edpauditapi.dll
Description: EDP Audit API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 32-bit
Operating System: Windows NT
SHA256: 4b2ad7825e9f0b67a97088f09fcc2d62
File Size: 102.5 KB
Uploaded At: Dec. 1, 2025, 7:55 a.m.
Views: 5
Exported Functions
- EdpFlushTraces (Ordinal: 1, Address: 0x63d0)
- EdpAuditHarden (Ordinal: 2, Address: 0x5dd0)
- EdpAuditLogApplicationGenerated (Ordinal: 3, Address: 0x10f60)
- EdpAuditLogApplicationLearning (Ordinal: 4, Address: 0x11050)
- EdpAuditLogDataCopied (Ordinal: 5, Address: 0x10e30)
- EdpAuditLogProtectionRemoved (Ordinal: 6, Address: 0x112a0)
- EdpAuditLogSiteLearning (Ordinal: 7, Address: 0x111c0)
- EdpAuditLoggerRegister (Ordinal: 8, Address: 0x11390)
- EdpAuditLoggerUnregister (Ordinal: 9, Address: 0x113b0)
- EdpAuditRead (Ordinal: 10, Address: 0x5e50)
- EdpGetLogFullPathFromRelativePath (Ordinal: 11, Address: 0x5f10)
- ReadAuditLogByCount (Ordinal: 12, Address: 0x6ee0)
- ReadAuditLogByTimeRange (Ordinal: 13, Address: 0x6de0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoTaskMemAlloc (Address: 0x1001601c)
- CoTaskMemFree (Address: 0x10016020)
- StringFromGUID2 (Address: 0x10016018)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x10016028)
- IsDebuggerPresent (Address: 0x1001602c)
- OutputDebugStringW (Address: 0x10016030)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x10016038)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x10016040)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1001604c)
- SetLastError (Address: 0x10016054)
- SetUnhandledExceptionFilter (Address: 0x10016050)
- UnhandledExceptionFilter (Address: 0x10016048)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x1001605c)
- FindClose (Address: 0x1001606c)
- FindFirstFileW (Address: 0x10016064)
- FindNextFileW (Address: 0x10016068)
- GetFileAttributesW (Address: 0x10016060)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10016074)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1001608c)
- HeapAlloc (Address: 0x10016090)
- HeapDestroy (Address: 0x1001607c)
- HeapFree (Address: 0x10016084)
- HeapReAlloc (Address: 0x10016088)
- HeapSize (Address: 0x10016080)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1001609c)
- LocalFree (Address: 0x10016098)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x100160b0)
- GetModuleHandleExW (Address: 0x100160ac)
- GetModuleHandleW (Address: 0x100160a8)
- GetProcAddress (Address: 0x100160a4)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x100160b8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x100160c0)
- GetCurrentProcessId (Address: 0x100160cc)
- GetCurrentThreadId (Address: 0x100160c8)
- TerminateProcess (Address: 0x100160c4)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100160d4)
api-ms-win-core-string-l1-1-0.dll
- GetStringTypeW (Address: 0x100160e4)
- MultiByteToWideChar (Address: 0x100160dc)
- WideCharToMultiByte (Address: 0x100160e0)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x10016108)
- CreateMutexExW (Address: 0x10016118)
- CreateSemaphoreExW (Address: 0x10016110)
- DeleteCriticalSection (Address: 0x10016120)
- EnterCriticalSection (Address: 0x1001611c)
- InitializeCriticalSectionEx (Address: 0x100160f4)
- InitializeSRWLock (Address: 0x10016114)
- LeaveCriticalSection (Address: 0x10016104)
- OpenSemaphoreW (Address: 0x10016100)
- ReleaseMutex (Address: 0x100160f0)
- ReleaseSemaphore (Address: 0x1001610c)
- ReleaseSRWLockExclusive (Address: 0x100160f8)
- WaitForSingleObject (Address: 0x100160fc)
- WaitForSingleObjectEx (Address: 0x100160ec)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x1001612c)
- Sleep (Address: 0x10016128)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x10016134)
- GetTickCount (Address: 0x10016138)
- GetWindowsDirectoryW (Address: 0x1001613c)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x10016148)
- SystemTimeToTzSpecificLocalTime (Address: 0x10016144)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x10016150)
- EncodePointer (Address: 0x10016154)
api-ms-win-eventing-consumer-l1-1-0.dll
- CloseTrace (Address: 0x10016164)
- OpenTraceW (Address: 0x1001615c)
- ProcessTrace (Address: 0x10016160)
api-ms-win-eventing-controller-l1-1-0.dll
- ControlTraceW (Address: 0x10016170)
- EventAccessControl (Address: 0x1001616c)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1001617c)
- EventSetInformation (Address: 0x10016180)
- EventUnregister (Address: 0x10016184)
- EventWriteTransfer (Address: 0x10016178)
api-ms-win-eventing-tdh-l1-1-0.dll
- TdhGetEventInformation (Address: 0x10016194)
- TdhGetProperty (Address: 0x10016190)
- TdhGetPropertySize (Address: 0x1001618c)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1001619c)
msvcrt.dll
- ___lc_codepage_func (Address: 0x10016210)
- ___lc_handle_func (Address: 0x10016214)
- ___mb_cur_max_func (Address: 0x100161c8)
- __crtLCMapStringW (Address: 0x100161b0)
- __CxxFrameHandler3 (Address: 0x1001628c)
- __dllonexit (Address: 0x10016228)
- __pctype_func (Address: 0x10016250)
- __uncaught_exception (Address: 0x10016258)
- _amsg_exit (Address: 0x10016248)
- _callnewh (Address: 0x100161bc)
- _CxxThrowException (Address: 0x100161d0)
- _errno (Address: 0x100161c0)
- _except_handler4_common (Address: 0x1001621c)
- _initterm (Address: 0x10016234)
- _ismbblead (Address: 0x100161c4)
- _lock (Address: 0x10016230)
- _onexit (Address: 0x10016224)
- _purecall (Address: 0x100161f0)
- _unlock (Address: 0x1001622c)
- _vscwprintf (Address: 0x100161e0)
- _vsnprintf_s (Address: 0x10016268)
- _vsnwprintf (Address: 0x10016284)
- _wcsdup (Address: 0x100161ac)
- _wsetlocale (Address: 0x100161b4)
- _XcptFilter (Address: 0x10016264)
- ??_V@YAXPAX@Z (Address: 0x10016244)
- ??0bad_cast@@QAE@ABV0@@Z (Address: 0x1001620c)
- ??0bad_cast@@QAE@PBD@Z (Address: 0x10016218)
- ??0exception@@QAE@ABQBD@Z (Address: 0x100161e8)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x10016254)
- ??0exception@@QAE@ABV0@@Z (Address: 0x1001626c)
- ??0exception@@QAE@XZ (Address: 0x10016270)
- ??1bad_cast@@UAE@XZ (Address: 0x10016240)
- ??1exception@@UAE@XZ (Address: 0x10016278)
- ??1type_info@@UAE@XZ (Address: 0x10016220)
- ??3@YAXPAX@Z (Address: 0x1001627c)
- ?what@exception@@UBEPBDXZ (Address: 0x100161ec)
- abort (Address: 0x100161a8)
- calloc (Address: 0x10016208)
- free (Address: 0x1001623c)
- localeconv (Address: 0x100161e4)
- malloc (Address: 0x10016238)
- memcpy (Address: 0x10016260)
- memcpy_s (Address: 0x10016280)
- memmove (Address: 0x1001625c)
- memmove_s (Address: 0x100161d4)
- memset (Address: 0x100161a4)
- setlocale (Address: 0x100161b8)
- sprintf_s (Address: 0x100161cc)
- strcspn (Address: 0x100161f4)
- strncpy_s (Address: 0x10016204)
- strnlen (Address: 0x100161dc)
- swprintf_s (Address: 0x10016288)
- vswprintf_s (Address: 0x100161f8)
- wcscat_s (Address: 0x100161fc)
- wcscpy_s (Address: 0x10016200)
- wcsncpy_s (Address: 0x10016274)
- wcsnlen (Address: 0x1001624c)
- wcsrchr (Address: 0x100161d8)
ntdll.dll
- NtClose (Address: 0x100162a4)
- NtCreateFile (Address: 0x10016294)
- NtReadFile (Address: 0x100162b4)
- RtlAllocateHeap (Address: 0x100162b0)
- RtlFreeHeap (Address: 0x1001629c)
- RtlGetNtSystemRoot (Address: 0x100162a0)
- RtlInitUnicodeString (Address: 0x100162ac)
- RtlNtStatusToDosError (Address: 0x10016298)
- RtlValidSid (Address: 0x100162a8)
WS2_32.dll
- ntohl (Address: 0x10016008)
- ntohs (Address: 0x10016004)
- WSAAddressToStringW (Address: 0x10016000)
- WSACleanup (Address: 0x10016010)
- WSAStartup (Address: 0x1001600c)