auditcse.dll

Description: Windows Audit Settings CSE

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 2e3f64c77e4d101a1bc093b96bf41a57

File Size: 251.5 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 12

Exported Functions

  • GenerateGroupPolicy (Ordinal: 1, Address: 0x2400)
  • GenerateGroupPolicyCap (Ordinal: 2, Address: 0x2670)
  • ProcessGroupPolicyEx (Ordinal: 3, Address: 0x2070)
  • ProcessGroupPolicyExCap (Ordinal: 4, Address: 0x2da0)

Imported DLLs & Functions

ADVAPI32.dll
  • AuditEnumerateSubCategories (Address: 0x1800294a0)
  • AuditFree (Address: 0x1800294a8)
  • AuditLookupSubCategoryNameW (Address: 0x180029498)
  • AuditSetGlobalSaclW (Address: 0x1800294c0)
  • AuditSetPerUserPolicy (Address: 0x1800294b8)
  • AuditSetSystemPolicy (Address: 0x1800294b0)
  • LsaSetCAPs (Address: 0x1800294c8)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180029568)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateGuid (Address: 0x180029578)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180029588)
  • IsDebuggerPresent (Address: 0x180029590)
  • OutputDebugStringW (Address: 0x180029598)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800295a8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800295b8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800295e0)
  • SetLastError (Address: 0x1800295d8)
  • SetUnhandledExceptionFilter (Address: 0x1800295c8)
  • UnhandledExceptionFilter (Address: 0x1800295d0)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x1800295f0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180029600)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180029618)
  • HeapAlloc (Address: 0x180029610)
  • HeapFree (Address: 0x180029620)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180029630)
  • LocalFree (Address: 0x180029638)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180029670)
  • FreeLibrary (Address: 0x180029660)
  • FreeLibraryAndExitThread (Address: 0x180029650)
  • GetModuleFileNameA (Address: 0x180029668)
  • GetModuleHandleExW (Address: 0x180029648)
  • GetModuleHandleW (Address: 0x180029678)
  • GetProcAddress (Address: 0x180029680)
  • LoadLibraryExW (Address: 0x180029658)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180029690)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800296a0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x1800296d0)
  • GetCurrentProcess (Address: 0x1800296c8)
  • GetCurrentProcessId (Address: 0x1800296c0)
  • GetCurrentThread (Address: 0x1800296e0)
  • GetCurrentThreadId (Address: 0x1800296b0)
  • OpenThreadToken (Address: 0x1800296d8)
  • TerminateProcess (Address: 0x1800296b8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800296f0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180029708)
  • RegOpenKeyExW (Address: 0x180029710)
  • RegSetValueExW (Address: 0x180029700)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180029730)
  • RtlLookupFunctionEntry (Address: 0x180029728)
  • RtlVirtualUnwind (Address: 0x180029720)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180029758)
  • AcquireSRWLockShared (Address: 0x180029768)
  • CreateMutexExW (Address: 0x1800297b8)
  • CreateSemaphoreExW (Address: 0x180029780)
  • DeleteCriticalSection (Address: 0x180029770)
  • EnterCriticalSection (Address: 0x180029748)
  • InitializeCriticalSection (Address: 0x180029788)
  • InitializeCriticalSectionEx (Address: 0x180029740)
  • LeaveCriticalSection (Address: 0x180029778)
  • OpenSemaphoreW (Address: 0x180029760)
  • ReleaseMutex (Address: 0x180029798)
  • ReleaseSemaphore (Address: 0x1800297a0)
  • ReleaseSRWLockExclusive (Address: 0x180029790)
  • ReleaseSRWLockShared (Address: 0x1800297a8)
  • WaitForSingleObject (Address: 0x1800297b0)
  • WaitForSingleObjectEx (Address: 0x180029750)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1800297c8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800297d8)
  • GetTickCount (Address: 0x1800297e0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800297f0)
  • CreateThreadpoolTimer (Address: 0x1800297f8)
  • SetThreadpoolTimer (Address: 0x180029800)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180029808)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180029830)
  • GetTraceEnableLevel (Address: 0x180029828)
  • GetTraceLoggerHandle (Address: 0x180029818)
  • RegisterTraceGuidsW (Address: 0x180029838)
  • TraceMessage (Address: 0x180029820)
  • UnregisterTraceGuids (Address: 0x180029840)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventEnabled (Address: 0x180029858)
  • EventRegister (Address: 0x180029868)
  • EventUnregister (Address: 0x180029860)
  • EventWrite (Address: 0x180029850)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180029898)
  • CopySid (Address: 0x180029880)
  • GetLengthSid (Address: 0x180029878)
  • GetSecurityDescriptorSacl (Address: 0x1800298a8)
  • ImpersonateSelf (Address: 0x1800298a0)
  • PrivilegeCheck (Address: 0x180029888)
  • RevertToSelf (Address: 0x180029890)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x1800298b8)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800298d8)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800298c8)
  • ConvertStringSidToSidW (Address: 0x1800298d0)
msvcp110_win.dll
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x1800298e8)
  • ?_Winerror_map@std@@YAPEBDH@Z (Address: 0x1800298f8)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x180029908)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800298f0)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180029900)
msvcrt.dll
  • __C_specific_handler (Address: 0x180029940)
  • __CxxFrameHandler3 (Address: 0x180029a10)
  • __dllonexit (Address: 0x180029928)
  • __RTDynamicCast (Address: 0x180029a30)
  • _amsg_exit (Address: 0x180029958)
  • _callnewh (Address: 0x180029968)
  • _CxxThrowException (Address: 0x180029a28)
  • _initterm (Address: 0x180029948)
  • _lock (Address: 0x180029938)
  • _onexit (Address: 0x180029920)
  • _purecall (Address: 0x180029a08)
  • _unlock (Address: 0x180029930)
  • _vsnprintf_s (Address: 0x180029988)
  • _vsnwprintf (Address: 0x180029998)
  • _wfopen_s (Address: 0x1800299c8)
  • _wtoi (Address: 0x1800299e0)
  • _XcptFilter (Address: 0x180029960)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800299e8)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800299b8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800299f0)
  • ??0exception@@QEAA@XZ (Address: 0x180029a20)
  • ??1exception@@UEAA@XZ (Address: 0x1800299f8)
  • ??1type_info@@UEAA@XZ (Address: 0x180029918)
  • ??3@YAXPEAX@Z (Address: 0x180029a18)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180029a00)
  • fclose (Address: 0x1800299c0)
  • feof (Address: 0x1800299d0)
  • fgetws (Address: 0x1800299d8)
  • free (Address: 0x180029950)
  • malloc (Address: 0x180029970)
  • memcmp (Address: 0x180029a38)
  • memcpy (Address: 0x1800299a8)
  • memcpy_s (Address: 0x180029990)
  • memmove (Address: 0x1800299a0)
  • memmove_s (Address: 0x180029980)
  • memset (Address: 0x1800299b0)
  • tolower (Address: 0x180029978)
OLEAUT32.dll
  • SafeArrayCreate (Address: 0x1800294f8)
  • SafeArrayDestroy (Address: 0x1800294e8)
  • SafeArrayPutElement (Address: 0x1800294d8)
  • SysAllocString (Address: 0x180029500)
  • SysAllocStringByteLen (Address: 0x180029518)
  • SysFreeString (Address: 0x1800294f0)
  • SysStringByteLen (Address: 0x180029508)
  • VariantClear (Address: 0x180029510)
  • VariantInit (Address: 0x1800294e0)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x180029538)
  • UuidFromStringW (Address: 0x180029530)
  • UuidToStringW (Address: 0x180029528)
SHELL32.dll
  • SHCreateDirectoryExW (Address: 0x180029548)
USERENV.dll
  • ProcessGroupPolicyCompletedEx (Address: 0x180029558)