From bec0c5bd9470b0492cbfc3b9f2472c2397ff1813 Mon Sep 17 00:00:00 2001 From: Ori Damari <35385002+repnz@users.noreply.github.com> Date: Mon, 24 Jun 2019 20:09:10 +0300 Subject: [PATCH 1/9] Add a note --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index da7fdfa..fd88134 100644 --- a/README.md +++ b/README.md @@ -9,5 +9,5 @@ most of them are not documented very well. Using tdh.h API provider information can be dumped. For manifest based providers, a manifest can be recreated using the same method perfview uses: (https://github.com/Kae7in/perfview/blob/444fd391db9b8275846e2a5bbb8ec1d6e73a5dad/src/PerfView/Extensibility.cs#L2523) -For non-manifest based providers, currently only keywords are dumped. But theoretically you can register to the provider and just cache +(this is not the original manifest, because manifests are compiled) For non-manifest based providers, currently only keywords are dumped. But theoretically you can register to the provider and just cache all the results from all the events (in this case the event must be raised for it to be documented) From 6a2e2d7f98e14b0f54d5e54b6425b908a3142c30 Mon Sep 17 00:00:00 2001 From: repnz Date: Fri, 26 Jul 2019 20:43:39 +0300 Subject: [PATCH 2/9] Document Kernel Audit API --- ...crosoft-Windows-Kernel-Audit-API-Calls.xml | 30 +++++++++---------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/Manifests-Win10-17134/Microsoft-Windows-Kernel-Audit-API-Calls.xml b/Manifests-Win10-17134/Microsoft-Windows-Kernel-Audit-API-Calls.xml index f4601ff..65eecb4 100644 --- a/Manifests-Win10-17134/Microsoft-Windows-Kernel-Audit-API-Calls.xml +++ b/Manifests-Win10-17134/Microsoft-Windows-Kernel-Audit-API-Calls.xml @@ -8,45 +8,45 @@ - - - - - - - - + + + + + + + + -