13:48:28.7466621 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2391 | 13:48:28.7467212 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2392 | 13:48:28.7467361 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2393 | 13:48:28.7467436 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2394 | 13:48:28.7468348 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2395 | 13:48:28.7468582 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2396 | 13:48:28.7469527 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2397 | 13:48:28.7469822 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos\EDR-Introspection | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2398 | 13:48:28.7469907 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2399 | 13:48:28.7473531 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2400 | 13:48:28.7473887 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2401 | 13:48:28.7474173 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection | SUCCESS | |
| 2402 | 13:48:28.7475161 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2403 | 13:48:28.7475951 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2404 | 13:48:28.7476136 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2405 | 13:48:28.7476230 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2406 | 13:48:28.7476888 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2407 | 13:48:28.7477161 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2408 | 13:48:28.7478065 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2409 | 13:48:28.7479147 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source\repos | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2410 | 13:48:28.7479226 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2411 | 13:48:28.7480143 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2412 | 13:48:28.7480356 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2413 | 13:48:28.7480442 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos | SUCCESS | |
| 2414 | 13:48:28.7481137 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2415 | 13:48:28.7481771 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2416 | 13:48:28.7482053 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2417 | 13:48:28.7482138 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2418 | 13:48:28.7482801 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2419 | 13:48:28.7482961 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2420 | 13:48:28.7484759 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2421 | 13:48:28.7485050 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker\source | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2422 | 13:48:28.7485120 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2423 | 13:48:28.7486166 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2424 | 13:48:28.7486382 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2425 | 13:48:28.7486567 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source | SUCCESS | |
| 2426 | 13:48:28.7487301 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2427 | 13:48:28.7487954 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2428 | 13:48:28.7488132 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2429 | 13:48:28.7488219 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2430 | 13:48:28.7488854 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2431 | 13:48:28.7491222 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2432 | 13:48:28.7492076 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2433 | 13:48:28.7492327 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users\hacker | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2434 | 13:48:28.7492391 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2435 | 13:48:28.7493034 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2436 | 13:48:28.7493268 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2437 | 13:48:28.7493377 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker | SUCCESS | |
| 2438 | 13:48:28.7496489 | MsMpEng.exe | 3220 | CreateFile | C:\Users | IS DIRECTORY | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a |
| 2439 | 13:48:28.7497192 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2440 | 13:48:28.7497489 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2441 | 13:48:28.7497581 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2442 | 13:48:28.7498255 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2443 | 13:48:28.7498500 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2444 | 13:48:28.7499186 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2445 | 13:48:28.7499437 | MsMpEng.exe | 3220 | DeviceIoControl | C:\Users | INVALID PARAMETER | Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME |
| 2446 | 13:48:28.7499503 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2447 | 13:48:28.7500475 | MsMpEng.exe | 3220 | CreateFile | C:\Users | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open Reparse Point, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened |
| 2448 | 13:48:28.7500661 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users | NOT REPARSE POINT | Control: FSCTL_GET_REPARSE_POINT |
| 2449 | 13:48:28.7500749 | MsMpEng.exe | 3220 | CloseFile | C:\Users | SUCCESS | |
| 2450 | 13:48:28.7501453 | MsMpEng.exe | 3220 | CreateFile | C:\ | SUCCESS | Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened |
| 2451 | 13:48:28.7501729 | MsMpEng.exe | 3220 | QuerySizeInformationVolume | C:\ | SUCCESS | TotalAllocationUnits: 20’646’655, AvailableAllocationUnits: 5’331’773, SectorsPerAllocationUnit: 8, BytesPerSector: 512 |
| 2452 | 13:48:28.7501804 | MsMpEng.exe | 3220 | CloseFile | C:\ | SUCCESS | |
| 2453 | 13:48:28.7502491 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2454 | 13:48:28.7502770 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2455 | 13:48:28.7503784 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: True, Offset: 124, Length: 1, Fail Immediately: True |
| 2456 | 13:48:28.7503877 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 2457 | 13:48:28.7504024 | MsMpEng.exe | 3220 | LockFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Exclusive: False, Offset: 124, Length: 1, Fail Immediately: True |
| 2458 | 13:48:28.7504179 | MsMpEng.exe | 3220 | ReadFile | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal | SUCCESS | Offset: 82’456, Length: 4’096 |
| 2459 | 13:48:28.7504428 | MsMpEng.exe | 3220 | UnlockFileSingle | C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-shm | SUCCESS | Offset: 124, Length: 1 |
| 2460 | 13:48:28.7506266 | MsMpEng.exe | 3220 | CreateFile | C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\4F992D724B6D33EA543475A51B3D00E9 | NAME NOT FOUND | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a |
| 2461 | 13:48:28.7506805 | MsMpEng.exe | 3220 | RegCloseKey | HKCU | SUCCESS | |
| 2462 | 13:48:28.7507667 | MsMpEng.exe | 3220 | RegCloseKey | HKCU\Software\Classes | SUCCESS | |
| 2463 | 13:48:28.7511378 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2464 | 13:48:28.7511747 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 2465 | 13:48:28.7511923 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2466 | 13:48:28.7512035 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 2467 | 13:48:28.7512088 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2468 | 13:48:28.7512164 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 2469 | 13:48:28.7512261 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2470 | 13:48:28.7512435 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2471 | 13:48:28.7513327 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2472 | 13:48:28.7513516 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 2473 | 13:48:28.7513829 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2474 | 13:48:28.7513945 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winᄶ |
| 2475 | 13:48:28.7513998 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2476 | 13:48:28.7514115 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 2477 | 13:48:28.7514198 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2478 | 13:48:28.7514434 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2479 | 13:48:28.7515235 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2480 | 13:48:28.7515468 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: WinÄ |
| 2481 | 13:48:28.7515724 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2482 | 13:48:28.7515815 | MsMpEng.exe | 3220 | QueryInformationVolume | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | VolumeCreationTime: 12.08.2025 21:28:21, VolumeSerialNumber: 9C44-06ED, SupportsObjects: True, VolumeLabel: Winწ |
| 2483 | 13:48:28.7515869 | MsMpEng.exe | 3220 | QueryAllInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | BUFFER OVERFLOW | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, FileAttributes: A, AllocationSize: 380’928, EndOfFile: 378’880 |
| 2484 | 13:48:28.7515937 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 2485 | 13:48:28.7516014 | MsMpEng.exe | 3220 | QueryIdInformation | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2486 | 13:48:28.7516203 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2487 | 13:48:28.7517666 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2488 | 13:48:28.7517917 | MsMpEng.exe | 3220 | FileSystemControl | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Control: FSCTL_READ_FILE_USN_DATA |
| 2489 | 13:48:28.7518120 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2490 | 13:48:28.7520298 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2491 | 13:48:28.7520408 | MsMpEng.exe | 3220 | RegOpenKey | HKU\S-1-5-18 | REPARSE | Desired Access: Read |
| 2492 | 13:48:28.7520507 | MsMpEng.exe | 3220 | RegOpenKey | HKU\.DEFAULT | SUCCESS | Desired Access: Read |
| 2493 | 13:48:28.7520730 | MsMpEng.exe | 3220 | RegCloseKey | HKU\.DEFAULT | SUCCESS | |
| 2494 | 13:48:28.7520835 | MsMpEng.exe | 3220 | RegQueryKey | HKU | SUCCESS | Query: HandleTags, HandleTags: 0x0 |
| 2495 | 13:48:28.7520898 | MsMpEng.exe | 3220 | RegOpenKey | HKU\S-1-5-18 | REPARSE | Desired Access: Read |
| 2496 | 13:48:28.7520973 | MsMpEng.exe | 3220 | RegOpenKey | HKU\.DEFAULT | SUCCESS | Desired Access: Read |
| 2497 | 13:48:28.7522784 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Disposition: Open, Options: Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| 2498 | 13:48:28.7522935 | MsMpEng.exe | 3220 | QueryNetworkOpenInformationFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | CreationTime: 01.10.2025 20:10:03, LastAccessTime: 13.10.2025 13:48:28, LastWriteTime: 05.10.2025 15:57:40, ChangeTime: 05.10.2025 15:57:40, AllocationSize: 01.01.1601 02:00:00, EndOfFile: 01.01.1601 02:00:00, FileAttributes: A |
| 2499 | 13:48:28.7522999 | MsMpEng.exe | 3220 | CloseFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | |
| 2500 | 13:48:28.7525831 | MsMpEng.exe | 3220 | CreateFile | C:\Users\hacker\source\repos\EDR-Introspection\helpers\KDU\kdu.exe | SUCCESS | Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open For Backup, Open No Recall, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened |
| The file is too large to be shown. View Raw |