File tree Expand file tree Collapse file tree 1 file changed +48
-2
lines changed
src/PowerShell.Core.Instrumentation Expand file tree Collapse file tree 1 file changed +48
-2
lines changed Original file line number Diff line number Diff line change 2184
2184
value="0x6017"
2185
2185
version="1"
2186
2186
/>
2187
+ <event
2188
+ channel="C_ANALYTIC"
2189
+ keywords="AmsiState"
2190
+ level="win:Verbose"
2191
+ message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)"
2192
+ opcode="Method"
2193
+ symbol="AmsiState"
2194
+ task="Amsi"
2195
+ template="T_AmsiState"
2196
+ value="0x4001"
2197
+ version="1"
2198
+ />
2187
2199
</events>
2188
2200
<channels>
2189
2201
<!--There are two channels defined for Windows PowerShell instrumentation
2407
2419
symbol="T_ISEOperation"
2408
2420
value="120"
2409
2421
/>
2422
+ <task
2423
+ message="$(string.PS_PROVIDER.task.T_AmsiState.message)"
2424
+ name="Amsi"
2425
+ symbol="T_Amsi"
2426
+ value="130"
2427
+ />
2410
2428
</tasks>
2411
2429
<opcodes>
2412
2430
<opcode
2567
2585
name="PSWorkflow"
2568
2586
symbol="K_PSWORKFLOW"
2569
2587
/>
2588
+ <keyword
2589
+ mask="0x400"
2590
+ message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)"
2591
+ name="AmsiState"
2592
+ symbol="K_AmsiState"
2593
+ />
2570
2594
</keywords>
2571
2595
<maps>
2572
2596
<!-- please keep in sync with SerializationMethod from
4024
4048
name="FileName"
4025
4049
/>
4026
4050
</template>
4051
+ <template tid="T_AmsiState">
4052
+ <data
4053
+ inType="win:UnicodeString"
4054
+ name="Action"
4055
+ />
4056
+ <data
4057
+ inType="win:UnicodeString"
4058
+ name="AmsiContext"
4059
+ />
4060
+ </template>
4027
4061
</templates>
4028
4062
</provider>
4029
4063
</events>
4917
4951
id="PS_PROVIDER.event.E_O_M3PWorkflowExecutionStarted.message"
4918
4952
value="Workflow execution started. %n %t WorkflowId: %1 %n %t ManagedNodes: %2"
4919
4953
/>
4954
+ <string
4955
+ id="PS_PROVIDER.event.E_A_AmsiState.message"
4956
+ value="AmsiUtil state. %n %t state: %1 %n %t Context: %2"
4957
+ />
4920
4958
<string
4921
4959
id="PS_PROVIDER.event.E_O_M3PEndpointRegistered.message"
4922
4960
value="A new PowerShell endpoint was registered. %n %t EndpointName: %1 %n %t EndpointType: %2 %n %t RegisteredBy: %3"
5385
5423
id="PS_PROVIDER.keyword.K_PSWORKFLOW.message"
5386
5424
value="PSWorkflow Hosting And Execution Layer"
5387
5425
/>
5388
- <string
5426
+ <string
5427
+ id="PS_PROVIDER.keyword.K_AmsiState.message"
5428
+ value="Amsi state"
5429
+ />
5430
+ <string
5389
5431
id="PS_PROVIDER.keyword.K_SESSION.message"
5390
5432
value="All session layer"
5391
5433
/>
5545
5587
id="PS_PROVIDER.task.T_ISEOperation.message"
5546
5588
value="PowerShell ISE Operation"
5547
5589
/>
5548
- <string
5590
+ <string
5591
+ id="PS_PROVIDER.task.T_AmsiState.message"
5592
+ value="Amsi State"
5593
+ />
5594
+ <string
5549
5595
id="PS_PROVIDER.event.E_O_ISEExecuteScript.message"
5550
5596
value="Windows PowerShell ISE has started to run script file %1."
5551
5597
/>
You can’t perform that action at this time.
0 commit comments