Skip to content

Instantly share code, notes, and snippets.

@jsecurity101
Created March 4, 2023 16:35
Show Gist options
  • Save jsecurity101/9fa719c2bdeb6a476f30296c95f71cd2 to your computer and use it in GitHub Desktop.
Save jsecurity101/9fa719c2bdeb6a476f30296c95f71cd2 to your computer and use it in GitHub Desktop.
EventId Event Description
1 THREATINT_ALLOCVM_REMOTE
2 THREATINT_PROTECTVM_REMOTE
3 THREATINT_MAPVIEW_REMOTE
4 THREATINT_QUEUEUSERAPC_REMOTE
5 THREATINT_SETTHREADCONTEXT_REMOTE
6 THREATINT_ALLOCVM_LOCAL
7 THREATINT_PROTECTVM_LOCAL
8 THREATINT_MAPVIEW_LOCAL
11 THREATINT_READVM_LOCAL
12 THREATINT_WRITEVM_LOCAL
13 THREATINT_READVM_REMOTE
14 THREATINT_WRITEVM_REMOTE
15 THREATINT_SUSPEND_THREAD
16 THREATINT_RESUME_THREAD
17 THREATINT_SUSPEND_PROCESS
18 THREATINT_RESUME_PROCESS
19 THREATINT_FREEZE_PROCESS
20 THREATINT_THAW_PROCESS
21 THREATINT_ALLOCVM_REMOTE_KERNEL_CALLER
22 THREATINT_PROTECTVM_REMOTE_KERNEL_CALLER
23 THREATINT_MAPVIEW_REMOTE_KERNEL_CALLER
24 THREATINT_QUEUEUSERAPC_REMOTE_KERNEL_CALLER
25 THREATINT_SETTHREADCONTEXT_REMOTE_KERNEL_CALLER
26 THREATINT_ALLOCVM_LOCAL_KERNEL_CALLER
27 THREATINT_PROTECTVM_LOCAL_KERNEL_CALLER
28 THREATINT_MAPVIEW_LOCAL_KERNEL_CALLER
29 THREATINT_DRIVER_OBJECT_LOAD
30 THREATINT_DRIVER_OBJECT_UNLOAD
31 THREATINT_DEVICE_OBJECT_LOAD
32 THREATINT_DEVICE_OBJECT_UNLOAD
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment