EventAggregation.dll

Description: Event Aggregation User Mode Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: d5726a6fd14e328363446dbab08607bb

File Size: 77.5 KB

Uploaded At: Dec. 1, 2025, 7:27 a.m.

Views: 10

Exported Functions

  • BriAllocateRpcBuffer (Ordinal: 1, Address: 0x6f20)
  • BriCleanup (Ordinal: 2, Address: 0x7020)
  • BriCreateBrokeredEvent (Ordinal: 3, Address: 0x72b0)
  • BriCreateBrokeredEventEx (Ordinal: 4, Address: 0x7300)
  • BriDeleteBrokeredEvent (Ordinal: 5, Address: 0x7d20)
  • BriFreeRpcBuffer (Ordinal: 6, Address: 0x7ea0)
  • BriGetBrokerAvailabilityChangeStamp (Ordinal: 7, Address: 0x8940)
  • BriIsBrokerRegistered (Ordinal: 8, Address: 0x6f30)
  • BriRegisterToBrokerAvailability (Ordinal: 9, Address: 0x8a90)
  • BriResolveBrokerIdByEventId (Ordinal: 10, Address: 0x88a0)
  • BriUnregisterFromBrokerAvailability (Ordinal: 11, Address: 0x8bf0)
  • EACreateAggregateEvent (Ordinal: 12, Address: 0x3e50)
  • EADeleteAggregateEvent (Ordinal: 13, Address: 0x45c0)
  • EAEnumerateAggregateEvents (Ordinal: 14, Address: 0x4630)
  • EAQueryAggregateEventData (Ordinal: 15, Address: 0x47e0)
  • EaCreateAggregatedEvent (Ordinal: 16, Address: 0x6e50)
  • EaCreateAggregation (Ordinal: 17, Address: 0x51f0)
  • EaDecodeBrokeredEvent (Ordinal: 18, Address: 0x8f90)
  • EaDeleteAggregatedEvent (Ordinal: 19, Address: 0x6830)
  • EaDeleteAggregatedEventParameters (Ordinal: 20, Address: 0xb410)
  • EaDeleteAggregation (Ordinal: 21, Address: 0x5b80)
  • EaDisableAggregatedEvent (Ordinal: 22, Address: 0x6160)
  • EaEnableAggregatedEvent (Ordinal: 23, Address: 0x5f20)
  • EaEncodeBrokeredEvent (Ordinal: 24, Address: 0x8ea0)
  • EaFreeAggregatedEventParameters (Ordinal: 25, Address: 0x9e20)
  • EaFreeBuffer (Ordinal: 26, Address: 0x8910)
  • EaGetAggregation (Ordinal: 27, Address: 0x5f10)
  • EaQueryAggregateEventConditionState (Ordinal: 28, Address: 0x64a0)
  • EaQueryAggregatedEvent (Ordinal: 29, Address: 0x4c70)
  • EaQueryAggregatedEventParameters (Ordinal: 30, Address: 0xafc0)
  • EaSignalAggregatedEvent (Ordinal: 31, Address: 0x4a00)
  • EaStoreAggregatedEventParameters (Ordinal: 32, Address: 0xad50)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • IsDebuggerPresent (Address: 0x18000ea70)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18000ea80)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18000ea90)
api-ms-win-core-errorhandling-l1-1-0.dll
  • SetUnhandledExceptionFilter (Address: 0x18000eaa0)
  • UnhandledExceptionFilter (Address: 0x18000eaa8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x18000eab8)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x18000eac8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000ead8)
  • GetCurrentProcessId (Address: 0x18000eae8)
  • GetCurrentThreadId (Address: 0x18000eaf0)
  • TerminateProcess (Address: 0x18000eae0)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x18000eb00)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000eb10)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18000eb20)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x18000eb70)
  • _o___std_type_info_destroy_list (Address: 0x18000eb30)
  • _o__cexit (Address: 0x18000eb38)
  • _o__configure_narrow_argv (Address: 0x18000eb40)
  • _o__execute_onexit_table (Address: 0x18000eb48)
  • _o__initialize_narrow_environment (Address: 0x18000eb50)
  • _o__initialize_onexit_table (Address: 0x18000eb58)
  • _o__seh_filter_dll (Address: 0x18000eb60)
  • memcpy (Address: 0x18000eb68)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x18000eb80)
  • _initterm_e (Address: 0x18000eb88)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x18000eb98)
  • wcsnlen (Address: 0x18000eba0)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18000ebb0)
  • GetTraceEnableLevel (Address: 0x18000ebc0)
  • GetTraceLoggerHandle (Address: 0x18000ebb8)
  • RegisterTraceGuidsW (Address: 0x18000ebc8)
  • TraceMessage (Address: 0x18000ebd8)
  • UnregisterTraceGuids (Address: 0x18000ebd0)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x18000ebe8)
  • EventSetInformation (Address: 0x18000ebf0)
  • EventUnregister (Address: 0x18000ebf8)
  • EventWriteTransfer (Address: 0x18000ec00)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000ec10)
  • ConvertStringSidToSidW (Address: 0x18000ec18)
ntdll.dll
  • NtClose (Address: 0x18000ecf0)
  • NtDuplicateObject (Address: 0x18000ece0)
  • NtQueryWnfStateData (Address: 0x18000ed08)
  • RtlAcquireSRWLockExclusive (Address: 0x18000ed20)
  • RtlAcquireSRWLockShared (Address: 0x18000ecb8)
  • RtlAllocateHeap (Address: 0x18000ed88)
  • RtlAllocateWnfSerializationGroup (Address: 0x18000ec28)
  • RtlCaptureContext (Address: 0x18000ec78)
  • RtlCompareMemory (Address: 0x18000ec40)
  • RtlCompareUnicodeString (Address: 0x18000ec38)
  • RtlComputeCrc32 (Address: 0x18000ecc0)
  • RtlCreateHashTable (Address: 0x18000ed68)
  • RtlDeleteHashTable (Address: 0x18000ed38)
  • RtlEndEnumerationHashTable (Address: 0x18000ed70)
  • RtlEnumerateEntryHashTable (Address: 0x18000ed78)
  • RtlFreeHeap (Address: 0x18000ec88)
  • RtlFreeUnicodeString (Address: 0x18000ec90)
  • RtlGetLastWin32Error (Address: 0x18000ecc8)
  • RtlGetNextEntryHashTable (Address: 0x18000ec68)
  • RtlGUIDFromString (Address: 0x18000edb0)
  • RtlInitEnumerationHashTable (Address: 0x18000ed58)
  • RtlInitializeSRWLock (Address: 0x18000ed80)
  • RtlInitUnicodeString (Address: 0x18000ed10)
  • RtlInitUnicodeStringEx (Address: 0x18000ece8)
  • RtlInsertEntryHashTable (Address: 0x18000ed50)
  • RtlLengthSid (Address: 0x18000ed00)
  • RtlLookupEntryHashTable (Address: 0x18000ed40)
  • RtlLookupFunctionEntry (Address: 0x18000ec58)
  • RtlNtStatusToDosError (Address: 0x18000ed48)
  • RtlReleaseSRWLockExclusive (Address: 0x18000ec80)
  • RtlReleaseSRWLockShared (Address: 0x18000ecb0)
  • RtlRemoveEntryHashTable (Address: 0x18000ed60)
  • RtlRunOnceExecuteOnce (Address: 0x18000ecf8)
  • RtlStringFromGUID (Address: 0x18000ecd8)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x18000ed18)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x18000ec98)
  • RtlValidSid (Address: 0x18000ed28)
  • RtlVirtualUnwind (Address: 0x18000ec48)
  • TpAllocTimer (Address: 0x18000eca8)
  • TpReleaseTimer (Address: 0x18000ed30)
  • TpSetTimer (Address: 0x18000ed98)
  • TpWaitForTimer (Address: 0x18000eca0)
  • ZwClose (Address: 0x18000ec60)
  • ZwCreateKey (Address: 0x18000ec30)
  • ZwDeleteKey (Address: 0x18000eda8)
  • ZwEnumerateKey (Address: 0x18000ecd0)
  • ZwEnumerateValueKey (Address: 0x18000ed90)
  • ZwOpenKey (Address: 0x18000ec50)
  • ZwQueryValueKey (Address: 0x18000ec70)
  • ZwSetValueKey (Address: 0x18000eda0)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x18000ea58)
  • RpcBindingBind (Address: 0x18000ea40)
  • RpcBindingCreateW (Address: 0x18000ea38)
  • RpcBindingFree (Address: 0x18000ea48)
  • UuidCreate (Address: 0x18000ea50)
  • UuidEqual (Address: 0x18000ea60)