Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <instrumentationManifest xmlns="http://schemas.microsoft.com/win/2004/08/events">
- <instrumentation xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:win="http://manifests.microsoft.com/win/2004/08/windows/events">
- <events>
- <provider name="Microsoft-Windows-Security-Mitigations" guid="{fae10392-f0af-4ac0-b8ff-9f4d920c3cdf}" resourceFileName="Microsoft-Windows-Security-Mitigations" messageFileName="Microsoft-Windows-Security-Mitigations" symbol="MicrosoftWindowsSecurityMitigations" source="Xml" >
- <keywords>
- </keywords>
- <tasks>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE)" value="1"/>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION)" value="2"/>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP)" value="3"/>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP)" value="4"/>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS)" value="5"/>
- <task name="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES" message="$(string.task_KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES)" value="6"/>
- <task name="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER" message="$(string.task_USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER)" value="7"/>
- <task name="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS" message="$(string.task_USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS)" value="8"/>
- <task name="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER" message="$(string.task_USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER)" value="9"/>
- <task name="USER_MITIGATION_TASK_ROP_STACKPIVOT" message="$(string.task_USER_MITIGATION_TASK_ROP_STACKPIVOT)" value="10"/>
- <task name="USER_MITIGATION_TASK_ROP_CALLERCHECK" message="$(string.task_USER_MITIGATION_TASK_ROP_CALLERCHECK)" value="11"/>
- <task name="USER_MITIGATION_TASK_ROP_SIMEXEC" message="$(string.task_USER_MITIGATION_TASK_ROP_SIMEXEC)" value="12"/>
- </tasks>
- <events>
- <event value="1" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="2" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE2" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="3" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATIONArgs"/>
- <event value="4" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION4" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATIONArgs"/>
- <event value="5" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAPArgs"/>
- <event value="6" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP6" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAPArgs"/>
- <event value="7" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="8" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP8" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="9" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="10" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS10" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs"/>
- <event value="11" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES" level="win:Always" template="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIESArgs"/>
- <event value="12" symbol="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES12" version="0" task="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES" level="win:Warning" template="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIESArgs"/>
- <event value="13" symbol="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER" version="0" task="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER" level="win:Always" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="14" symbol="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER14" version="0" task="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER" level="win:Warning" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="15" symbol="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS" version="0" task="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS" level="win:Always" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="16" symbol="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS16" version="0" task="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS" level="win:Warning" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="17" symbol="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER" version="0" task="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER" level="win:Always" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="18" symbol="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER18" version="0" task="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER" level="win:Warning" template="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs"/>
- <event value="19" symbol="USER_MITIGATION_TASK_ROP_STACKPIVOT" version="0" task="USER_MITIGATION_TASK_ROP_STACKPIVOT" level="win:Always" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- <event value="20" symbol="USER_MITIGATION_TASK_ROP_STACKPIVOT20" version="0" task="USER_MITIGATION_TASK_ROP_STACKPIVOT" level="win:Warning" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- <event value="21" symbol="USER_MITIGATION_TASK_ROP_CALLERCHECK" version="0" task="USER_MITIGATION_TASK_ROP_CALLERCHECK" level="win:Always" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- <event value="22" symbol="USER_MITIGATION_TASK_ROP_CALLERCHECK22" version="0" task="USER_MITIGATION_TASK_ROP_CALLERCHECK" level="win:Warning" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- <event value="23" symbol="USER_MITIGATION_TASK_ROP_SIMEXEC" version="0" task="USER_MITIGATION_TASK_ROP_SIMEXEC" level="win:Always" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- <event value="24" symbol="USER_MITIGATION_TASK_ROP_SIMEXEC24" version="0" task="USER_MITIGATION_TASK_ROP_SIMEXEC" level="win:Warning" template="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs"/>
- </events>
- <templates>
- <template tid="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODEArgs">
- <data name="ProcessPathLength" inType="win:UInt16"/>
- <data name="ProcessPath" inType="win:UnicodeString" length="ProcessPathLength"/>
- <data name="ProcessCommandLineLength" inType="win:UInt16"/>
- <data name="ProcessCommandLine" inType="win:UnicodeString" length="ProcessCommandLineLength"/>
- <data name="CallingProcessId" inType="win:UInt32"/>
- <data name="CallingProcessCreateTime" inType="win:FILETIME"/>
- <data name="CallingProcessStartKey" inType="win:UInt64"/>
- <data name="CallingProcessSignatureLevel" inType="win:UInt8"/>
- <data name="CallingProcessSectionSignatureLevel" inType="win:UInt8"/>
- <data name="CallingProcessProtection" inType="win:UInt8"/>
- <data name="CallingThreadId" inType="win:UInt32"/>
- <data name="CallingThreadCreateTime" inType="win:FILETIME"/>
- </template>
- <template tid="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATIONArgs">
- <data name="ProcessPathLength" inType="win:UInt16"/>
- <data name="ProcessPath" inType="win:UnicodeString" length="ProcessPathLength"/>
- <data name="ProcessCommandLineLength" inType="win:UInt16"/>
- <data name="ProcessCommandLine" inType="win:UnicodeString" length="ProcessCommandLineLength"/>
- <data name="CallingProcessId" inType="win:UInt32"/>
- <data name="CallingProcessCreateTime" inType="win:FILETIME"/>
- <data name="CallingProcessStartKey" inType="win:UInt64"/>
- <data name="CallingProcessSignatureLevel" inType="win:UInt8"/>
- <data name="CallingProcessSectionSignatureLevel" inType="win:UInt8"/>
- <data name="CallingProcessProtection" inType="win:UInt8"/>
- <data name="CallingThreadId" inType="win:UInt32"/>
- <data name="CallingThreadCreateTime" inType="win:FILETIME"/>
- <data name="ChildImagePathNameLength" inType="win:UInt16"/>
- <data name="ChildImagePathName" inType="win:UnicodeString" length="ChildImagePathNameLength"/>
- <data name="ChildCommandLineLength" inType="win:UInt16"/>
- <data name="ChildCommandLine" inType="win:UnicodeString" length="ChildCommandLineLength"/>
- </template>
- <template tid="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAPArgs">
- <data name="ProcessPathLength" inType="win:UInt16"/>
- <data name="ProcessPath" inType="win:UnicodeString" length="ProcessPathLength"/>
- <data name="ProcessCommandLineLength" inType="win:UInt16"/>
- <data name="ProcessCommandLine" inType="win:UnicodeString" length="ProcessCommandLineLength"/>
- <data name="ProcessId" inType="win:UInt32"/>
- <data name="ProcessCreateTime" inType="win:FILETIME"/>
- <data name="ProcessStartKey" inType="win:UInt64"/>
- <data name="ProcessSignatureLevel" inType="win:UInt8"/>
- <data name="ProcessSectionSignatureLevel" inType="win:UInt8"/>
- <data name="ProcessProtection" inType="win:UInt8"/>
- <data name="TargetThreadId" inType="win:UInt32"/>
- <data name="TargetThreadCreateTime" inType="win:FILETIME"/>
- <data name="ImageNameLength" inType="win:UInt16"/>
- <data name="ImageName" inType="win:UnicodeString" length="ImageNameLength"/>
- </template>
- <template tid="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIESArgs">
- <data name="ProcessPathLength" inType="win:UInt16"/>
- <data name="ProcessPath" inType="win:UnicodeString" length="ProcessPathLength"/>
- <data name="ProcessCommandLineLength" inType="win:UInt16"/>
- <data name="ProcessCommandLine" inType="win:UnicodeString" length="ProcessCommandLineLength"/>
- <data name="ProcessId" inType="win:UInt32"/>
- <data name="ProcessCreateTime" inType="win:FILETIME"/>
- <data name="ProcessStartKey" inType="win:UInt64"/>
- <data name="ProcessSignatureLevel" inType="win:UInt8"/>
- <data name="ProcessSectionSignatureLevel" inType="win:UInt8"/>
- <data name="ProcessProtection" inType="win:UInt8"/>
- <data name="TargetThreadId" inType="win:UInt32"/>
- <data name="TargetThreadCreateTime" inType="win:FILETIME"/>
- <data name="RequiredSignatureLevel" inType="win:UInt8"/>
- <data name="SignatureLevel" inType="win:UInt8"/>
- <data name="ImageNameLength" inType="win:UInt16"/>
- <data name="ImageName" inType="win:UnicodeString" length="ImageNameLength"/>
- </template>
- <template tid="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTERArgs">
- <data name="Subcode" inType="win:UInt32"/>
- <data name="ProcessPath" inType="win:UnicodeString"/>
- <data name="ProcessId" inType="win:UInt32"/>
- <data name="ModuleFullPath" inType="win:UnicodeString"/>
- <data name="ModuleBase" inType="win:Pointer"/>
- <data name="ModuleAddress" inType="win:Pointer"/>
- <data name="MemAddress" inType="win:Pointer"/>
- <data name="MemModuleFullPath" inType="win:UnicodeString"/>
- <data name="MemModuleBase" inType="win:Pointer"/>
- <data name="APIName" inType="win:UnicodeString"/>
- <data name="ProcessStartTime" inType="win:FILETIME"/>
- <data name="ThreadId" inType="win:UInt32"/>
- </template>
- <template tid="USER_MITIGATION_TASK_ROP_STACKPIVOTArgs">
- <data name="Subcode" inType="win:UInt32"/>
- <data name="ProcessPath" inType="win:UnicodeString"/>
- <data name="ProcessId" inType="win:UInt32"/>
- <data name="HookedAPI" inType="win:UnicodeString"/>
- <data name="ReturnAddress" inType="win:Pointer"/>
- <data name="CalledAddress" inType="win:Pointer"/>
- <data name="TargetAddress" inType="win:Pointer"/>
- <data name="StackAddress" inType="win:Pointer"/>
- <data name="FrameAddress" inType="win:Pointer"/>
- <data name="ReturnAddressModuleFullPath" inType="win:UnicodeString"/>
- <data name="ProcessStartTime" inType="win:FILETIME"/>
- <data name="ThreadId" inType="win:UInt32"/>
- </template>
- </templates>
- </provider>
- </events>
- </instrumentation>
- <localization>
- <resources culture="en-US">
- <stringTable>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE" value="KERNEL_MITIGATION_TASK_PROHIBIT_DYNAMIC_CODE"/>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION" value="KERNEL_MITIGATION_TASK_PROHIBIT_CHILD_PROCESS_CREATION"/>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP" value="KERNEL_MITIGATION_TASK_PROHIBIT_REMOTE_IMAGE_MAP"/>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP" value="KERNEL_MITIGATION_TASK_PROHIBIT_LOWIL_IMAGE_MAP"/>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS" value="KERNEL_MITIGATION_TASK_PROHIBIT_WIN32K_SYSTEM_CALLS"/>
- <string id="task_KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES" value="KERNEL_MITIGATION_TASK_PROHIBIT_NON_MICROSOFT_BINARIES"/>
- <string id="task_USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER" value="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER"/>
- <string id="task_USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS" value="USER_MITIGATION_TASK_EXPORT_ADDRESS_FILTER_PLUS"/>
- <string id="task_USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER" value="USER_MITIGATION_TASK_IMPORT_ADDRESS_FILTER"/>
- <string id="task_USER_MITIGATION_TASK_ROP_STACKPIVOT" value="USER_MITIGATION_TASK_ROP_STACKPIVOT"/>
- <string id="task_USER_MITIGATION_TASK_ROP_CALLERCHECK" value="USER_MITIGATION_TASK_ROP_CALLERCHECK"/>
- <string id="task_USER_MITIGATION_TASK_ROP_SIMEXEC" value="USER_MITIGATION_TASK_ROP_SIMEXEC"/>
- </stringTable>
- </resources>
- </localization>
- </instrumentationManifest>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement