mssecuser.dll

Description: Microsoft Security Events Component Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.8804.27858.1000

Architecture: 64-bit

Operating System: Windows NT

SHA256: fc666987c3c567550a34c213ca71e639

File Size: 325.4 KB

Uploaded At: Dec. 1, 2025, 7:34 a.m.

Views: 5

Exported Functions

  • SecClearKseRegistryOperations (Ordinal: 1, Address: 0x85f0)
  • SecClearRegistryOperations (Ordinal: 2, Address: 0x8600)
  • SecCreateSessionFilter (Ordinal: 3, Address: 0x6dc0)
  • SecDeleteSessionFilter (Ordinal: 4, Address: 0x6e60)
  • SecGetCiInformation (Ordinal: 5, Address: 0x6eb0)
  • SecGetDriverVersion (Ordinal: 6, Address: 0x6ff0)
  • SecGetFileHashes (Ordinal: 7, Address: 0x70a0)
  • SecGetProcessInfo (Ordinal: 8, Address: 0x7310)
  • SecGetUserLibVersion (Ordinal: 9, Address: 0x7520)
  • SecOpenFileAndRequestOplock (Ordinal: 10, Address: 0x7540)
  • SecRegisterConsumer (Ordinal: 11, Address: 0x12f0)
  • SecRequestOplock (Ordinal: 12, Address: 0x7720)
  • SecSetCiInformation (Ordinal: 13, Address: 0x7830)
  • SecSetConfiguration (Ordinal: 14, Address: 0xfe40)
  • SecSetDlpConfiguration (Ordinal: 15, Address: 0x10630)
  • SecSetFileMonitorOperations (Ordinal: 16, Address: 0x13ab0)
  • SecSetKseConfiguration (Ordinal: 17, Address: 0x85f0)
  • SecSetKseFileMonitorOperations (Ordinal: 18, Address: 0x85f0)
  • SecSetKseRegistryOperations (Ordinal: 19, Address: 0x85f0)
  • SecSetLmfConfiguration (Ordinal: 20, Address: 0x10820)
  • SecSetLmfNetworkShareConfiguration (Ordinal: 21, Address: 0x10a70)
  • SecSetLmfSysvolAccessConfiguration (Ordinal: 22, Address: 0x10f50)
  • SecSetRegistryOperations (Ordinal: 23, Address: 0x8960)
  • SecUninitializeDriver (Ordinal: 24, Address: 0x1430)
  • SecUnregisterConsumer (Ordinal: 25, Address: 0x1490)
  • SecWriteExtendedFileHashEA (Ordinal: 26, Address: 0x7920)
  • SecWriteFileDlpEA (Ordinal: 27, Address: 0x7a90)
  • SecWriteFileHashEA (Ordinal: 28, Address: 0x7c40)
  • SecWriteFileMarkOfTheWebEA (Ordinal: 29, Address: 0x7de0)

Imported DLLs & Functions

api-ms-win-core-console-l1-1-0.dll
  • GetConsoleMode (Address: 0x180035018)
  • GetConsoleOutputCP (Address: 0x180035020)
  • WriteConsoleW (Address: 0x180035028)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180035048)
  • IsDebuggerPresent (Address: 0x180035040)
  • OutputDebugStringW (Address: 0x180035038)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180035068)
  • RaiseException (Address: 0x180035060)
  • SetLastError (Address: 0x180035058)
  • SetUnhandledExceptionFilter (Address: 0x180035070)
  • UnhandledExceptionFilter (Address: 0x180035078)
api-ms-win-core-featurestaging-l1-1-0.dll
  • GetFeatureEnabledState (Address: 0x1800350a0)
  • RecordFeatureError (Address: 0x180035098)
  • RecordFeatureUsage (Address: 0x1800350a8)
  • SubscribeFeatureStateChangeNotification (Address: 0x180035088)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180035090)
api-ms-win-core-featurestaging-l1-1-1.dll
  • GetFeatureVariant (Address: 0x1800350b8)
api-ms-win-core-fibers-l1-1-0.dll
  • FlsAlloc (Address: 0x1800350d8)
  • FlsFree (Address: 0x1800350d0)
  • FlsGetValue (Address: 0x1800350e0)
  • FlsSetValue (Address: 0x1800350c8)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180035118)
  • FindClose (Address: 0x180035120)
  • FindFirstFileExW (Address: 0x1800350f8)
  • FindNextFileW (Address: 0x180035128)
  • FlushFileBuffers (Address: 0x1800350f0)
  • GetFileType (Address: 0x180035100)
  • SetFilePointerEx (Address: 0x180035110)
  • WriteFile (Address: 0x180035108)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180035138)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180035148)
  • HeapAlloc (Address: 0x180035150)
  • HeapFree (Address: 0x180035160)
  • HeapReAlloc (Address: 0x180035168)
  • HeapSize (Address: 0x180035158)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180035178)
  • InterlockedFlushSList (Address: 0x180035180)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x180035190)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FindStringOrdinal (Address: 0x1800351c8)
  • FreeLibrary (Address: 0x1800351d8)
  • GetModuleFileNameA (Address: 0x1800351a0)
  • GetModuleFileNameW (Address: 0x1800351a8)
  • GetModuleHandleExA (Address: 0x1800351e0)
  • GetModuleHandleExW (Address: 0x1800351b8)
  • GetModuleHandleW (Address: 0x1800351d0)
  • GetProcAddress (Address: 0x1800351c0)
  • LoadLibraryExW (Address: 0x1800351b0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180035208)
  • GetACP (Address: 0x180035200)
  • GetCPInfo (Address: 0x180035218)
  • GetOEMCP (Address: 0x180035210)
  • IsValidCodePage (Address: 0x1800351f8)
  • LCMapStringW (Address: 0x1800351f0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • FreeEnvironmentStringsW (Address: 0x180035238)
  • GetCommandLineA (Address: 0x180035250)
  • GetCommandLineW (Address: 0x180035248)
  • GetEnvironmentStringsW (Address: 0x180035240)
  • GetStdHandle (Address: 0x180035228)
  • SetStdHandle (Address: 0x180035230)
api-ms-win-core-processthreads-l1-1-0.dll
  • ExitProcess (Address: 0x180035298)
  • GetCurrentProcess (Address: 0x180035270)
  • GetCurrentProcessId (Address: 0x180035280)
  • GetCurrentThreadId (Address: 0x180035288)
  • GetStartupInfoW (Address: 0x180035278)
  • TerminateProcess (Address: 0x1800352a8)
  • TlsAlloc (Address: 0x180035260)
  • TlsFree (Address: 0x1800352a0)
  • TlsGetValue (Address: 0x180035290)
  • TlsSetValue (Address: 0x180035268)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x1800352b8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800352c8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800352d8)
  • GetStringTypeW (Address: 0x1800352f0)
  • MultiByteToWideChar (Address: 0x1800352e0)
  • WideCharToMultiByte (Address: 0x1800352e8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180035338)
  • AcquireSRWLockShared (Address: 0x180035340)
  • CreateMutexExW (Address: 0x180035378)
  • CreateSemaphoreExW (Address: 0x180035370)
  • DeleteCriticalSection (Address: 0x180035328)
  • EnterCriticalSection (Address: 0x180035308)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180035330)
  • InitializeSRWLock (Address: 0x180035300)
  • LeaveCriticalSection (Address: 0x180035310)
  • OpenSemaphoreW (Address: 0x180035368)
  • ReleaseMutex (Address: 0x180035350)
  • ReleaseSemaphore (Address: 0x180035348)
  • ReleaseSRWLockExclusive (Address: 0x180035318)
  • ReleaseSRWLockShared (Address: 0x180035320)
  • WaitForSingleObject (Address: 0x180035358)
  • WaitForSingleObjectEx (Address: 0x180035360)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180035388)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180035398)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800353b8)
  • CreateThreadpoolTimer (Address: 0x1800353a8)
  • SetThreadpoolTimer (Address: 0x1800353b0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800353c0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x1800353d0)
  • EncodePointer (Address: 0x1800353d8)
api-ms-win-security-base-l1-1-0.dll
  • CopySid (Address: 0x1800353f0)
  • GetLengthSid (Address: 0x1800353f8)
  • GetSecurityDescriptorLength (Address: 0x180035400)
  • IsValidSid (Address: 0x1800353e8)
FLTLIB.DLL
  • FilterConnectCommunicationPort (Address: 0x180035008)
  • FilterSendMessage (Address: 0x180035000)
ntdll.dll
  • RtlCaptureContext (Address: 0x180035430)
  • RtlInitUnicodeStringEx (Address: 0x180035440)
  • RtlLookupFunctionEntry (Address: 0x180035418)
  • RtlPcToFileHeader (Address: 0x180035428)
  • RtlPrefixUnicodeString (Address: 0x180035410)
  • RtlUnwindEx (Address: 0x180035420)
  • RtlVirtualUnwind (Address: 0x180035438)