viewer9 documentation

RegSetKeySecurity PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegSetKeySecurity opcode=2,16

ev=36604 modify=1

Time:2022-05-17 20:43:23.2181579
Duration:0.0000453
ResultCode:SUCCESS
Tid:312
Path:HKLM\BCD00000000\Description

evdata[0-29] file offset 11255448

01c 80 48 4b 4c 4d 5c 42 ..HKLM\B
843 44 30 30 30 30 30 30 CD000000
1630 30 5c 44 65 73 63 72 00\Descr
2469 70 74 69 6f 6e iption

Call Stack stacksize=20

StackAddressmodModNameModPath
0xfffff80002be347049ntoskrnl.exe + 0x3e0470C:\Windows\system32\ntoskrnl.exe
0xfffff80002b7e2f249ntoskrnl.exe + 0x37b2f2C:\Windows\system32\ntoskrnl.exe
0xfffff80002ac540649ntoskrnl.exe + 0x2c2406C:\Windows\system32\ntoskrnl.exe
0xfffff80002c6709a49ntoskrnl.exe + 0x46409aC:\Windows\system32\ntoskrnl.exe
0xfffff80002c7238049ntoskrnl.exe + 0x46f380C:\Windows\system32\ntoskrnl.exe
0xfffff80002cf130e49ntoskrnl.exe + 0x4ee30eC:\Windows\system32\ntoskrnl.exe
0xfffff80002cf146449ntoskrnl.exe + 0x4ee464C:\Windows\system32\ntoskrnl.exe
0xfffff80002cf15e149ntoskrnl.exe + 0x4ee5e1C:\Windows\system32\ntoskrnl.exe
0xfffff80002cf1da049ntoskrnl.exe + 0x4eeda0C:\Windows\system32\ntoskrnl.exe
0xfffff80002cf204b49ntoskrnl.exe + 0x4ef04bC:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0xfffff8000289a6c049ntoskrnl.exe + 0x976c0C:\Windows\system32\ntoskrnl.exe
0xfffff80002cf1f0f49ntoskrnl.exe + 0x4eef0fC:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x7708a54a4ntdll.dll + 0x6a54aC:\Windows\System32\ntdll.dll
0x4811e0ef0smss.exe + 0xe0efC:\Windows\System32\smss.exe
0x4811da410smss.exe + 0xda41C:\Windows\System32\smss.exe
0x481253860smss.exe + 0x15386C:\Windows\System32\smss.exe
0x48127d690smss.exe + 0x17d69C:\Windows\System32\smss.exe
0x770737354ntdll.dll + 0x53735C:\Windows\System32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.