viewer9 documentation

QuerySecurityFile PML Operation

SecInfo ("Information" in Procmon) is bit flags.

Example from 64-bit PML

Hover over field values like Time, ResultCode, SecInfo, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

QuerySecurityFile opcode=3,40

ev=6650 advop=IRP_MJ_QUERY_SECURITY

Time:2022-05-17 19:41:46.3614994
Duration:0.0000046
ResultCode:SUCCESS
Tid:1312
Path:C:\Users\John\Desktop\ChromeSetup 64-bit.exe
SecInfo:Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100

evdata[0-113] file offset 2904829

000 00 00 00 5c 00 44 00 ....\.D.
800 00 00 00 01 00 00 00 ........
16bf 01 00 00 00 00 00 00 ........
2480 03 00 00 00 00 00 00 ........
3270 3c 1d b6 08 b8 ff ff p<......
4000 00 00 00 00 00 00 00 ........
4800 00 00 00 00 00 00 00 ........
5600 00 00 00 00 00 00 00 ........
642c 80 5c 00 43 3a 5c 55 ,.\.C:\U
7273 65 72 73 5c 4a 6f 68 sers\Joh
806e 5c 44 65 73 6b 74 6f n\Deskto
8870 5c 43 68 72 6f 6d 65 p\Chrome
9653 65 74 75 70 20 36 34 Setup 64
1042d 62 69 74 2e 65 78 65 -bit.exe
112d8 01 ..

Call Stack stacksize=37

StackAddressmodModNameModPath
0xfffff80434e8608c172FLTMGR.SYS + 0x608cC:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff80434e85b37172FLTMGR.SYS + 0x5b37C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff80434e84b46172FLTMGR.SYS + 0x4b46C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff80434e848bb172FLTMGR.SYS + 0x48bbC:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff80437c52f55174ntoskrnl.exe + 0x252f55C:\WINDOWS\system32\ntoskrnl.exe
0xfffff80437fe3702174ntoskrnl.exe + 0x5e3702C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8043802c3ab174ntoskrnl.exe + 0x62c3abC:\WINDOWS\system32\ntoskrnl.exe
0xfffff80437fe10d9174ntoskrnl.exe + 0x5e10d9C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8043ddc142b312ahcache.sys + 0x142bC:\WINDOWS\system32\DRIVERS\ahcache.sys
0xfffff8043dde1821312ahcache.sys + 0x21821C:\WINDOWS\system32\DRIVERS\ahcache.sys
0xfffff8043dde4358312ahcache.sys + 0x24358C:\WINDOWS\system32\DRIVERS\ahcache.sys
0xfffff8043dde40d1312ahcache.sys + 0x240d1C:\WINDOWS\system32\DRIVERS\ahcache.sys
0xfffff80437c52f55174ntoskrnl.exe + 0x252f55C:\WINDOWS\system32\ntoskrnl.exe
0xfffff80437fdb320174ntoskrnl.exe + 0x5db320C:\WINDOWS\system32\ntoskrnl.exe
0xfffff80437e077b5174ntoskrnl.exe + 0x4077b5C:\WINDOWS\system32\ntoskrnl.exe
0x7ffc927ed6a477ntdll.dll + 0x9d6a4C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffc7cc922ff754pcasvc.dll + 0x122ffc:\windows\system32\pcasvc.dll
0x7ffc7cc923c2754pcasvc.dll + 0x123c2c:\windows\system32\pcasvc.dll
0x7ffc7cccd8d7754pcasvc.dll + 0x4d8d7c:\windows\system32\pcasvc.dll
0x7ffc7cc872c5754pcasvc.dll + 0x72c5c:\windows\system32\pcasvc.dll
0x7ffc7cc85f7c754pcasvc.dll + 0x5f7cc:\windows\system32\pcasvc.dll
0x7ffc7cc85e16754pcasvc.dll + 0x5e16c:\windows\system32\pcasvc.dll
0x7ffc9154a0e361RPCRT4.dll + 0x7a0e3C:\WINDOWS\System32\RPCRT4.dll
0x7ffc915b21cb61RPCRT4.dll + 0xe21cbC:\WINDOWS\System32\RPCRT4.dll
0x7ffc9152cd6c61RPCRT4.dll + 0x5cd6cC:\WINDOWS\System32\RPCRT4.dll
0x7ffc9152783861RPCRT4.dll + 0x57838C:\WINDOWS\System32\RPCRT4.dll
0x7ffc91509e0661RPCRT4.dll + 0x39e06C:\WINDOWS\System32\RPCRT4.dll
0x7ffc91509a3661RPCRT4.dll + 0x39a36C:\WINDOWS\System32\RPCRT4.dll
0x7ffc91517dbf61RPCRT4.dll + 0x47dbfC:\WINDOWS\System32\RPCRT4.dll
0x7ffc9151737861RPCRT4.dll + 0x47378C:\WINDOWS\System32\RPCRT4.dll
0x7ffc9151696161RPCRT4.dll + 0x46961C:\WINDOWS\System32\RPCRT4.dll
0x7ffc915163ce61RPCRT4.dll + 0x463ceC:\WINDOWS\System32\RPCRT4.dll
0x7ffc9151a9d261RPCRT4.dll + 0x4a9d2C:\WINDOWS\System32\RPCRT4.dll
0x7ffc9277033077ntdll.dll + 0x20330C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffc927a2f2677ntdll.dll + 0x52f26C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffc91c1703470KERNEL32.DLL + 0x17034C:\WINDOWS\System32\KERNEL32.DLL
0x7ffc927a265177ntdll.dll + 0x52651C:\WINDOWS\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.