Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

 Windows 2000 SP4 >> ADVAPI32
AbortSystemShutdownA AbortSystemShutdownW
AccessCheck AccessCheckAndAuditAlarmA
AccessCheckAndAuditAlarmW AccessCheckByType
AccessCheckByTypeAndAuditAlarmA AccessCheckByTypeAndAuditAlarmW
AccessCheckByTypeResultList AccessCheckByTypeResultListAndAuditAlarmA
AccessCheckByTypeResultListAndAuditAlarmByHandleA AccessCheckByTypeResultListAndAuditAlarmByHandleW
AccessCheckByTypeResultListAndAuditAlarmW AddAccessAllowedAce
AddAccessAllowedAceEx AddAccessAllowedObjectAce
AddAccessDeniedAce AddAccessDeniedAceEx
AddAccessDeniedObjectAce AddAce
AddAuditAccessAce AddAuditAccessAceEx
AddAuditAccessObjectAce AdjustTokenGroups
AdjustTokenPrivileges AllocateAndInitializeSid
AllocateLocallyUniqueId AreAllAccessesGranted
AreAnyAccessesGranted BackupEventLogA
BackupEventLogW BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameW BuildSecurityDescriptorA
BuildSecurityDescriptorW ChangeServiceConfig2A
ChangeServiceConfig2W ChangeServiceConfigA
ChangeServiceConfigW CheckTokenMembership
ClearEventLogA ClearEventLogW
CloseEventLog CommandLineFromMsiDescriptor
ControlTraceA ControlTraceW
ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW
ConvertSDToStringSDRootDomainA ConvertSDToStringSDRootDomainW
ConvertSecurityDescriptorToStringSecurityDescriptorA ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertSidToStringSidA ConvertSidToStringSidW
ConvertStringSDToSDRootDomainA ConvertStringSDToSDRootDomainW
ConvertStringSecurityDescriptorToSecurityDescriptorA ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidA ConvertStringSidToSidW
ConvertToAutoInheritPrivateObjectSecurity CopySid
CreatePrivateObjectSecurity CreatePrivateObjectSecurityEx
CreateProcessAsUserA CreateProcessAsUserW
CreateProcessWithLogonW CreateRestrictedToken
CreateServiceA CreateServiceW
CreateTraceInstanceId CreateWellKnownSid
CryptAcquireContextA CryptAcquireContextW
CryptContextAddRef CryptDeriveKey
CryptDestroyHash CryptDestroyKey
CryptDuplicateHash CryptDuplicateKey
CryptEnumProvidersA CryptEnumProvidersW
CryptEnumProviderTypesA CryptEnumProviderTypesW
CryptGenKey CryptGetDefaultProviderA
CryptGetDefaultProviderW CryptGetUserKey
CryptReleaseContext CryptSetHashParam
CryptSetKeyParam CryptSetProviderA
CryptSetProviderExA CryptSetProviderExW
CryptSetProviderW CryptSetProvParam
CryptSignHashA CryptVerifySignatureA
DecryptFileA DecryptFileW
DeleteAce DeleteService
DeregisterEventSource DestroyPrivateObjectSecurity
DuplicateToken DuplicateTokenEx
ElfBackupEventLogFileA ElfBackupEventLogFileW
ElfOpenBackupEventLogA ElfOpenBackupEventLogW
ElfOpenEventLogA ElfOpenEventLogW
ElfReadEventLogA ElfReadEventLogW
ElfRegisterEventSourceA ElfRegisterEventSourceW
ElfReportEventA ElfReportEventW
EnableTrace EncryptFileA
EncryptFileW EnumDependentServicesA
EnumDependentServicesW EnumServicesStatusA
EnumServicesStatusExW EnumServicesStatusW
EqualDomainSid EqualPrefixSid
EqualSid FileEncryptionStatusA
FindFirstFreeAce FreeSid
GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW
GetAce GetAclInformation
GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW
GetCurrentHwProfileA GetCurrentHwProfileW
GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW
GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW
GetFileSecurityA GetFileSecurityW
GetKernelObjectSecurity GetLengthSid
GetLocalManagedApplications GetMangledSiteSid
GetNamedSecurityInfoA GetNamedSecurityInfoExA
GetNamedSecurityInfoExW GetNamedSecurityInfoW
GetNumberOfEventLogRecords GetOldestEventLogRecord
GetOverlappedAccessResults GetPrivateObjectSecurity
GetSecurityDescriptorControl GetSecurityDescriptorDacl
GetSecurityDescriptorGroup GetSecurityDescriptorLength
GetSecurityDescriptorOwner GetSecurityDescriptorRMControl
GetSecurityDescriptorSacl GetSecurityInfo
GetSecurityInfoExA GetSecurityInfoExW
GetServiceDisplayNameA GetServiceDisplayNameW
GetServiceKeyNameA GetServiceKeyNameW
GetSidIdentifierAuthority GetSidLengthRequired
GetSidSubAuthority GetSidSubAuthorityCount
GetSiteDirectoryA GetSiteDirectoryW
GetSiteNameFromSid GetSiteSidFromToken
GetSiteSidFromUrl GetTokenInformation
GetUserNameA GetWindowsAccountDomainSid
ImpersonateAnonymousToken ImpersonateLoggedOnUser
ImpersonateNamedPipeClient ImpersonateSelf
InitializeAcl InitializeSecurityDescriptor
InitializeSid InitiateSystemShutdownA
InitiateSystemShutdownExA InitiateSystemShutdownExW
InitiateSystemShutdownW InstallApplication
IsProcessRestricted IsTextUnicode
IsTokenRestricted IsValidAcl
IsValidSecurityDescriptor IsValidSid
IsWellKnownSid I_ScPnPGetServiceName
I_ScSetServiceBitsA LockServiceDatabase
LogonUserA LogonUserW
LookupAccountNameA LookupAccountSidA
LookupPrivilegeDisplayNameA LookupPrivilegeDisplayNameW
LookupPrivilegeNameA LookupPrivilegeNameW
LookupPrivilegeValueA LookupPrivilegeValueW
LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW
LsaCreateTrustedDomainEx LsaGetRemoteUserName
LsaLookupNames LsaLookupSids
LsaNtStatusToWinError LsaOpenPolicySce
LsaQuerySecret LsaQueryTrustedDomainInfo
LsaSetInformationPolicy LsaSetInformationTrustedDomain
LsaSetSecret LsaSetSecurityObject
LsaSetTrustedDomainInfoByName LsaSetTrustedDomainInformation
LsaStorePrivateData MakeAbsoluteSD
MakeAbsoluteSD2 MakeSelfRelativeSD
MapGenericMask NotifyChangeEventLog
ObjectCloseAuditAlarmA ObjectCloseAuditAlarmW
ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW
ObjectOpenAuditAlarmA ObjectOpenAuditAlarmW
ObjectPrivilegeAuditAlarmA ObjectPrivilegeAuditAlarmW
OpenBackupEventLogA OpenBackupEventLogW
OpenEncryptedFileRawA OpenEncryptedFileRawW
OpenEventLogA OpenEventLogW
OpenProcessToken OpenServiceW
OpenThreadToken PrivilegeCheck
PrivilegedServiceAuditAlarmA PrivilegedServiceAuditAlarmW
ProcessTrace QueryAllTracesA
QueryAllTracesW QueryServiceConfig2A
QueryServiceConfig2W QueryServiceConfigA
QueryServiceConfigW QueryServiceLockStatusA
QueryServiceObjectSecurity QueryServiceStatusEx
ReadEventLogA ReadEventLogW
RegConnectRegistryA RegCreateKeyA
RegCreateKeyExA RegCreateKeyExW
RegCreateKeyW RegDeleteKeyA
RegDeleteKeyW RegDeleteValueA
RegDeleteValueW RegDisablePredefinedCache
RegEnumKeyA RegEnumKeyExA
RegEnumKeyW RegEnumValueA
RegisterEventSourceA RegisterEventSourceW
RegisterServiceCtrlHandlerA RegisterServiceCtrlHandlerExA
RegisterTraceGuidsA RegisterTraceGuidsW
RegLoadKeyA RegLoadKeyW
RegNotifyChangeKeyValue RegOpenCurrentUser
RegOpenKeyA RegOpenKeyExA
RegOpenKeyExW RegOpenKeyW
RegOpenUserClassesRoot RegOverridePredefKey
RegQueryInfoKeyA RegQueryMultipleValuesA
RegQueryMultipleValuesW RegQueryValueA
RegQueryValueExA RegQueryValueExW
RegQueryValueW RegReplaceKeyA
RegReplaceKeyW RegRestoreKeyA
RegRestoreKeyW RegSaveKeyA
RegSaveKeyW RegSetKeySecurity
RegSetValueA RegSetValueExA
RegSetValueExW RegSetValueW
RegUnLoadKeyA RegUnLoadKeyW
RemoveTraceCallback ReportEventA
ReportEventW RevertToSelf
SetAclInformation SetEntriesInAclA
SetEntriesInAclW SetFileSecurityA
SetFileSecurityW SetKernelObjectSecurity
SetNamedSecurityInfoA SetNamedSecurityInfoExA
SetNamedSecurityInfoExW SetNamedSecurityInfoW
SetPrivateObjectSecurity SetPrivateObjectSecurityEx
SetSecurityDescriptorControl SetSecurityDescriptorDacl
SetSecurityDescriptorGroup SetSecurityDescriptorOwner
SetSecurityDescriptorRMControl SetSecurityDescriptorSacl
SetSecurityInfo SetSecurityInfoExA
SetSecurityInfoExW SetServiceBits
SetServiceObjectSecurity SetServiceStatus
SetThreadToken SetTokenInformation
SetTraceCallback start
StartServiceCtrlDispatcherA StartServiceCtrlDispatcherW
StartServiceW StartTraceA
StartTraceW SynchronizeWindows31FilesAndWindowsNTRegistry
SystemFunction006 SystemFunction007
SystemFunction008 SystemFunction009
SystemFunction010 SystemFunction011
SystemFunction012 SystemFunction013
SystemFunction016 SystemFunction017
SystemFunction018 SystemFunction019
SystemFunction020 SystemFunction021
SystemFunction022 SystemFunction023
SystemFunction024 SystemFunction025
SystemFunction026 SystemFunction027
SystemFunction028 SystemFunction029
SystemFunction031 SystemFunction034
SystemFunction035 SystemFunction040
SystemFunction041 TrusteeAccessToObjectA
TrusteeAccessToObjectW UnlockServiceDatabase
UnregisterTraceGuids WmiCloseBlock
WmiDevInstToInstanceNameA WmiDevInstToInstanceNameW
WmiEnumerateGuids WmiExecuteMethodA
WmiExecuteMethodW WmiFileHandleToInstanceNameA
WmiFileHandleToInstanceNameW WmiFreeBuffer
WmiMofEnumerateResourcesA WmiMofEnumerateResourcesW
WmiOpenBlock WmiQueryAllDataA
WmiQueryAllDataW WmiQueryGuidInformation
WmiQuerySingleInstanceA WmiQuerySingleInstanceW
WmiSetSingleInstanceA WmiSetSingleInstanceW
WmiSetSingleItemA WmiSetSingleItemW

There are 31,320 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit