auditpolcore.dll
Description: Audit Policy Program
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: 68cdd62715e783be533d9ac32439e4a0
File Size: 78.5 KB
Uploaded At: Dec. 1, 2025, 7:23 a.m.
Views: 12
Exported Functions
- AdtBackupPolicy (Ordinal: 1, Address: 0x3e20)
- AdtBackupPolicyGeneralized (Ordinal: 2, Address: 0x3de0)
- AdtClearPolicy (Ordinal: 3, Address: 0x44d0)
- AdtConstructAllCategoryGuids (Ordinal: 4, Address: 0x62b0)
- AdtConvertGuidStringToGuid (Ordinal: 5, Address: 0x6230)
- AdtConvertGuidToString (Ordinal: 6, Address: 0x6120)
- AdtDisableSinglePrivilege (Ordinal: 7, Address: 0x5f60)
- AdtEnableSinglePrivilege (Ordinal: 8, Address: 0x5f50)
- AdtGetOption (Ordinal: 9, Address: 0x3880)
- AdtGetPerUserPolicy (Ordinal: 10, Address: 0x37e0)
- AdtGetSystemPolicy (Ordinal: 11, Address: 0x3750)
- AdtListCategories (Ordinal: 12, Address: 0x6890)
- AdtListSubCategories (Ordinal: 13, Address: 0x6a00)
- AdtLoadStringEx (Ordinal: 14, Address: 0x6520)
- AdtParseAuditOptionName (Ordinal: 15, Address: 0x6380)
- AdtParseGuidOrNameArray (Ordinal: 16, Address: 0x6540)
- AdtRemoveAllUsers (Ordinal: 17, Address: 0x4ac0)
- AdtRemoveBasePolicy (Ordinal: 18, Address: 0x4870)
- AdtRestorePolicy (Ordinal: 19, Address: 0x4000)
- AdtRestorePolicyGeneralized (Ordinal: 20, Address: 0x3fc0)
- AdtSetOption (Ordinal: 21, Address: 0x3d20)
- AdtSetPerUserPolicy (Ordinal: 22, Address: 0x3c40)
- AdtSetSystemPolicy (Ordinal: 23, Address: 0x3b60)
- AuditPolicyData_DeleteAuditDataInstance (Ordinal: 24, Address: 0x7e70)
- DisplayMessage (Ordinal: 25, Address: 0x9040)
- DisplayMessageToSpecificConsoleHandle (Ordinal: 26, Address: 0x9160)
- GetDisplayPolicy (Ordinal: 27, Address: 0x8b90)
- LoadFormatStringAndPrintToConsole (Ordinal: 28, Address: 0x90a0)
- SetDisplayPolicy (Ordinal: 29, Address: 0x8ba0)
Imported DLLs & Functions
api-ms-win-core-console-l1-1-0.dll
- WriteConsoleW (Address: 0x18000ed48)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18000ed68)
- IsDebuggerPresent (Address: 0x18000ed60)
- OutputDebugStringW (Address: 0x18000ed58)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18000ed80)
- SetLastError (Address: 0x18000ed90)
- SetUnhandledExceptionFilter (Address: 0x18000ed78)
- UnhandledExceptionFilter (Address: 0x18000ed88)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x18000eda8)
- DeleteFileW (Address: 0x18000eda0)
- WriteFile (Address: 0x18000edb0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18000edc0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18000edd0)
- HeapAlloc (Address: 0x18000ede0)
- HeapFree (Address: 0x18000edd8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x18000edf8)
- LocalFree (Address: 0x18000edf0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetComputerNameW (Address: 0x18000ee08)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18000ee20)
- GetModuleFileNameA (Address: 0x18000ee30)
- GetModuleHandleExW (Address: 0x18000ee38)
- GetModuleHandleW (Address: 0x18000ee18)
- GetProcAddress (Address: 0x18000ee28)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18000ee48)
api-ms-win-core-memory-l1-1-0.dll
- VirtualAlloc (Address: 0x18000ee68)
- VirtualProtect (Address: 0x18000ee58)
- VirtualQuery (Address: 0x18000ee60)
api-ms-win-core-processenvironment-l1-1-0.dll
- GetStdHandle (Address: 0x18000ee78)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18000eeb0)
- GetCurrentProcessId (Address: 0x18000ee98)
- GetCurrentThreadId (Address: 0x18000ee88)
- OpenProcessToken (Address: 0x18000eea0)
- SetThreadStackGuarantee (Address: 0x18000eea8)
- TerminateProcess (Address: 0x18000ee90)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18000eec0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18000eee0)
- RegOpenKeyExW (Address: 0x18000eed8)
- RegQueryValueExW (Address: 0x18000eed0)
- RegSetValueExW (Address: 0x18000eee8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18000ef10)
- RtlCompareMemory (Address: 0x18000ef00)
- RtlLookupFunctionEntry (Address: 0x18000ef08)
- RtlVirtualUnwind (Address: 0x18000eef8)
api-ms-win-core-string-l1-1-0.dll
- WideCharToMultiByte (Address: 0x18000ef20)
api-ms-win-core-synch-l1-1-0.dll
- CreateMutexExW (Address: 0x18000ef58)
- CreateSemaphoreExW (Address: 0x18000ef50)
- OpenSemaphoreW (Address: 0x18000ef30)
- ReleaseMutex (Address: 0x18000ef60)
- ReleaseSemaphore (Address: 0x18000ef48)
- WaitForSingleObject (Address: 0x18000ef40)
- WaitForSingleObjectEx (Address: 0x18000ef38)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18000ef70)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemInfo (Address: 0x18000ef90)
- GetSystemTimeAsFileTime (Address: 0x18000ef88)
- GetTickCount (Address: 0x18000ef80)
api-ms-win-security-audit-l1-1-0.dll
- AuditFree (Address: 0x18000efa8)
- AuditQuerySystemPolicy (Address: 0x18000efb0)
- AuditSetSystemPolicy (Address: 0x18000efa0)
api-ms-win-security-audit-l1-1-1.dll
- AuditEnumerateCategories (Address: 0x18000eff8)
- AuditEnumeratePerUserPolicy (Address: 0x18000efc8)
- AuditEnumerateSubCategories (Address: 0x18000f000)
- AuditLookupCategoryNameW (Address: 0x18000efe0)
- AuditLookupSubCategoryNameW (Address: 0x18000efe8)
- AuditQueryGlobalSaclW (Address: 0x18000efd0)
- AuditQueryPerUserPolicy (Address: 0x18000efd8)
- AuditSetGlobalSaclW (Address: 0x18000eff0)
- AuditSetPerUserPolicy (Address: 0x18000efc0)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x18000f038)
- EqualSid (Address: 0x18000f030)
- GetSecurityDescriptorSacl (Address: 0x18000f040)
- InitializeSecurityDescriptor (Address: 0x18000f020)
- IsValidSid (Address: 0x18000f010)
- IsWellKnownSid (Address: 0x18000f028)
- SetSecurityDescriptorSacl (Address: 0x18000f018)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x18000f050)
api-ms-win-security-provider-l1-1-0.dll
- GetExplicitEntriesFromAclW (Address: 0x18000f068)
- SetEntriesInAclW (Address: 0x18000f060)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x18000f078)
- ConvertSidToStringSidW (Address: 0x18000f080)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000f090)
- ConvertStringSidToSidW (Address: 0x18000f088)
msvcrt.dll
- __C_specific_handler (Address: 0x18000f200)
- __CxxFrameHandler3 (Address: 0x18000f0f8)
- __dllonexit (Address: 0x18000f0b8)
- __iob_func (Address: 0x18000f0d0)
- _amsg_exit (Address: 0x18000f1f8)
- _callnewh (Address: 0x18000f1b8)
- _CxxThrowException (Address: 0x18000f1d8)
- _initterm (Address: 0x18000f0d8)
- _lock (Address: 0x18000f0a8)
- _onexit (Address: 0x18000f0a0)
- _purecall (Address: 0x18000f130)
- _unlock (Address: 0x18000f0c0)
- _vsnprintf_s (Address: 0x18000f150)
- _vsnwprintf (Address: 0x18000f100)
- _vsnwprintf_s (Address: 0x18000f198)
- _wcsicmp (Address: 0x18000f118)
- _wcsnicmp (Address: 0x18000f180)
- _wfopen (Address: 0x18000f160)
- _wtoi (Address: 0x18000f1b0)
- _XcptFilter (Address: 0x18000f0f0)
- ??_V@YAXPEAX@Z (Address: 0x18000f190)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18000f1c0)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000f1c8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000f148)
- ??0exception@@QEAA@XZ (Address: 0x18000f140)
- ??1exception@@UEAA@XZ (Address: 0x18000f138)
- ??1type_info@@UEAA@XZ (Address: 0x18000f1f0)
- ??3@YAXPEAX@Z (Address: 0x18000f128)
- ?what@exception@@UEBAPEBDXZ (Address: 0x18000f1d0)
- fclose (Address: 0x18000f120)
- feof (Address: 0x18000f178)
- ferror (Address: 0x18000f108)
- fgetws (Address: 0x18000f170)
- free (Address: 0x18000f0e8)
- malloc (Address: 0x18000f0e0)
- memcmp (Address: 0x18000f0c8)
- memcpy (Address: 0x18000f1e0)
- memcpy_s (Address: 0x18000f110)
- memmove (Address: 0x18000f1e8)
- memset (Address: 0x18000f0b0)
- qsort (Address: 0x18000f1a8)
- vfwprintf (Address: 0x18000f1a0)
- wcschr (Address: 0x18000f158)
- wcscmp (Address: 0x18000f208)
- wprintf (Address: 0x18000f188)
- wscanf (Address: 0x18000f168)
ntdll.dll
- RtlAllocateHeap (Address: 0x18000f218)
- RtlFreeHeap (Address: 0x18000f238)
- RtlGUIDFromString (Address: 0x18000f228)
- RtlImageNtHeader (Address: 0x18000f230)
- RtlNtStatusToDosError (Address: 0x18000f220)