Skip to content

Commit 4386fa9

Browse files
Merge pull request #11 from EricZimmerman/master
update repo
2 parents eea40b8 + 73e6ab3 commit 4386fa9

19 files changed

+1197
-6
lines changed

evtx/Maps/Application_MsiInstaller_10002.map evtx/Maps/Application_Microsoft-Windows-RestartManager_10002.map

+5-5
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,25 @@
11
Author: Hyun Yi @hyuunnn
2-
Description: Terminated due to non-response
2+
Description: Shutting down application or service
33
EventId: 10002
44
Channel: "Application"
55
Provider: "Microsoft-Windows-RestartManager"
66
Maps:
77
-
8-
Property: PayloadData1
9-
PropertyValue: "FullPath: %FullPath%"
8+
Property: ExecutableInfo
9+
PropertyValue: "%FullPath%"
1010
Values:
1111
-
1212
Name: FullPath
1313
Value: "/Event/UserData/RmApplicationEvent/FullPath"
1414
-
15-
Property: PayloadData2
15+
Property: PayloadData1
1616
PropertyValue: "DisplayName: %DisplayName%"
1717
Values:
1818
-
1919
Name: DisplayName
2020
Value: "/Event/UserData/RmApplicationEvent/DisplayName"
2121
-
22-
Property: PayloadData3
22+
Property: PayloadData2
2323
PropertyValue: "Files: %Files%"
2424
Values:
2525
-
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
Author: Hyun Yi @hyuunnn
2+
Description: Terminated due to non-response
3+
EventId: 10002
4+
Channel: "Application"
5+
Provider: "Microsoft-Windows-Winsrv"
6+
Maps:
7+
-
8+
Property: ExecutableInfo
9+
PropertyValue: "%AppName%"
10+
Values:
11+
-
12+
Name: AppName
13+
Value: "/Event/UserData/HungAppEvent/AppName"
14+
15+
# Documentation:
16+
# N/A
17+
#
18+
# Example Event Data:
19+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
20+
# <System>
21+
# <Provider Name="Microsoft-Windows-Winsrv" Guid="{GUID}" />
22+
# <EventID>10002</EventID>
23+
# <Version>0</Version>
24+
# <Level>4</Level>
25+
# <Task>0</Task>
26+
# <Opcode>0</Opcode>
27+
# <Keywords>0x8000000000000000</Keywords>
28+
# <TimeCreated SystemTime="2020-12-28T16:45:14.6424242Z" />
29+
# <EventRecordID>31565</EventRecordID>
30+
# <Correlation />
31+
# <Execution ProcessID="11364" ThreadID="23376" />
32+
# <Channel>Application</Channel>
33+
# <Computer>ComputerName</Computer>
34+
# <Security UserID="{UserID}" />
35+
# </System>
36+
# <UserData>
37+
# <HungAppEvent xmlns="http://manifests.microsoft.com/win/2004/08/windows/winsrv">
38+
# <AppName>PotPlayer.exe</AppName>
39+
# </HungAppEvent>
40+
# </UserData>
41+
# </Event>
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
Author: Hyun Yi @hyuunnn
2+
Description: Restore point created successfully
3+
EventId: 8194
4+
Channel: "Application"
5+
Provider: "System Restore"
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "Data: %Data%"
10+
Values:
11+
-
12+
Name: Data
13+
Value: "/Event/EventData/Data"
14+
15+
# Documentation:
16+
# N/A
17+
#
18+
# Example Event Data:
19+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
20+
# <System>
21+
# <Provider Name="System Restore" />
22+
# <EventID Qualifiers="0">8194</EventID>
23+
# <Version>0</Version>
24+
# <Level>4</Level>
25+
# <Task>0</Task>
26+
# <Opcode>0</Opcode>
27+
# <Keywords>0x80000000000000</Keywords>
28+
# <TimeCreated SystemTime="2020-10-12T07:13:41.6976173Z" />
29+
# <EventRecordID>2347</EventRecordID>
30+
# <Correlation />
31+
# <Execution ProcessID="0" ThreadID="0" />
32+
# <Channel>Application</Channel>
33+
# <Computer>ComputerName</Computer>
34+
# <Security />
35+
# </System>
36+
# <EventData>
37+
# <Data>C:\WINDOWS\system32\msiexec.exe /V</Data>
38+
# <Data>Installed AccessData FTK Imager.</Data>
39+
# <Binary>{Binary}</Binary>
40+
# </EventData>
41+
# </Event>
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
Author: Hyun Yi @hyuunnn
2+
Description: System Restore has been disabled
3+
EventId: 8195
4+
Channel: "Application"
5+
Provider: "System Restore"
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "Data: %Data%"
10+
Values:
11+
-
12+
Name: Data
13+
Value: "/Event/EventData/Data"
14+
15+
# Documentation:
16+
# N/A
17+
#
18+
# Example Event Data:
19+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
20+
# <System>
21+
# <Provider Name="System Restore" />
22+
# <EventID Qualifiers="0">8195</EventID>
23+
# <Version>0</Version>
24+
# <Level>4</Level>
25+
# <Task>0</Task>
26+
# <Opcode>0</Opcode>
27+
# <Keywords>0x80000000000000</Keywords>
28+
# <TimeCreated SystemTime="2020-10-06T16:54:14.3633432Z" />
29+
# <EventRecordID>390</EventRecordID>
30+
# <Correlation />
31+
# <Execution ProcessID="0" ThreadID="0" />
32+
# <Channel>Application</Channel>
33+
# <Computer>ComputerName</Computer>
34+
# <Security />
35+
# </System>
36+
# <EventData>
37+
# <Data>C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.504_none_e781e76525fb2269\TiWorker.exe -Embedding</Data>
38+
# <Data />
39+
# <Binary>{Binary}</Binary>
40+
# </EventData>
41+
# </Event>
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
Author: Hyun Yi @hyuunnn
2+
Description: System Restore has been enabled
3+
EventId: 8196
4+
Channel: "Application"
5+
Provider: "System Restore"
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "Data: %Data%"
10+
Values:
11+
-
12+
Name: Data
13+
Value: "/Event/EventData/Data"
14+
15+
# Documentation:
16+
# N/A
17+
#
18+
# Example Event Data:
19+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
20+
# <System>
21+
# <Provider Name="System Restore" />
22+
# <EventID Qualifiers="0">8196</EventID>
23+
# <Version>0</Version>
24+
# <Level>4</Level>
25+
# <Task>0</Task>
26+
# <Opcode>0</Opcode>
27+
# <Keywords>0x80000000000000</Keywords>
28+
# <TimeCreated SystemTime="2020-10-06T16:54:14.5351795Z" />
29+
# <EventRecordID>391</EventRecordID>
30+
# <Correlation />
31+
# <Execution ProcessID="0" ThreadID="0" />
32+
# <Channel>Application</Channel>
33+
# <Computer>ComputerName</Computer>
34+
# <Security />
35+
# </System>
36+
# <EventData>
37+
# <Data>C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.504_none_e781e76525fb2269\TiWorker.exe -Embedding</Data>
38+
# <Data />
39+
# <Binary>{Binary}</Binary>
40+
# </EventData>
41+
# </Event>

0 commit comments

Comments
 (0)