auditpolcore.dll

Description: Audit Policy Program

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 32-bit

Operating System: Windows NT

SHA256: 22cfd0f6e0dccaf229cae4c4fe983f48

File Size: 57.5 KB

Uploaded At: Dec. 1, 2025, 7:53 a.m.

Views: 5

Exported Functions

  • AdtBackupPolicy (Ordinal: 1, Address: 0x4b50)
  • AdtBackupPolicyGeneralized (Ordinal: 2, Address: 0x4b10)
  • AdtClearPolicy (Ordinal: 3, Address: 0x4e50)
  • AdtConstructAllCategoryGuids (Ordinal: 4, Address: 0x6460)
  • AdtConvertGuidStringToGuid (Ordinal: 5, Address: 0x63f0)
  • AdtConvertGuidToString (Ordinal: 6, Address: 0x6360)
  • AdtDisableSinglePrivilege (Ordinal: 7, Address: 0x6230)
  • AdtEnableSinglePrivilege (Ordinal: 8, Address: 0x6210)
  • AdtGetOption (Ordinal: 9, Address: 0x4760)
  • AdtGetPerUserPolicy (Ordinal: 10, Address: 0x46f0)
  • AdtGetSystemPolicy (Ordinal: 11, Address: 0x4680)
  • AdtListCategories (Ordinal: 12, Address: 0x69e0)
  • AdtListSubCategories (Ordinal: 13, Address: 0x6ad0)
  • AdtLoadStringEx (Ordinal: 14, Address: 0x66c0)
  • AdtParseAuditOptionName (Ordinal: 15, Address: 0x6500)
  • AdtParseGuidOrNameArray (Ordinal: 16, Address: 0x66e0)
  • AdtRemoveAllUsers (Ordinal: 17, Address: 0x5280)
  • AdtRemoveBasePolicy (Ordinal: 18, Address: 0x50f0)
  • AdtRestorePolicy (Ordinal: 19, Address: 0x4cb0)
  • AdtRestorePolicyGeneralized (Ordinal: 20, Address: 0x4c70)
  • AdtSetOption (Ordinal: 21, Address: 0x4aa0)
  • AdtSetPerUserPolicy (Ordinal: 22, Address: 0x4a10)
  • AdtSetSystemPolicy (Ordinal: 23, Address: 0x4990)
  • AuditPolicyData_DeleteAuditDataInstance (Ordinal: 24, Address: 0x7880)
  • DisplayMessage (Ordinal: 25, Address: 0x8450)
  • DisplayMessageToSpecificConsoleHandle (Ordinal: 26, Address: 0x8500)
  • GetDisplayPolicy (Ordinal: 27, Address: 0x8080)
  • LoadFormatStringAndPrintToConsole (Ordinal: 28, Address: 0x8480)
  • SetDisplayPolicy (Ordinal: 29, Address: 0x8090)

Imported DLLs & Functions

api-ms-win-core-console-l1-1-0.dll
  • WriteConsoleW (Address: 0x1000e000)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1000e010)
  • IsDebuggerPresent (Address: 0x1000e00c)
  • OutputDebugStringW (Address: 0x1000e008)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1000e024)
  • SetLastError (Address: 0x1000e020)
  • SetUnhandledExceptionFilter (Address: 0x1000e01c)
  • UnhandledExceptionFilter (Address: 0x1000e018)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x1000e034)
  • DeleteFileW (Address: 0x1000e02c)
  • WriteFile (Address: 0x1000e030)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1000e03c)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1000e044)
  • HeapAlloc (Address: 0x1000e04c)
  • HeapFree (Address: 0x1000e048)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1000e054)
  • LocalFree (Address: 0x1000e058)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x1000e060)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1000e070)
  • GetModuleFileNameA (Address: 0x1000e078)
  • GetModuleHandleExW (Address: 0x1000e068)
  • GetModuleHandleW (Address: 0x1000e06c)
  • GetProcAddress (Address: 0x1000e074)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1000e080)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x1000e088)
  • VirtualProtect (Address: 0x1000e08c)
  • VirtualQuery (Address: 0x1000e090)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetStdHandle (Address: 0x1000e098)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1000e0a0)
  • GetCurrentProcessId (Address: 0x1000e0a4)
  • GetCurrentThreadId (Address: 0x1000e0a8)
  • OpenProcessToken (Address: 0x1000e0b0)
  • SetThreadStackGuarantee (Address: 0x1000e0ac)
  • TerminateProcess (Address: 0x1000e0b4)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1000e0bc)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1000e0c4)
  • RegOpenKeyExW (Address: 0x1000e0c8)
  • RegQueryValueExW (Address: 0x1000e0d0)
  • RegSetValueExW (Address: 0x1000e0cc)
api-ms-win-core-rtlsupport-l1-2-0.dll
  • RtlCompareMemory (Address: 0x1000e0d8)
api-ms-win-core-string-l1-1-0.dll
  • WideCharToMultiByte (Address: 0x1000e0e0)
api-ms-win-core-synch-l1-1-0.dll
  • CreateMutexExW (Address: 0x1000e100)
  • CreateSemaphoreExW (Address: 0x1000e0f0)
  • OpenSemaphoreW (Address: 0x1000e0f8)
  • ReleaseMutex (Address: 0x1000e0ec)
  • ReleaseSemaphore (Address: 0x1000e0f4)
  • WaitForSingleObject (Address: 0x1000e0fc)
  • WaitForSingleObjectEx (Address: 0x1000e0e8)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1000e108)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x1000e118)
  • GetSystemTimeAsFileTime (Address: 0x1000e114)
  • GetTickCount (Address: 0x1000e110)
api-ms-win-security-audit-l1-1-0.dll
  • AuditFree (Address: 0x1000e128)
  • AuditQuerySystemPolicy (Address: 0x1000e124)
  • AuditSetSystemPolicy (Address: 0x1000e120)
api-ms-win-security-audit-l1-1-1.dll
  • AuditEnumerateCategories (Address: 0x1000e134)
  • AuditEnumeratePerUserPolicy (Address: 0x1000e144)
  • AuditEnumerateSubCategories (Address: 0x1000e138)
  • AuditLookupCategoryNameW (Address: 0x1000e14c)
  • AuditLookupSubCategoryNameW (Address: 0x1000e140)
  • AuditQueryGlobalSaclW (Address: 0x1000e130)
  • AuditQueryPerUserPolicy (Address: 0x1000e148)
  • AuditSetGlobalSaclW (Address: 0x1000e150)
  • AuditSetPerUserPolicy (Address: 0x1000e13c)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x1000e158)
  • EqualSid (Address: 0x1000e168)
  • GetSecurityDescriptorSacl (Address: 0x1000e170)
  • InitializeSecurityDescriptor (Address: 0x1000e164)
  • IsValidSid (Address: 0x1000e160)
  • IsWellKnownSid (Address: 0x1000e15c)
  • SetSecurityDescriptorSacl (Address: 0x1000e16c)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x1000e178)
api-ms-win-security-provider-l1-1-0.dll
  • GetExplicitEntriesFromAclW (Address: 0x1000e180)
  • SetEntriesInAclW (Address: 0x1000e184)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x1000e198)
  • ConvertSidToStringSidW (Address: 0x1000e18c)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1000e194)
  • ConvertStringSidToSidW (Address: 0x1000e190)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x1000e1cc)
  • __dllonexit (Address: 0x1000e1ac)
  • __iob_func (Address: 0x1000e1b4)
  • _amsg_exit (Address: 0x1000e1c8)
  • _callnewh (Address: 0x1000e22c)
  • _CxxThrowException (Address: 0x1000e23c)
  • _except_handler4_common (Address: 0x1000e24c)
  • _initterm (Address: 0x1000e1a8)
  • _lock (Address: 0x1000e1c0)
  • _onexit (Address: 0x1000e1a4)
  • _purecall (Address: 0x1000e1e8)
  • _unlock (Address: 0x1000e1b8)
  • _vsnprintf_s (Address: 0x1000e1f8)
  • _vsnwprintf (Address: 0x1000e1d0)
  • _vsnwprintf_s (Address: 0x1000e21c)
  • _wcsicmp (Address: 0x1000e1dc)
  • _wcsnicmp (Address: 0x1000e210)
  • _wfopen (Address: 0x1000e200)
  • _wtoi (Address: 0x1000e228)
  • _XcptFilter (Address: 0x1000e1c4)
  • ??_V@YAXPAX@Z (Address: 0x1000e218)
  • ??0exception@@QAE@ABQBD@Z (Address: 0x1000e230)
  • ??0exception@@QAE@ABQBDH@Z (Address: 0x1000e234)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x1000e1f4)
  • ??0exception@@QAE@XZ (Address: 0x1000e1f0)
  • ??1exception@@UAE@XZ (Address: 0x1000e1ec)
  • ??1type_info@@UAE@XZ (Address: 0x1000e248)
  • ??3@YAXPAX@Z (Address: 0x1000e1e4)
  • ?what@exception@@UBEPBDXZ (Address: 0x1000e238)
  • fclose (Address: 0x1000e1e0)
  • feof (Address: 0x1000e20c)
  • ferror (Address: 0x1000e1d4)
  • fgetws (Address: 0x1000e208)
  • free (Address: 0x1000e1bc)
  • malloc (Address: 0x1000e1b0)
  • memcmp (Address: 0x1000e1a0)
  • memcpy (Address: 0x1000e240)
  • memcpy_s (Address: 0x1000e1d8)
  • memmove (Address: 0x1000e244)
  • memset (Address: 0x1000e250)
  • qsort (Address: 0x1000e224)
  • vfwprintf (Address: 0x1000e220)
  • wcschr (Address: 0x1000e1fc)
  • wprintf (Address: 0x1000e214)
  • wscanf (Address: 0x1000e204)
ntdll.dll
  • RtlAllocateHeap (Address: 0x1000e258)
  • RtlFreeHeap (Address: 0x1000e268)
  • RtlGUIDFromString (Address: 0x1000e260)
  • RtlImageNtHeader (Address: 0x1000e264)
  • RtlNtStatusToDosError (Address: 0x1000e25c)