auditpolcore.dll

Description: Audit Policy Program

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 64-bit

Operating System: Windows NT

SHA256: 68cdd62715e783be533d9ac32439e4a0

File Size: 78.5 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 12

Exported Functions

  • AdtBackupPolicy (Ordinal: 1, Address: 0x3e20)
  • AdtBackupPolicyGeneralized (Ordinal: 2, Address: 0x3de0)
  • AdtClearPolicy (Ordinal: 3, Address: 0x44d0)
  • AdtConstructAllCategoryGuids (Ordinal: 4, Address: 0x62b0)
  • AdtConvertGuidStringToGuid (Ordinal: 5, Address: 0x6230)
  • AdtConvertGuidToString (Ordinal: 6, Address: 0x6120)
  • AdtDisableSinglePrivilege (Ordinal: 7, Address: 0x5f60)
  • AdtEnableSinglePrivilege (Ordinal: 8, Address: 0x5f50)
  • AdtGetOption (Ordinal: 9, Address: 0x3880)
  • AdtGetPerUserPolicy (Ordinal: 10, Address: 0x37e0)
  • AdtGetSystemPolicy (Ordinal: 11, Address: 0x3750)
  • AdtListCategories (Ordinal: 12, Address: 0x6890)
  • AdtListSubCategories (Ordinal: 13, Address: 0x6a00)
  • AdtLoadStringEx (Ordinal: 14, Address: 0x6520)
  • AdtParseAuditOptionName (Ordinal: 15, Address: 0x6380)
  • AdtParseGuidOrNameArray (Ordinal: 16, Address: 0x6540)
  • AdtRemoveAllUsers (Ordinal: 17, Address: 0x4ac0)
  • AdtRemoveBasePolicy (Ordinal: 18, Address: 0x4870)
  • AdtRestorePolicy (Ordinal: 19, Address: 0x4000)
  • AdtRestorePolicyGeneralized (Ordinal: 20, Address: 0x3fc0)
  • AdtSetOption (Ordinal: 21, Address: 0x3d20)
  • AdtSetPerUserPolicy (Ordinal: 22, Address: 0x3c40)
  • AdtSetSystemPolicy (Ordinal: 23, Address: 0x3b60)
  • AuditPolicyData_DeleteAuditDataInstance (Ordinal: 24, Address: 0x7e70)
  • DisplayMessage (Ordinal: 25, Address: 0x9040)
  • DisplayMessageToSpecificConsoleHandle (Ordinal: 26, Address: 0x9160)
  • GetDisplayPolicy (Ordinal: 27, Address: 0x8b90)
  • LoadFormatStringAndPrintToConsole (Ordinal: 28, Address: 0x90a0)
  • SetDisplayPolicy (Ordinal: 29, Address: 0x8ba0)

Imported DLLs & Functions

api-ms-win-core-console-l1-1-0.dll
  • WriteConsoleW (Address: 0x18000ed48)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18000ed68)
  • IsDebuggerPresent (Address: 0x18000ed60)
  • OutputDebugStringW (Address: 0x18000ed58)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000ed80)
  • SetLastError (Address: 0x18000ed90)
  • SetUnhandledExceptionFilter (Address: 0x18000ed78)
  • UnhandledExceptionFilter (Address: 0x18000ed88)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x18000eda8)
  • DeleteFileW (Address: 0x18000eda0)
  • WriteFile (Address: 0x18000edb0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18000edc0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000edd0)
  • HeapAlloc (Address: 0x18000ede0)
  • HeapFree (Address: 0x18000edd8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18000edf8)
  • LocalFree (Address: 0x18000edf0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x18000ee08)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18000ee20)
  • GetModuleFileNameA (Address: 0x18000ee30)
  • GetModuleHandleExW (Address: 0x18000ee38)
  • GetModuleHandleW (Address: 0x18000ee18)
  • GetProcAddress (Address: 0x18000ee28)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18000ee48)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x18000ee68)
  • VirtualProtect (Address: 0x18000ee58)
  • VirtualQuery (Address: 0x18000ee60)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetStdHandle (Address: 0x18000ee78)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000eeb0)
  • GetCurrentProcessId (Address: 0x18000ee98)
  • GetCurrentThreadId (Address: 0x18000ee88)
  • OpenProcessToken (Address: 0x18000eea0)
  • SetThreadStackGuarantee (Address: 0x18000eea8)
  • TerminateProcess (Address: 0x18000ee90)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000eec0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18000eee0)
  • RegOpenKeyExW (Address: 0x18000eed8)
  • RegQueryValueExW (Address: 0x18000eed0)
  • RegSetValueExW (Address: 0x18000eee8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18000ef10)
  • RtlCompareMemory (Address: 0x18000ef00)
  • RtlLookupFunctionEntry (Address: 0x18000ef08)
  • RtlVirtualUnwind (Address: 0x18000eef8)
api-ms-win-core-string-l1-1-0.dll
  • WideCharToMultiByte (Address: 0x18000ef20)
api-ms-win-core-synch-l1-1-0.dll
  • CreateMutexExW (Address: 0x18000ef58)
  • CreateSemaphoreExW (Address: 0x18000ef50)
  • OpenSemaphoreW (Address: 0x18000ef30)
  • ReleaseMutex (Address: 0x18000ef60)
  • ReleaseSemaphore (Address: 0x18000ef48)
  • WaitForSingleObject (Address: 0x18000ef40)
  • WaitForSingleObjectEx (Address: 0x18000ef38)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18000ef70)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x18000ef90)
  • GetSystemTimeAsFileTime (Address: 0x18000ef88)
  • GetTickCount (Address: 0x18000ef80)
api-ms-win-security-audit-l1-1-0.dll
  • AuditFree (Address: 0x18000efa8)
  • AuditQuerySystemPolicy (Address: 0x18000efb0)
  • AuditSetSystemPolicy (Address: 0x18000efa0)
api-ms-win-security-audit-l1-1-1.dll
  • AuditEnumerateCategories (Address: 0x18000eff8)
  • AuditEnumeratePerUserPolicy (Address: 0x18000efc8)
  • AuditEnumerateSubCategories (Address: 0x18000f000)
  • AuditLookupCategoryNameW (Address: 0x18000efe0)
  • AuditLookupSubCategoryNameW (Address: 0x18000efe8)
  • AuditQueryGlobalSaclW (Address: 0x18000efd0)
  • AuditQueryPerUserPolicy (Address: 0x18000efd8)
  • AuditSetGlobalSaclW (Address: 0x18000eff0)
  • AuditSetPerUserPolicy (Address: 0x18000efc0)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x18000f038)
  • EqualSid (Address: 0x18000f030)
  • GetSecurityDescriptorSacl (Address: 0x18000f040)
  • InitializeSecurityDescriptor (Address: 0x18000f020)
  • IsValidSid (Address: 0x18000f010)
  • IsWellKnownSid (Address: 0x18000f028)
  • SetSecurityDescriptorSacl (Address: 0x18000f018)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x18000f050)
api-ms-win-security-provider-l1-1-0.dll
  • GetExplicitEntriesFromAclW (Address: 0x18000f068)
  • SetEntriesInAclW (Address: 0x18000f060)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x18000f078)
  • ConvertSidToStringSidW (Address: 0x18000f080)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000f090)
  • ConvertStringSidToSidW (Address: 0x18000f088)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000f200)
  • __CxxFrameHandler3 (Address: 0x18000f0f8)
  • __dllonexit (Address: 0x18000f0b8)
  • __iob_func (Address: 0x18000f0d0)
  • _amsg_exit (Address: 0x18000f1f8)
  • _callnewh (Address: 0x18000f1b8)
  • _CxxThrowException (Address: 0x18000f1d8)
  • _initterm (Address: 0x18000f0d8)
  • _lock (Address: 0x18000f0a8)
  • _onexit (Address: 0x18000f0a0)
  • _purecall (Address: 0x18000f130)
  • _unlock (Address: 0x18000f0c0)
  • _vsnprintf_s (Address: 0x18000f150)
  • _vsnwprintf (Address: 0x18000f100)
  • _vsnwprintf_s (Address: 0x18000f198)
  • _wcsicmp (Address: 0x18000f118)
  • _wcsnicmp (Address: 0x18000f180)
  • _wfopen (Address: 0x18000f160)
  • _wtoi (Address: 0x18000f1b0)
  • _XcptFilter (Address: 0x18000f0f0)
  • ??_V@YAXPEAX@Z (Address: 0x18000f190)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18000f1c0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000f1c8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000f148)
  • ??0exception@@QEAA@XZ (Address: 0x18000f140)
  • ??1exception@@UEAA@XZ (Address: 0x18000f138)
  • ??1type_info@@UEAA@XZ (Address: 0x18000f1f0)
  • ??3@YAXPEAX@Z (Address: 0x18000f128)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18000f1d0)
  • fclose (Address: 0x18000f120)
  • feof (Address: 0x18000f178)
  • ferror (Address: 0x18000f108)
  • fgetws (Address: 0x18000f170)
  • free (Address: 0x18000f0e8)
  • malloc (Address: 0x18000f0e0)
  • memcmp (Address: 0x18000f0c8)
  • memcpy (Address: 0x18000f1e0)
  • memcpy_s (Address: 0x18000f110)
  • memmove (Address: 0x18000f1e8)
  • memset (Address: 0x18000f0b0)
  • qsort (Address: 0x18000f1a8)
  • vfwprintf (Address: 0x18000f1a0)
  • wcschr (Address: 0x18000f158)
  • wcscmp (Address: 0x18000f208)
  • wprintf (Address: 0x18000f188)
  • wscanf (Address: 0x18000f168)
ntdll.dll
  • RtlAllocateHeap (Address: 0x18000f218)
  • RtlFreeHeap (Address: 0x18000f238)
  • RtlGUIDFromString (Address: 0x18000f228)
  • RtlImageNtHeader (Address: 0x18000f230)
  • RtlNtStatusToDosError (Address: 0x18000f220)