ctf-writeup/2020/flare-on/7_-_re_crowd/WindowsAPIhash-master/advapi32.txt
2021-02-05 23:42:57 +07:00

806 lines
25 KiB
Plaintext

CC326262 = WriteEncryptedFileRaw
EE5F8AA9 = WmiSetSingleItemW
EE5F8ABF = WmiSetSingleItemA
F30952B6 = WmiSetSingleInstanceW
F30952A0 = WmiSetSingleInstanceA
C7666583 = WmiReceiveNotificationsW
C7666595 = WmiReceiveNotificationsA
B775AF30 = WmiQuerySingleInstanceW
B447F4DE = WmiQuerySingleInstanceMultipleW
B447F4C8 = WmiQuerySingleInstanceMultipleA
B775AF26 = WmiQuerySingleInstanceA
FB4547D4 = WmiQueryGuidInformation
78A0957D = WmiQueryAllDataW
F98821E4 = WmiQueryAllDataMultipleW
F98821F2 = WmiQueryAllDataMultipleA
78A0956B = WmiQueryAllDataA
E2709DEB = WmiOpenBlock
1330F5FE = WmiNotificationRegistrationW
1330F5E8 = WmiNotificationRegistrationA
0E9B2F8C = WmiMofEnumerateResourcesW
0E9B2F9A = WmiMofEnumerateResourcesA
2B6F9E86 = WmiFreeBuffer
0B4FA0B0 = WmiFileHandleToInstanceNameW
0B4FA0A6 = WmiFileHandleToInstanceNameA
960BA624 = WmiExecuteMethodW
960BA632 = WmiExecuteMethodA
A2C0C18B = WmiEnumerateGuids
202EC15B = WmiDevInstToInstanceNameW
202EC14D = WmiDevInstToInstanceNameA
C43984A6 = WmiCloseBlock
F32E5D1E = UsePinForEncryptedFilesW
F32E5D08 = UsePinForEncryptedFilesA
4DDBD842 = UpdateTraceW
4DDBD854 = UpdateTraceA
2A5084E9 = UnregisterTraceGuids
BC7B7228 = UnregisterIdleTask
E119AEA6 = UnlockServiceDatabase
D460ADE0 = UninstallApplication
9E999C03 = TrusteeAccessToObjectW
9E999C15 = TrusteeAccessToObjectA
FA7A6F2E = TreeSetNamedSecurityInfoW
FA7A6F38 = TreeSetNamedSecurityInfoA
33415E00 = TreeResetNamedSecurityInfoW
33415E16 = TreeResetNamedSecurityInfoA
DF7AE974 = TraceSetInformation
761E9C0F = TraceMessageVa
DDB9D87A = TraceMessage
3E841082 = TraceEventInstance
2C1AF872 = TraceEvent
B5058B0A = SystemFunction041
B5058B0B = SystemFunction040
B505888D = SystemFunction036
B505888E = SystemFunction035
B505888F = SystemFunction034
B5058888 = SystemFunction033
B5058889 = SystemFunction032
B505888A = SystemFunction031
B505888B = SystemFunction030
B5058802 = SystemFunction029
B5058803 = SystemFunction028
B505880C = SystemFunction027
B505880D = SystemFunction026
B505880E = SystemFunction025
B505880F = SystemFunction024
B5058808 = SystemFunction023
B5058809 = SystemFunction022
B505880A = SystemFunction021
B505880B = SystemFunction020
B5058982 = SystemFunction019
B5058983 = SystemFunction018
B505898C = SystemFunction017
B505898D = SystemFunction016
B505898E = SystemFunction015
B505898F = SystemFunction014
B5058988 = SystemFunction013
B5058989 = SystemFunction012
B505898A = SystemFunction011
B505898B = SystemFunction010
B5058902 = SystemFunction009
B5058903 = SystemFunction008
B505890C = SystemFunction007
B505890D = SystemFunction006
B505890E = SystemFunction005
B505890F = SystemFunction004
B5058908 = SystemFunction003
B5058909 = SystemFunction002
B505890A = SystemFunction001
D8E73059 = StopTraceW
D8E7304F = StopTraceA
4DDD348A = StartTraceW
4DDD349C = StartTraceA
1CA1FD39 = StartServiceW
1B529B72 = StartServiceCtrlDispatcherW
1B529B64 = StartServiceCtrlDispatcherA
1CA1FD2F = StartServiceA
5D08F35B = SetUserFileEncryptionKeyEx
468D7423 = SetUserFileEncryptionKey
8C91096B = SetTraceCallback
D4ECC75C = SetTokenInformation
A16FE0FD = SetThreadToken
80C6B740 = SetServiceStatus
F81C4F9A = SetServiceObjectSecurity
34E9499D = SetServiceBits
9ED90EDA = SetSecurityInfoExW
9ED90ECC = SetSecurityInfoExA
43946CF6 = SetSecurityInfo
CE303C3A = SetSecurityDescriptorSacl
9E45D624 = SetSecurityDescriptorRMControl
DADD5994 = SetSecurityDescriptorOwner
5A7D1196 = SetSecurityDescriptorGroup
CCD03C3A = SetSecurityDescriptorDacl
5445319B = SetSecurityDescriptorControl
65018B7E = SetSecurityAccessMask
14DF2CFD = SetPrivateObjectSecurityEx
3814537C = SetPrivateObjectSecurity
6D523BCB = SetNamedSecurityInfoW
8EF66703 = SetNamedSecurityInfoExW
8EF66715 = SetNamedSecurityInfoExA
6D523BDD = SetNamedSecurityInfoA
E29136DD = SetKernelObjectSecurity
AD60E377 = SetInformationCodeAuthzPolicyW
E219C688 = SetInformationCodeAuthzLevelW
5A9B2FDD = SetFileSecurityW
5A9B2FCB = SetFileSecurityA
6226DD65 = SetEntriesInAuditListW
6226DD73 = SetEntriesInAuditListA
25AE42B7 = SetEntriesInAclW
25AE42A1 = SetEntriesInAclA
47377E97 = SetEntriesInAccessListW
47377E81 = SetEntriesInAccessListA
39968B1D = SetEncryptedFileMetadata
762BE525 = SetAclInformation
7A24EC61 = SaferiSearchMatchingHashRules
24D6FE0E = SaferiRecordEventLogEntry
96FAB802 = SaferiPopulateDefaultsInRegistry
E51854CB = SaferiIsExecutableFileType
1E5C04F7 = SaferiIsDllAllowed
5CE7FC1C = SaferiCompareTokenLevels
8DF02930 = SaferiChangeRegistryScope
D70528FE = SaferSetPolicyInformation
BBDAE993 = SaferSetLevelInformation
38CFDE0A = SaferRecordEventLogEntry
05137DC0 = SaferIdentifyLevel
D7052A7E = SaferGetPolicyInformation
BBDAE996 = SaferGetLevelInformation
9F2096BE = SaferCreateLevel
C36D4157 = SaferComputeTokenFromLevel
2E0EC02E = SaferCloseLevel
9F96FDBB = RevertToSelf
03543100 = ReportEventW
03543116 = ReportEventA
2B794B56 = RemoveUsersFromEncryptedFile
B67C7133 = RemoveTraceCallback
F1EA62DC = RegisterWaitChainCOMCallback
2847290A = RegisterTraceGuidsW
2847291C = RegisterTraceGuidsA
16B6D738 = RegisterServiceCtrlHandlerW
B5CAB9FA = RegisterServiceCtrlHandlerExW
B5CAB9EC = RegisterServiceCtrlHandlerExA
16B6D72E = RegisterServiceCtrlHandlerA
96953228 = RegisterIdleTask
EC70ED90 = RegisterEventSourceW
EC70ED86 = RegisterEventSourceA
A2CC7A33 = RegUnLoadKeyW
A2CC7A25 = RegUnLoadKeyA
CE5CF912 = RegSetValueW
3E400FC0 = RegSetValueExW
3E400FD6 = RegSetValueExA
CE5CF904 = RegSetValueA
782CEC50 = RegSetKeyValueW
782CEC46 = RegSetKeyValueA
39F1B40A = RegSetKeySecurity
BEDEEFD3 = RegSaveKeyW
BBF053E0 = RegSaveKeyExW
BBF053F6 = RegSaveKeyExA
BEDEEFC5 = RegSaveKeyA
3CCC37F1 = RegRestoreKeyW
3CCC37E7 = RegRestoreKeyA
3FFC0F79 = RegReplaceKeyW
3FFC0F6F = RegReplaceKeyA
0E731084 = RegRenameKey
6E246019 = RegQueryValueW
1802E7DE = RegQueryValueExW
1802E7C8 = RegQueryValueExA
6E24600F = RegQueryValueA
BDC97F73 = RegQueryReflectionKey
356031AA = RegQueryMultipleValuesW
356031BC = RegQueryMultipleValuesA
BDF4DB0F = RegQueryInfoKeyW
BDF4DB19 = RegQueryInfoKeyA
68D5BB23 = RegOverridePredefKey
3F11E989 = RegOpenUserClassesRoot
0EE6AB4B = RegOpenKeyW
E6EE6F63 = RegOpenKeyTransactedW
E6EE6F75 = RegOpenKeyTransactedA
AAD67FEE = RegOpenKeyExW
AAD67FF8 = RegOpenKeyExA
0EE6AB5D = RegOpenKeyA
17617A40 = RegOpenCurrentUser
266722A7 = RegNotifyChangeKeyValue
9E060EC8 = RegLoadMUIStringW
9E060EDE = RegLoadMUIStringA
AEE0D76B = RegLoadKeyW
AEE0D77D = RegLoadKeyA
7EEC8865 = RegLoadAppKeyW
7EEC8873 = RegLoadAppKeyA
DA5CF912 = RegGetValueW
DA5CF904 = RegGetValueA
99F1B40A = RegGetKeySecurity
DA9F55E4 = RegFlushKey
F65A7D83 = RegEnumValueW
F65A7D95 = RegEnumValueA
3EF2D3CB = RegEnumKeyW
B4F673EB = RegEnumKeyExW
B4F673FD = RegEnumKeyExA
3EF2D3DD = RegEnumKeyA
C0CE0143 = RegEnableReflectionKey
87F62529 = RegDisableReflectionKey
FF70A9C4 = RegDisablePredefinedCacheEx
2CF3FDC2 = RegDisablePredefinedCache
560C7C5C = RegDeleteValueW
560C7C4A = RegDeleteValueA
34CE50CA = RegDeleteTreeW
34CE50DC = RegDeleteTreeA
398C5293 = RegDeleteKeyW
D1FFE640 = RegDeleteKeyValueW
D1FFE656 = RegDeleteKeyValueA
3C50196E = RegDeleteKeyTransactedW
3C501978 = RegDeleteKeyTransactedA
14A07234 = RegDeleteKeyExW
14A07222 = RegDeleteKeyExA
398C5285 = RegDeleteKeyA
AE9E4290 = RegCreateKeyW
F8D4198B = RegCreateKeyTransactedW
F8D4199D = RegCreateKeyTransactedA
90A097F0 = RegCreateKeyExW
90A097E6 = RegCreateKeyExA
AE9E4286 = RegCreateKeyA
8D8CE869 = RegCopyTreeW
8D8CE87F = RegCopyTreeA
A85C1CC9 = RegConnectRegistryW
0736D640 = RegConnectRegistryExW
0736D656 = RegConnectRegistryExA
A85C1CDF = RegConnectRegistryA
DB355534 = RegCloseKey
095ADCD2 = ReadEventLogW
095ADCC4 = ReadEventLogA
C6B61661 = ReadEncryptedFileRaw
200351DA = QueryUsersOnEncryptedFile
C9DD000A = QueryTraceW
C9DD001C = QueryTraceA
F6C712F4 = QueryServiceStatusEx
C033DB1C = QueryServiceStatus
A45CBAF6 = QueryServiceObjectSecurity
9D3D3EC2 = QueryServiceLockStatusW
9D3D3ED4 = QueryServiceLockStatusA
EBAAC4EF = QueryServiceConfigW
EBAAC4F9 = QueryServiceConfigA
D5624522 = QueryServiceConfig2W
D5624534 = QueryServiceConfig2A
62AAE99C = QuerySecurityAccessMask
8AE29566 = QueryRecoveryAgentsOnEncryptedFile
5EFE7566 = QueryAllTracesW
5EFE7570 = QueryAllTracesA
AD99A2CF = ProcessTrace
E4ADF62A = ProcessIdleTasksW
FBC95BEC = ProcessIdleTasks
E0ACBB18 = PrivilegedServiceAuditAlarmW
E0ACBB0E = PrivilegedServiceAuditAlarmA
56FFD371 = PrivilegeCheck
0BF2252D = PerfStopProvider
AA8FE9C5 = PerfStartProviderEx
2CF6AA3F = PerfStartProvider
8D117003 = PerfSetULongLongCounterValue
196925ED = PerfSetULongCounterValue
81768094 = PerfSetCounterSetInfo
4AA0C7B4 = PerfSetCounterRefValue
00E678C8 = PerfQueryInstance
6C2CE1AC = PerfQueryCounterSetRegistrationInfo
8AAFF979 = PerfQueryCounterInfo
8B0C3077 = PerfQueryCounterData
4C93C972 = PerfOpenQueryHandle
21409DEC = PerfIncrementULongLongCounterValue
DC77FB17 = PerfIncrementULongCounterValue
5DF8AEEF = PerfEnumerateCounterSetInstances
13FB2774 = PerfEnumerateCounterSet
2790769A = PerfDeleteInstance
8526BA3D = PerfDeleteCounters
2140F55C = PerfDecrementULongLongCounterValue
DC717017 = PerfDecrementULongCounterValue
1EE1579A = PerfCreateInstance
FE66E9F3 = PerfCloseQueryHandle
A53217EC = PerfAddCounters
DCF34857 = OpenTraceW
DCF34841 = OpenTraceA
528A93E4 = OpenThreadWaitChainSession
B96CA1C0 = OpenThreadToken
83969972 = OpenServiceW
83969964 = OpenServiceA
A06E458A = OpenSCManagerW
A06E459C = OpenSCManagerA
80DBBE07 = OpenProcessToken
08887DD7 = OpenEventLogW
08887DC1 = OpenEventLogA
5E0AE215 = OpenEncryptedFileRawW
5E0AE203 = OpenEncryptedFileRawA
FA2EC4C0 = OpenBackupEventLogW
FA2EC4D6 = OpenBackupEventLogA
255DAFD9 = ObjectPrivilegeAuditAlarmW
255DAFCF = ObjectPrivilegeAuditAlarmA
1C55A1C6 = ObjectOpenAuditAlarmW
1C55A1D0 = ObjectOpenAuditAlarmA
C2F1B3A9 = ObjectDeleteAuditAlarmW
C2F1B3BF = ObjectDeleteAuditAlarmA
24597E49 = ObjectCloseAuditAlarmW
24597E5F = ObjectCloseAuditAlarmA
9B6643F4 = NotifyServiceStatusChangeW
9B6643E2 = NotifyServiceStatusChangeA
4736CC87 = NotifyServiceStatusChange
EFFD1347 = NotifyChangeEventLog
24A9A4BE = NotifyBootConfigStatus
B96DA355 = MapGenericMask
43BCA05D = MakeSelfRelativeSD
31D7E0DB = MakeAbsoluteSD2
D263AFC1 = MakeAbsoluteSD
8CCEC5F7 = MSChapSrvChangePassword2
8B199D8B = MSChapSrvChangePassword
4110ACCA = MD5Update
593A82D7 = MD5Init
6DA0A140 = MD5Final
4110A8CA = MD4Update
493A82D7 = MD4Init
6DA0A148 = MD4Final
77B8EE3E = LsaStorePrivateData
FBC31C4C = LsaSetTrustedDomainInformation
0012C5B3 = LsaSetTrustedDomainInfoByName
D86BF37C = LsaSetSystemAccessAccount
2A3F28BD = LsaSetSecurityObject
8FBEFC9A = LsaSetSecret
DDC7D36A = LsaSetQuotasForAccount
830F05FA = LsaSetInformationTrustedDomain
A2BFB4E6 = LsaSetInformationPolicy
E049AAA7 = LsaSetForestTrustInformation
F7369383 = LsaSetDomainInformationPolicy
AE8A906D = LsaRetrievePrivateData
F88C5CFD = LsaRemovePrivilegesFromAccount
F5B173FD = LsaRemoveAccountRights
443A487D = LsaQueryTrustedDomainInfoByName
23F7788F = LsaQueryTrustedDomainInfo
A26E3321 = LsaQuerySecurityObject
DEA56012 = LsaQuerySecret
D12EBEC5 = LsaQueryInformationPolicy
4E7B7671 = LsaQueryInfoTrustedDomain
7CC1FBBC = LsaQueryForestTrustInformation
B31E1E4D = LsaQueryDomainInformationPolicy
50969EC1 = LsaOpenTrustedDomainByName
8CF253BA = LsaOpenTrustedDomain
A879700D = LsaOpenSecret
6315C213 = LsaOpenPolicySce
099FB318 = LsaOpenPolicy
3F1C4390 = LsaOpenAccount
59CDC5C7 = LsaNtStatusToWinError
39B205F7 = LsaManageSidNameMapping
616BA5BA = LsaLookupSids
C3A86A24 = LsaLookupPrivilegeValue
80875044 = LsaLookupPrivilegeName
277AC660 = LsaLookupPrivilegeDisplayName
684B2100 = LsaLookupNames2
64D09642 = LsaLookupNames
9454D733 = LsaICLookupSidsWithCreds
FBBCEC09 = LsaICLookupSids
EE3086F0 = LsaICLookupNamesWithCreds
0F744F8F = LsaICLookupNames
BA4F883A = LsaGetUserName
D8CBF37C = LsaGetSystemAccessAccount
2AE9C07E = LsaGetRemoteUserName
DDC7D36F = LsaGetQuotasForAccount
2BBE1774 = LsaFreeMemory
47C6FEC3 = LsaEnumerateTrustedDomainsEx
70ED1F1B = LsaEnumerateTrustedDomains
DC835BD3 = LsaEnumeratePrivilegesOfAccount
5D665773 = LsaEnumeratePrivileges
9D8E431F = LsaEnumerateAccountsWithUserRight
05A3B95C = LsaEnumerateAccounts
B1E7F19D = LsaEnumerateAccountRights
14B64C53 = LsaDeleteTrustedDomain
117EFC43 = LsaDelete
D1149537 = LsaCreateTrustedDomainEx
DF3F4452 = LsaCreateTrustedDomain
238D59EB = LsaCreateSecret
C508B0D5 = LsaCreateAccount
3D0236E9 = LsaClose
602DE07E = LsaClearAuditLog
301964C7 = LsaAddPrivilegesToAccount
74DA1392 = LsaAddAccountRights
E322E8BE = LookupSecurityDescriptorPartsW
E322E8A8 = LookupSecurityDescriptorPartsA
1B3D12AF = LookupPrivilegeValueW
1B3D12B9 = LookupPrivilegeValueA
70363216 = LookupPrivilegeNameW
70363200 = LookupPrivilegeNameA
9D615778 = LookupPrivilegeDisplayNameW
9D61576E = LookupPrivilegeDisplayNameA
F6B76AEE = LookupAccountSidW
F6B76AF8 = LookupAccountSidA
8AB72E2D = LookupAccountNameW
8AB72E3B = LookupAccountNameA
31B6C604 = LogonUserW
B185B03A = LogonUserExW
6C0A1036 = LogonUserExExW
B185B02C = LogonUserExA
31B6C612 = LogonUserA
E11CF36E = LockServiceDatabase
5E79B6EF = IsWellKnownSid
6F3973A6 = IsValidSid
1F8F650F = IsValidSecurityDescriptor
5D551455 = IsValidRelativeSecurityDescriptor
6F3DF6AE = IsValidAcl
AD5D0BCA = IsTokenUntrusted
876FBD88 = IsTokenRestricted
600CD021 = IsTextUnicode
4460A75B = InstallApplication
0690EC53 = InitiateSystemShutdownW
3B107DF3 = InitiateSystemShutdownExW
3B107DE5 = InitiateSystemShutdownExA
0690EC45 = InitiateSystemShutdownA
38F9C064 = InitiateShutdownW
38F9C072 = InitiateShutdownA
C1EA9DD1 = InitializeSid
B8538A52 = InitializeSecurityDescriptor
C1EE18D9 = InitializeAcl
DAA84C5E = ImpersonateSelf
8D434363 = ImpersonateNamedPipeClient
35AE2A45 = ImpersonateLoggedOnUser
9A8650F9 = ImpersonateAnonymousToken
C7848298 = IdentifyCodeAuthzLevelW
8F49847D = I_ScValidatePnPService
1B7708DF = I_ScSetServiceBitsW
1B7708C9 = I_ScSetServiceBitsA
77AA4037 = I_ScSendTSMessage
EA5B3A6C = I_ScSendPnPMessage
B39AAFF1 = I_ScQueryServiceConfig
64BF03BF = I_ScPnPGetServiceName
D779FA6A = I_ScIsSecurityProcess
63D1B178 = I_ScGetCurrentGroupStateW
A4B830E5 = I_QueryTagInformation
636B72AD = GetWindowsAccountDomainSid
B9D41C39 = GetUserNameW
B9D41C2F = GetUserNameA
939F385F = GetTrusteeTypeW
939F3849 = GetTrusteeTypeA
3098785E = GetTrusteeNameW
30987848 = GetTrusteeNameA
B15FBC5E = GetTrusteeFormW
B15FBC48 = GetTrusteeFormA
9E1F8AAE = GetTraceLoggerHandle
51B0196D = GetTraceEnableLevel
F095D872 = GetTraceEnableFlags
D4ECC759 = GetTokenInformation
0E12826B = GetThreadWaitChain
AD0C9F7E = GetSidSubAuthorityCount
D21E3D01 = GetSidSubAuthority
299727FA = GetSidLengthRequired
512796CC = GetSidIdentifierAuthority
0567D625 = GetServiceKeyNameW
0567D633 = GetServiceKeyNameA
F276DC51 = GetServiceDisplayNameW
F276DC47 = GetServiceDisplayNameA
94D90EDA = GetSecurityInfoExW
94D90ECC = GetSecurityInfoExA
43946CA6 = GetSecurityInfo
CE30283A = GetSecurityDescriptorSacl
9E457624 = GetSecurityDescriptorRMControl
DAD75994 = GetSecurityDescriptorOwner
4BAC491C = GetSecurityDescriptorLength
5A771196 = GetSecurityDescriptorGroup
CCD0283A = GetSecurityDescriptorDacl
D4453199 = GetSecurityDescriptorControl
38145354 = GetPrivateObjectSecurity
E625538B = GetOverlappedAccessResults
12827260 = GetOldestEventLogRecord
A6ACD0DC = GetNumberOfEventLogRecords
6D537BCB = GetNamedSecurityInfoW
DEF66703 = GetNamedSecurityInfoExW
DEF66715 = GetNamedSecurityInfoExA
6D537BDD = GetNamedSecurityInfoA
CE891E88 = GetMultipleTrusteeW
5AB4B310 = GetMultipleTrusteeOperationW
5AB4B306 = GetMultipleTrusteeOperationA
CE891E9E = GetMultipleTrusteeA
7D70D948 = GetManagedApplications
A10B8971 = GetManagedApplicationCategories
D1A26ED1 = GetLocalManagedApplications
DCC24E2C = GetLocalManagedApplicationData
01D7B6A1 = GetLengthSid
B29136DD = GetKernelObjectSecurity
8FE788F5 = GetInheritanceSourceW
8FE788E3 = GetInheritanceSourceA
AD604377 = GetInformationCodeAuthzPolicyW
E219C7C8 = GetInformationCodeAuthzLevelW
5A9B07DD = GetFileSecurityW
5A9B07CB = GetFileSecurityA
3AF6663F = GetExplicitEntriesFromAclW
3AF66629 = GetExplicitEntriesFromAclA
67E2CDB4 = GetEventLogInformation
39968B35 = GetEncryptedFileMetadata
D055A3D4 = GetEffectiveRightsFromAclW
D055A3C2 = GetEffectiveRightsFromAclA
F684C7BF = GetCurrentHwProfileW
F684C7A9 = GetCurrentHwProfileA
1CFC7058 = GetAuditedPermissionsFromAclW
1CFC704E = GetAuditedPermissionsFromAclA
763FE525 = GetAclInformation
5E9073DB = GetAce
64A72F44 = GetAccessPermissionsForObjectW
64A72F52 = GetAccessPermissionsForObjectA
5CB5EF72 = FreeSid
A8FE6BC9 = FreeInheritedFromArray
C645C79D = FreeEncryptionCertificateHashList
391ECD5F = FreeEncryptedFileMetadata
A970A601 = FreeEncryptedFileKeyInfo
59DF41C6 = FlushTraceW
59DF41D0 = FlushTraceA
D0DEF280 = FlushEfsCache
59113DAD = FindFirstFreeAce
541F9BF1 = FileEncryptionStatusW
541F9BE7 = FileEncryptionStatusA
0C58E83D = EventWriteTransfer
095DFFDA = EventWriteString
89E12DB7 = EventWriteStartScenario
707880DC = EventWriteEx
B0A77BA4 = EventWriteEndScenario
8891C1E2 = EventWrite
C6C579F1 = EventUnregister
EE867CBB = EventRegister
5DAE1E1E = EventProviderEnabled
F2BA9820 = EventEnabled
D0562EC6 = EventActivityIdControl
CF51E095 = EventAccessRemove
D39CAD4E = EventAccessQuery
9B910BDB = EventAccessControl
1D1F334A = EqualSid
E0EFDBA6 = EqualPrefixSid
F615FB9E = EqualDomainSid
AFECD9BC = EnumerateTraceGuidsEx
ED12BFB3 = EnumerateTraceGuids
A321375E = EnumServicesStatusW
4DD3149F = EnumServicesStatusExW
4DD31489 = EnumServicesStatusExA
A3213748 = EnumServicesStatusA
29438F04 = EnumServiceGroupW
D9B506F7 = EnumDependentServicesW
D9B506E1 = EnumDependentServicesA
443E6591 = EncryptionDisable
625EF68C = EncryptedFileKeyInfo
9FC04AC2 = EncryptFileW
9FC04AD4 = EncryptFileA
77F48F88 = EnableTraceEx2
74EFE91F = EnableTraceEx
2F9DD3BF = EnableTrace
65343017 = ElfReportEventW
820BA5A8 = ElfReportEventAndSourceW
65343001 = ElfReportEventA
FB168D91 = ElfRegisterEventSourceW
FB168D87 = ElfRegisterEventSourceA
395A5761 = ElfReadEventLogW
395A5777 = ElfReadEventLogA
3888F664 = ElfOpenEventLogW
3888F672 = ElfOpenEventLogA
F8000800 = ElfOpenBackupEventLogW
F8000816 = ElfOpenBackupEventLogA
5FF5D1D7 = ElfOldestRecord
FE016D1F = ElfNumberOfRecords
3275FA03 = ElfFlushEventLog
3CECADF8 = ElfDeregisterEventSource
3F25FC83 = ElfCloseEventLog
2C14C282 = ElfClearEventLogFileW
2C14C294 = ElfClearEventLogFileA
763D9E28 = ElfChangeNotify
2F314F9B = ElfBackupEventLogFileW
2F314F8D = ElfBackupEventLogFileA
CEBD40A1 = DuplicateTokenEx
89673AF5 = DuplicateToken
0D8D7EAF = DuplicateEncryptionInfoFile
8905A736 = DestroyPrivateObjectSecurity
8FDCAD73 = DeregisterEventSource
DE5D85F8 = DeleteService
087BC2CA = DeleteAce
9FC06802 = DecryptFileW
9FC06814 = DecryptFileA
499F4478 = CryptVerifySignatureW
499F446E = CryptVerifySignatureA
C0C0571B = CryptSignHashW
C0C0570D = CryptSignHashA
4B755A7C = CryptSetProviderW
569BAE8A = CryptSetProviderExW
569BAE9C = CryptSetProviderExA
4B755A6A = CryptSetProviderA
DBD093C5 = CryptSetProvParam
37A53419 = CryptSetKeyParam
C3F6E335 = CryptSetHashParam
72760BB8 = CryptReleaseContext
78660DBE = CryptImportKey
A752A65C = CryptHashSessionKey
F837A387 = CryptHashData
2C25B94B = CryptGetUserKey
DBD213C5 = CryptGetProvParam
37A53119 = CryptGetKeyParam
C3F46335 = CryptGetHashParam
C359FA5A = CryptGetDefaultProviderW
C359FA4C = CryptGetDefaultProviderA
453DB143 = CryptGenRandom
2433303E = CryptGenKey
744C0DBE = CryptExportKey
E9F43833 = CryptEnumProvidersW
E9F43825 = CryptEnumProvidersA
D0863B6E = CryptEnumProviderTypesW
D0863B78 = CryptEnumProviderTypesA
CEBF13BE = CryptEncrypt
A76A0569 = CryptDuplicateKey
B563B1BB = CryptDuplicateHash
0D4B3D42 = CryptDestroyKey
A5FFA46E = CryptDestroyHash
3756058E = CryptDeriveKey
CEBF17E6 = CryptDecrypt
3C4DE260 = CryptCreateHash
ACAA6891 = CryptContextAddRef
8AD7DE22 = CryptAcquireContextW
8AD7DE34 = CryptAcquireContextA
94FE7A4C = CredpEncodeSecret
70D9CF41 = CredpEncodeCredential
70D9CD6D = CredpDecodeCredential
A4DC8268 = CredpConvertTargetInfo
67F5A6CA = CredpConvertOneCredentialSize
90534DE1 = CredpConvertCredential
DFF6A049 = CredWriteW
1B18DE14 = CredWriteDomainCredentialsW
1B18DE02 = CredWriteDomainCredentialsA
DFF6A05F = CredWriteA
BD758800 = CredUnprotectW
BD758816 = CredUnprotectA
1323DE2A = CredUnmarshalCredentialW
1323DE3C = CredUnmarshalCredentialA
7CA79A97 = CredRestoreCredentials
89F22900 = CredRenameW
89F22916 = CredRenameA
6F5DE572 = CredReadW
86C08BB6 = CredReadDomainCredentialsW
86C08BA0 = CredReadDomainCredentialsA
A06B4CCA = CredReadByTokenHandle
6F5DE564 = CredReadA
A8114D9A = CredProtectW
A8114D8C = CredProtectA
F60B9AA7 = CredProfileUnloaded
B0AD1AE6 = CredProfileLoaded
4A12B8AF = CredMarshalCredentialW
4A12B8B9 = CredMarshalCredentialA
620F1A5A = CredIsProtectedW
620F1A4C = CredIsProtectedA
A5B06B2D = CredIsMarshaledCredentialW
A5B06B3B = CredIsMarshaledCredentialA
70BA7ED1 = CredGetTargetInfoW
70BA7EC7 = CredGetTargetInfoA
6AC03DF0 = CredGetSessionTypes
485B79CB = CredFree
BCB7E442 = CredFindBestCredentialW
BCB7E454 = CredFindBestCredentialA
DDFA3CD8 = CredEnumerateW
DDFA3CCE = CredEnumerateA
AAB8F51D = CredEncryptAndMarshalBinaryBlob
A9743100 = CredDeleteW
A9743116 = CredDeleteA
05E90C2B = CredBackupCredentials
96EB7D6A = CreateWellKnownSid
E4723B84 = CreateTraceInstanceId
17B3DD38 = CreateServiceW
17B3DD2E = CreateServiceA
F1DD0C6D = CreateRestrictedToken
37881099 = CreateProcessWithTokenW
360A9059 = CreateProcessWithLogonW
985267D2 = CreateProcessAsUserW
985267C4 = CreateProcessAsUserA
5F550058 = CreatePrivateObjectSecurityWithMultipleInheritance
4D8639E1 = CreatePrivateObjectSecurityEx
6C653618 = CreatePrivateObjectSecurity
954969B2 = CreateCodeAuthzLevel
0F35FB9B = CopySid
ADF5011E = ConvertToAutoInheritPrivateObjectSecurity
3E68CFD0 = ConvertStringSidToSidW
3E68CFC6 = ConvertStringSidToSidA
F2F9DE1E = ConvertStringSecurityDescriptorToSecurityDescriptorW
F2F9DE08 = ConvertStringSecurityDescriptorToSecurityDescriptorA
6F2FB8E2 = ConvertStringSDToSDRootDomainW
6F2FB8F4 = ConvertStringSDToSDRootDomainA
13F7E3EC = ConvertStringSDToSDDomainW
13F7E3FA = ConvertStringSDToSDDomainA
70395A5A = ConvertSidToStringSidW
70395A4C = ConvertSidToStringSidA
E16F2876 = ConvertSecurityDescriptorToStringSecurityDescriptorW
E16F2860 = ConvertSecurityDescriptorToStringSecurityDescriptorA
97F800E0 = ConvertSecurityDescriptorToAccessW
A279759D = ConvertSecurityDescriptorToAccessNamedW
A279758B = ConvertSecurityDescriptorToAccessNamedA
97F800F6 = ConvertSecurityDescriptorToAccessA
670C82C5 = ConvertSDToStringSDRootDomainW
670C82D3 = ConvertSDToStringSDRootDomainA
C2C7481F = ConvertAccessToSecurityDescriptorW
C2C74809 = ConvertAccessToSecurityDescriptorA
5ADABBCA = ControlTraceW
5ADABBDC = ControlTraceA
7E3A838B = ControlServiceExW
7E3A839D = ControlServiceExA
5FFEE3F1 = ControlService
4CFEC25E = ComputeAccessTokenFromCodeAuthzLevel
E5300749 = CommandLineFromMsiDescriptor
A287BEE9 = CloseTrace
6E5B0CC8 = CloseThreadWaitChainSession
78CEC357 = CloseServiceHandle
0F257730 = CloseEventLog
4FB321A3 = CloseEncryptedFileRaw
D1C76FDE = CloseCodeAuthzLevel
12BADCDB = ClearEventLogW
12BADCCD = ClearEventLogA
87FEDB50 = CheckTokenMembership
A1A1E6F1 = ChangeServiceConfigW
A1A1E6E7 = ChangeServiceConfigA
D0F34A07 = ChangeServiceConfig2W
D0F34A11 = ChangeServiceConfig2A
936DF186 = CancelOverlappedAccess
8C6769CD = BuildTrusteeWithSidW
8C6769DB = BuildTrusteeWithSidA
47F6CAF3 = BuildTrusteeWithObjectsAndSidW
47F6CAE5 = BuildTrusteeWithObjectsAndSidA
2A6720F5 = BuildTrusteeWithObjectsAndNameW
2A6720E3 = BuildTrusteeWithObjectsAndNameA
E2B6BF90 = BuildTrusteeWithNameW
E2B6BF86 = BuildTrusteeWithNameA
97BE24F0 = BuildSecurityDescriptorW
97BE24E6 = BuildSecurityDescriptorA
647366DE = BuildImpersonateTrusteeW
647366C8 = BuildImpersonateTrusteeA
C445B542 = BuildImpersonateExplicitAccessWithNameW
C445B554 = BuildImpersonateExplicitAccessWithNameA
1E8E1536 = BuildExplicitAccessWithNameW
1E8E1520 = BuildExplicitAccessWithNameA
024B18D3 = BackupEventLogW
024B18C5 = BackupEventLogA
54725874 = AuditSetSystemPolicy
8C63FA43 = AuditSetSecurity
9FADBEFB = AuditSetPerUserPolicy
B7473306 = AuditSetGlobalSaclW
B7473310 = AuditSetGlobalSaclA
E6950E0B = AuditQuerySystemPolicy
A2169DB8 = AuditQuerySecurity
EC068122 = AuditQueryPerUserPolicy
4822FDAA = AuditQueryGlobalSaclW
4822FDBC = AuditQueryGlobalSaclA
27343AD7 = AuditLookupSubCategoryNameW
27343AC1 = AuditLookupSubCategoryNameA
6F11CDEE = AuditLookupCategoryNameW
6F11CDF8 = AuditLookupCategoryNameA
4B176B3B = AuditLookupCategoryIdFromCategoryGuid
E7768ED0 = AuditLookupCategoryGuidFromCategoryId
093721AA = AuditFree
822B94D7 = AuditEnumerateSubCategories
93FBCE6E = AuditEnumeratePerUserPolicy
29FE3929 = AuditEnumerateCategories
56014C34 = AuditComputeEffectivePolicyByToken
FB689B0A = AuditComputeEffectivePolicyBySid
86EC7CD5 = AreAnyAccessesGranted
86EE56D5 = AreAllAccessesGranted
EEBCE257 = AllocateLocallyUniqueId
28E9E291 = AllocateAndInitializeSid
7A2167DC = AdjustTokenPrivileges
69499ED0 = AdjustTokenGroups
B4170CD4 = AddUsersToEncryptedFileEx
B8B2D05C = AddUsersToEncryptedFile
6DBA1BEA = AddMandatoryAce
F7FFDE35 = AddConditionalAce
9A26C709 = AddAuditAccessObjectAce
AB48BED2 = AddAuditAccessAceEx
70AAAD22 = AddAuditAccessAce
4C9073EB = AddAce
3E6F1851 = AddAccessDeniedObjectAce
EFD54B58 = AddAccessDeniedAceEx
A683BF55 = AddAccessDeniedAce
FC56DDBA = AddAccessAllowedObjectAce
CC4915E4 = AddAccessAllowedAceEx
DC733124 = AddAccessAllowedAce
B1944799 = AccessCheckByTypeResultListAndAuditAlarmW
60D9859E = AccessCheckByTypeResultListAndAuditAlarmByHandleW
60D98588 = AccessCheckByTypeResultListAndAuditAlarmByHandleA
B194478F = AccessCheckByTypeResultListAndAuditAlarmA
25E5ECCE = AccessCheckByTypeResultList
669A7086 = AccessCheckByTypeAndAuditAlarmW
669A7090 = AccessCheckByTypeAndAuditAlarmA
D0266109 = AccessCheckByType
5D494CBA = AccessCheckAndAuditAlarmW
5D494CAC = AccessCheckAndAuditAlarmA
DED2AE06 = AccessCheck
E6E058F0 = AbortSystemShutdownW
E6E058E6 = AbortSystemShutdownA
DF096CA5 = A_SHAUpdate
5884FAB0 = A_SHAInit
B29C92C0 = A_SHAFinal