Skip to content

Commit b653177

Browse files
authored
Moving amsistate event changed to this repo (#87)
1 parent 06d8c01 commit b653177

File tree

1 file changed

+48
-2
lines changed

1 file changed

+48
-2
lines changed

src/PowerShell.Core.Instrumentation/PowerShell.Core.Instrumentation.man

Lines changed: 48 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2184,6 +2184,18 @@
21842184
value="0x6017"
21852185
version="1"
21862186
/>
2187+
<event
2188+
channel="C_ANALYTIC"
2189+
keywords="AmsiState"
2190+
level="win:Verbose"
2191+
message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)"
2192+
opcode="Method"
2193+
symbol="AmsiState"
2194+
task="Amsi"
2195+
template="T_AmsiState"
2196+
value="0x4001"
2197+
version="1"
2198+
/>
21872199
</events>
21882200
<channels>
21892201
<!--There are two channels defined for Windows PowerShell instrumentation
@@ -2407,6 +2419,12 @@
24072419
symbol="T_ISEOperation"
24082420
value="120"
24092421
/>
2422+
<task
2423+
message="$(string.PS_PROVIDER.task.T_AmsiState.message)"
2424+
name="Amsi"
2425+
symbol="T_Amsi"
2426+
value="130"
2427+
/>
24102428
</tasks>
24112429
<opcodes>
24122430
<opcode
@@ -2567,6 +2585,12 @@
25672585
name="PSWorkflow"
25682586
symbol="K_PSWORKFLOW"
25692587
/>
2588+
<keyword
2589+
mask="0x400"
2590+
message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)"
2591+
name="AmsiState"
2592+
symbol="K_AmsiState"
2593+
/>
25702594
</keywords>
25712595
<maps>
25722596
<!-- please keep in sync with SerializationMethod from
@@ -4024,6 +4048,16 @@
40244048
name="FileName"
40254049
/>
40264050
</template>
4051+
<template tid="T_AmsiState">
4052+
<data
4053+
inType="win:UnicodeString"
4054+
name="Action"
4055+
/>
4056+
<data
4057+
inType="win:UnicodeString"
4058+
name="AmsiContext"
4059+
/>
4060+
</template>
40274061
</templates>
40284062
</provider>
40294063
</events>
@@ -4917,6 +4951,10 @@
49174951
id="PS_PROVIDER.event.E_O_M3PWorkflowExecutionStarted.message"
49184952
value="Workflow execution started. %n %t WorkflowId: %1 %n %t ManagedNodes: %2"
49194953
/>
4954+
<string
4955+
id="PS_PROVIDER.event.E_A_AmsiState.message"
4956+
value="AmsiUtil state. %n %t state: %1 %n %t Context: %2"
4957+
/>
49204958
<string
49214959
id="PS_PROVIDER.event.E_O_M3PEndpointRegistered.message"
49224960
value="A new PowerShell endpoint was registered. %n %t EndpointName: %1 %n %t EndpointType: %2 %n %t RegisteredBy: %3"
@@ -5385,7 +5423,11 @@
53855423
id="PS_PROVIDER.keyword.K_PSWORKFLOW.message"
53865424
value="PSWorkflow Hosting And Execution Layer"
53875425
/>
5388-
<string
5426+
<string
5427+
id="PS_PROVIDER.keyword.K_AmsiState.message"
5428+
value="Amsi state"
5429+
/>
5430+
<string
53895431
id="PS_PROVIDER.keyword.K_SESSION.message"
53905432
value="All session layer"
53915433
/>
@@ -5545,7 +5587,11 @@
55455587
id="PS_PROVIDER.task.T_ISEOperation.message"
55465588
value="PowerShell ISE Operation"
55475589
/>
5548-
<string
5590+
<string
5591+
id="PS_PROVIDER.task.T_AmsiState.message"
5592+
value="Amsi State"
5593+
/>
5594+
<string
55495595
id="PS_PROVIDER.event.E_O_ISEExecuteScript.message"
55505596
value="Windows PowerShell ISE has started to run script file %1."
55515597
/>

0 commit comments

Comments
 (0)