|
| 1 | +(cmd) python etw\uac_trace.py |
| 2 | +Recording UAC event in file <uac.trace> using session named <MY_UAC_MONITOR> |
| 3 | +0x1d65bb1febaceea: <EventRecord provider="68FDD900-4A3E-11D1-84F4-0000F80464E3" id=0> |
| 4 | + guid: 68FDD900-4A3E-11D1-84F4-0000F80464E3 |
| 5 | + id: 0 |
| 6 | + opcode: 0 |
| 7 | + level: 0 |
| 8 | + data: '\x01\n\x01\x05\xbbG\x04-D\xd5\xff\xb1[\xd6\x01Zb\x02\t\x01\x04\xf0\x0c\t\x06\xc4\xff\xff\xff@tzres.dll,-302\n\x05\x03@tzres.dll,-301\x03\x05\x02\xc4\xff\xff\xff\xc0\x92\x1c\xd2D[\xd6\x01\x80\x96\x98\xea\xce\xba\xfe\xb1[\xd6\x01\x01MY_UAC_MONITORC:\\Users\\hakril\\Documents\\projets\\PythonForWindows\\samples\\uac.trace' |
| 9 | +[...] |
| 10 | +0x1d65bb1fec4c011: <EventRecord provider="DEB74A23-5444-3F3B-924B-0E653973F55A" id=11> |
| 11 | + guid: DEB74A23-5444-3F3B-924B-0E653973F55A |
| 12 | + id: 11 |
| 13 | + opcode: 0 |
| 14 | + level: 0 |
| 15 | + data: '\x9e\x06\x04\x19\x14\x04\x08\x04\xff\xff\xff\xffWinSta0\\DefaultC:\\Windows\\System32\\mmc.exe"C:\\Windows\\System32\\mmc.exe" BAD_MMC_FILENAMEC:\\Users\\hakril\\Documents\\projets\\PythonForWindows\\samples' |
| 16 | +0x1d65bb1fec4e48b: <EventRecord provider="C0B508D3-5459-339F-A213-889C238CA5B1" id=10> |
| 17 | + guid: C0B508D3-5459-339F-A213-889C238CA5B1 |
| 18 | + id: 10 |
| 19 | + opcode: 0 |
| 20 | + level: 0 |
| 21 | + data: 'C:\\WINDOWS\\SysWOW64\\mmc.exe"C:\\WINDOWS\\SysWOW64\\mmc.exe" BAD_MMC_FILENAME` ' |
| 22 | +0x1d65bb1fec7c8eb: <EventRecord provider="C0B508D3-5459-339F-A213-889C238CA5B1" id=13> |
| 23 | + guid: C0B508D3-5459-339F-A213-889C238CA5B1 |
| 24 | + id: 13 |
| 25 | + opcode: 0 |
| 26 | + level: 0 |
| 27 | + data: 'C:\\WINDOWS\\SysWOW64\\mmc.exe' |
| 28 | +0x1d65bb1fec7c8f0: <EventRecord provider="C0B508D3-5459-339F-A213-889C238CA5B1" id=14> |
| 29 | + guid: C0B508D3-5459-339F-A213-889C238CA5B1 |
| 30 | + id: 14 |
| 31 | + opcode: 0 |
| 32 | + level: 0 |
| 33 | + data: '"C:\\WINDOWS\\SysWOW64\\mmc.exe" BAD_MMC_FILENAME' |
| 34 | +[...] |
| 35 | +0x1d65bb1feca018d: <EventRecord provider="172FF31C-2D80-31A6-FCA8-EB000D380666" id=11> |
| 36 | + guid: 172FF31C-2D80-31A6-FCA8-EB000D380666 |
| 37 | + id: 11 |
| 38 | + opcode: 0 |
| 39 | + level: 0 |
| 40 | + data: 'C:\\WINDOWS\\SysWOW64\\mmc.exe' |
| 41 | +0x1d65bb1feca030d: <EventRecord provider="172FF31C-2D80-31A6-FCA8-EB000D380666" id=25> |
| 42 | + guid: 172FF31C-2D80-31A6-FCA8-EB000D380666 |
| 43 | + id: 25 |
| 44 | + opcode: 0 |
| 45 | + level: 0 |
| 46 | + data: 'C:\\WINDOWS\\SysWOW64\\mmc.exe\x08\x02TRUEFALSE\x10' |
| 47 | +0x1d65bb1fecfcdc0: <EventRecord provider="172FF31C-2D80-31A6-FCA8-EB000D380666" id=27> |
| 48 | + guid: 172FF31C-2D80-31A6-FCA8-EB000D380666 |
| 49 | + id: 27 |
| 50 | + opcode: 0 |
| 51 | + level: 0 |
| 52 | + data: '\x05TRUETRUE' |
| 53 | +[...] |
0 commit comments