auditpolcore.dll
Description: Audit Policy Program
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 32-bit
Operating System: Windows NT
SHA256: 22cfd0f6e0dccaf229cae4c4fe983f48
File Size: 57.5 KB
Uploaded At: Dec. 1, 2025, 7:53 a.m.
Views: 5
Exported Functions
- AdtBackupPolicy (Ordinal: 1, Address: 0x4b50)
- AdtBackupPolicyGeneralized (Ordinal: 2, Address: 0x4b10)
- AdtClearPolicy (Ordinal: 3, Address: 0x4e50)
- AdtConstructAllCategoryGuids (Ordinal: 4, Address: 0x6460)
- AdtConvertGuidStringToGuid (Ordinal: 5, Address: 0x63f0)
- AdtConvertGuidToString (Ordinal: 6, Address: 0x6360)
- AdtDisableSinglePrivilege (Ordinal: 7, Address: 0x6230)
- AdtEnableSinglePrivilege (Ordinal: 8, Address: 0x6210)
- AdtGetOption (Ordinal: 9, Address: 0x4760)
- AdtGetPerUserPolicy (Ordinal: 10, Address: 0x46f0)
- AdtGetSystemPolicy (Ordinal: 11, Address: 0x4680)
- AdtListCategories (Ordinal: 12, Address: 0x69e0)
- AdtListSubCategories (Ordinal: 13, Address: 0x6ad0)
- AdtLoadStringEx (Ordinal: 14, Address: 0x66c0)
- AdtParseAuditOptionName (Ordinal: 15, Address: 0x6500)
- AdtParseGuidOrNameArray (Ordinal: 16, Address: 0x66e0)
- AdtRemoveAllUsers (Ordinal: 17, Address: 0x5280)
- AdtRemoveBasePolicy (Ordinal: 18, Address: 0x50f0)
- AdtRestorePolicy (Ordinal: 19, Address: 0x4cb0)
- AdtRestorePolicyGeneralized (Ordinal: 20, Address: 0x4c70)
- AdtSetOption (Ordinal: 21, Address: 0x4aa0)
- AdtSetPerUserPolicy (Ordinal: 22, Address: 0x4a10)
- AdtSetSystemPolicy (Ordinal: 23, Address: 0x4990)
- AuditPolicyData_DeleteAuditDataInstance (Ordinal: 24, Address: 0x7880)
- DisplayMessage (Ordinal: 25, Address: 0x8450)
- DisplayMessageToSpecificConsoleHandle (Ordinal: 26, Address: 0x8500)
- GetDisplayPolicy (Ordinal: 27, Address: 0x8080)
- LoadFormatStringAndPrintToConsole (Ordinal: 28, Address: 0x8480)
- SetDisplayPolicy (Ordinal: 29, Address: 0x8090)
Imported DLLs & Functions
api-ms-win-core-console-l1-1-0.dll
- WriteConsoleW (Address: 0x1000e000)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1000e010)
- IsDebuggerPresent (Address: 0x1000e00c)
- OutputDebugStringW (Address: 0x1000e008)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1000e024)
- SetLastError (Address: 0x1000e020)
- SetUnhandledExceptionFilter (Address: 0x1000e01c)
- UnhandledExceptionFilter (Address: 0x1000e018)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x1000e034)
- DeleteFileW (Address: 0x1000e02c)
- WriteFile (Address: 0x1000e030)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1000e03c)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1000e044)
- HeapAlloc (Address: 0x1000e04c)
- HeapFree (Address: 0x1000e048)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1000e054)
- LocalFree (Address: 0x1000e058)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetComputerNameW (Address: 0x1000e060)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1000e070)
- GetModuleFileNameA (Address: 0x1000e078)
- GetModuleHandleExW (Address: 0x1000e068)
- GetModuleHandleW (Address: 0x1000e06c)
- GetProcAddress (Address: 0x1000e074)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1000e080)
api-ms-win-core-memory-l1-1-0.dll
- VirtualAlloc (Address: 0x1000e088)
- VirtualProtect (Address: 0x1000e08c)
- VirtualQuery (Address: 0x1000e090)
api-ms-win-core-processenvironment-l1-1-0.dll
- GetStdHandle (Address: 0x1000e098)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1000e0a0)
- GetCurrentProcessId (Address: 0x1000e0a4)
- GetCurrentThreadId (Address: 0x1000e0a8)
- OpenProcessToken (Address: 0x1000e0b0)
- SetThreadStackGuarantee (Address: 0x1000e0ac)
- TerminateProcess (Address: 0x1000e0b4)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1000e0bc)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1000e0c4)
- RegOpenKeyExW (Address: 0x1000e0c8)
- RegQueryValueExW (Address: 0x1000e0d0)
- RegSetValueExW (Address: 0x1000e0cc)
api-ms-win-core-rtlsupport-l1-2-0.dll
- RtlCompareMemory (Address: 0x1000e0d8)
api-ms-win-core-string-l1-1-0.dll
- WideCharToMultiByte (Address: 0x1000e0e0)
api-ms-win-core-synch-l1-1-0.dll
- CreateMutexExW (Address: 0x1000e100)
- CreateSemaphoreExW (Address: 0x1000e0f0)
- OpenSemaphoreW (Address: 0x1000e0f8)
- ReleaseMutex (Address: 0x1000e0ec)
- ReleaseSemaphore (Address: 0x1000e0f4)
- WaitForSingleObject (Address: 0x1000e0fc)
- WaitForSingleObjectEx (Address: 0x1000e0e8)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1000e108)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemInfo (Address: 0x1000e118)
- GetSystemTimeAsFileTime (Address: 0x1000e114)
- GetTickCount (Address: 0x1000e110)
api-ms-win-security-audit-l1-1-0.dll
- AuditFree (Address: 0x1000e128)
- AuditQuerySystemPolicy (Address: 0x1000e124)
- AuditSetSystemPolicy (Address: 0x1000e120)
api-ms-win-security-audit-l1-1-1.dll
- AuditEnumerateCategories (Address: 0x1000e134)
- AuditEnumeratePerUserPolicy (Address: 0x1000e144)
- AuditEnumerateSubCategories (Address: 0x1000e138)
- AuditLookupCategoryNameW (Address: 0x1000e14c)
- AuditLookupSubCategoryNameW (Address: 0x1000e140)
- AuditQueryGlobalSaclW (Address: 0x1000e130)
- AuditQueryPerUserPolicy (Address: 0x1000e148)
- AuditSetGlobalSaclW (Address: 0x1000e150)
- AuditSetPerUserPolicy (Address: 0x1000e13c)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x1000e158)
- EqualSid (Address: 0x1000e168)
- GetSecurityDescriptorSacl (Address: 0x1000e170)
- InitializeSecurityDescriptor (Address: 0x1000e164)
- IsValidSid (Address: 0x1000e160)
- IsWellKnownSid (Address: 0x1000e15c)
- SetSecurityDescriptorSacl (Address: 0x1000e16c)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x1000e178)
api-ms-win-security-provider-l1-1-0.dll
- GetExplicitEntriesFromAclW (Address: 0x1000e180)
- SetEntriesInAclW (Address: 0x1000e184)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x1000e198)
- ConvertSidToStringSidW (Address: 0x1000e18c)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1000e194)
- ConvertStringSidToSidW (Address: 0x1000e190)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x1000e1cc)
- __dllonexit (Address: 0x1000e1ac)
- __iob_func (Address: 0x1000e1b4)
- _amsg_exit (Address: 0x1000e1c8)
- _callnewh (Address: 0x1000e22c)
- _CxxThrowException (Address: 0x1000e23c)
- _except_handler4_common (Address: 0x1000e24c)
- _initterm (Address: 0x1000e1a8)
- _lock (Address: 0x1000e1c0)
- _onexit (Address: 0x1000e1a4)
- _purecall (Address: 0x1000e1e8)
- _unlock (Address: 0x1000e1b8)
- _vsnprintf_s (Address: 0x1000e1f8)
- _vsnwprintf (Address: 0x1000e1d0)
- _vsnwprintf_s (Address: 0x1000e21c)
- _wcsicmp (Address: 0x1000e1dc)
- _wcsnicmp (Address: 0x1000e210)
- _wfopen (Address: 0x1000e200)
- _wtoi (Address: 0x1000e228)
- _XcptFilter (Address: 0x1000e1c4)
- ??_V@YAXPAX@Z (Address: 0x1000e218)
- ??0exception@@QAE@ABQBD@Z (Address: 0x1000e230)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x1000e234)
- ??0exception@@QAE@ABV0@@Z (Address: 0x1000e1f4)
- ??0exception@@QAE@XZ (Address: 0x1000e1f0)
- ??1exception@@UAE@XZ (Address: 0x1000e1ec)
- ??1type_info@@UAE@XZ (Address: 0x1000e248)
- ??3@YAXPAX@Z (Address: 0x1000e1e4)
- ?what@exception@@UBEPBDXZ (Address: 0x1000e238)
- fclose (Address: 0x1000e1e0)
- feof (Address: 0x1000e20c)
- ferror (Address: 0x1000e1d4)
- fgetws (Address: 0x1000e208)
- free (Address: 0x1000e1bc)
- malloc (Address: 0x1000e1b0)
- memcmp (Address: 0x1000e1a0)
- memcpy (Address: 0x1000e240)
- memcpy_s (Address: 0x1000e1d8)
- memmove (Address: 0x1000e244)
- memset (Address: 0x1000e250)
- qsort (Address: 0x1000e224)
- vfwprintf (Address: 0x1000e220)
- wcschr (Address: 0x1000e1fc)
- wprintf (Address: 0x1000e214)
- wscanf (Address: 0x1000e204)
ntdll.dll
- RtlAllocateHeap (Address: 0x1000e258)
- RtlFreeHeap (Address: 0x1000e268)
- RtlGUIDFromString (Address: 0x1000e260)
- RtlImageNtHeader (Address: 0x1000e264)
- RtlNtStatusToDosError (Address: 0x1000e25c)