AccountProtection_MicrosoftAccount_Disconnected_Dismissed2
IsSampleSubmissionByPolicy
ScRunAssessmentFailed
api-ms-win-core-kernel32-legacy-l1-1-0.dll
@.data
CleanPCLastRunTime
?I;}p
.?AVAutoUserImpersonator@ShieldProvider@@
L$4A;N u
Threat_3rdP_SettingsNeeded_ScanRecommended
SVWATAVAWH
DefenderAvHealth
RevertToSelf
`A_A^A\_^][
hA_A^A]A\_^[]
SetThreadpoolThreadMaximum
WindowsCreateStringReference
</trustInfo>
InstallDate
fD94_u
ReleaseMutex
wf.msc
AccountProtection_DynamicLock_Monitoring
G(9C(u
CryptCATCatalogInfoFromContext
4.18.1807.16384 (WinBuild.160101.0800)
_initterm_e
Company
.?AV?$CSecurityAttributesAlloc@U?$CAutoLocalPtr@PEAX@CommonUtil@@@CommonUtil@@
t$hH;
wevtapi.dll
Windows Defender Exploit Guard\ASR
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@U?$IAsyncOperationCompletedHandler@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@VFtmBase@23@@WRL@Microsoft@@
fD9<Ou
MpCleanOpen
CreateSemaphoreExW
PillarStatusFlag_AppAndBrowser_StoreAppsSmartScreenOff
I;F(u
zuNH9
Software\Microsoft\Windows\Signature
SeDebugPrivilege
Real-Time Protection
)xGmj
SOFTWARE\Microsoft\Windows Security Health\State\Persist
/clearTpm
A_A^A\_^][
u.A8Y
f9,Nu
.?AVCPeriodicTaskManagerWorkItem@CPeriodicTaskManager@ShieldProvider@@
SecurityHealthService
Threat_3rdP_ScanRecommended
PolicyManager_GetPolicyInt
AccountProtection_DynamicLock_BluetoothOff
Environment : %ls
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@U?$IAsyncOperationCompletedHandler@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@VFtmBase@23@@WRL@Microsoft@@
RegSetValueExW
MpConfigOpen
Threat_3rdP_SettingsNeeded_UpdatesRecommended
RemoveAllImageMitigationPolicies
D$tE;
IsDefenderAsDisabled
list<T> too long
TlP0X
Family options
TimeServiceAssessmentStart
Malgun Gothic
D9d$hu"9U
H9iHuO
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$02@WRL@Microsoft@@UIWscBrokerManagerSink@SecurityCenter@Windows@@@WRL@Microsoft@@
SetEntriesInAclW
UpdateMonitorBinaryCorruptionStart
0A_A^A]A\_^[
DeleteTimerQueueTimer
H AVH
\$0H9
UnregisterServer done, hr = %08X
System\WaaS\WaasMedic\State
api-ms-win-core-string-l1-1-0.dll
VWAVH
ManagementShield
X_^[]
Firewall and network protection
191123202700Z0
PA_A^A]A\_^[
Defender_SModeSigsDue
90tZH
L$xH3
__std_exception_destroy
Defender_RebootRequired
f94Gu
O0M0K
o\$PH
Microsoft Corporation
SummaryNotificationDisabled
L9}0u8
Event/System/TimeCreated/@SystemTime
LoadLibraryExW
fD9,Qu
D!t$$H
D8}HtyH
X\?E/5
D$pH;
.?AVNotificationsManager@ShieldProvider@@
.?AVStorageHealthEvalResults@HealthAdvisor@WSD@@
USVWATAUAVAWH
nQi ,];
.?AVShieldProcessLauncher@0@
expectedPayload
@SUVWAVH
DisableRealtimeMonitoring
H9<1tIH
180823202700Z
Account protection
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Application Error
Threat_3rdP_ScanNeeded_UpdatesRecommended
AccountProtection_DynamicLock_NoPairedDevices
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIForceFieldShield@@@WRL@Microsoft@@
d$`E3
L9] u\
MpCleanStart
AppID
.?AUIDefenderShield@@
_initterm
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIExploitShield@@@Details@WRL@Microsoft@@
.?AVFirewallManager@ShieldProvider@@
SetServiceStatus
AppHVSIPrintingSettings
.idata$5
False
FwAnalyzeFirewallPolicy
h UAVAWH
HA_A^A]_^[
S~=5p
Network_ThirdPartyInstalled
.pdata
NtQuerySystemInformation
Microsoft
.?AVApplicationErrorEvent@HealthAdvisor@WSD@@
NtQueryWnfStateData
VbsGetIssues
.didat$2
D$`A3
Number of System Errors
fD9,Hu
Application
t$`I;
Microsoft JhengHei UI
SeIncreaseQuotaPrivilege
`A_A^A\_[
.?AVDeviceDriverResults@HealthAdvisor@WSD@@
.data$r$brc
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIWeakReference@@@Details@WRL@Microsoft@@
_set_new_mode
8A_A^A]A\_^][
H;X(u
CloseServiceHandle
GetMessageW
.?AUIAdvisorEngineSink@HealthAdvisor@WSD@@
payload
Products
Wldp.dll
D9d$huJL
api-ms-win-security-lsalookup-l1-1-2.dll
y:I9n
fD94Bu
ew0hp
SetEvent
`A_A^A]A\^[]
MpQuarantineRequest
SYSTEM\WaaS\Upfc
_exit
fD9,Ou
m]#0D
8A_A^A\_^[
HealthAdvisor_StorageDiskspaceLow
0A^_^
Defender_AsSigsDue
Network_3rdP_Expired
ReliabilityScore
Legal_Policy_Statement
Network_3rdP_L2L1_NoAction
%hs!%p:
"Gfhr=0x%08X
hResult
, Name : %ls
f4Og|
0A_A^A\_^
SOFTWARE\Microsoft\Windows Defender Security Center\Account protection
SWATH
&:.%e
CoCreateFreeThreadedMarshaler
DisableTpmFirmwareUpdateWarning
p WAVAWH
D$X9Ktu
@A_A^A\_]
api-ms-win-crt-locale-l1-1-0.dll
Third Party
.tls$ZZZ
CoCreateInstance
.?AUIForceFieldShield@@
t$XI;
MpGetCallistoDetections
SpecRequiredMemoryInGB
DpaDisabled
millisecondsTimeout
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
FirewallAPI.dll
GetFileAttributesW
Microsoft Time-Stamp PCA 20100
UnexpectedAction
api-ms-win-crt-string-l1-1-0.dll
I+?E3
Yu Gothic UI Semibold
QueryMitigationPolicyFailure
.?AVWscManager@ShieldProvider@@
Exploit Shield
CompareFileTime
.rdata$r
f9,Ku
Unexpected
`A^_^
SwitchToThread
ExploitShield
MpDeleteAsrHistory
Hardware_Healthy
Microsoft-Windows-HVSI-Enabled
MitigationPolicyValuePostSet
.CRT$XIA
RtlNtStatusToDosError
111019184142Z
|$(E3
DispatchMessageW
Hardware Shield
EnableASRConsumers
hA_A^A]A\_^][
D$pA3
BlockReason
ScDiskAllGood
DisableAntiSpyware
Microsoft JhengHei UI Bold
tjf9t_
HvciIncompatibilityScanInitialize
ImpersonateLoggedOnUser
ResetEvent
SELECT ConfigManagerErrorCode, Name, Status FROM Win32_PnPEntity
x UAVAWH
ThreatProtectionHealth
HealthAdvisor_BatteryBrightnessAlert
CoRevertToSelf
Health Advisor Shield
FileDescription
%Microsoft Windows Production PCA 2011
T$|E3
_configthreadlocale
\$ UVWH
ul%G1
S-1-5-18
L9}0uJ
HealthAdvisor_Unknown
ti5s!n
PA_A^A]A\_[]
\$ VWAVH
UWATAVAWH
A_A^A]A\_[
RtlSubscribeWnfStateChangeNotification
LcMxH
bgOne
<?xml version="1.0" encoding="UTF-16"?><Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task" version="1.4"> <RegistrationInfo> <Author>$(@%systemroot%\system32\WaasMedicSvc.dll,-102)</Author> <Source>$(@%systemroot%\system32\WaasMedicSvc.dll,-103)</Source> <Description>$(@%systemroot%\system32\WaasMedicSvc.dll,-104)</Description> <URI>\Microsoft\Windows\WaaSMedic\PerformRemediation</URI> <SecurityDescriptor>D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)</SecurityDescriptor> </RegistrationInfo> <Triggers> <TimeTrigger> <Enabled>true</Enabled> <RandomDelay>PT4H</RandomDelay> <StartBoundary>2000-10-15T03:00:00</StartBoundary> <Repetition> <Interval>P7D</Interval> </Repetition> </TimeTrigger> </Triggers> <Principals> <Principal id="LocalSystem"> <UserId>S-1-5-18</UserId> <RunLevel>LeastPrivilege</RunLevel> </Principal> </Principals> <Settings> <AllowHardTerminate>true</AllowHardTerminate> <AllowStartOnDemand>true</AllowStartOnDemand> <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries> <DisallowStartOnRemoteAppSession>false</DisallowStartOnRemoteAppSession> <Enabled>false</Enabled> <ExecutionTimeLimit>PT72H</ExecutionTimeLimit> <Hidden>false</Hidden> <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy> <Priority>7</Priority> <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable> <StartWhenAvailable>true</StartWhenAvailable> <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries> <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine> <WakeToRun>false</WakeToRun> </Settings> <Actions Context="LocalSystem"> <ComHandler> <ClassId>{72566e27-1abb-4eb3-b4f0-eb431cb1cb32}</ClassId> <Data>None</Data> </ComHandler> </Actions> </Task>
uzEoG
yLI9n
ntdll.dll
0A_A]A\_^][
WinVerifyTrust
CreateEnvironmentBlock
WakeAllConditionVariable
SetThreadPriority
AccountProtection_WindowsHello_Configured
<F.uSA
UVAVH
A_A^A\_^
Microsoft Time-Stamp PCA 2010
RemoveDllDirectory
D$H9Kdu
.?AV_com_error@@
FWGetConfig
H SVWH
41Q)<
Normal
UnregisterGPNotification
AdjustTokenPrivileges
%ls!%ls!%ls
AccountProtection_MicrosoftAccount_Disconnected_Dismissed1
.?AVOSProtectionShield@ShieldProvider@@
CoWaitForMultipleHandles
DriverStatus
Threat_3rdP_SignaturesOutOfDate
MpManagerVersionQuery
D$(E3
%programdata%\Microsoft\Windows Security Health
fD9<Hu
CLSID
Battery
RtlPublishWnfStateData
fA9,Qu
ThreatProtectionShield
Threat_3rdP_UpdatesNeeded
|$0(
%ls %ls
.?AV?$CRefObjectFor@UIMpThreadPool@CommonUtil@@@CommonUtil@@
<security>
Threat_3rdP_Expired
0A_A^_^]
ConvertSidToStringSidW
SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\SystemGuard
####-##-##T##:##:##S
GetTickCount64
D9d$hu(D9U
_configure_wide_argv
UWATH
.?AVCRefCountedBaseX@@
Windows Security Health Service
Device performance and health
NT AUTHORITY
Containers\WindowsDefenderApplicationGuard.wim
D$pL9?t
H UATAUAVAWH
Threat_3rdP_UpdatesNeeded_ScanSettingsRecommended
.rdata$zETW9
/update
Enterprise Customization
Threat_3rdP_L1_SingleActionNeeded
K WATAUAVAWH
Threat_3rdP_SettingsUpdatesNeeded_ScanRecommended
.?AVSystemErrorEvent@HealthAdvisor@WSD@@
UVWAVAWH
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIDataProtectionShield@@@WRL@Microsoft@@
L$0E3
.?AUIClassFactory@@
MsMpLics.dll
RtlRunOnceExecuteOnce
u6H!]8H
ohI+o`H
A_A^A\_]
MpHandleClose
CapturedMitigationAuditPolicyValue
100701213655Z
IsCloudByPolicy
EnablePrinters
%s-%s.etl
/disable
L9]0u^
D$Xy9H
RoOriginateError
Application Guard Shield
TerminateProcess
ReliabilityAssessmentStart
Threat_3rdP_UpdatesNeeded_ScanRecommended
9sTvIH
f9,Au
x2D97ur
InitializeConditionVariable
ForceField_Error
AccountProtection_DynamicLock_Scanning
L!mHE;
Rpcss
USWAVH
SetupDiDestroyDeviceInfoList
h0|g%
9:vXH
D!t$`H
CompareStringW
%ls <Query Path='Application'> <Select>Event/System[Provider[@Name="%ls"] and Level <=3 and TimeCreated[timediff(@SystemTime) <=%lu]]</Select> </Query>
?_Xout_of_range@std@@YAXPEBD@Z
.?AVUpdateMonitorTask@UpdateMonitor@WSD@@
OS Protection Shield
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
D$`H+
@A_A^A]A\_^[
PUAProtection
.CRT$XPZ
LastSuccessfullyAppliedPolicyTimeUTC
Version : %ls
EvtQuery
PA_A^A\_^
t7I9n
ChangeServiceConfig2W
__stdio_common_vswprintf
Threat_3rdP_ScanSettingsNeeded_UpdatesRecommended
.text$x
R!s4Z
/launch /av
>$7<EK
AccountProtection_WindowsHello_NotAvailable
.?AUIDataProtectionShield@@
BatteryStatus
D$pI;
ToastThrottling
.xdata$x
L$HH3
A^_^
CryptCATAdminAcquireContext
GetModuleHandleW
Segoe UI
DataProtection_CloudBackupProviderSetupRequired
ForceField_Healthy
Threat_3rdP_L1_NoAction
api-ms-win-core-registry-l1-1-0.dll
ApplicationGuardShield
OS Protection Shield Class
L$ E3
EnableLifetimeManagement
TpmGetDeviceInformation
.CRT$XLZ
AccessCheck
mpssvc
WDSC UI
.giats
kernelbase.dll
Account Protection Shield
%ls\MpClient.dll
.rsrc
9wLv[H
api-ms-win-core-shutdown-l1-1-0.dll
AccountProtection_MicrosoftAccount_Disconnected
H;_Pu
ScLowDisk
SystemTimeToFileTime
.?AVForceFieldShield@ShieldProvider@@
api-ms-win-core-winrt-error-l1-1-0.dll
@USVWATAUH
HealthAdvisor_DriverStatusNonOperationalOther
0A_A^_
OriginalFilename
SmartScreenStorePolicy
Windows.Internal.Security.SmartScreen.UriReputationService
?S;zF0B
A^A]A\_[
/renew
@USVAVAWH
AccountProtectionStatus
FileTimeToSystemTime
ReliabilityStatus
RemoveAllImageMitigationPoliciesFailure
HcD$@
PayloadRestriction
MpManagerDisable
FileTrustOriginRemovableMedia
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIDefenderNotificationsSink@@@Details@WRL@Microsoft@@
$Microsoft Ireland Operations Limited1
M;a s:H
NetworkProtectionShield
ScIsSmartStorageEnabled
.?AVCMpThreadPoolProviderVista@CommonUtil@@
fD94Au
@A_A^^[]
%ls{ FwList : [
u#H9<
AddDllDirectory
length
.?AVHardwareShield@ShieldProvider@@
EnableInApp
UVWATAUAVAWH
Network_MultipleFwOff
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
HealthAdvisor_Critical
CloseHandle
L$8E3
.?AVexception@std@@
Data Protection Shield Class
SOFTWARE\Microsoft\CleanPC
@.reloc
bad array new length
FreeSid
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIDashboard@@UIManagementStatusSink@@UIDefenderNotificationsSink@@UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
20190116062834.857Z0
HA_A^A]A\_^[]
@8t$`@
0A_A^A]_^
WlanOpenHandle
z.9Wv
l$xE3
.?AU?$IAsyncOperationCompletedHandler_impl@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@
LoadResource
_purecall
.?AUIAccountProtectionNotificationsSink@@
Failed to register class %ls, hr = %08X
ChangeServiceConfigW
D9K(t
GetSystemTimeAsFileTime
|$8Hi
;L$xr
A^_]
RegEnumValueW
SeShutdownPrivilege
ControlTraceW
PowerReadDCValue
mmc.exe
9|$,u
DefenderAvStatus
ThreatProtectionStatus
Network_3rdP_Off
Software\Microsoft\HVSI
D$HH#
xv#?H
Threat protection Shield Class
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIApplicationGuardShield@@@WRL@Microsoft@@
TaskUpdateActionBitmask
Network_Unknown
Leelawadee UI Bold
L9}0uM
f9<Hu
vY}xW
SetUnhandledExceptionFilter
.?AUINetworkProtectionHealthSink@@
Defender_ActiveThreats
wcscmp
%ws\%ws
.?AVtype_info@@
D$ E3
.text
D$ (
Thales TSS ESN:86DF-4BBC-93351%0#
Version
@UATAUAVAWH
__stdio_common_vsprintf
SpyNet
ReliabilityAssessmentEnd
.?AUIStorageHealthEvalResults@@
.rdata$brc
fF9<wu
l$tE3
%windir%\system32\firewall.cpl
Microsoft Windows Publisher0
.?AUIShieldProcessLauncher@@
AppHVSIClipboardSettings
.?AUIUtilRegListener@CommonUtil@@
9;vXH
PeriodicTaskSubmitDelay
L$`E3
.?AV?$CRefObjectFor@UIUtilRegListener@CommonUtil@@@CommonUtil@@
Exploit Shield Class
DllEnumerateClasses
api-ms-win-crt-heap-l1-1-0.dll
@%systemroot%\system32\SecurityHealthAgent.dll,-1002
api-ms-win-security-provider-l1-1-0.dll
VbsApi.dll
_initialize_wide_environment
RegisterServer
.?AV?$RuntimeClassBaseT@$01@Details@WRL@Microsoft@@
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00$00$0A@UISecurityAppBrokerSink@SecurityCenter@Windows@@@Details@WRL@Microsoft@@
isAssessmentBlocked
RegisterServer done, hr = %08X
SVWATAUAWH
.?AUIUtilRegEnumKeyValues@CommonUtil@@
LocalAlloc
.idata$4
D8}Pt
MpFreeMemory
Application Hang
HA^_[]
ke|u!
.?AUIWeakReference@@
D:P(A;;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;OICIIO;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GA;;;SY)(A;OICIIO;GA;;;SY)(A;;GRGX;;;BU)(A;OICIIO;GRGX;;;BU)(A;;GRGX;;;AC)(A;OICIIO;GRGX;;;AC)
D$tD3
Shield systray SSO
PA^_]
Defender Shield Class
App and Browser Shield Class
SeTakeOwnershipPrivilege
.rdata$T$brc
GetTokenInformation
Microsoft YaHei UI Bold
`A_A^A]A\_^[
L$xH;E
ForceField Web Protection Shield
FWOpenPolicyStore
ATAUAVH
Hardware_SecureBootOnRecommended
setupapi.dll
VerSetConditionMask
9sTvEH
Appliation Guard Shield Class
HealthAdvisor_Healthy
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-core-com-l1-1-0.dll
Defender_AvSigsDue
!D$ A
.?AVCMpPrivateThreadPool@CommonUtil@@
Network_3rdP_NoAction
HcD$ H
Shield Provider Service
L9]0uO
Network_3rdP_L2L1_ActionRecommended
L9}@D
OneDrive Business
__C_specific_handler
DynamicCode
AllowPersistence
TraceMessage
0A_A^A]A\_^]
9|$4u
Network_3rdP_L2L1_MultipleActionNeeded
.?AVCExplicitAccessControl@CommonUtil@@
Microsoft Corporation1-0+
AppAndBrowser_StoreAppsSmartScreenOff
EnableForToasts
oLW\f
%s\%s
SetMitigationPolicy
CreateEventW
Network_PublicFwOff
A]A\_^[]
zCg/`
|$ AVH
bad allocation
SpecRequiredProcessorCount
\$pIi
.text$mn$00
t$ WH
.?AUIMpPrivateThreadPool@CommonUtil@@
SetLastError
%ls , %ls , %ls , %ls , %ls , %ls , %ls
.rsrc$01
CallContext:[%hs]
Microsoft JhengHei UI Light
DebugBreak
SHS-*.etl
SecurityHealthService.exe
SeImpersonatePrivilege
A_A^A]A\_^[]
RegDeleteValueW
NetworkProtectionStatus
D$pE3
.?AV?$CRegListenerFunctorAdapter@V<lambda_a24e8a6029b8f6fea26431f3bf5e7760>@@@CommonUtil@@
_beginthreadex
y^1",e
forwarders\%ws
fE9<lu
A_A^A]
__stdio_common_vfwprintf
.?AUIDefenderNotificationsSink@@
ntelD
.?AVDefenderToastManager@ShieldProvider@@
D;u0r
Managed
L$pI+
AuditApplicationGuard
N8H9F
.?AVEventLogEvent@HealthAdvisor@WSD@@
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIHardwareShield@@@WRL@Microsoft@@
BI+~{Vs<i
HvciGetConfig
InitializeAcl
9]@~kH
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIDataProtectionShield@@@Details@WRL@Microsoft@@
DataProtectionShield
USERENV.dll
} D9}
GetSecurityDescriptorDacl
api-ms-win-core-registry-l2-1-0.dll
InitializeSListHead
Network_NonSecureState
AccountProtectionHealth
GetTraceEnableLevel
T$PD9
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIAccountProtectionShield@@@WRL@Microsoft@@
.?AUIWaitForServiceCancellation@CommonUtil@@
deque<T> too long
_CxxThrowException
HealthAdvisor_Warning
$(SQO
fD9<Wu
LeaveCriticalSection
.?AUIExploitShield@@
##:##
4.18.1807.16384
HideRansomwareRecovery
OSProtectionShield
Hardware Shield Class
|$ AWH
L$ SVWH
GetTraceLoggerHandle
MpThreatHistoryRequest
AppAndBrowser_Unknown
D$(H;
Hardware_NoTPM
Microsoft Corporation. All rights reserved.
AppAndBrowser_Healthy
^`H;^ht_H
L$PH3
DsrFreeCxhScenarioInfo
L$PI;
Hardware_TpmClearNeeded
DefenderShield
@A^_^][
.text$yd
IM8x)
UpdateMonitorHealthAssessmentStart
CreateDirectoryW
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIForceFieldShield@@@Details@WRL@Microsoft@@
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$$V@Details@WRL@Microsoft@@
WATAVH
api-ms-win-core-localization-l1-2-0.dll
D$xH;
GetStoragePolicySettings
@USVWAUAVAWH
.?AVCError@@
.?AUIShieldProviderToast@@
.?AVManagementShield@ShieldProvider@@
BlackoutNotExpired
BlockNonEnterpriseContent
api-ms-win-core-winrt-l1-1-0.dll
.?AUIForceFieldSink@@
@8kauOH
.?AVWscForceFieldBrokerSink@ShieldProvider@@
Status Codes
api-ms-win-core-threadpool-legacy-l1-1-0.dll
api-ms-win-crt-private-l1-1-0.dll
byjA`
RegisterWaitForSingleObject
ImageSignature
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIDataProtectionSink@@@Details@WRL@Microsoft@@
`A_A^A]A\_^]
.?AVExploitShield@ShieldProvider@@
l$ E3
DriverRunAssessmentStart
.?AUIAssessmentSink@HealthAdvisor@WSD@@
O:BAG:BAD:(A;;0x3;;;SY)(A;;0x3;;;BA)(A;;0x3;;;IU)(A;;0x3;;;LS)(A;;0x3;;;S-1-15-2-2668987081-2569674137-3179742174-4270009011-3803107086-2981642713-3349210623)
ExploitGuard_ASR_Rules
LegalCopyright
SHS-*.bin
sTfD;
Not Set
WSC Broker
NgcIsAnyContainerInVsm
Enabled
/enable
UnregisterServer
GetSystemTime
Malgun Gothic Semilight
,B>DY
SmartScreenAppPolicy
<QueryList>
.?AV?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@
EHH;EX
A_A]]
Virus and threat protection
H9_xt
D:P(A;;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;OICIIO;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GA;;;SY)(A;OICIIO;GA;;;SY)(A;;GA;;;BA)(A;OICIIO;GA;;;BA)(A;;GRGX;;;BU)(A;OICIIO;GRGX;;;BU)(A;;GRGX;;;AC)(A;OICIIO;GRGX;;;AC)
M0K0I
zuWL9
H;H A
.?AVFtmBaseMarker@Details@WRL@Microsoft@@
Ly^X`
Network_Healthy
@A_A^A]A\_^]
@.r"S-4
>HiD$ P
L$0H3
.?AVAssessmentBase@HealthAdvisor@WSD@@
T$0v^H
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00$$V@Details@WRL@Microsoft@@
EvtNext
.?AVThreatProtectionShield@ShieldProvider@@
BootAfterCleanPC
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@U?$IAsyncOperationCompletedHandler@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@VFtmBase@23@@Details@WRL@Microsoft@@
IsCloudEnabled
Shield Provider Toast Class
.rdata$zzzdbg
api-ms-win-core-path-l1-1-0.dll
WAxK0i
WAVAWH
A__^
.rdata
api-ms-win-core-errorhandling-l1-1-0.dll
RegDeleteKeyW
SetThreadpoolThreadMinimum
.?AVMpClientForwarder@ShieldProvider@@
BatteryRunAssessmentStart
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
Unknown parameter.
OpenSCManagerW
QueryFullProcessImageNameW
Da6N^
D9l$huBH
%UM;%
D$P9Klu
I;]hu
Device Driver
h_^[]
MpUpdateControl
Defender_Healthy
fD9,Au
NoBuildInfo
%Microsoft Windows Production PCA 20110
ErrorInvalidReason
EnablePersistence
0A^A\_^]
ProviderType
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIForceFieldShield@@@Details@WRL@Microsoft@@
WaitForSingleObject
.?AVRuntimeClassBase@Details@WRL@Microsoft@@
ScRunAssessmentStart
Threat_3rdP_Snoozed
t$pE3
__stdio_common_vswscanf
TpmGetCapLockoutInfo
OpenProcessToken
BlockUntilTimeStatus
.?AVAssessmentRuntimeInfo@HealthAdvisor@WSD@@
GetModuleFileNameA
.?AUIDashboard@@
StartTraceW
.?AUIManagementStatusSink@@
SVWATAUAVAWH
.?AVQueryAndActionManager@ShieldProvider@@
Phone
0A_A^A\
d$HyDH
_register_thread_local_exe_atexit_callback
api-ms-win-core-sysinfo-l1-1-0.dll
ForceField_Warning
SOFTWARE\Microsoft\Windows Security Health\Miscellaneous
SHGetKnownFolderPath
CM_Get_DevNode_Status
SetNamedSecurityInfoW
memcpy
H!\$
.idata$3
.?AUIInspectable@@
DisallowExploitProtectionOverride
261019185142Z0
EnableClipboard
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
D9l$huAL
Microsoft Time-Stamp service
%windir%\explorer.exe
D8}Ht
NotifyServiceStatusChangeW
1!!!Z
MpConveyUserChoiceForSampleList
S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464
.didat$5
H!\$ H
SeAssignPrimaryTokenPrivilege
RtlDllShutdownInProgress
SmartScreenEdgePolicy
/id PowerDiagnostic
FilesBlockedNotificationDisabled
.?AUINetworkProtectionShield@@
ew|>&=4_
DefenderAvCurrentRunningMode
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
Software\Microsoft\Windows Security Health\Health Advisor\
.?AVOSProtectionManager@ShieldProvider@@
WlanQueryInterface
Threat_3rdP_UpdatesRecommended
Defender_FullScanRequired
string too long
"Microsoft Window
D8}Hu;D8}Pu5
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$0A@UIWscBrokerManagerSink@SecurityCenter@Windows@@UIWeakReferenceSource@@@Details@WRL@Microsoft@@
O:BAG:BAD:(A;;CCDCLC;;;SY)(A;;CCDCLC;;;BA)(A;;CCDCLC;;;IU)(A;;CCDCLC;;;LS)(A;;CCDCLC;;;S-1-15-2-2668987081-2569674137-3179742174-4270009011-3803107086-2981642713-3349210623)
ExpandEnvironmentStringsW
BatteryRunAssessmentEnd
Management Shield Class
T$JI+
UATAUAVAWH
TgeG*
HeapFree
Malgun Gothic Bold
UWATAUAVH
.?AVBatteryAssessment@HealthAdvisor@WSD@@
@A_A^A\_^
d}mifU{
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
CLSID\%ls
SeRestorePrivilege
AppID\%ls
SOFTWARE\Microsoft\Microsoft Security Client
GetTickCount
Microsoft YaHei UI Light
]HH!]@H
DisableEnhancedNotifications
HvciIncompatibilityScanFree
DriverRunAssessmentEnd
+D$hD3
Threat_3rdP_ScanNeeded_SettingsUpdatesRecommended
Network protection Shield
L$@H3
USWATAUAVAWH
wcstok_s
.?AV?$CRefObjectFor@UIWaitForServiceCancellation@CommonUtil@@@CommonUtil@@
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIAppAndBrowserShield@@@WRL@Microsoft@@
.?AVDeviceDriverAssessment@HealthAdvisor@WSD@@
MpConfigGetValueAlloc
QueryServiceConfigW
.?AVCHResultException@CommonUtil@@
Block
actualMilliseconds
.?AUIDataProtectionSink@@
SUVWATAUAWH
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIManagementStatusSink@@UIDefenderNotificationsSink@@UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
T$`E3
UWAVH
M0uaM
r;ext-ms-win-storage-sense-l1-2-0.dll
.?AVSignatureUpdateManager@ShieldProvider@@
{ Firewall : %ls, Exe : %ls, State: %d, SigUpToDate: %ls%ls}
EvtCreateRenderContext
HideSecureBoot
NoActionNotificationDisabled
UpdateMonitorHealthAssessmentEnd
.?AVFTMEventDelegate@?1???$WaitForCompletion@U?$IAsyncOperationCompletedHandler@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@U?$IAsyncOperation@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@23@@@YAJPEAU?$IAsyncOperation@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@W4tagCOWAIT_FLAGS@@PEAX@Z@
A_A^A\
NetworkProtectionHealth
C0H!,
@VWAVH
L9a sEL
ShieldProcessLauncher
AppAndBrowserHealth
EventSetInformation
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
230280+4361160
\$pMi
0A_A^A]^]
Chttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a
_c_exit
UWAUAVAWH
@A^A]A\_]
IsAvDisableByPolicy
OutputDebugStringW
AppAndBrowserShield
UnregisterTraceGuids
SEHOP
stoi argument out of range
@SVWAVAWH
PathToSignedReportingExe : %ls
<requestedPrivileges>
StartServiceCtrlDispatcherW
ReturnHr
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
WldpQueryWindowsLockdownMode
OLE32.dll
WscUnRegisterChanges
WINTRUST.dll
VbsIsCapable
CoAddRefServerProcess
IcfChangeNotificationDestroy
UUUUUUU
L!*L!.A
t$hI;
@A^_]
A^A\]
IcfChangeNotificationCreate
.CRT$XTA
consumers
Threat_3rdP_ScanSettingsUpdatesNeeded
GetSystemPowerStatus
.?AVFtmBase@WRL@Microsoft@@
`A_A^^[]
DataProtectionRevokeWarning
ERy*g!
@8,1u
.?AVAutoGetUserToken@ShieldProvider@@
.?AVCHResultExceptionImpl@CommonUtil@@
@SUVWATAVAWH
UWATAUAWH
WATAUAVAWH
HealthAdvisor_DriverStatusNeedsUpdate
NotSupportedInThisSku
H!\$(L
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@U?$IAsyncOperationCompletedHandler@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@VFtmBase@23@@Details@WRL@Microsoft@@
A^_^[]
fD9t]
$`2X`F
0A^_^[]
20190117024319Z0w0=
api-ms-win-crt-convert-l1-1-0.dll
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIDashboard@@UIManagementStatusSink@@UIDefenderNotificationsSink@@UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@WRL@Microsoft@@
!J+R}
api-ms-win-security-base-l1-1-0.dll
DataProtectionDismissWarning
A_A^A]A\_
|$ E3
.CRT$XCAA
api-ms-win-core-sysinfo-l1-2-0.dll
D$ t9H
MpConfigIteratorOpen
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIDataProtectionShield@@@Details@WRL@Microsoft@@
WTHelperGetProvSignerFromChain
\$ UH
_initialize_onexit_table
.?AUIAssessmentBase@HealthAdvisor@WSD@@
WlanEnumInterfaces
/id AppsDiagnostic
.CRT$XTZ
CoRevokeClassObject
L9{0t#H
.00cfg
.?AUCAutoProcessInformation@HealthAdvisor@WSD@@
_wcsicmp
D8%wa
FreeLibrary
RoRevokeActivationFactories
HealthAdvisorShield
H;s8vEH
FailFast
t$hA;
xA_A]A\_^[
T$0E3
'R{=f
HardwareShield
T$dE3
http://www.microsoft.com/windows0
UVWATAVH
OpenThreadToken
ATAVAWH
H!}XH
UAUAWI
AccountProtection_MicrosoftAccount_Associated
CompanyName
hgtlCm
f9,Zu
RemoveAllImageMitigationAuditPoliciesFailure
ChangedInBootCycle
ValidateXML
@A_A^_
GetCurrentThreadId
L$pI;
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIApplicationGuardShield@@@Details@WRL@Microsoft@@
AccountProtection_MicrosoftAccount_Connected
@UVWATAVH
Runtime_platform : %ls
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIDefenderNotificationsSink@@UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIWeakReference@@@Details@WRL@Microsoft@@
NgcQueryEnabled
{ H;{(
@SVWATAUAVAWH
;D$X}
calloc
https://login.microsoft.com
CoRegisterClassObject
CryptCATAdminReleaseContext
Threat_3rdP_ScanUpdatesRecommended
GetProcessHeap
Network_3rdP_ActionNeeded
Sleep
GetFileSizeEx
SetMitigationAuditPolicyFailure
/launch /fw
QueryServiceStatus
CLASSES_ROOT\%s
AppHVSIClipboardFileType
.?AVCWscProductInfoEntry@ShieldProvider@@
.?AVAccountProtectionShield@ShieldProvider@@
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIDashboard@@UIManagementStatusSink@@UIDefenderNotificationsSink@@UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
ImageType
z?801i:It6
SOFTWARE\Microsoft\Windows NT\CurrentVersion
u0HcH<H
EvtRender
t$ UWATAVAWH
MpGetAsrBlockedProcesses
GetDiskFreeSpaceExW
.?AU?$IAsyncOperationCompletedHandler@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@@Foundation@Windows@@
HighEndThresholdMB
.?AVAdvisorEngine@HealthAdvisor@WSD@@
@SUVWAVAWH
{ AVH
</security>
.?AVTimeServiceAssessment@HealthAdvisor@WSD@@
Windows.Internal.Security.Authentication.Web.TokenBrokerInternal
_`H;_ht
TpmGatherLogs
|$ H;
.?AVCMpShutterWait@CommonUtil@@
oT$@f
)Microsoft Root Certificate Authority 20100
.?AVStorageHealthEvalAssessment@HealthAdvisor@WSD@@
_wtol
D$pA;
%ls%ls
RegOpenKeyExW
H9_Hs<
ReleaseSemaphore
.?AVStorageHealthResults@HealthAdvisor@WSD@@
CreateEventExW
D$@!|$@H
TimeServiceAssessmentEnd
_wcsnicmp
FindFirstFileW
UnregisterWaitEx
GetPhysicallyInstalledSystemMemory
09/(G
.?AUIUnknown@@
H91u^H
EnforceToastCallerCheck
PA_A^A]A\_^]
D9D$$u
LockResource
FwIsGroupPolicyEnforced
l$ VWAVH
`A_A^A\_^[]
DisableAntiVirus
ContainerImages\hvsi.wim
USVWAVH
D$8H;
Data Protection Shield
A^_^][
T$xL+
ExportMitigation
.?AUISecurityAppBrokerSink@SecurityCenter@Windows@@
.?AUIWinSecurityAcl@CommonUtil@@
.?AUIUtilRegListenerCallback@CommonUtil@@
Time Service
VbsSetScenarioEnable
cryptngc.dll
ResolveDelayLoadedAPI
DataProtection_Unknown
MD9MLH
TpmClearWithPolicyOrPPI
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00UIWeakReferenceSource@@@Details@WRL@Microsoft@@
v#fD9t^
Default
Network_3rdP_ActionRecommended
|hK,_
Common_Healthy
Microsoft.Windows.Defender.Shield
CheckTokenMembership
.?AV?$CRefObjectFor@UIEnumFiles@CommonUtil@@@CommonUtil@@
.?AVCFlatEnumFiles@CommonUtil@@
?_Xlength_error@std@@YAXPEBD@Z
MitigationConfiguration.dll
TimeServiceStatus
WaitForMultipleObjects
PA^A\_^]
UATAVH
RtlSetImageMitigationPolicy
D$PE3
@USVATAUAVAWH
EnableControlledFolderAccess
%windir%\system32\UsoClient.exe startscan
DeviceHealthScanThrottle
.didat$7
windowsdefender://
memmove
Windows.SecurityCenter.SecurityAppBroker
O:BAG:BAD:(A;;0x3;;;SY)(A;;0x3;;;BA)(A;;0x3;;;IU)(A;;0x3;;;LS)(A;;0x3;;;AC)
(caller: %p)
fD94Fu
H!\$PE
-cleanpc
9?Zh:
CapturedMitigationPolicyValue
N(9M8u
WDSC-*.etl
MpForcedReboot
CryptCATAdminEnumCatalogFromHash
_callnewh
D$(L!L$ L
OpenProcess
250701214655Z0|1
Timestamp of assessment run
L$xD+
.rtc$TAA
DsrFreeJoinInfo
{(uAH
^HH;^PtQH
D$0=
.?AVDataProtectionShield@ShieldProvider@@
MpAllocMemory
E(H9E
uNH!]8H
Threat_3rdP_SettingsNeeded
L9] u8
Threat_3rdP_ScanUpdatesNeeded
HealthAdvisor_PristineShellContentPresent
040904B0
HardwareSecurityHealth
.CRT$XIC
.rdata$zETW2
H;\$0teH
D9u0vjA
M H1E
MpManagerEnable
SizeofResource
wcstol
w~(cMx
fD9$ru
.?AVHealthAdvisorShield@HealthAdvisor@WSD@@
@USVWAVH
WindowsDeleteString
fB94Su
'zsge
.?AUIHealthAdvisorShield@@
VerifyVersionInfoW
.?AVbad_alloc@std@@
A_A^A]A\_^]
TpmCoreProvisioning.DLL
SYSTEM\Setup
SummaryHealth
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIAppAndBrowserShield@@@Details@WRL@Microsoft@@
.rtc$IZZ
I!<$H
A_A^]
.?AVNetworkProtectionShield@ShieldProvider@@
Network protection Shield Class
Dashboard
JHcH<
Failed to unregister service, hr = %08X
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00U?$ImplementsMarker@VFtmBase@WRL@Microsoft@@@Details@23@@Details@WRL@Microsoft@@
.?AV?$_String_alloc@U?$_String_base_types@GV?$allocator@G@std@@@std@@@std@@
SHLWAPI.dll
ext-ms-win-shell32-shellfolders-l1-1-0.dll
GetComputerNameW
Microsoft-Windows-Defender-AntivirusAllowed
.?AVWeakReferenceImpl@Details@WRL@Microsoft@@
180606185719Z
Defender_EngineUnavailable
Defender_AutoSampleSubmissionDisabled
?_Xinvalid_argument@std@@YAXPEBD@Z
DataProtectionHealth
?{LQ>
CreateTimerQueueTimer
Dashboard Class
7P?O}
SOFTWARE\Policies\Microsoft\Windows Defender Security Center
.rtc$IAA
Threat_3rdP_ScanSettingsUpdatesRecommended
RegQueryValueExW
@SVWH
VarFileInfo
VWAUAVAWH
4$OkoV
WlanCloseHandle
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIApplicationGuardShield@@@Details@WRL@Microsoft@@
LHcH<
ET$hH
SecurityHealthService.pdb
MpThreatQuery
api-ms-win-service-management-l2-1-0.dll
PA_A^_
D9d$h
AllowAppHVSI
Cf9)s
</requestedPrivileges>
TUUUUUU
VWAWH
D9u0vIK
K SUVWAVAWH
StrictHandleCheck
9{Ee@
api-ms-win-core-libraryloader-l1-2-0.dll
RtlUnsubscribeWnfNotificationWaitForCompletion
OSProtection_ResetRequired
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIAppAndBrowserShield@@@Details@WRL@Microsoft@@
H9u8t
CreateFileW
D$pA9
Defender_CloudProtectionDisabled
|$(H;|$Xt}H
AllocateAndInitializeSid
D$`HcH
OneDrive Consumer
.?AUIOSProtectionHealthSink@@
BlackoutNotSet
z~Pe&
BlackoutEndTime
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIDefenderNotificationsSink@@@Details@WRL@Microsoft@@
Local\SM0:%d:%d:%hs
Runtime_platform
!\$DD
AccountProtection_DynamicLock_NotMonitoring
_seh_filter_exe
RegGetValueW
FileTrustCriteria
.?AVDashboardEx@ShieldProvider@@
USVWATAUAVH
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIThreatProtectionStatusSink@@UINetworkProtectionHealthSink@@UIAdvisorEngineSink@HealthAdvisor@WSD@@UIAppAndBrowserNotificationsSink@@UIHardwareNotificationsSink@@UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
__acrt_iob_func
api-ms-win-core-winrt-string-l1-1-0.dll
FormatMessageW
SVWAUAVAWH
InitializeCriticalSectionAndSpinCount
/id DeviceDiagnostic
TPM_Logs
@WAVAWH
HealthAdvisor_StorageHealthOkWithIssues
CoUninitialize
<!-- Copyright (c) Microsoft Corporation -->
App and Browser Shield
Microsoft Corporation1$0"
Event/EventData[Data='AppsDiagnostic']
A_A^A]A\_
.rtc$TZZ
sQPI[5T
DeleteCriticalSection
u$D9U
RaiseException
\$ WH
RtlCaptureContext
SOFTWARE\Microsoft\Windows Security Health\State
N J;<
H;Q(vBH
T$HH+
EnableCameraMicrophoneRedirection
CloseThreadpoolWork
SWATAVAWH
x ATAVAWH
CreateProcessAsUserW
%ls\%ls
Hardware_TpmUpdateNeeded
d|BNeU
api-ms-win-power-base-l1-1-0.dll
.CRT$XLA
<?xml version="1.0" encoding="UTF-8" ?>
t-9\$0
.?AVCRefCountedBase@@
__std_exception_copy
Systray
!\$p3
api-ms-win-service-management-l1-1-0.dll
ShieldHeartbeat
@WATAUAVAW
UnregisterWaitUntilOOBECompleted
WTHelperProvDataFromStateData
!\$(L
GetActiveProcessorCount
AppAndBrowser_AppRepSmartScreenOff
` UAVAWH
Shield Provider Toast
CoResumeClassObjects
u1@8-Fz
.?AUIDeviceDriverResults@@
GetLengthSid
9Edt
T$8H+
LogonUserW
A_A^_
Windows Defender Exploit Guard\Controlled Folder Access
Microsoft Corporation1200
isSmartStorageEnabled
ControlFlowGuard
AppAndBrowser_EdgeSmartScreenOff
Reliability
NtClose
\MsMpLics.dll
Washington1
msvcp_win.dll
terminate
A_A^A\
OptionalFeatures.exe
D$0H;
Shield Provider Agent
UX Configuration
wscsvc
D$x;0H
api-ms-win-core-heap-l2-1-0.dll
CoIncrementMTAUsage
api-ms-win-core-processthreads-l1-1-0.dll
H91u\H
onecoreuap\base\power\batteryalertsmanager\batteryalertsmanager.cpp
D$4A;F
_set_app_type
UseFilter
@USVWATAVAWH
GetSystemTimePreciseAsFileTime
Threat_3rdP_ScanNeeded_SettingsRecommended
!M;` s]H
imageName
^BNQ,^
LastHeartbeat
EHH!]H
UnsupportedSku
api-ms-win-oobe-notification-l1-1-0.dll
api-ms-win-devices-config-l1-1-1.dll
.?AUIWscBrokerManagerSink@SecurityCenter@Windows@@
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIAccountProtectionShield@@@Details@WRL@Microsoft@@
GH9CH
ShieldHeartbeatThrottle
MpTriggerStatusRefreshNotification
Threat_3rdP_SettingsRecommended
RtlLookupFunctionEntry
.?AVCUtilRegEnumKeyValues@CommonUtil@@
internal\sdk\inc\wil\resource.h
GetTraceEnableFlags
L$xH;
FilterFullPath
TpmInit.exe
[%hs(%hs)]
H9E8s1H
Software\Policies\Microsoft\PassportForWork\DynamicLock
QueryPerformanceCounter
effffff
Threat_3rdP_L1_MultipleActionNeeded
CreateThreadpool
DisableNotifications
D$`Li
VY$[X
\$ UVWATAUAVAWH
StringFileInfo
RegNotifyChangeKeyValue
oD$ f
t$ WAVAWH
t$ UWATAUAWH
0A_A^A]A\_
Microsoft YaHei UI
MitigationAuditPolicyValuePostSet
D$hH;
App and Browser protection
gxI3!'
Microsoft.Windows.ImageMitigationPolicy
Side by side passive
G09C0u
SeChangeNotifyPrivilege
@WATAUAVAWH
WasEnabledBy
Threat_3rdP_ScanSettingsNeeded
Vving1
Microsoft Time-Stamp service0
SeTcbPrivilege
$>b~t
7T})gW
Number of Application Errors
.text$mn
.?AUIMarshal@@
H;\$hu
D9h voH
Size(in days) of query search window
9M<t
O:BAG:BAD:(A;;CCDCLCSWRP;;;SY)(A;;CCDCLCSWRP;;;BA)(A;;CCDCLCSWRP;;;IU)(A;;CCDCLCSWRP;;;LS)(A;;0xb;;;AC)S:(ML;;NX;;;LW)
D9l$hu&D9
ClassFactory
L$XH+
9\$Pt H
RegisterServiceCtrlHandlerExW
.?AVbad_array_new_length@std@@
SUVWATAUAVAWH
.?AVDefenderSink@ShieldProvider@@
\$xIc
Threats\ThreatIDDefaultAction
%ls <Query Path='System'> <Select>Event/System[Provider[@Name="EventLog"] and Level <=3 and TimeCreated[timediff(@SystemTime) <=%lu]]</Select> </Query>
systemreset.exe
HealthAdvisorHealth
.?AUIApplicationGuardShield@@
CryptBinaryToStringW
DecodePointer
.?AVFTMEventDelegate@?1???$WaitForCompletion@U?$IAsyncOperationCompletedHandler@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@U?$IAsyncOperation@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@23@@@YAJPEAU?$IAsyncOperation@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@W4tagCOWAIT_FLAGS@@PEAX@Z@
EventWriteTransfer
Q2SWM
T$8H!t$8H
hwp1p0
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIHardwareShield@@@Details@WRL@Microsoft@@
9u@v:H
8\$@t
AllowVirtualGPU
.?AUIHardwareNotificationsSink@@
.?AV?$CRefObjectFor@UIMpPrivateThreadPool@CommonUtil@@@CommonUtil@@
oL$0f
ImportMitigation
CoDecrementMTAUsage
AccountProtection_WindowsHello_Available
api-ms-win-crt-utility-l1-1-0.dll
T$@E3
.?AVCPeriodicTaskManager@ShieldProvider@@
__stdio_common_vsnprintf_s
NtQueryValueKey
L$`H3
Threat_3rdP_Off
D$@E3
@A_A^_^[
.?AVComClientImpersonator@ShieldProvider@@
L$XH;
DataProtection_UnsupportedOSSku
TraceMask
GD9CDu
GREEN
OHcP<
L$ SWH
T$ L!t$
SpecRequiredFreeDiskSpaceInGB
.didat$6
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@U?$IAsyncOperationCompletedHandler@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@VFtmBase@23@@Details@WRL@Microsoft@@
D;{Tr
d$`H;
Company : %ls
Management Provider
WindowsGetStringRawBuffer
Upgrade
DataProtection_Healthy
LowEndThresholdMB
MinutesSinceOSInstall
Software\Microsoft\CleanPC
Threat_3rdP_SettingsUpdatesNeeded
D9l$hu&D9}
_get_initial_wide_environment
ForceFieldShield
t$`A;
8A^_^[
IsDebuggerPresent
MpConfigIteratorClose
PowerGetActiveScheme
AllowCameraMicrophoneRedirection
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
.?AVStrongReference@Details@WRL@Microsoft@@
HA_A^A]A\_^][
.rdata$zETW1
20190116024319Z
SWATAUAVH
A^A\_^]
.?AUIWeakReferenceSource@@
@A_A^A\
u&H!D$0H
RtlQueryImageMitigationPolicy
MpConfigGetValue
t$ H!t$(H
RtlVirtualUnwind
ext-ms-win-networking-wlanapi-l1-1-0.dll
|$ UH
}`E9|$
GetModuleFileNameW
pA_A^_^]
RaiseFailFastException
SkipPPLRegistration
@A^A]A\_^[]
+dBVY
api-ms-win-core-processthreads-l1-1-1.dll
A_A^A]_^
.?AUIMpThreadPool@CommonUtil@@
InstallLocation
.?AVNullEvent@HealthAdvisor@WSD@@
System
L$@H;
AccountProtection_MicrosoftAccount_NotAvailable
|$HH9l$Pt
M H!] H
Defender_WdoRequired
.CRT$XCA
w9X!P/
RoGetActivationFactory
NtQueryInformationProcess
DataProtectionStatus
KERNEL32.dll
A^A]A\_]
NoAction
u\fIy
L9}0u
k UAVAWH
H UWAVH
api-ms-win-eventing-legacy-l1-1-0.dll
Threat_3rdP_UpdatesNeeded_SettingsRecommended
T$8H!\$8
FWph?r
UnhandledExceptionFilter
_set_fmode
.?AUIAppAndBrowserNotificationsSink@@
__p___argc
.?AVPathAdder@ShieldProvider@@
UpdateRunCadence
GetWindowsDirectoryW
api-ms-win-eventing-classicprovider-l1-1-0.dll
FindResourceW
EventUnregister
.?AVCPoolItem@CUtilRegListener@CommonUtil@@
t$ AVH
UVAUAVAWH
U0S0Q
GetVersionExW
Threat_3rdP_ScanSettingsRecommended
@SUVWATAUAVAWH
SetupDiGetClassDevsW
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIExploitShield@@@WRL@Microsoft@@
GetSystemDirectoryW
.?AVDontUseNewUseMake@Details@WRL@Microsoft@@
VS_VERSION_INFO
S-1-5-80-3232712927-1625117661-2590453128-1738570065-3637376297
DynamicLock
CreateWellKnownSid
api-ms-win-core-synch-l1-2-0.dll
SWATAUAVAWH
AppAndBrowserStatus
x UATAUAVAWH
A_A^_^]
w32time
.CRT$XCZ
MpErrorMessageFormat
LsaLookupUserAccountType
A;,$t
DisableLocalAdminMerge
msdt.exe
^(I9n
H;\$0tkH
D9l$huhD
S-1-5-80-1523878533-411328482-2798077809-3098663872-2604013308
EvtClose
Network_ServiceStopped
map/set<T> too long
tCH;2u/H
Exception
L$pH;E
NgcFreeEnumState
.?AV?$RuntimeClassBaseT@$02@Details@WRL@Microsoft@@
\microsoft\windows\waasmedic
IsAsDisableByPolicy
MpConfigDelValue
\hvsicontainerservice.dll
t$XH;
Health Advisor Shield Class
.?AV?$CRefObjectFor@UIUtilRegListenerCallback@CommonUtil@@@CommonUtil@@
MpScanControl
RtlGetActiveConsoleId
USVWH
\$PE3
*System Defaults*
{ AntiVirus : %ls, Exe : %ls , State : %d , SigUpToDate : %ls%ls}
H!k0H
.CRT$XPA
SeBackupPrivilege
L$pE3
WaitForMultipleObjectsEx
HealthAdvisor_ReliabilityStatusAppError
.data
TraceLevel
CRYPT32.dll
L$pH;
ScRunAssessmentEnd
YELLOW
T$$D!t$ H
H;|$hu
PathFileExistsW
Segoe UI SemiBold
SubmitSamplesConsent
0A\_[
MpCleanControl
memset
[%hs]
H!|$@H
ForceField Web Protection Shield Class
/id NetworkDiagnosticsWeb
0A_A^A\_^][
.?AUIOSProtectionShield@@
fA94Au
_crt_atexit
L$xI;
FileTrustOriginNetworkShare
\$ UVWAVAWH
GetProcAddress
l6s+o
Es|0m
ProductName
PillarStatusFlag_AppAndBrowser_EdgeSmartScreenOff
IsRtpEnabled
HardwareSecurityStatus
DuplicateTokenEx
.?AVStorageHealthAssessment@HealthAdvisor@WSD@@
wscapi.dll
Microsoft Corporation1.0,
CryptCATAdminCalcHashFromFileHandle
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@U?$IAsyncOperationCompletedHandler@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@VFtmBase@23@@Details@WRL@Microsoft@@
@8utt
I;_hu
.idata$6
H;t$0s
ImageLoad
RoRegisterActivationFactories
@SUVH
t$`E3
190529185719Z0z1
MpScanResult
Storage Health
DllSurrogate
D$`E3
MpGetRunningMode
CertVerifyCertificateChainPolicy
_8\$`tq
.?AUIMpThreadPoolProvider@CommonUtil@@
D$8L+
api-ms-win-core-heap-l1-1-0.dll
WarningState
Threat_3rdP_NearExpiry
NtEnumerateKey
AccountProtection_DynamicLock_Remote
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00U?$CloakedIid@UIMarshal@@@23@@Details@WRL@Microsoft@@
@A_A^_^]
D$HE3
LocalService
MpConfigClose
fD9t^
.?AVCWString@@
IsRtpByPolicy
GetPwrCapabilities
MpNotificationRegister
H;_pu
UILockdown
D9d$huDH
ChildProcess
Threat protection Shield
0A^A]A\
HvciIncompatibilityScanStart
PA^_^
.?AU?$IAsyncOperationCompletedHandler_impl@U?$AggregateType@PEAVGetDefaultSignInAccountResult@Web@Authentication@Security@Internal@Windows@@PEAUIGetDefaultSignInAccountResult@23456@@Internal@Foundation@Windows@@@Foundation@Windows@@
AppHVSI
t$ UWAVH
FileVersion
@8k8uD
.?AUIRefObject@CommonUtil@@
D9D$,u
%s%02hu%02hu%04hu-%02hu%02hu%02hu-%x-%x
WTSAPI32.dll
|$hA;
L$hH3
FileTrustOriginMarkOfTheWeb
Microsoft Corporation1&0$
windefend
.?AVCUtilRegListener@CommonUtil@@
SVWAVH
AccountProtection_WindowsHello_Available_Dismissed1
p AWH
D9d$hu%D9U
t$ I!s
CoImpersonateClient
1(0&0
Email
<unknown>
rY&'K
t$ E3
pA^_^][
System\CurrentControlSet\Control\DeviceGuard\Scenarios\CredentialGuard
LogonUserExExW
WDSC-
Defender_FullScanDue
$Microsoft Ireland Operations Limited1&0$
@W=7A=
GetProcessMitigationPolicy
UAVAWH
A_A^A\_]
HealthAdvisor_BatterySleepSettingsAlert
Segoe UI Light
.?AVReliabilityAssessment@HealthAdvisor@WSD@@
9D$h}
D8=tT
D;u0s:
SOFTWARE\Microsoft\Windows Security Health
DsrGetJoinInfo
MpConfigSetValue
SetMitigationPolicyFailure
CompareStringOrdinal
FileTimeToLocalFileTime
0A_A^_^[
CoInitializeSecurity
api-ms-win-service-core-l1-1-0.dll
Not running
Unknown exception
l~~!m
L$pA3
ext-ms-win-devmgmt-policy-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
4 WsU
Passive
@VWAV
H;_8u
fD9d~
MpManagerStatusQueryEx
Threat_3rdP_ScanUpdatesNeeded_SettingsRecommended
Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0
WaasMedicAction
__std_terminate
MakeAbsoluteSD
Network_3rdP_Snoozed
Threat_EnterpriseG
.?AVAssessmentQueueItem@HealthAdvisor@WSD@@
.?AVCMpShutter@CommonUtil@@
513h[
Upgrade : %ls
CoTaskMemAlloc
Defender_ServiceStopped
%ls%ls%ls
@UVWATAUAVAWH
.?AVWscBrokerSink@ShieldProvider@@
CreateMutexExW
@%systemroot%\system32\SecurityHealthAgent.dll,-1001
EventRegister
d$`I;
9;v[H
AccountProtectionShield
@UVWH
A_A^_^]
DeleteFileW
CoInitializeEx
L$hH9
GetPrivateProfileStringW
MpThreatEnumerate
.?AVScanManager@ShieldProvider@@
]erZS@
H;|$X
L$ H;
VbsIsRecommended
.?AU?$RuntimeClassFlags@$03@WRL@Microsoft@@
.?AVout_of_range@std@@
HeapAlloc
A_A^A\_^
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIAccountProtectionNotificationsSink@@UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
FAILED. This command is supported only if dev mode license is present, hr = %08X
0A__^
\SecurityProductInformation.ini
d$`A;
Failed to load plugin %ls, hr = %08X
SVWAVAWH
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIWeakReference@@@WRL@Microsoft@@
D9{Tv(H
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00UIMarshal@@@Details@WRL@Microsoft@@
SOFTWARE\Microsoft\Windows Defender Security Center
.data$brc
\$xL;
L$pH3
9w,v[H
Y3SnA7o
H3E H3E
InternalName
.?AVILockable@@
DisableClearTpmButton
$PB2r
D9d$hu%9U
G,9C,u
malloc
Unknown switch.
m0D9m
IsProcessorFeaturePresent
M@L9y
L$pD3
uI.[j,}fl
NtOpenKey
UnknownSku
IsProviderRuntimeRegistered
.rsrc$02
IsCfaByPolicy
H9u@t
;D$ u
MonitoringPulse
__p___wargv
Failed to register AppID, hr = %08X
EnableTrace
H;\$0tpH
FindNextFileW
OLEAUT32.dll
HealthAdvisor_TimeServiceStatusDisabled
kernel32.dll
CoSetProxyBlanket
/launch
MpThreatOpen
.?AVNWPServiceWaitCancel@ShieldProvider@@
.text$di
FindClose
DD9D$4u
MpGetAsrBlockedActions
A8V0u
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$0A@UISecurityAppBrokerSink@SecurityCenter@Windows@@UIWeakReferenceSource@@@Details@WRL@Microsoft@@
L$XtQ
9+tPH
9{ v)H
VWATAVAWH
SeSecurityPrivilege
MpManagerOpen
UpdateMonitorBinaryCorruptionEnd
L$ 9y8v=
GetCurrentProcessId
L$XH3
api-ms-win-service-winsvc-l1-1-0.dll
RegCreateKeyExW
ConvertStringSidToSidW
@A^_^[]
I0G1-0+
.rdata$zETW0
8T$>u
$&v6v
t$hE3
CreateThreadpoolWork
StringFromCLSID
L!d$xL!d$pH
api-ms-win-core-file-l1-1-0.dll
.?AUIHardwareShield@@
+D$x3
pA_A^_^[
.?AV?$CWinSecurityAclAlloc@U?$CAutoLocalPtr@PEAU_ACL@@@CommonUtil@@@CommonUtil@@
DelayLoadFailureHook
0A^_^][
WaitForSingleObjectEx
FWClosePolicyStore
%s\Logs
D9l$hu#D9}
Defender_QuickScanDue
Microsoft-Windows-WaasMedic-Enable-Remediations
L$ E;
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$0A@$0A@UIExploitShield@@@Details@WRL@Microsoft@@
api-ms-win-eventing-controller-l1-1-0.dll
\]#17
H;_hu
.?AVShieldManagementProvider@ShieldProvider@@
AccountProtection_DynamicLock_NotConfigured
U@!]@H
Xdj[qD4
sspicli.dll
DestroyEnvironmentBlock
errorCode
@USWH
.?AVApplicationGuardShield@ShieldProvider@@
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$02@WRL@Microsoft@@UISecurityAppBrokerSink@SecurityCenter@Windows@@@WRL@Microsoft@@
@USVWH
CoTaskMemFree
H9kH@
PostThreadMessageW
%ls</QueryList>
.?AUIAppAndBrowserShield@@
H;\$0tzH
Containers\Serviced\WindowsDefenderApplicationGuard.wim
Common_Unknown
IsDefenderAvDisabled
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIHardwareShield@@@Details@WRL@Microsoft@@
.CRT$XIZ
PathCchAppend
Storage Health Metrics
HideSystray
+|$xA3
.?AVinvalid_argument@std@@
OsProtectionStatus
PA__^
DsrGetCxhScenarioInfo
EncodePointer
!This program cannot be run in DOS mode.
+YBu3
Failed to unregister AppID, hr = %08X
RunCadenceInHours
Msg:[%ws]
.?AU?$Implements@U?$RuntimeClassFlags@$02@WRL@Microsoft@@U?$CloakedIid@UIMarshal@@@23@@WRL@Microsoft@@
SystemCallDisable
@A^_^
A_A^A]_^[]
WaitForThreadpoolWorkCallbacks
CreateServiceW
api-ms-win-eventing-provider-l1-1-0.dll
.?AVCSecurityAttributesHolder@CommonUtil@@
Lct$$H
.?AUIExplicitAccessControl@CommonUtil@@
.?AVIRefCounted@@
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$0A@UIAccountProtectionShield@@@Details@WRL@Microsoft@@
x=@8uut7
A_A^A]A\_^[
.?AVCMpThreadPoolItemBase@CommonUtil@@
Redmond1
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
RegisterWaitForSingleObjectEx
api-ms-win-core-kernel32-legacy-l1-1-1.dll
winsta0\default
L9h0t|A
S-1-5-80-259296475-4084429506-1152984619-38739575-565535606
PathToSignedReportingExe
A^_^[]
ProviderState
L9]0u@
USER32.dll
RegisterGPNotification
GetCurrentThread
A^A\_
OpenServiceW
t"D8=
a4x6
Yu Gothic UI Light
L$X99vIL
Defender_RtpDisabled
api-ms-win-core-synch-l1-1-0.dll
.?AV?$RuntimeClass@U?$RuntimeClassFlags@$01@WRL@Microsoft@@UIDefenderNotificationsSink@@@WRL@Microsoft@@
OsProtectionHealth
ROOT\CIMV2
Microsoft-Windows-Immersive-Shell
D$ fD
OSProtection_Healthy
D$@9K\u
L9{@u
HealthAdvisorStatus
OpenSemaphoreW
D$xH9X
api-ms-win-core-psapi-l1-1-0.dll
.?AUIThreatProtectionStatusSink@@
.9|$$u
r~akow
.?AUIAccountProtectionShield@@
IsCfaEnabled
folder
EnterCriticalSection
.CRT$XCU
Software\Microsoft\Windows Defender
G@9C@u
,gyC8oWSwmk2EVQrFoTsElvTsAyxniNZ1a9ux3hBSQl0=0Z
\$ E3
ConvertStringSecurityDescriptorToSecurityDescriptorW
_errno
LookupAccountNameW
SOFTWARE\Microsoft\Windows Defender\Real-Time Protection
Threat_3rdP_ScanNeeded
Threat_3rdP_SettingsUpdatesRecommended
Network_PrivateFwOff
onecore\windows\hvsi\policymanager\lib\hvsipolicymanager.cpp
DataProtectionCloudBackupProviderUpdate
CryptCATAdminReleaseCatalogContext
%hs(%d) tid(%x) %08X %ws
oK0D$"<
.?AUIEnumFiles@CommonUtil@@
2333333
X VWAVH
G49C4
MpOfflineScanStatusQuery
MpUpdateStartEx
.?AVUpdateMonitorAssessment@UpdateMonitor@WSD@@
.?AVShieldProviderToast@ShieldProvider@@
SeSystemEnvironmentPrivilege
GetCurrentProcess
I;]Pu
fD96u"3
Leelawadee UI Semilight
Failed to unregister class %ls, hr = %08X
AccountProtection_Healthy
QueryMitigationPolicy
MpScanStart
MpIsGivenRunningModeSupported
D$pD3
d$ E3
OSProtection_RebootRequired
MpQueryDefaultFolderGuardList
NgcEnumContainers
advapi32.dll
.?AU?$IAsyncOperationCompletedHandler@PEAU?$IVectorView@PEAVWebAccount@Credentials@Security@Windows@@@Collections@Foundation@Windows@@@Foundation@Windows@@
.?AVTracer@ShieldProvider@@
{2eb6d15c-5239-41cf-82fb-353d20b816cf}
PeriodicTaskInitialDelay
PillarStatusFlag_HealthAdvisor_TimeServiceStatusDisabled
LocalFree
C4~$vP>C
ExtensionPointDisable
D$D;E
L9o@t
`A^_]
.?AVResultException@wil@@
BuildLabEx
S-1-5-80-1601830629-990752416-3372939810-977361409-3075122917
</assembly>
Network_3rdP_L2L1_ActionNeeded
tFH;:u2
.didat$3
.?AVAppAndBrowserShield@ShieldProvider@@
ms-cxh://NTHNGCUPSELL
Translation
api-ms-win-power-setting-l1-1-0.dll
D$`D3
u2V3I
A_A^A]A\_^]
H;H(u
L$ VWAWH
Network_DomainFwOff
LastSuccessfullyAppliedPolicy
MpGetSampleListRequiringConsent
Windows Defender Exploit Guard\ASR\Rules
Threat_3rdP_L1_MultipleActionRecommended
freeMb
WilError_02
DataProtection_DataRestoreRequired
Threat_3rdP_L1_SingleActionRecommended
x\fD9
GetNamedSecurityInfoW
RegisterTraceGuidsW
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIOSProtectionHealthSink@@UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
(A_A^_^][
Threat_3rdP_NoAction
L9} uF
SetupDiEnumDeviceInfo
fD9<Gu
WscRegisterForChanges
.?AVCMpSimpleThreadPool@CommonUtil@@
.CRT$XIAC
WscStatusAvFw
ProductVersion
WinSta0
dsreg.dll
WlanFreeMemory
__p__commode
.?AV?$RuntimeClassImpl@U?$RuntimeClassFlags@$02@WRL@Microsoft@@$00$00$0A@UIWscBrokerManagerSink@SecurityCenter@Windows@@@Details@WRL@Microsoft@@
RtlQueryWnfStateData
zuRH9
FwActivate
.didat$4
AccountProtection_WindowsHello_Available_Dismissed2
ServicesActive
__CxxFrameHandler3
L9}0u^
H WAVAWH
IsSampleSubmissionEnabled
`A_A^_^[
.CRT$XIAA
@A_A^A\_^[]
|$xI;
fD9<Au
Windows.Internal.Security.SmartScreen.AppReputationService
1o?-XfF
WscJsonStatusAvFw
A_A^A\_^[]
` AVH
Windows
ForceField_Unknown
SleepConditionVariableCS
_register_onexit_function
SUVWATAVAWH
returnCode
.?AUIStorageHealthResults@@
D$0E3
8A_A^_^][
Account Protection Shield Class
LcMxE
Notifications
.idata$2
HideTPMTroubleshooting
SubmitThreadpoolWork
api-ms-win-core-debug-l1-1-0.dll
x AVH
Yu Gothic UI
{ AvList : [
EnableVirtualGPU
CLSID\{bfe74cfe-3264-4d44-a930-64b77e14b685}
1/0-0
NHcH<
toast type
-{>J@
H9l$Pt H
CoReleaseServerProcess
L$dE3
t$`H;
InitiateSystemShutdownExW
.?AVDefenderShield@ShieldProvider@@
.tls$
fD94Cu
+D$h3
DataProtection_UnsupportedODVersion
LookupPrivilegeValueW
.?AV?$CWinSecurityAclAlloc@V?$CAutoUniquePtr@U_ACL@@X@CommonUtil@@@CommonUtil@@
.xdata
L9] uQ
.gfids
performremediation
G89C8
t$PHi
\$`Ii
Hardware_Unknown
Segoe Pseudo
LaunchPermission
WTSQueryUserToken
SOFTWARE\Microsoft\Windows Security Health\State\Dynamic
statusCode
Software\Microsoft\Policies\PassportForWork\DynamicLock
%hs(%d)\%hs!%p:
Operating System
RoActivateInstance
Environment
Update Monitor
mitigationOption
N0L0J
vector<T> too long
@.didat
SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity
.?AVCClassFactory@@
System\WaaS\WaasMedic
GetModuleHandleExW
Failed to register service, hr = %08X
%ProgramFiles%\Windows Defender
Defender_Unknown
QueryMitigationAuditPolicyFailure
_cexit
Device security
MpOfflineScanInstall
GetSecurityDescriptorOwner
GetLocalTime
FontDisable
_invalid_parameter_noinfo_noreturn
M(H!](H
VG2/iI
9+v9H
Common_ThirdParty_UnknownStatus
"%s" %s
PeriodicTaskPeriodicity
CloseThreadpool
RegOpenCurrentUser
t$ WATAUAVAWH
MpConfigIteratorEnum
ConfigManagerErrorCode
GetLastError
@USVWATAUAVAWH
tII9n
Defender Shield
.?AVCRefObject@CommonUtil@@
Embedding
AuthD
LogHr
O:BAG:BAD:(A;;CCDCLC;;;SY)(A;;CCDCLC;;;BA)(A;;CCDCLC;;;IU)(A;;CCDCLC;;;LS)(A;;CCDCLC;;;AC)
E@H;EP
p WATAUAVAWH
A_A]A\_]
DataProtectionEnterWarning
.?AU?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00UIForceFieldSink@@UIDataProtectionSink@@@Details@WRL@Microsoft@@
AUAVAWH
H;0u2
@+ljM
|$ UAVAWH
fD94Ku
LcEpH
T$@H+
KpH91u^H
@A^A\_^]
fD94Hu
HA_A^_^][
u'D9U
Unknown
fD94Gu
api-ms-win-security-sddl-l1-1-0.dll
api-ms-win-security-lsalookup-l2-1-0.dll
microsoft-windows-diagnosis-scripted/operational
Network_3rdP_L2L1_MultipleActionRecommended
ShieldProviderToast
Action
HvciIncompatibilityScanGetResult
StartServiceW
PurgeAgeIndays
Threat_3rdP_SettingsNeeded_ScanUpdatesRecommended
.?AU?$Selector@U?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00$$V@Details@WRL@Microsoft@@U?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00U?$ImplementsMarker@VFtmBase@WRL@Microsoft@@@Details@23@@234@@Details@WRL@Microsoft@@
OSProtection_Unknown
pA_A^A]A\_^]
DeleteService
M@;1r
_invalid_parameter_noinfo
invalid stoi argument
f9)sB
RegisterWaitUntilOOBECompleted
api-ms-win-core-timezone-l1-1-0.dll
Leelawadee UI
D9d$`
@A^^]
A_A^A]A\]
A_A^A]_]
AccountProtection_Unknown
CopySid
.?AUIManagementShield@@
SpyNetReporting
HvciIsActive
.?AUIThreatProtectionShield@@
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
`.rdata
.?AVCMpThreadPoolVistaHelper@CommonUtil@@
.?AUImplementsBase@Details@WRL@Microsoft@@
bWti^
Hardware_HvciOnRecommended
.?AU?$Selector@VFtmBase@WRL@Microsoft@@U?$ImplementsHelper@U?$RuntimeClassFlags@$01@WRL@Microsoft@@$00U?$ImplementsMarker@VFtmBase@WRL@Microsoft@@@Details@23@@Details@23@@Details@WRL@Microsoft@@
RegCloseKey
0A_A^A\_]
t^@8=A
Windows.SecurityCenter.WscBrokerManager
|$ UATAUAVAWH
H;D$(u
.?AUISecurityAttributes@CommonUtil@@