keyiso.dll

Description: CNG Key Isolation Service

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5438

Architecture: 32-bit

Operating System: Windows NT

SHA256: 9c0d571b79170575d061e7e09c8f8a85

File Size: 65.5 KB

Uploaded At: Dec. 1, 2025, 7:59 a.m.

Views: 13

Exported Functions

  • KeyIsoServiceMain (Ordinal: 1, Address: 0x60d0)
  • KeyIsoSetAuditingInterface (Ordinal: 2, Address: 0xe904)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x10010038)
  • SetLastError (Address: 0x1001003c)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10010044)
  • DuplicateHandle (Address: 0x10010048)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x10010050)
  • LocalFree (Address: 0x10010054)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x10010060)
  • GetModuleFileNameW (Address: 0x1001006c)
  • GetModuleHandleExW (Address: 0x10010064)
  • GetProcAddress (Address: 0x1001005c)
  • LoadLibraryExW (Address: 0x10010068)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x10010074)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1001007c)
  • GetCurrentThread (Address: 0x10010084)
  • OpenProcessToken (Address: 0x10010080)
  • OpenThreadToken (Address: 0x10010088)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10010094)
  • RegOpenKeyExW (Address: 0x10010090)
  • RegQueryValueExW (Address: 0x10010098)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x100100a0)
  • AcquireSRWLockShared (Address: 0x100100b4)
  • CreateEventW (Address: 0x100100ac)
  • DeleteCriticalSection (Address: 0x100100b0)
  • EnterCriticalSection (Address: 0x100100c0)
  • InitializeCriticalSection (Address: 0x100100a4)
  • InitializeSRWLock (Address: 0x100100bc)
  • LeaveCriticalSection (Address: 0x100100c4)
  • ReleaseSRWLockExclusive (Address: 0x100100b8)
  • ReleaseSRWLockShared (Address: 0x100100c8)
  • SetEvent (Address: 0x100100a8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x100100d0)
api-ms-win-security-base-l1-1-0.dll
  • DuplicateTokenEx (Address: 0x100100d8)
  • EqualSid (Address: 0x100100e0)
  • GetTokenInformation (Address: 0x100100e4)
  • IsWellKnownSid (Address: 0x100100dc)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x100100ec)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x100100f8)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100100fc)
  • ConvertStringSidToSidW (Address: 0x100100f4)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x10010108)
  • SetServiceStatus (Address: 0x10010104)
bcrypt.dll
  • BCryptDestroyKey (Address: 0x10010120)
  • BCryptExportKey (Address: 0x10010114)
  • BCryptFinalizeKeyPair (Address: 0x10010124)
  • BCryptFreeBuffer (Address: 0x10010118)
  • BCryptGenerateKeyPair (Address: 0x1001011c)
  • BCryptResolveProviders (Address: 0x10010110)
CRYPTBASE.dll
  • SystemFunction040 (Address: 0x10010000)
ncrypt.dll
  • NCryptFreeObject (Address: 0x1001012c)
  • NCryptImportKey (Address: 0x10010138)
  • NCryptOpenStorageProvider (Address: 0x10010130)
  • NCryptSetProperty (Address: 0x10010134)
ntdll.dll
  • _wcsicmp (Address: 0x10010180)
  • EtwGetTraceEnableFlags (Address: 0x1001016c)
  • EtwGetTraceEnableLevel (Address: 0x10010198)
  • EtwGetTraceLoggerHandle (Address: 0x100101a4)
  • EtwRegisterTraceGuidsW (Address: 0x10010168)
  • EtwTraceMessage (Address: 0x100101a0)
  • EtwUnregisterTraceGuids (Address: 0x10010190)
  • LdrDisableThreadCalloutsForDll (Address: 0x1001015c)
  • memcpy (Address: 0x10010158)
  • memset (Address: 0x100101ac)
  • NtAdjustPrivilegesToken (Address: 0x10010150)
  • NtClose (Address: 0x100101a8)
  • NtOpenProcess (Address: 0x10010164)
  • NtQueryInformationToken (Address: 0x10010188)
  • NtTerminateProcess (Address: 0x1001019c)
  • RtlAllocateHeap (Address: 0x10010170)
  • RtlCompareUnicodeString (Address: 0x1001017c)
  • RtlDeleteCriticalSection (Address: 0x10010194)
  • RtlEnterCriticalSection (Address: 0x10010144)
  • RtlFreeHeap (Address: 0x10010178)
  • RtlInitializeCriticalSection (Address: 0x10010148)
  • RtlInitUnicodeString (Address: 0x10010184)
  • RtlIsMultiSessionSku (Address: 0x1001018c)
  • RtlLeaveCriticalSection (Address: 0x10010140)
  • RtlNtStatusToDosError (Address: 0x10010154)
  • RtlSizeHeap (Address: 0x10010174)
  • RtlUnhandledExceptionFilter (Address: 0x1001014c)
  • RtlUnwind (Address: 0x10010160)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x10010024)
  • NdrServerCall2 (Address: 0x1001000c)
  • RpcBindingVectorFree (Address: 0x10010008)
  • RpcEpRegisterW (Address: 0x10010030)
  • RpcEpUnregister (Address: 0x1001002c)
  • RpcImpersonateClient (Address: 0x10010018)
  • RpcRevertToSelf (Address: 0x10010020)
  • RpcServerInqBindings (Address: 0x10010028)
  • RpcServerRegisterIf3 (Address: 0x10010010)
  • RpcServerUnregisterIfEx (Address: 0x10010014)
  • RpcServerUseProtseqW (Address: 0x1001001c)