aadrt.dll

Description: AAD Runtime

Authors: Copyright (c) Microsoft Corporation. All rights reserved.

Version: 1.1009.0.0

Architecture: 64-bit

Operating System: Windows

SHA256: 8905294c232b7e28efe23dbfa12584b3

File Size: 1.6 MB

Uploaded At: Dec. 1, 2025, 8:30 a.m.

Views: 17

Exported Functions

  • aadFreeMemory (Ordinal: 1, Address: 0x196d0)
  • aadGetDeviceJoinState (Ordinal: 2, Address: 0x19720)
  • aadGetDeviceOnlyAccessToken (Ordinal: 3, Address: 0x19870)
  • aadGetDevicePreprovisioningBlob (Ordinal: 4, Address: 0x1bcd0)
  • aadHybridJoinDevice (Ordinal: 5, Address: 0x1e3a0)
  • aadJoinPreprovisionedDevice (Ordinal: 6, Address: 0x22710)
  • aadMaintenanceTasks (Ordinal: 7, Address: 0x24fa0)
  • aadSetHttpProxy (Ordinal: 8, Address: 0x25dc0)
  • aadUnjoinDevice (Ordinal: 9, Address: 0x25f80)

Imported DLLs & Functions

ADVAPI32.dll
  • ConvertSidToStringSidA (Address: 0x18011b0b8)
  • ConvertSidToStringSidW (Address: 0x18011b018)
  • ConvertStringSidToSidW (Address: 0x18011b0b0)
  • CryptCreateHash (Address: 0x18011b048)
  • CryptDestroyHash (Address: 0x18011b058)
  • CryptHashData (Address: 0x18011b050)
  • CryptReleaseContext (Address: 0x18011b020)
  • CryptSignHashW (Address: 0x18011b060)
  • DeregisterEventSource (Address: 0x18011b028)
  • EventRegister (Address: 0x18011b0d0)
  • EventSetInformation (Address: 0x18011b000)
  • EventUnregister (Address: 0x18011b0a8)
  • EventWriteTransfer (Address: 0x18011b008)
  • GetTokenInformation (Address: 0x18011b098)
  • IsWellKnownSid (Address: 0x18011b0a0)
  • LookupAccountSidW (Address: 0x18011b0c8)
  • OpenProcessToken (Address: 0x18011b090)
  • RegCloseKey (Address: 0x18011b068)
  • RegCreateKeyExW (Address: 0x18011b040)
  • RegDeleteKeyValueW (Address: 0x18011b080)
  • RegDeleteTreeW (Address: 0x18011b088)
  • RegGetValueW (Address: 0x18011b010)
  • RegisterEventSourceW (Address: 0x18011b030)
  • RegOpenKeyExW (Address: 0x18011b070)
  • RegQueryInfoKeyW (Address: 0x18011b078)
  • RegSetKeyValueW (Address: 0x18011b0c0)
  • ReportEventW (Address: 0x18011b038)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18011b780)
  • RoGetActivationFactory (Address: 0x18011b778)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x18011b798)
  • WindowsDeleteString (Address: 0x18011b7a0)
  • WindowsGetStringRawBuffer (Address: 0x18011b790)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x18011b190)
  • CertAddEncodedCertificateToStore (Address: 0x18011b128)
  • CertCloseStore (Address: 0x18011b118)
  • CertComparePublicKeyInfo (Address: 0x18011b198)
  • CertCreateCertificateContext (Address: 0x18011b180)
  • CertCreateSelfSignCertificate (Address: 0x18011b0f8)
  • CertDeleteCertificateFromStore (Address: 0x18011b168)
  • CertDuplicateCertificateContext (Address: 0x18011b178)
  • CertFindCertificateInStore (Address: 0x18011b170)
  • CertFindExtension (Address: 0x18011b130)
  • CertFreeCertificateContext (Address: 0x18011b0f0)
  • CertGetCertificateContextProperty (Address: 0x18011b120)
  • CertGetNameStringW (Address: 0x18011b148)
  • CertOpenStore (Address: 0x18011b110)
  • CertSetCertificateContextProperty (Address: 0x18011b188)
  • CertStrToNameW (Address: 0x18011b140)
  • CryptAcquireCertificatePrivateKey (Address: 0x18011b138)
  • CryptBinaryToStringW (Address: 0x18011b0e8)
  • CryptDecodeObjectEx (Address: 0x18011b100)
  • CryptEncodeObjectEx (Address: 0x18011b160)
  • CryptExportPublicKeyInfo (Address: 0x18011b158)
  • CryptFindOIDInfo (Address: 0x18011b108)
  • CryptSignAndEncodeCertificate (Address: 0x18011b150)
  • CryptStringToBinaryW (Address: 0x18011b0e0)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18011b550)
  • CloseHandle (Address: 0x18011b288)
  • CompareFileTime (Address: 0x18011b1e8)
  • CompareStringW (Address: 0x18011b3d0)
  • CreateEventW (Address: 0x18011b270)
  • CreateFileW (Address: 0x18011b1d0)
  • CreateProcessW (Address: 0x18011b220)
  • DecodePointer (Address: 0x18011b300)
  • DeleteCriticalSection (Address: 0x18011b2c0)
  • DeleteFileW (Address: 0x18011b248)
  • EncodePointer (Address: 0x18011b578)
  • EnterCriticalSection (Address: 0x18011b510)
  • EnumSystemLocalesW (Address: 0x18011b3a8)
  • ExitProcess (Address: 0x18011b430)
  • ExpandEnvironmentStringsW (Address: 0x18011b250)
  • FileTimeToSystemTime (Address: 0x18011b2b0)
  • FindClose (Address: 0x18011b358)
  • FindFirstFileExW (Address: 0x18011b350)
  • FindNextFileW (Address: 0x18011b348)
  • FindResourceExW (Address: 0x18011b4f8)
  • FindResourceW (Address: 0x18011b1f0)
  • FlsAlloc (Address: 0x18011b408)
  • FlsFree (Address: 0x18011b3f0)
  • FlsGetValue (Address: 0x18011b400)
  • FlsSetValue (Address: 0x18011b3f8)
  • FlushFileBuffers (Address: 0x18011b3a0)
  • FormatMessageW (Address: 0x18011b500)
  • FreeEnvironmentStringsW (Address: 0x18011b1b8)
  • FreeLibrary (Address: 0x18011b2a0)
  • FreeResource (Address: 0x18011b218)
  • GetACP (Address: 0x18011b338)
  • GetCommandLineA (Address: 0x18011b328)
  • GetCommandLineW (Address: 0x18011b1b0)
  • GetComputerNameExW (Address: 0x18011b260)
  • GetConsoleMode (Address: 0x18011b388)
  • GetConsoleOutputCP (Address: 0x18011b390)
  • GetCPInfo (Address: 0x18011b4e8)
  • GetCurrentProcess (Address: 0x18011b268)
  • GetCurrentProcessId (Address: 0x18011b508)
  • GetCurrentThreadId (Address: 0x18011b570)
  • GetDateFormatW (Address: 0x18011b3e0)
  • GetEnvironmentStringsW (Address: 0x18011b1a8)
  • GetExitCodeProcess (Address: 0x18011b228)
  • GetFileSizeEx (Address: 0x18011b378)
  • GetFileType (Address: 0x18011b410)
  • GetLastError (Address: 0x18011b310)
  • GetLocaleInfoW (Address: 0x18011b3c0)
  • GetModuleFileNameW (Address: 0x18011b210)
  • GetModuleHandleExW (Address: 0x18011b428)
  • GetModuleHandleW (Address: 0x18011b258)
  • GetOEMCP (Address: 0x18011b330)
  • GetProcAddress (Address: 0x18011b298)
  • GetProcessHeap (Address: 0x18011b2d0)
  • GetStartupInfoW (Address: 0x18011b498)
  • GetStdHandle (Address: 0x18011b418)
  • GetStringTypeW (Address: 0x18011b520)
  • GetSystemTime (Address: 0x18011b2b8)
  • GetSystemTimeAsFileTime (Address: 0x18011b588)
  • GetTempFileNameW (Address: 0x18011b240)
  • GetTempPathW (Address: 0x18011b238)
  • GetTimeFormatW (Address: 0x18011b3d8)
  • GetTimeZoneInformation (Address: 0x18011b360)
  • GetUserDefaultLCID (Address: 0x18011b3b0)
  • HeapAlloc (Address: 0x18011b2f0)
  • HeapDestroy (Address: 0x18011b2f8)
  • HeapFree (Address: 0x18011b2e0)
  • HeapQueryInformation (Address: 0x18011b420)
  • HeapReAlloc (Address: 0x18011b2e8)
  • HeapSize (Address: 0x18011b2d8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18011b460)
  • InitializeCriticalSectionEx (Address: 0x18011b2c8)
  • InitializeSListHead (Address: 0x18011b488)
  • InitOnceBeginInitialize (Address: 0x18011b528)
  • InitOnceComplete (Address: 0x18011b530)
  • InterlockedFlushSList (Address: 0x18011b468)
  • IsDebuggerPresent (Address: 0x18011b4a0)
  • IsProcessorFeaturePresent (Address: 0x18011b4a8)
  • IsValidCodePage (Address: 0x18011b340)
  • IsValidLocale (Address: 0x18011b3b8)
  • LCMapStringEx (Address: 0x18011b580)
  • LCMapStringW (Address: 0x18011b3c8)
  • LeaveCriticalSection (Address: 0x18011b518)
  • LoadLibraryExW (Address: 0x18011b438)
  • LoadLibraryW (Address: 0x18011b290)
  • LoadResource (Address: 0x18011b208)
  • LocalFree (Address: 0x18011b308)
  • LockResource (Address: 0x18011b200)
  • MultiByteToWideChar (Address: 0x18011b320)
  • OutputDebugStringW (Address: 0x18011b480)
  • QueryPerformanceCounter (Address: 0x18011b538)
  • QueryPerformanceFrequency (Address: 0x18011b540)
  • RaiseException (Address: 0x18011b280)
  • ReadConsoleW (Address: 0x18011b368)
  • ReadFile (Address: 0x18011b380)
  • ReleaseSRWLockExclusive (Address: 0x18011b548)
  • RtlCaptureContext (Address: 0x18011b4d8)
  • RtlLookupFunctionEntry (Address: 0x18011b4d0)
  • RtlPcToFileHeader (Address: 0x18011b478)
  • RtlUnwind (Address: 0x18011b490)
  • RtlUnwindEx (Address: 0x18011b470)
  • RtlVirtualUnwind (Address: 0x18011b4c8)
  • SetEndOfFile (Address: 0x18011b1e0)
  • SetEnvironmentVariableW (Address: 0x18011b1c0)
  • SetEvent (Address: 0x18011b278)
  • SetFilePointerEx (Address: 0x18011b370)
  • SetLastError (Address: 0x18011b4f0)
  • SetStdHandle (Address: 0x18011b1c8)
  • SetUnhandledExceptionFilter (Address: 0x18011b4b8)
  • SizeofResource (Address: 0x18011b1f8)
  • Sleep (Address: 0x18011b568)
  • SleepConditionVariableSRW (Address: 0x18011b560)
  • SystemTimeToFileTime (Address: 0x18011b2a8)
  • TerminateProcess (Address: 0x18011b4b0)
  • TlsAlloc (Address: 0x18011b458)
  • TlsFree (Address: 0x18011b440)
  • TlsGetValue (Address: 0x18011b450)
  • TlsSetValue (Address: 0x18011b448)
  • TryAcquireSRWLockExclusive (Address: 0x18011b558)
  • UnhandledExceptionFilter (Address: 0x18011b4c0)
  • VirtualProtect (Address: 0x18011b3e8)
  • WaitForSingleObject (Address: 0x18011b230)
  • WakeAllConditionVariable (Address: 0x18011b4e0)
  • WideCharToMultiByte (Address: 0x18011b318)
  • WriteConsoleW (Address: 0x18011b1d8)
  • WriteFile (Address: 0x18011b398)
ncrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18011b7d8)
  • BCryptCreateHash (Address: 0x18011b840)
  • BCryptDecrypt (Address: 0x18011b7b0)
  • BCryptDestroyHash (Address: 0x18011b858)
  • BCryptDestroyKey (Address: 0x18011b7b8)
  • BCryptFinishHash (Address: 0x18011b7e8)
  • BCryptGenerateSymmetricKey (Address: 0x18011b820)
  • BCryptGetProperty (Address: 0x18011b828)
  • BCryptHashData (Address: 0x18011b7e0)
  • BCryptOpenAlgorithmProvider (Address: 0x18011b830)
  • BCryptSetProperty (Address: 0x18011b818)
  • NCryptCreatePersistedKey (Address: 0x18011b808)
  • NCryptDecrypt (Address: 0x18011b7c0)
  • NCryptDeleteKey (Address: 0x18011b838)
  • NCryptExportKey (Address: 0x18011b848)
  • NCryptFinalizeKey (Address: 0x18011b7f0)
  • NCryptFreeObject (Address: 0x18011b850)
  • NCryptGetProperty (Address: 0x18011b810)
  • NCryptOpenKey (Address: 0x18011b800)
  • NCryptOpenStorageProvider (Address: 0x18011b7f8)
  • NCryptSetProperty (Address: 0x18011b7c8)
  • NCryptSignHash (Address: 0x18011b7d0)
NETAPI32.dll
  • NetApiBufferFree (Address: 0x18011b5b0)
  • NetGetJoinInformation (Address: 0x18011b5a8)
  • NetLocalGroupAddMembers (Address: 0x18011b5a0)
  • NetLocalGroupDelMembers (Address: 0x18011b598)
ole32.dll
  • CoCreateGuid (Address: 0x18011b880)
  • CoCreateInstance (Address: 0x18011b878)
  • CoInitializeEx (Address: 0x18011b890)
  • CoUninitialize (Address: 0x18011b870)
  • OleRun (Address: 0x18011b888)
  • StringFromGUID2 (Address: 0x18011b868)
OLEAUT32.dll
  • GetErrorInfo (Address: 0x18011b5c8)
  • SysAllocString (Address: 0x18011b5d8)
  • SysFreeString (Address: 0x18011b5e8)
  • SysStringLen (Address: 0x18011b5c0)
  • VariantClear (Address: 0x18011b5d0)
  • VariantInit (Address: 0x18011b5e0)
RPCRT4.dll
  • UuidFromStringW (Address: 0x18011b5f8)
Secur32.dll
  • GetComputerObjectNameW (Address: 0x18011b608)
  • GetUserNameExW (Address: 0x18011b638)
  • LsaCallAuthenticationPackage (Address: 0x18011b620)
  • LsaConnectUntrusted (Address: 0x18011b630)
  • LsaDeregisterLogonProcess (Address: 0x18011b628)
  • LsaFreeReturnBuffer (Address: 0x18011b618)
  • LsaLookupAuthenticationPackage (Address: 0x18011b610)
USER32.dll
  • DispatchMessageW (Address: 0x18011b650)
  • MsgWaitForMultipleObjects (Address: 0x18011b660)
  • PeekMessageW (Address: 0x18011b648)
  • TranslateMessage (Address: 0x18011b658)
WINHTTP.dll
  • WinHttpAddRequestHeaders (Address: 0x18011b6b0)
  • WinHttpCloseHandle (Address: 0x18011b6b8)
  • WinHttpConnect (Address: 0x18011b6d0)
  • WinHttpCrackUrl (Address: 0x18011b670)
  • WinHttpOpen (Address: 0x18011b678)
  • WinHttpOpenRequest (Address: 0x18011b6c8)
  • WinHttpQueryDataAvailable (Address: 0x18011b6a8)
  • WinHttpQueryHeaders (Address: 0x18011b680)
  • WinHttpReadData (Address: 0x18011b690)
  • WinHttpReceiveResponse (Address: 0x18011b6d8)
  • WinHttpSendRequest (Address: 0x18011b688)
  • WinHttpSetCredentials (Address: 0x18011b6c0)
  • WinHttpSetOption (Address: 0x18011b698)
  • WinHttpSetStatusCallback (Address: 0x18011b6a0)
WLDAP32.dll
  • (Address: 0x18011b6e8)
  • (Address: 0x18011b6f0)
  • (Address: 0x18011b6f8)
  • (Address: 0x18011b700)
  • (Address: 0x18011b708)
  • (Address: 0x18011b710)
  • (Address: 0x18011b718)
  • (Address: 0x18011b720)
  • (Address: 0x18011b728)
  • (Address: 0x18011b730)
  • (Address: 0x18011b738)
  • (Address: 0x18011b740)
  • (Address: 0x18011b748)
  • (Address: 0x18011b750)
  • (Address: 0x18011b758)
  • (Address: 0x18011b760)
  • (Address: 0x18011b768)