appid
|
text
|
base
|
text
|
bit
|
integer
|
category_name
|
text
|
cmdline
|
text
|
create_time
|
date
|
curdir
|
text
|
handles
|
integer
|
ilevel
|
text
|
isdebugged
|
boolean
|
kernel_time
|
text
|
memory_usage.other_op
|
long
|
memory_usage.pagefaults
|
long
|
memory_usage.pagefile_usage
|
long
|
memory_usage.peak_pagefile_usage
|
long
|
memory_usage.peak_virtual_size
|
long
|
memory_usage.peak_workingset
|
long
|
memory_usage.quota_non_pagedpool
|
long
|
memory_usage.quota_pagedpool
|
long
|
memory_usage.quota_peak_non_pagedpool
|
long
|
memory_usage.quota_peak_pagedpool
|
long
|
memory_usage.read_op
|
long
|
memory_usage.virtual_size
|
long
|
memory_usage.workingset
|
long
|
memory_usage.write_op
|
long
|
mitigations.aslr_policy.disallow_stripped_images
|
text
|
mitigations.aslr_policy.enable_bottom_up_randomization
|
text
|
mitigations.aslr_policy.enable_force_relocate_images
|
text
|
mitigations.aslr_policy.enable_high_entropy
|
text
|
mitigations.cfg_policy.enable_cfg
|
text
|
mitigations.cfg_policy.enable_export_suppression
|
text
|
mitigations.cfg_policy.strict_mode
|
text
|
mitigations.child_process_policy.allow_secure_process_creation
|
text
|
mitigations.child_process_policy.audit_no_child_process_creation
|
text
|
mitigations.child_process_policy.no_child_process_creation
|
text
|
mitigations.dynamic_code_policy.allow_remote_downgrade
|
text
|
mitigations.dynamic_code_policy.allow_thread_opt_out
|
text
|
mitigations.dynamic_code_policy.audit_prohibit_dynamic_code
|
text
|
mitigations.dynamic_code_policy.prohibit_dynamic_code
|
text
|
mitigations.extension_point_disable_policy.disable_extension_points
|
text
|
mitigations.font_disable_policy.audit_non_system_font_loading
|
text
|
mitigations.font_disable_policy.disable_non_system_fonts
|
text
|
mitigations.image_load_policy.audit_no_low_mandatory_label_images
|
text
|
mitigations.image_load_policy.audit_no_remote_images
|
text
|
mitigations.image_load_policy.no_low_mandatory_label_images
|
text
|
mitigations.image_load_policy.no_remote_images
|
text
|
mitigations.image_load_policy.prefer_system32_images
|
text
|
mitigations.payload_restriction_policy.audit_export_address_filter
|
text
|
mitigations.payload_restriction_policy.audit_export_address_filter_plus
|
text
|
mitigations.payload_restriction_policy.audit_import_address_filter
|
text
|
mitigations.payload_restriction_policy.audit_rop_caller_check
|
text
|
mitigations.payload_restriction_policy.audit_rop_sim_exec
|
text
|
mitigations.payload_restriction_policy.audit_rop_stack_pivot
|
text
|
mitigations.payload_restriction_policy.enable_export_address_filter
|
text
|
mitigations.payload_restriction_policy.enable_export_address_filter_plus
|
text
|
mitigations.payload_restriction_policy.enable_import_address_filter
|
text
|
mitigations.payload_restriction_policy.enable_rop_caller_check
|
text
|
mitigations.payload_restriction_policy.enable_rop_sim_exec
|
text
|
mitigations.payload_restriction_policy.enable_rop_stack_pivot
|
text
|
mitigations.redirection_trust_policy.audit_redirectiont_rust
|
text
|
mitigations.redirection_trust_policy.enforce_redirection_trust
|
text
|
mitigations.side_channel_isolation_policy.disable_page_combine
|
text
|
mitigations.side_channel_isolation_policy.isolate_security_domain
|
text
|
mitigations.side_channel_isolation_policy.smt_branch_target_isolation
|
text
|
mitigations.side_channel_isolation_policy.speculative_store_bypass_disable
|
text
|
mitigations.signature_policy.audit_microsoft_signed_only
|
text
|
mitigations.signature_policy.audit_store_signed_only
|
text
|
mitigations.signature_policy.microsoft_signed_only
|
text
|
mitigations.signature_policy.mitigation_opt_in
|
text
|
mitigations.signature_policy.store_signed_only
|
text
|
mitigations.strict_handle_check_policy.handle_exceptions_permanently_enabled
|
text
|
mitigations.strict_handle_check_policy.raise_exception_on_invalid_handle_reference
|
text
|
mitigations.syscall_disable_policy.audit_disallow_win32k_syscalls
|
text
|
mitigations.syscall_disable_policy.disallow_win32k_syscalls
|
text
|
mitigations.systemcall_filter_policy.filter_id
|
text
|
mitigations.user_shadow_stack_policy.audit
|
text
|
mitigations.user_shadow_stack_policy.audit_block_non_cet_binaries
|
text
|
mitigations.user_shadow_stack_policy.audit_set_context_ip_validation
|
text
|
mitigations.user_shadow_stack_policy.block_non_cet_binaries
|
text
|
mitigations.user_shadow_stack_policy.block_non_cet_binaries_non_ehcont
|
text
|
mitigations.user_shadow_stack_policy.cet_dynamic_apis_out_of_proc_only
|
text
|
mitigations.user_shadow_stack_policy.enable
|
text
|
mitigations.user_shadow_stack_policy.enable_strict_mode
|
text
|
mitigations.user_shadow_stack_policy.set_context_ip_validation
|
text
|
mitigations.user_shadow_stack_policy.set_context_ip_validation_relaxed_mode
|
text
|
module.arkstatus
|
text
|
module.base
|
text
|
module.buildtime
|
date
|
module.path
|
text
|
module.size
|
long
|
path
|
text
|
peb
|
text
|
pid
|
integer
|
ppid
|
integer
|
priority
|
integer
|
protection_level
|
text
|
section_info.checksum
|
text
|
section_info.committed_stack_size
|
long
|
section_info.dll_characteristics
|
text
|
section_info.image_characteristics
|
text
|
section_info.image_contains_code
|
boolean
|
section_info.image_file_size
|
long
|
section_info.image_flags
|
text
|
section_info.loader_flags
|
text
|
section_info.machine
|
text
|
section_info.max_stack_size
|
long
|
section_info.os_major_ver
|
text
|
section_info.os_minor_ver
|
text
|
section_info.subsystem
|
text
|
section_info.subsystem_major_ver
|
text
|
section_info.subsystem_minor_ver
|
text
|
section_info.transfer_address
|
text
|
section_info.zero_bits
|
text
|
session_id
|
text
|
shell_info
|
text
|
shortcut
|
text
|
size
|
long
|
threads.count
|
text
|
threads.thread.base_priority
|
text
|
threads.thread.create_time
|
text
|
threads.thread.kernel_time
|
text
|
threads.thread.path
|
text
|
threads.thread.priority
|
text
|
threads.thread.start_address
|
text
|
threads.thread.state
|
text
|
threads.thread.tid
|
text
|
threads.thread.user_time
|
text
|
threads.thread.win32_start_address
|
text
|
title
|
text
|
type
|
text
|
unique_id
|
text
|
user_time
|
text
|
window_flags
|
text
|