viewer9 documentation

SetSecurityFile PML Operation

SecInfo is bit flags.

Example from 64-bit PML

Hover over field values like Time, ResultCode, SecInfo, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

SetSecurityFile opcode=3,41

ev=76594 advop=IRP_MJ_SET_SECURITY modify=1

Time:2022-05-17 16:06:26.9793181
Path:C:\Users\johnk\AppData\Local\Google\Chrome\User Data\Default\Network\889df60f-0cc4-4b44-9232-b11f12817dbe.tmp
SecInfo:DACL, DACL Unprotected

evdata[0-180] file offset 44004575

000 f8 ff ff 7a 9b c8 77 ....z..w
800 00 00 00 01 00 00 00 ........
1604 00 00 20 00 00 00 00 ... ....
2460 cf e9 02 a0 f8 ff ff `.......
3200 00 00 00 00 00 00 00 ........
4000 00 00 00 00 00 00 00 ........
4800 00 00 00 00 00 00 00 ........
5600 00 00 00 00 00 00 00 ........
646d 80 00 00 43 3a 5c 55 m...C:\U
7273 65 72 73 5c 6a 6f 68 sers\joh
806e 6b 5c 41 70 70 44 61 nk\AppDa
8874 61 5c 4c 6f 63 61 6c ta\Local
965c 47 6f 6f 67 6c 65 5c \Google\
10443 68 72 6f 6d 65 5c 55 Chrome\U
11273 65 72 20 44 61 74 61 ser Data
1205c 44 65 66 61 75 6c 74 \Default
1285c 4e 65 74 77 6f 72 6b \Network
1365c 38 38 39 64 66 36 30 \889df60
14466 2d 30 63 63 34 2d 34 f-0cc4-4
15262 34 34 2d 39 32 33 32 b44-9232
1602d 62 31 31 66 31 32 38 -b11f128
16831 37 64 62 65 2e 74 6d
17670 fe 07 00 00 p....

Call Stack stacksize=28

0xfffff880011730f7194fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001173fc7194fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011726c7194fltmgr.sys + 0x16c7C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002b40d23161ntoskrnl.exe + 0x2f2d23C:\Windows\system32\ntoskrnl.exe
0xfffff80002b10406161ntoskrnl.exe + 0x2c2406C:\Windows\system32\ntoskrnl.exe
0xfffff80002cb209a161ntoskrnl.exe + 0x46409aC:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c8ae6a2ntdll.dll + 0x6ae6aC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7e413a43KERNELBASE.dll + 0x1413aC:\Windows\system32\KERNELBASE.dll
0x7fefb772a14146ntmarta.dll + 0x2a14C:\Windows\system32\ntmarta.dll
0x7fefb774466146ntmarta.dll + 0x4466C:\Windows\system32\ntmarta.dll
0x7fefb7747f0146ntmarta.dll + 0x47f0C:\Windows\system32\ntmarta.dll
0x7feff84afaf58ADVAPI32.dll + 0xafafC:\Windows\system32\ADVAPI32.dll
0x77a641d40kernel32.dll + 0x641d4C:\Windows\system32\kernel32.dll
0x77a948620kernel32.dll + 0x94862C:\Windows\system32\kernel32.dll
0x7fee5e950ab683chrome.dll + 0x7750abC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5e94e13683chrome.dll + 0x774e13C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5e94b27683chrome.dll + 0x774b27C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee7ccf8c1683chrome.dll + 0x25af8c1C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee621bf00683chrome.dll + 0xafbf00C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8bd8f60683chrome.dll + 0x34b8f60C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5a7b955683chrome.dll + 0x35b955C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee936f18b683chrome.dll + 0x3c4f18bC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee936dce0683chrome.dll + 0x3c4dce0C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5a7b6f8683chrome.dll + 0x35b6f8C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee60739d1683chrome.dll + 0x9539d1C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.