Skip to content

Instantly share code, notes, and snippets.

@mgeeky
Created July 9, 2016 15:07
Show Gist options
  • Save mgeeky/505be4959e91ea133418dc2baa3a4064 to your computer and use it in GitHub Desktop.
Save mgeeky/505be4959e91ea133418dc2baa3a4064 to your computer and use it in GitHub Desktop.
API Filters list for Rohitab API Monitor
<?xml version="1.0"?>
<!--
API Monitor Filter
(c) 2010-2013, Rohitab Batra <rohitab@rohitab.com>
http://www.rohitab.com/apimonitor/
-->
<ApiMonitor>
<CaptureFilter>
<Module Name="Advapi32.dll">
<Api Name="ControlService"/>
<Api Name="ControlServiceExA"/>
<Api Name="ControlServiceExW"/>
<Api Name="CreateProcessAsUserA"/>
<Api Name="CreateProcessAsUserW">
<Breakpoint Before="True"/>
</Api>
<Api Name="CreateProcessWithLogonW"/>
<Api Name="CreateProcessWithTokenW"/>
<Api Name="CreateServiceA"/>
<Api Name="CreateServiceW"/>
<Api Name="DeleteService"/>
<Api Name="OpenSCManagerA"/>
<Api Name="OpenSCManagerW"/>
<Api Name="OpenServiceA"/>
<Api Name="OpenServiceW"/>
<Api Name="RegDeleteKeyA"/>
<Api Name="RegDeleteKeyExW"/>
<Api Name="RegOpenKeyExA"/>
<Api Name="RegOpenKeyExW"/>
<Api Name="RegQueryValueExA"/>
<Api Name="RegQueryValueExW"/>
<Api Name="RegSetValueExA"/>
<Api Name="RegSetValueExW"/>
<Api Name="StartServiceA"/>
<Api Name="StartServiceW"/>
</Module>
<Module Name="Kernel32.dll">
<Api Name="CheckRemoteDebuggerPresent"/>
<Api Name="CopyFileA"/>
<Api Name="CopyFileExA"/>
<Api Name="CopyFileExW"/>
<Api Name="CopyFileW"/>
<Api Name="CreateFileW"/>
<Api Name="CreateProcessA">
<Breakpoint Before="True"/>
</Api>
<Api Name="CreateProcessW">
<Breakpoint Before="True"/>
</Api>
<Api Name="CreateRemoteThread">
<Breakpoint Before="True"/>
</Api>
<Api Name="CreateRemoteThreadEx">
<Breakpoint Before="True"/>
</Api>
<Api Name="CreateToolhelp32Snapshot"/>
<Api Name="DeleteFileA"/>
<Api Name="DeleteFileW"/>
<Api Name="DeviceIoControl"/>
<Api Name="FindFirstFileA"/>
<Api Name="FindFirstFileExA"/>
<Api Name="FindFirstFileExW"/>
<Api Name="FindFirstFileW"/>
<Api Name="FindNextFileA"/>
<Api Name="FindNextFileW"/>
<Api Name="FindResourceA"/>
<Api Name="FindResourceW"/>
<Api Name="GetThreadContext"/>
<Api Name="IsDebuggerPresent"/>
<Api Name="LoadResource"/>
<Api Name="Module32First"/>
<Api Name="Module32FirstW"/>
<Api Name="Module32Next"/>
<Api Name="Module32NextW"/>
<Api Name="MoveFileA"/>
<Api Name="MoveFileExA"/>
<Api Name="MoveFileExW"/>
<Api Name="OpenProcess"/>
<Api Name="OutputDebugStringW"/>
<Api Name="Process32First"/>
<Api Name="Process32FirstW"/>
<Api Name="Process32Next"/>
<Api Name="Process32NextW"/>
<Api Name="ReadFile"/>
<Api Name="ReadFileEx"/>
<Api Name="ReadProcessMemory">
<Breakpoint Before="True"/>
</Api>
<Api Name="SetThreadContext"/>
<Api Name="VirtualAllocEx"/>
<Api Name="WinExec">
<Breakpoint Before="True"/>
</Api>
<Api Name="Wow64GetThreadContext"/>
<Api Name="Wow64GetThreadSelectorEntry"/>
<Api Name="Wow64SetThreadContext"/>
<Api Name="WriteFile"/>
<Api Name="WriteFileEx"/>
<Api Name="WriteProcessMemory">
<Breakpoint Before="True"/>
</Api>
</Module>
<Module Name="Ntdll.dll">
<Api Name="LdrLoadDll"/>
<Api Name="NtOpenFile"/>
<Api Name="NtQueryDirectoryFile"/>
<Api Name="NtQuerySystemInformation"/>
<Api Name="NtQueryVirtualMemory"/>
<Api Name="NtReadFile"/>
<Api Name="NtReadVirtualMemory"/>
<Api Name="NtSetSystemInformation"/>
<Api Name="NtWriteFile"/>
<Api Name="NtWriteVirtualMemory"/>
</Module>
<Module Name="Ole32.dll">
<Api Name="CoCreateInstance"/>
<Api Name="CoCreateInstanceEx"/>
<Api Name="OleInitialize"/>
</Module>
<Module Name="Psapi.dll">
<Api Name="EnumProcesses"/>
</Module>
<Module Name="Shell32.dll">
<Api Name="ShellExecuteA">
<Breakpoint Before="True"/>
</Api>
<Api Name="ShellExecuteExA">
<Breakpoint Before="True"/>
</Api>
<Api Name="ShellExecuteExW">
<Breakpoint Before="True"/>
</Api>
<Api Name="ShellExecuteW">
<Breakpoint Before="True"/>
</Api>
</Module>
<Module Name="urlmon.dll">
<Api Name="URLDownloadToCacheFileA"/>
<Api Name="URLDownloadToCacheFileW"/>
<Api Name="URLDownloadToFileA"/>
<Api Name="URLDownloadToFileW">
<Breakpoint Before="True"/>
</Api>
</Module>
<Module Name="User32.dll">
<Api Name="AttachThreadInput"/>
<Api Name="BlockInput">
<Breakpoint Before="True"/>
</Api>
<Api Name="CallNextHookEx"/>
<Api Name="GetAsyncKeyState"/>
<Api Name="GetKeyState"/>
<Api Name="GetKeyboardState"/>
<Api Name="SetWindowsHookExA">
<Breakpoint Before="True"/>
</Api>
<Api Name="SetWindowsHookExW">
<Breakpoint Before="True"/>
</Api>
</Module>
<Module Name="Wininet.dll">
<Api Name="AppCacheCheckManifest"/>
<Api Name="AppCacheCloseHandle"/>
<Api Name="AppCacheDeleteGroup"/>
<Api Name="AppCacheDeleteIEGroup"/>
<Api Name="AppCacheDuplicateHandle"/>
<Api Name="AppCacheFinalize"/>
<Api Name="AppCacheFreeDownloadList"/>
<Api Name="AppCacheFreeGroupList"/>
<Api Name="AppCacheFreeIESpace"/>
<Api Name="AppCacheGetDownloadList"/>
<Api Name="AppCacheGetFallbackUrl"/>
<Api Name="AppCacheGetGroupList"/>
<Api Name="AppCacheGetIEGroupList"/>
<Api Name="AppCacheGetInfo"/>
<Api Name="AppCacheGetManifestUrl"/>
<Api Name="AppCacheLookup"/>
<Api Name="CommitUrlCacheEntryA"/>
<Api Name="CommitUrlCacheEntryBinaryBlob"/>
<Api Name="CommitUrlCacheEntryW"/>
<Api Name="CreateMD5SSOHash"/>
<Api Name="CreateUrlCacheContainerA"/>
<Api Name="CreateUrlCacheContainerW"/>
<Api Name="CreateUrlCacheEntryA"/>
<Api Name="CreateUrlCacheEntryExW"/>
<Api Name="CreateUrlCacheEntryW"/>
<Api Name="CreateUrlCacheGroup"/>
<Api Name="DeleteIE3Cache"/>
<Api Name="DeleteUrlCacheContainerA"/>
<Api Name="DeleteUrlCacheContainerW"/>
<Api Name="DeleteUrlCacheEntry"/>
<Api Name="DeleteUrlCacheEntryA"/>
<Api Name="DeleteUrlCacheEntryW"/>
<Api Name="DeleteUrlCacheGroup"/>
<Api Name="DeleteWpadCacheForNetworks"/>
<Api Name="DetectAutoProxyUrl"/>
<Api Name="DoConnectoidsExist"/>
<Api Name="ExportCookieFileA"/>
<Api Name="ExportCookieFileW"/>
<Api Name="FindCloseUrlCache"/>
<Api Name="FindFirstUrlCacheContainerA"/>
<Api Name="FindFirstUrlCacheContainerW"/>
<Api Name="FindFirstUrlCacheEntryA"/>
<Api Name="FindFirstUrlCacheEntryExA"/>
<Api Name="FindFirstUrlCacheEntryExW"/>
<Api Name="FindFirstUrlCacheEntryW"/>
<Api Name="FindFirstUrlCacheGroup"/>
<Api Name="FindNextUrlCacheContainerA"/>
<Api Name="FindNextUrlCacheContainerW"/>
<Api Name="FindNextUrlCacheEntryA"/>
<Api Name="FindNextUrlCacheEntryExA"/>
<Api Name="FindNextUrlCacheEntryExW"/>
<Api Name="FindNextUrlCacheEntryW"/>
<Api Name="FindNextUrlCacheGroup"/>
<Api Name="FindP3PPolicySymbol"/>
<Api Name="FreeP3PObject"/>
<Api Name="FreeUrlCacheSpaceA"/>
<Api Name="FreeUrlCacheSpaceW"/>
<Api Name="FtpCommandA"/>
<Api Name="FtpCommandW"/>
<Api Name="FtpCreateDirectoryA"/>
<Api Name="FtpCreateDirectoryW"/>
<Api Name="FtpDeleteFileA"/>
<Api Name="FtpDeleteFileW"/>
<Api Name="FtpFindFirstFileA"/>
<Api Name="FtpFindFirstFileW"/>
<Api Name="FtpGetCurrentDirectoryA"/>
<Api Name="FtpGetCurrentDirectoryW"/>
<Api Name="FtpGetFileA"/>
<Api Name="FtpGetFileEx"/>
<Api Name="FtpGetFileSize"/>
<Api Name="FtpGetFileW"/>
<Api Name="FtpOpenFileA"/>
<Api Name="FtpOpenFileW"/>
<Api Name="FtpPutFileA"/>
<Api Name="FtpPutFileEx"/>
<Api Name="FtpPutFileW"/>
<Api Name="FtpRemoveDirectoryA"/>
<Api Name="FtpRemoveDirectoryW"/>
<Api Name="FtpRenameFileA"/>
<Api Name="FtpRenameFileW"/>
<Api Name="FtpSetCurrentDirectoryA"/>
<Api Name="FtpSetCurrentDirectoryW"/>
<Api Name="GetDiskInfoA"/>
<Api Name="GetP3PPolicy"/>
<Api Name="GetP3PRequestStatus"/>
<Api Name="GetUrlCacheConfigInfoA"/>
<Api Name="GetUrlCacheConfigInfoW"/>
<Api Name="GetUrlCacheContainerInfoA"/>
<Api Name="GetUrlCacheContainerInfoW"/>
<Api Name="GetUrlCacheEntryBinaryBlob"/>
<Api Name="GetUrlCacheEntryInfoA"/>
<Api Name="GetUrlCacheEntryInfoExA"/>
<Api Name="GetUrlCacheEntryInfoExW"/>
<Api Name="GetUrlCacheEntryInfoW"/>
<Api Name="GetUrlCacheGroupAttributeA"/>
<Api Name="GetUrlCacheGroupAttributeW"/>
<Api Name="GetUrlCacheHeaderData"/>
<Api Name="GopherCreateLocatorA"/>
<Api Name="GopherCreateLocatorW"/>
<Api Name="GopherFindFirstFileA"/>
<Api Name="GopherFindFirstFileW"/>
<Api Name="GopherGetAttributeA"/>
<Api Name="GopherGetAttributeW"/>
<Api Name="GopherGetLocatorTypeA"/>
<Api Name="GopherGetLocatorTypeW"/>
<Api Name="GopherOpenFileA"/>
<Api Name="GopherOpenFileW"/>
<Api Name="HttpAddRequestHeadersA"/>
<Api Name="HttpAddRequestHeadersW"/>
<Api Name="HttpCheckDavCompliance"/>
<Api Name="HttpCheckDavComplianceA"/>
<Api Name="HttpCheckDavComplianceW"/>
<Api Name="HttpCloseDependencyHandle"/>
<Api Name="HttpDuplicateDependencyHandle"/>
<Api Name="HttpEndRequestA"/>
<Api Name="HttpEndRequestW"/>
<Api Name="HttpOpenDependencyHandle"/>
<Api Name="HttpOpenRequestA"/>
<Api Name="HttpOpenRequestW"/>
<Api Name="HttpPushClose"/>
<Api Name="HttpPushEnable"/>
<Api Name="HttpPushWait"/>
<Api Name="HttpQueryInfoA"/>
<Api Name="HttpQueryInfoW"/>
<Api Name="HttpSendRequestA"/>
<Api Name="HttpSendRequestExA"/>
<Api Name="HttpSendRequestExW"/>
<Api Name="HttpSendRequestW"/>
<Api Name="ImportCookieFileA"/>
<Api Name="ImportCookieFileW"/>
<Api Name="IncrementUrlCacheHeaderData"/>
<Api Name="InternalInternetGetCookie"/>
<Api Name="InternetAlgIdToStringA"/>
<Api Name="InternetAlgIdToStringW"/>
<Api Name="InternetAttemptConnect"/>
<Api Name="InternetAutodial"/>
<Api Name="InternetAutodialHangup"/>
<Api Name="InternetCanonicalizeUrlA"/>
<Api Name="InternetCanonicalizeUrlW"/>
<Api Name="InternetCheckConnectionA"/>
<Api Name="InternetCheckConnectionW"/>
<Api Name="InternetCloseHandle"/>
<Api Name="InternetCombineUrlA"/>
<Api Name="InternetCombineUrlW"/>
<Api Name="InternetConfirmZoneCrossing"/>
<Api Name="InternetConfirmZoneCrossingA"/>
<Api Name="InternetConfirmZoneCrossingW"/>
<Api Name="InternetConnectA"/>
<Api Name="InternetConnectW"/>
<Api Name="InternetCrackUrlA"/>
<Api Name="InternetCrackUrlW"/>
<Api Name="InternetCreateUrlA"/>
<Api Name="InternetCreateUrlW"/>
<Api Name="InternetDebugGetLocalTime"/>
<Api Name="InternetDial"/>
<Api Name="InternetDialA"/>
<Api Name="InternetDialW"/>
<Api Name="InternetErrorDlg"/>
<Api Name="InternetFindNextFileA"/>
<Api Name="InternetFindNextFileW"/>
<Api Name="InternetFortezzaCommand"/>
<Api Name="InternetFreeProxyInfoList"/>
<Api Name="InternetGetCertByURL"/>
<Api Name="InternetGetCertByURLA"/>
<Api Name="InternetGetConnectedState"/>
<Api Name="InternetGetConnectedStateEx"/>
<Api Name="InternetGetConnectedStateExA"/>
<Api Name="InternetGetConnectedStateExW"/>
<Api Name="InternetGetCookieA"/>
<Api Name="InternetGetCookieExA"/>
<Api Name="InternetGetCookieExW"/>
<Api Name="InternetGetCookieW"/>
<Api Name="InternetGetDialBrandingW"/>
<Api Name="InternetGetDialEngineW"/>
<Api Name="InternetGetLastResponseInfoA"/>
<Api Name="InternetGetLastResponseInfoW"/>
<Api Name="InternetGetProxyForUrl"/>
<Api Name="InternetGetSecurityInfoByURL"/>
<Api Name="InternetGetSecurityInfoByURLA"/>
<Api Name="InternetGetSecurityInfoByURLW"/>
<Api Name="InternetGoOnline"/>
<Api Name="InternetGoOnlineA"/>
<Api Name="InternetGoOnlineW"/>
<Api Name="InternetHangUp"/>
<Api Name="InternetLockRequestFile"/>
<Api Name="InternetOpenA"/>
<Api Name="InternetOpenUrlA"/>
<Api Name="InternetOpenUrlW"/>
<Api Name="InternetOpenW"/>
<Api Name="InternetQueryDataAvailable"/>
<Api Name="InternetQueryFortezzaStatus"/>
<Api Name="InternetQueryOptionA"/>
<Api Name="InternetQueryOptionW"/>
<Api Name="InternetReadFile"/>
<Api Name="InternetReadFileExA"/>
<Api Name="InternetReadFileExW"/>
<Api Name="InternetSecurityProtocolToStringA"/>
<Api Name="InternetSecurityProtocolToStringW"/>
<Api Name="InternetSetCookieA"/>
<Api Name="InternetSetCookieExA"/>
<Api Name="InternetSetCookieExW"/>
<Api Name="InternetSetCookieW"/>
<Api Name="InternetSetDialState"/>
<Api Name="InternetSetDialStateA"/>
<Api Name="InternetSetDialStateW"/>
<Api Name="InternetSetFilePointer"/>
<Api Name="InternetSetOptionA"/>
<Api Name="InternetSetOptionExA"/>
<Api Name="InternetSetOptionExW"/>
<Api Name="InternetSetOptionW"/>
<Api Name="InternetSetStatusCallback"/>
<Api Name="InternetSetStatusCallbackA"/>
<Api Name="InternetSetStatusCallbackW"/>
<Api Name="InternetShowSecurityInfoByURL"/>
<Api Name="InternetShowSecurityInfoByURLA"/>
<Api Name="InternetShowSecurityInfoByURLW"/>
<Api Name="InternetTimeFromSystemTime"/>
<Api Name="InternetTimeFromSystemTimeA"/>
<Api Name="InternetTimeFromSystemTimeW"/>
<Api Name="InternetTimeToSystemTime"/>
<Api Name="InternetTimeToSystemTimeA"/>
<Api Name="InternetTimeToSystemTimeW"/>
<Api Name="InternetUnlockRequestFile"/>
<Api Name="InternetWriteFile"/>
<Api Name="InternetWriteFileExA"/>
<Api Name="InternetWriteFileExW"/>
<Api Name="IsDomainLegalCookieDomainA"/>
<Api Name="IsDomainLegalCookieDomainW"/>
<Api Name="IsHostInProxyBypassList"/>
<Api Name="IsProfilesEnabled"/>
<Api Name="IsUrlCacheEntryExpiredA"/>
<Api Name="IsUrlCacheEntryExpiredW"/>
<Api Name="LoadUrlCacheContent"/>
<Api Name="MapResourceToPolicy"/>
<Api Name="ParseX509EncodedCertificateForListBoxEntry"/>
<Api Name="PerformOperationOverUrlCacheA"/>
<Api Name="ReadGuidsForConnectedNetworks"/>
<Api Name="ReadUrlCacheEntryStream"/>
<Api Name="ReadUrlCacheEntryStreamEx"/>
<Api Name="RegisterUrlCacheNotification"/>
<Api Name="ResumeSuspendedDownload"/>
<Api Name="RetrieveUrlCacheEntryFileA"/>
<Api Name="RetrieveUrlCacheEntryFileW"/>
<Api Name="RetrieveUrlCacheEntryStreamA"/>
<Api Name="RetrieveUrlCacheEntryStreamW"/>
<Api Name="RunOnceUrlCache"/>
<Api Name="SetUrlCacheConfigInfoA"/>
<Api Name="SetUrlCacheConfigInfoW"/>
<Api Name="SetUrlCacheEntryGroup"/>
<Api Name="SetUrlCacheEntryGroupA"/>
<Api Name="SetUrlCacheEntryGroupW"/>
<Api Name="SetUrlCacheEntryInfoA"/>
<Api Name="SetUrlCacheEntryInfoW"/>
<Api Name="SetUrlCacheGroupAttributeA"/>
<Api Name="SetUrlCacheGroupAttributeW"/>
<Api Name="SetUrlCacheHeaderData"/>
<Api Name="ShowClientAuthCerts"/>
<Api Name="ShowSecurityInfo"/>
<Api Name="ShowX509EncodedCertificate"/>
<Api Name="UnlockUrlCacheEntryFile"/>
<Api Name="UnlockUrlCacheEntryFileA"/>
<Api Name="UnlockUrlCacheEntryFileW"/>
<Api Name="UnlockUrlCacheEntryStream"/>
<Api Name="UpdateUrlCacheContentPath"/>
<Api Name="UrlCacheCheckEntriesExist"/>
<Api Name="UrlCacheCloseEntryHandle"/>
<Api Name="UrlCacheContainerSetEntryMaximumAge"/>
<Api Name="UrlCacheCreateContainer"/>
<Api Name="UrlCacheFreeEntryInfo"/>
<Api Name="UrlCacheGetContentPaths"/>
<Api Name="UrlCacheGetEntryInfo"/>
<Api Name="UrlCacheGetGlobalLimit"/>
<Api Name="UrlCacheReadEntryStream"/>
<Api Name="UrlCacheReloadSettings"/>
<Api Name="UrlCacheRetrieveEntryFile"/>
<Api Name="UrlCacheRetrieveEntryStream"/>
<Api Name="UrlCacheSetGlobalLimit"/>
<Api Name="UrlCacheUpdateEntryExtraData"/>
<Api Name="UrlZonesDetach"/>
<Api Name="_GetFileExtensionFromUrl"/>
</Module>
<Module Name="Ws2_32.dll">
<Api Name="WSARecv"/>
<Api Name="WSASend"/>
<Api Name="WSASocketA"/>
<Api Name="WSAStartup"/>
<Api Name="accept"/>
<Api Name="bind"/>
<Api Name="connect"/>
<Api Name="getaddrinfo"/>
<Api Name="gethostbyaddr"/>
<Api Name="gethostbyname"/>
<Api Name="getprotobynumber"/>
<Api Name="getservbyname"/>
<Api Name="getservbyport"/>
<Api Name="getsockname"/>
<Api Name="listen"/>
<Api Name="recv"/>
<Api Name="send"/>
<Api Name="socket"/>
</Module>
</CaptureFilter>
</ApiMonitor>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment