lsadb.dll

Description: LSA Database

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5915

Architecture: 64-bit

Operating System: Windows NT

SHA256: 2cbfcb1ca98fb8c605ad29bde094cd25

File Size: 353.0 KB

Uploaded At: Dec. 1, 2025, 8:11 a.m.

Views: 13

Exported Functions

  • InitializeLsaDbExtension (Ordinal: 1, Address: 0x12c0)
  • DllMain (Ordinal: 2, Address: 0x1220)

Imported DLLs & Functions

ADVAPI32.dll
  • LsaClose (Address: 0x18003a5a0)
  • SystemFunction004 (Address: 0x18003a598)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18003ab48)
  • IsDebuggerPresent (Address: 0x18003ab38)
  • OutputDebugStringW (Address: 0x18003ab40)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18003ab58)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18003ab68)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18003ab80)
  • RaiseException (Address: 0x18003ab98)
  • SetLastError (Address: 0x18003ab78)
  • SetUnhandledExceptionFilter (Address: 0x18003ab90)
  • UnhandledExceptionFilter (Address: 0x18003ab88)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18003aba8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18003abc0)
  • HeapAlloc (Address: 0x18003abb8)
  • HeapFree (Address: 0x18003abc8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18003abe0)
  • LocalFree (Address: 0x18003abe8)
  • LocalReAlloc (Address: 0x18003abd8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18003ac28)
  • FreeLibrary (Address: 0x18003ac10)
  • FreeLibraryAndExitThread (Address: 0x18003abf8)
  • GetModuleFileNameA (Address: 0x18003ac20)
  • GetModuleHandleExW (Address: 0x18003ac08)
  • GetModuleHandleW (Address: 0x18003ac00)
  • GetProcAddress (Address: 0x18003ac18)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18003ac38)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18003ac48)
  • ExitThread (Address: 0x18003ac90)
  • GetCurrentProcess (Address: 0x18003ac70)
  • GetCurrentProcessId (Address: 0x18003ac60)
  • GetCurrentThreadId (Address: 0x18003ac80)
  • TerminateProcess (Address: 0x18003ac88)
  • TlsAlloc (Address: 0x18003ac78)
  • TlsFree (Address: 0x18003ac50)
  • TlsGetValue (Address: 0x18003ac68)
  • TlsSetValue (Address: 0x18003ac58)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18003aca0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18003acc0)
  • RegNotifyChangeKeyValue (Address: 0x18003acb0)
  • RegOpenKeyExW (Address: 0x18003acb8)
  • RegQueryValueExW (Address: 0x18003acc8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18003ace0)
  • RtlCompareMemory (Address: 0x18003acf0)
  • RtlLookupFunctionEntry (Address: 0x18003acd8)
  • RtlVirtualUnwind (Address: 0x18003ace8)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18003ad08)
  • WideCharToMultiByte (Address: 0x18003ad00)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18003ad88)
  • AcquireSRWLockShared (Address: 0x18003ad38)
  • CreateEventW (Address: 0x18003ad50)
  • CreateMutexExW (Address: 0x18003ad40)
  • CreateSemaphoreExW (Address: 0x18003ad68)
  • DeleteCriticalSection (Address: 0x18003ad30)
  • EnterCriticalSection (Address: 0x18003ad98)
  • InitializeCriticalSectionEx (Address: 0x18003ada0)
  • LeaveCriticalSection (Address: 0x18003ad58)
  • OpenEventW (Address: 0x18003ad20)
  • OpenSemaphoreW (Address: 0x18003ad78)
  • ReleaseMutex (Address: 0x18003ad48)
  • ReleaseSemaphore (Address: 0x18003ad70)
  • ReleaseSRWLockExclusive (Address: 0x18003ad90)
  • ReleaseSRWLockShared (Address: 0x18003ad60)
  • SetEvent (Address: 0x18003ad18)
  • WaitForSingleObject (Address: 0x18003ad28)
  • WaitForSingleObjectEx (Address: 0x18003ad80)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18003adb0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18003adc0)
  • GetTickCount (Address: 0x18003adc8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18003add8)
  • CreateThreadpoolTimer (Address: 0x18003ade0)
  • SetThreadpoolTimer (Address: 0x18003ade8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18003adf0)
api-ms-win-security-base-l1-1-0.dll
  • CheckTokenMembership (Address: 0x18003ae20)
  • CopySid (Address: 0x18003ae70)
  • CreateWellKnownSid (Address: 0x18003ae18)
  • EqualDomainSid (Address: 0x18003ae48)
  • EqualSid (Address: 0x18003ae68)
  • GetLengthSid (Address: 0x18003ae88)
  • GetSecurityDescriptorDacl (Address: 0x18003ae60)
  • GetSecurityDescriptorLength (Address: 0x18003ae30)
  • GetSecurityDescriptorSacl (Address: 0x18003ae50)
  • GetWindowsAccountDomainSid (Address: 0x18003ae80)
  • InitializeSecurityDescriptor (Address: 0x18003ae38)
  • IsValidSid (Address: 0x18003ae40)
  • MakeSelfRelativeSD (Address: 0x18003ae58)
  • MapGenericMask (Address: 0x18003ae78)
  • SetSecurityDescriptorDacl (Address: 0x18003ae08)
  • SetSecurityDescriptorGroup (Address: 0x18003ae00)
  • SetSecurityDescriptorOwner (Address: 0x18003ae28)
  • SetSecurityDescriptorSacl (Address: 0x18003ae10)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSidToSidW (Address: 0x18003ae98)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18003aee0)
  • BCryptCreateHash (Address: 0x18003aeb0)
  • BCryptDecrypt (Address: 0x18003aef8)
  • BCryptDestroyHash (Address: 0x18003aec8)
  • BCryptDestroyKey (Address: 0x18003aee8)
  • BCryptEncrypt (Address: 0x18003aec0)
  • BCryptFinishHash (Address: 0x18003aef0)
  • BCryptGenerateSymmetricKey (Address: 0x18003af00)
  • BCryptGetProperty (Address: 0x18003aea8)
  • BCryptHashData (Address: 0x18003aeb8)
  • BCryptOpenAlgorithmProvider (Address: 0x18003aed0)
  • BCryptSetProperty (Address: 0x18003aed8)
DSPARSE.dll
  • DsCrackSpn3W (Address: 0x18003a5b8)
  • DsIsMangledDnW (Address: 0x18003a5b0)
KERNEL32.dll
  • GetSystemInfo (Address: 0x18003a5c8)
  • QueueUserWorkItem (Address: 0x18003a5f0)
  • SetThreadStackGuarantee (Address: 0x18003a5d0)
  • VirtualAlloc (Address: 0x18003a5e8)
  • VirtualProtect (Address: 0x18003a5e0)
  • VirtualQuery (Address: 0x18003a5d8)
logoncli.dll
  • DsGetDcNameW (Address: 0x18003af10)
LSASRV.dll
  • _fgs__LSAPR_TRUST_INFORMATION (Address: 0x18003a870)
  • _fgs__LSAPR_TRUSTED_DOMAIN_FULL_INFORMATION2 (Address: 0x18003a758)
  • _fgs__LSAPR_TRUSTED_DOMAIN_INFORMATION_EX2 (Address: 0x18003a750)
  • _fgu__LSAPR_TRUSTED_DOMAIN_INFO (Address: 0x18003a890)
  • IsTraceLevelEnabled (Address: 0x18003a948)
  • LsaDbLookupSidChainRequest (Address: 0x18003a6a0)
  • LsaIForestTrustFindMatch (Address: 0x18003a720)
  • LsaIFree_LSAP_SITE_INFO (Address: 0x18003a638)
  • LsaIFree_LSAP_SITENAME_INFO (Address: 0x18003a640)
  • LsaIFree_LSAP_SUBNET_INFO (Address: 0x18003a630)
  • LsaIFree_LSAP_UPN_SUFFIXES (Address: 0x18003a650)
  • LsaIFree_LSAPR_POLICY_INFORMATION (Address: 0x18003a968)
  • LsaIFree_LSAPR_TRUSTED_DOMAIN_INFO (Address: 0x18003a868)
  • LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER (Address: 0x18003a788)
  • LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER_EX (Address: 0x18003a790)
  • LsaIFree_LSAPR_UNICODE_STRING_BUFFER (Address: 0x18003a838)
  • LsaIFreeForestTrustInfo (Address: 0x18003a648)
  • LsaIIsDsPaused (Address: 0x18003a6b0)
  • LsaIIsTrustedDomainsEnabled (Address: 0x18003a828)
  • LsaINotifyChangeNotification (Address: 0x18003a8c8)
  • LsaIOpenPolicyTrusted (Address: 0x18003a628)
  • LsaIQueryForestTrustInfo (Address: 0x18003a660)
  • LsaIQueryInformationPolicyTrusted (Address: 0x18003a780)
  • LsaIQueryUpnSuffixes (Address: 0x18003a658)
  • LsaIRegisterNotification (Address: 0x18003a8a0)
  • LsaLookupPerfCounterAddAmount (Address: 0x18003a6e8)
  • LsaLookupPerfCounterAddLargeAmount (Address: 0x18003a6e0)
  • LsaLookupPerfCounterIncrementCount (Address: 0x18003a700)
  • LsapAdtAuditingEnabledByLogonId (Address: 0x18003a610)
  • LsapAdtAuditingEnabledBySubCategory (Address: 0x18003a740)
  • LsapAdtAuditingEnabledHint (Address: 0x18003a888)
  • LsapAdtInitParametersArray (Address: 0x18003a608)
  • LsapAdtWriteLog (Address: 0x18003a600)
  • LsapAllocateLsaHeap (Address: 0x18003a990)
  • LsapAuditFailed (Address: 0x18003a7a0)
  • LsapCloseHandle (Address: 0x18003a730)
  • LsapCompareDomainNames (Address: 0x18003a970)
  • LsapCrServerGetSessionKeySafe (Address: 0x18003a7b8)
  • LsapDbAcquireLockEx (Address: 0x18003a8e0)
  • LsapDbApplyTransaction (Address: 0x18003a7f8)
  • LsapDbBuildObjectCaches (Address: 0x18003a8d8)
  • LsapDbCloseHandle (Address: 0x18003a670)
  • LsapDbCloseObject (Address: 0x18003a770)
  • LsapDbCopyUnicodeAttribute (Address: 0x18003a7d8)
  • LsapDbCopyUnicodeAttributeNoAlloc (Address: 0x18003a910)
  • LsapDbCreateObject (Address: 0x18003a808)
  • LsapDbDeleteObject (Address: 0x18003a880)
  • LsapDbDereferenceHandle (Address: 0x18003a878)
  • LsapDbDereferenceObject (Address: 0x18003a900)
  • LsapDbEnumerateTrustedDomainsEx (Address: 0x18003a7b0)
  • LsapDbExpAcquireReadLockTrustedDomainList (Address: 0x18003a940)
  • LsapDbExpAcquireWriteLockTrustedDomainList (Address: 0x18003a898)
  • LsapDbExpConvertReadLockTrustedDomainListToExclusive (Address: 0x18003a748)
  • LsapDbExpConvertWriteLockTrustedDomainListToShared (Address: 0x18003a668)
  • LsapDbExpIsCacheBuilding (Address: 0x18003a798)
  • LsapDbExpIsCacheValid (Address: 0x18003a938)
  • LsapDbExpMakeCacheBuilding (Address: 0x18003a768)
  • LsapDbExpMakeCacheInvalid (Address: 0x18003a988)
  • LsapDbExpMakeCacheValid (Address: 0x18003a850)
  • LsapDbExpReleaseLockTrustedDomainList (Address: 0x18003a928)
  • LsapDbFreeAttributes (Address: 0x18003a8f0)
  • LsapDbFreeTrustedDomainsEx (Address: 0x18003a9a8)
  • LsapDbGetDbObjectTypeName (Address: 0x18003a858)
  • LsapDbInitializeAttribute (Address: 0x18003a920)
  • LsapDbLookupAddListReferencedDomains (Address: 0x18003a728)
  • LsapDbLookupCreateListReferencedDomains (Address: 0x18003a6b8)
  • LsapDbLookupGetDomainInfo (Address: 0x18003a6c8)
  • LsapDbLookupListReferencedDomains (Address: 0x18003a6f0)
  • LsapDbLookupMergeDisjointReferencedDomains (Address: 0x18003a6d8)
  • LsapDbLookupNameChainRequest (Address: 0x18003a6c0)
  • LsapDbLookupNamesInPrimaryDomain (Address: 0x18003a6a8)
  • LsapDbLookupSidsInPrimaryDomain (Address: 0x18003a698)
  • LsapDbMakeGuidAttribute (Address: 0x18003a680)
  • LsapDbMakeSidAttribute (Address: 0x18003a688)
  • LsapDbMakeUnicodeAttribute (Address: 0x18003a690)
  • LsapDbOpenObject (Address: 0x18003a930)
  • LsapDbQueryInformationPolicy (Address: 0x18003a978)
  • LsapDbReadAttribute (Address: 0x18003a778)
  • LsapDbReadAttributesObject (Address: 0x18003a918)
  • LsapDbReferenceObject (Address: 0x18003a908)
  • LsapDbReleaseLockEx (Address: 0x18003a8d0)
  • LsapDbSidToLogicalNameObject (Address: 0x18003a810)
  • LsapDbSlowEnumerateTrustedDomains (Address: 0x18003a760)
  • LsapDbUpdateCountCompUnmappedNames (Address: 0x18003a6d0)
  • LsapDbVerifyHandle (Address: 0x18003a7c0)
  • LsapDbVerifyInfoQueryTrustedDomain (Address: 0x18003a7e0)
  • LsapDbVerifyInfoSetTrustedDomain (Address: 0x18003a7c8)
  • LsapDbWriteAttributesObject (Address: 0x18003a9a0)
  • LsapDomainRenameHandlerForLogonSessions (Address: 0x18003a8f8)
  • LsapDsInitializeDsStateInfo (Address: 0x18003a960)
  • LsapDuplicateSid (Address: 0x18003a738)
  • LsapDuplicateString (Address: 0x18003a840)
  • LsapFreeLsaHeap (Address: 0x18003a998)
  • LsapFreeString (Address: 0x18003a848)
  • LsapGetAccountDomainHandle (Address: 0x18003a8a8)
  • LsapGetGlobalRestrictAnonymous (Address: 0x18003a800)
  • LsapGetLookupRestrictIsolatedNameLevel (Address: 0x18003a708)
  • LsapGetPolicyHandle (Address: 0x18003a980)
  • LsapGetWellKnownSid (Address: 0x18003a8c0)
  • LsapIsSamOpened (Address: 0x18003a678)
  • LsapOpenSam (Address: 0x18003a8b8)
  • LsapQueryClientInfo (Address: 0x18003a618)
  • LsapRemoveTrailingDot (Address: 0x18003a818)
  • LsapRpcCopySid (Address: 0x18003a7a8)
  • LsapRpcCopyUnicodeString (Address: 0x18003a820)
  • LsapRtlValidateControllerTrustedDomain (Address: 0x18003a710)
  • LsapRtlValidateControllerTrustedDomainByHandle (Address: 0x18003a718)
  • LsapSetErrorInfo (Address: 0x18003a958)
  • LsapTraceEvent (Address: 0x18003a7e8)
  • LsapTraceEventWithData (Address: 0x18003a6f8)
  • LsapTruncateUnicodeString (Address: 0x18003a860)
  • LsarClose (Address: 0x18003a620)
  • LsarDeleteObject (Address: 0x18003a7f0)
  • LsarQuerySecret (Address: 0x18003a830)
  • LsarQueryTrustedDomainInfoByName (Address: 0x18003a8b0)
  • SpmpEventWrite (Address: 0x18003a8e8)
  • TracePrint (Address: 0x18003a950)
  • TracePrintCallerInformation (Address: 0x18003a7d0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18003afa8)
  • __dllonexit (Address: 0x18003af20)
  • _amsg_exit (Address: 0x18003af58)
  • _callnewh (Address: 0x18003af68)
  • _initterm (Address: 0x18003af50)
  • _lock (Address: 0x18003af48)
  • _onexit (Address: 0x18003af78)
  • _purecall (Address: 0x18003afc0)
  • _unlock (Address: 0x18003af30)
  • _vsnprintf (Address: 0x18003af98)
  • _vsnwprintf (Address: 0x18003af40)
  • _wcsicmp (Address: 0x18003af90)
  • _wcsnicmp (Address: 0x18003afa0)
  • _wtoi (Address: 0x18003af88)
  • _XcptFilter (Address: 0x18003af60)
  • free (Address: 0x18003af80)
  • malloc (Address: 0x18003afd0)
  • memcmp (Address: 0x18003af28)
  • memcpy (Address: 0x18003af70)
  • memcpy_s (Address: 0x18003afc8)
  • memmove (Address: 0x18003af38)
  • memmove_s (Address: 0x18003afb8)
  • memset (Address: 0x18003afd8)
  • qsort (Address: 0x18003afb0)
ntdll.dll
  • NtAccessCheckByTypeResultListAndAuditAlarm (Address: 0x18003b0a8)
  • NtAllocateLocallyUniqueId (Address: 0x18003b008)
  • NtClose (Address: 0x18003b068)
  • NtCreateEvent (Address: 0x18003b0f0)
  • NtOpenThreadToken (Address: 0x18003b058)
  • NtQueryInformationToken (Address: 0x18003b050)
  • NtQuerySystemTime (Address: 0x18003b098)
  • NtSetEvent (Address: 0x18003b000)
  • NtWaitForSingleObject (Address: 0x18003aff8)
  • RtlAllocateHeap (Address: 0x18003b040)
  • RtlAreAllAccessesGranted (Address: 0x18003b0a0)
  • RtlCompareUnicodeString (Address: 0x18003b030)
  • RtlCopySid (Address: 0x18003b078)
  • RtlCopyUnicodeString (Address: 0x18003b060)
  • RtlDeleteCriticalSection (Address: 0x18003b100)
  • RtlDeleteElementGenericTableAvl (Address: 0x18003b010)
  • RtlEnterCriticalSection (Address: 0x18003b0b8)
  • RtlEnumerateGenericTableAvl (Address: 0x18003b048)
  • RtlEqualSid (Address: 0x18003b088)
  • RtlEqualUnicodeString (Address: 0x18003b0e0)
  • RtlFindCharInUnicodeString (Address: 0x18003afe8)
  • RtlFreeHeap (Address: 0x18003b038)
  • RtlFreeUnicodeString (Address: 0x18003b080)
  • RtlGetLastNtStatus (Address: 0x18003b090)
  • RtlImageNtHeader (Address: 0x18003b070)
  • RtlInitializeCriticalSection (Address: 0x18003b108)
  • RtlInitializeGenericTableAvl (Address: 0x18003b020)
  • RtlInitUnicodeString (Address: 0x18003b0e8)
  • RtlInsertElementGenericTableAvl (Address: 0x18003b018)
  • RtlLeaveCriticalSection (Address: 0x18003b0b0)
  • RtlLengthSid (Address: 0x18003b0d0)
  • RtlLookupElementGenericTableAvl (Address: 0x18003b028)
  • RtlNtStatusToDosError (Address: 0x18003b0c0)
  • RtlNumberGenericTableElementsAvl (Address: 0x18003b0f8)
  • RtlPrefixUnicodeString (Address: 0x18003b0c8)
  • RtlSubAuthorityCountSid (Address: 0x18003b110)
  • RtlSubAuthoritySid (Address: 0x18003aff0)
  • RtlValidSid (Address: 0x18003b0d8)
RPCRT4.dll
  • I_RpcBindingIsClientLocal (Address: 0x18003a9f0)
  • I_RpcMapWin32Status (Address: 0x18003a9e8)
  • RpcBindingFree (Address: 0x18003a9b8)
  • RpcBindingServerFromClient (Address: 0x18003a9d0)
  • RpcBindingToStringBindingW (Address: 0x18003a9c8)
  • RpcImpersonateClient (Address: 0x18003a9d8)
  • RpcRevertToSelf (Address: 0x18003a9e0)
  • RpcServerInqCallAttributesW (Address: 0x18003aa10)
  • RpcStringBindingParseW (Address: 0x18003a9c0)
  • RpcStringFreeW (Address: 0x18003a9f8)
  • UuidCreate (Address: 0x18003aa08)
  • UuidToStringW (Address: 0x18003aa00)
SAMSRV.dll
  • SamIFree_SAMPR_ENUMERATION_BUFFER (Address: 0x18003aaa0)
  • SamIFree_SAMPR_RETURNED_USTRING_ARRAY (Address: 0x18003aa20)
  • SamIFree_SAMPR_ULONG_ARRAY (Address: 0x18003aa98)
  • SamIFree_SAMPR_USER_INFO_BUFFER (Address: 0x18003aa30)
  • SamIFreeSidAndAttributesList (Address: 0x18003aa40)
  • SamIFreeSidArray (Address: 0x18003aa80)
  • SamIGetUserLogonInformationEx (Address: 0x18003aa48)
  • SamIQueryCapabilities (Address: 0x18003aaa8)
  • SamIQueryServerRole (Address: 0x18003aa70)
  • SampDsIsRunning (Address: 0x18003aa78)
  • SampUsingDsData (Address: 0x18003aa88)
  • SamrCloseHandle (Address: 0x18003aa28)
  • SamrCreateUser2InDomain (Address: 0x18003aa58)
  • SamrDeleteUser (Address: 0x18003aa50)
  • SamrEnumerateUsersInDomain (Address: 0x18003aa60)
  • SamrLookupNamesInDomain (Address: 0x18003aa68)
  • SamrOpenUser (Address: 0x18003aa90)
  • SamrSetInformationUser (Address: 0x18003aa38)
WLDAP32.dll
  • (Address: 0x18003aab8)
  • (Address: 0x18003aac0)
  • (Address: 0x18003aac8)
  • (Address: 0x18003aad0)
  • (Address: 0x18003aad8)
  • (Address: 0x18003aae0)
  • (Address: 0x18003aae8)
  • (Address: 0x18003aaf0)
  • (Address: 0x18003aaf8)
  • (Address: 0x18003ab00)
  • (Address: 0x18003ab08)
  • (Address: 0x18003ab10)
  • (Address: 0x18003ab18)
  • (Address: 0x18003ab20)
  • (Address: 0x18003ab28)