EventAggregation.dll
Description: Event Aggregation User Mode Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: d5726a6fd14e328363446dbab08607bb
File Size: 77.5 KB
Uploaded At: Dec. 1, 2025, 7:27 a.m.
Views: 10
Exported Functions
- BriAllocateRpcBuffer (Ordinal: 1, Address: 0x6f20)
- BriCleanup (Ordinal: 2, Address: 0x7020)
- BriCreateBrokeredEvent (Ordinal: 3, Address: 0x72b0)
- BriCreateBrokeredEventEx (Ordinal: 4, Address: 0x7300)
- BriDeleteBrokeredEvent (Ordinal: 5, Address: 0x7d20)
- BriFreeRpcBuffer (Ordinal: 6, Address: 0x7ea0)
- BriGetBrokerAvailabilityChangeStamp (Ordinal: 7, Address: 0x8940)
- BriIsBrokerRegistered (Ordinal: 8, Address: 0x6f30)
- BriRegisterToBrokerAvailability (Ordinal: 9, Address: 0x8a90)
- BriResolveBrokerIdByEventId (Ordinal: 10, Address: 0x88a0)
- BriUnregisterFromBrokerAvailability (Ordinal: 11, Address: 0x8bf0)
- EACreateAggregateEvent (Ordinal: 12, Address: 0x3e50)
- EADeleteAggregateEvent (Ordinal: 13, Address: 0x45c0)
- EAEnumerateAggregateEvents (Ordinal: 14, Address: 0x4630)
- EAQueryAggregateEventData (Ordinal: 15, Address: 0x47e0)
- EaCreateAggregatedEvent (Ordinal: 16, Address: 0x6e50)
- EaCreateAggregation (Ordinal: 17, Address: 0x51f0)
- EaDecodeBrokeredEvent (Ordinal: 18, Address: 0x8f90)
- EaDeleteAggregatedEvent (Ordinal: 19, Address: 0x6830)
- EaDeleteAggregatedEventParameters (Ordinal: 20, Address: 0xb410)
- EaDeleteAggregation (Ordinal: 21, Address: 0x5b80)
- EaDisableAggregatedEvent (Ordinal: 22, Address: 0x6160)
- EaEnableAggregatedEvent (Ordinal: 23, Address: 0x5f20)
- EaEncodeBrokeredEvent (Ordinal: 24, Address: 0x8ea0)
- EaFreeAggregatedEventParameters (Ordinal: 25, Address: 0x9e20)
- EaFreeBuffer (Ordinal: 26, Address: 0x8910)
- EaGetAggregation (Ordinal: 27, Address: 0x5f10)
- EaQueryAggregateEventConditionState (Ordinal: 28, Address: 0x64a0)
- EaQueryAggregatedEvent (Ordinal: 29, Address: 0x4c70)
- EaQueryAggregatedEventParameters (Ordinal: 30, Address: 0xafc0)
- EaSignalAggregatedEvent (Ordinal: 31, Address: 0x4a00)
- EaStoreAggregatedEventParameters (Ordinal: 32, Address: 0xad50)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- IsDebuggerPresent (Address: 0x18000ea70)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18000ea80)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18000ea90)
api-ms-win-core-errorhandling-l1-1-0.dll
- SetUnhandledExceptionFilter (Address: 0x18000eaa0)
- UnhandledExceptionFilter (Address: 0x18000eaa8)
api-ms-win-core-heap-l2-1-0.dll
- LocalFree (Address: 0x18000eab8)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x18000eac8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18000ead8)
- GetCurrentProcessId (Address: 0x18000eae8)
- GetCurrentThreadId (Address: 0x18000eaf0)
- TerminateProcess (Address: 0x18000eae0)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x18000eb00)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18000eb10)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18000eb20)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x18000eb70)
- _o___std_type_info_destroy_list (Address: 0x18000eb30)
- _o__cexit (Address: 0x18000eb38)
- _o__configure_narrow_argv (Address: 0x18000eb40)
- _o__execute_onexit_table (Address: 0x18000eb48)
- _o__initialize_narrow_environment (Address: 0x18000eb50)
- _o__initialize_onexit_table (Address: 0x18000eb58)
- _o__seh_filter_dll (Address: 0x18000eb60)
- memcpy (Address: 0x18000eb68)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x18000eb80)
- _initterm_e (Address: 0x18000eb88)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x18000eb98)
- wcsnlen (Address: 0x18000eba0)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x18000ebb0)
- GetTraceEnableLevel (Address: 0x18000ebc0)
- GetTraceLoggerHandle (Address: 0x18000ebb8)
- RegisterTraceGuidsW (Address: 0x18000ebc8)
- TraceMessage (Address: 0x18000ebd8)
- UnregisterTraceGuids (Address: 0x18000ebd0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x18000ebe8)
- EventSetInformation (Address: 0x18000ebf0)
- EventUnregister (Address: 0x18000ebf8)
- EventWriteTransfer (Address: 0x18000ec00)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000ec10)
- ConvertStringSidToSidW (Address: 0x18000ec18)
ntdll.dll
- NtClose (Address: 0x18000ecf0)
- NtDuplicateObject (Address: 0x18000ece0)
- NtQueryWnfStateData (Address: 0x18000ed08)
- RtlAcquireSRWLockExclusive (Address: 0x18000ed20)
- RtlAcquireSRWLockShared (Address: 0x18000ecb8)
- RtlAllocateHeap (Address: 0x18000ed88)
- RtlAllocateWnfSerializationGroup (Address: 0x18000ec28)
- RtlCaptureContext (Address: 0x18000ec78)
- RtlCompareMemory (Address: 0x18000ec40)
- RtlCompareUnicodeString (Address: 0x18000ec38)
- RtlComputeCrc32 (Address: 0x18000ecc0)
- RtlCreateHashTable (Address: 0x18000ed68)
- RtlDeleteHashTable (Address: 0x18000ed38)
- RtlEndEnumerationHashTable (Address: 0x18000ed70)
- RtlEnumerateEntryHashTable (Address: 0x18000ed78)
- RtlFreeHeap (Address: 0x18000ec88)
- RtlFreeUnicodeString (Address: 0x18000ec90)
- RtlGetLastWin32Error (Address: 0x18000ecc8)
- RtlGetNextEntryHashTable (Address: 0x18000ec68)
- RtlGUIDFromString (Address: 0x18000edb0)
- RtlInitEnumerationHashTable (Address: 0x18000ed58)
- RtlInitializeSRWLock (Address: 0x18000ed80)
- RtlInitUnicodeString (Address: 0x18000ed10)
- RtlInitUnicodeStringEx (Address: 0x18000ece8)
- RtlInsertEntryHashTable (Address: 0x18000ed50)
- RtlLengthSid (Address: 0x18000ed00)
- RtlLookupEntryHashTable (Address: 0x18000ed40)
- RtlLookupFunctionEntry (Address: 0x18000ec58)
- RtlNtStatusToDosError (Address: 0x18000ed48)
- RtlReleaseSRWLockExclusive (Address: 0x18000ec80)
- RtlReleaseSRWLockShared (Address: 0x18000ecb0)
- RtlRemoveEntryHashTable (Address: 0x18000ed60)
- RtlRunOnceExecuteOnce (Address: 0x18000ecf8)
- RtlStringFromGUID (Address: 0x18000ecd8)
- RtlSubscribeWnfStateChangeNotification (Address: 0x18000ed18)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x18000ec98)
- RtlValidSid (Address: 0x18000ed28)
- RtlVirtualUnwind (Address: 0x18000ec48)
- TpAllocTimer (Address: 0x18000eca8)
- TpReleaseTimer (Address: 0x18000ed30)
- TpSetTimer (Address: 0x18000ed98)
- TpWaitForTimer (Address: 0x18000eca0)
- ZwClose (Address: 0x18000ec60)
- ZwCreateKey (Address: 0x18000ec30)
- ZwDeleteKey (Address: 0x18000eda8)
- ZwEnumerateKey (Address: 0x18000ecd0)
- ZwEnumerateValueKey (Address: 0x18000ed90)
- ZwOpenKey (Address: 0x18000ec50)
- ZwQueryValueKey (Address: 0x18000ec70)
- ZwSetValueKey (Address: 0x18000eda0)
RPCRT4.dll
- NdrClientCall3 (Address: 0x18000ea58)
- RpcBindingBind (Address: 0x18000ea40)
- RpcBindingCreateW (Address: 0x18000ea38)
- RpcBindingFree (Address: 0x18000ea48)
- UuidCreate (Address: 0x18000ea50)
- UuidEqual (Address: 0x18000ea60)