File tree Expand file tree Collapse file tree 1 file changed +48
-2
lines changed
src/PowerShell.Core.Instrumentation Expand file tree Collapse file tree 1 file changed +48
-2
lines changed Original file line number Diff line number Diff line change 21842184 value="0x6017"
21852185 version="1"
21862186 />
2187+ <event
2188+ channel="C_ANALYTIC"
2189+ keywords="AmsiState"
2190+ level="win:Verbose"
2191+ message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)"
2192+ opcode="Method"
2193+ symbol="AmsiState"
2194+ task="Amsi"
2195+ template="T_AmsiState"
2196+ value="0x4001"
2197+ version="1"
2198+ />
21872199 </events>
21882200 <channels>
21892201 <!--There are two channels defined for Windows PowerShell instrumentation
24072419 symbol="T_ISEOperation"
24082420 value="120"
24092421 />
2422+ <task
2423+ message="$(string.PS_PROVIDER.task.T_AmsiState.message)"
2424+ name="Amsi"
2425+ symbol="T_Amsi"
2426+ value="130"
2427+ />
24102428 </tasks>
24112429 <opcodes>
24122430 <opcode
25672585 name="PSWorkflow"
25682586 symbol="K_PSWORKFLOW"
25692587 />
2588+ <keyword
2589+ mask="0x400"
2590+ message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)"
2591+ name="AmsiState"
2592+ symbol="K_AmsiState"
2593+ />
25702594 </keywords>
25712595 <maps>
25722596 <!-- please keep in sync with SerializationMethod from
40244048 name="FileName"
40254049 />
40264050 </template>
4051+ <template tid="T_AmsiState">
4052+ <data
4053+ inType="win:UnicodeString"
4054+ name="Action"
4055+ />
4056+ <data
4057+ inType="win:UnicodeString"
4058+ name="AmsiContext"
4059+ />
4060+ </template>
40274061 </templates>
40284062 </provider>
40294063 </events>
49174951 id="PS_PROVIDER.event.E_O_M3PWorkflowExecutionStarted.message"
49184952 value="Workflow execution started. %n %t WorkflowId: %1 %n %t ManagedNodes: %2"
49194953 />
4954+ <string
4955+ id="PS_PROVIDER.event.E_A_AmsiState.message"
4956+ value="AmsiUtil state. %n %t state: %1 %n %t Context: %2"
4957+ />
49204958 <string
49214959 id="PS_PROVIDER.event.E_O_M3PEndpointRegistered.message"
49224960 value="A new PowerShell endpoint was registered. %n %t EndpointName: %1 %n %t EndpointType: %2 %n %t RegisteredBy: %3"
53855423 id="PS_PROVIDER.keyword.K_PSWORKFLOW.message"
53865424 value="PSWorkflow Hosting And Execution Layer"
53875425 />
5388- <string
5426+ <string
5427+ id="PS_PROVIDER.keyword.K_AmsiState.message"
5428+ value="Amsi state"
5429+ />
5430+ <string
53895431 id="PS_PROVIDER.keyword.K_SESSION.message"
53905432 value="All session layer"
53915433 />
55455587 id="PS_PROVIDER.task.T_ISEOperation.message"
55465588 value="PowerShell ISE Operation"
55475589 />
5548- <string
5590+ <string
5591+ id="PS_PROVIDER.task.T_AmsiState.message"
5592+ value="Amsi State"
5593+ />
5594+ <string
55495595 id="PS_PROVIDER.event.E_O_ISEExecuteScript.message"
55505596 value="Windows PowerShell ISE has started to run script file %1."
55515597 />
You can’t perform that action at this time.
0 commit comments