Skip to content

Commit

Permalink
Moving amsistate event changed to this repo (#87)
Browse files Browse the repository at this point in the history
  • Loading branch information
suajose authored and adityapatwardhan committed Jan 9, 2023
1 parent 842058b commit 8fb8207
Showing 1 changed file with 48 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -2184,6 +2184,18 @@
value="0x6017"
version="1"
/>
<event
channel="C_ANALYTIC"
keywords="AmsiState"
level="win:Verbose"
message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)"
opcode="Method"
symbol="AmsiState"
task="Amsi"
template="T_AmsiState"
value="0x4001"
version="1"
/>
</events>
<channels>
<!--There are two channels defined for Windows PowerShell instrumentation
Expand Down Expand Up @@ -2407,6 +2419,12 @@
symbol="T_ISEOperation"
value="120"
/>
<task
message="$(string.PS_PROVIDER.task.T_AmsiState.message)"
name="Amsi"
symbol="T_Amsi"
value="130"
/>
</tasks>
<opcodes>
<opcode
Expand Down Expand Up @@ -2567,6 +2585,12 @@
name="PSWorkflow"
symbol="K_PSWORKFLOW"
/>
<keyword
mask="0x400"
message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)"
name="AmsiState"
symbol="K_AmsiState"
/>
</keywords>
<maps>
<!-- please keep in sync with SerializationMethod from
Expand Down Expand Up @@ -4024,6 +4048,16 @@
name="FileName"
/>
</template>
<template tid="T_AmsiState">
<data
inType="win:UnicodeString"
name="Action"
/>
<data
inType="win:UnicodeString"
name="AmsiContext"
/>
</template>
</templates>
</provider>
</events>
Expand Down Expand Up @@ -4917,6 +4951,10 @@
id="PS_PROVIDER.event.E_O_M3PWorkflowExecutionStarted.message"
value="Workflow execution started. %n %t WorkflowId: %1 %n %t ManagedNodes: %2"
/>
<string
id="PS_PROVIDER.event.E_A_AmsiState.message"
value="AmsiUtil state. %n %t state: %1 %n %t Context: %2"
/>
<string
id="PS_PROVIDER.event.E_O_M3PEndpointRegistered.message"
value="A new PowerShell endpoint was registered. %n %t EndpointName: %1 %n %t EndpointType: %2 %n %t RegisteredBy: %3"
Expand Down Expand Up @@ -5385,7 +5423,11 @@
id="PS_PROVIDER.keyword.K_PSWORKFLOW.message"
value="PSWorkflow Hosting And Execution Layer"
/>
<string
<string
id="PS_PROVIDER.keyword.K_AmsiState.message"
value="Amsi state"
/>
<string
id="PS_PROVIDER.keyword.K_SESSION.message"
value="All session layer"
/>
Expand Down Expand Up @@ -5545,7 +5587,11 @@
id="PS_PROVIDER.task.T_ISEOperation.message"
value="PowerShell ISE Operation"
/>
<string
<string
id="PS_PROVIDER.task.T_AmsiState.message"
value="Amsi State"
/>
<string
id="PS_PROVIDER.event.E_O_ISEExecuteScript.message"
value="Windows PowerShell ISE has started to run script file %1."
/>
Expand Down

0 comments on commit 8fb8207

Please sign in to comment.