Time Stamp |
Event Type |
Event Time |
Severity |
Host Name |
Action |
Test Mode |
Description |
API |
Encoded API Name |
Begin Time |
End Time |
Rule ID |
Rule Name |
Caller Process ID |
Caller Process Name |
Return Address |
Return Module |
Parameter |
Alert |
Send Snmp Trap |
User Name |
Domain Name |
Site Name |
Server Name |
Group Name |
Computer Name |
1/18/2010 9:52 |
Application Control Driver |
1/18/2010 9:49 |
Info |
DOOLEY-OP4A |
Continue |
0 |
Application and Device Control is ready |
System |
|
1/18/2010 9:49 |
1/18/2010 9:49 |
|
Built-in rule |
0 |
SysPlant |
0 |
SysPlant |
None |
0 |
0 |
None |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-OP4A |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/Symantec AntiVirus/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SymEvent/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SysPlant/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/Teefer2/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/WPS/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/WpsHelper/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/ccEvtMgr/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF |
My Company\STF_MSP\DR EDWARD DOOLEY\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/ccSetMgr/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/EraserUtilRebootDrv/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SmcService/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SNAC/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SnacNp/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF |
My Company\STF_MSP\ \Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SPBBCDrv/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\orkstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SRTSP/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SRTSPL/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF- |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |
1/18/2010 9:31 |
Application Control Rules |
1/18/2010 9:25 |
Minor |
DOOLEY-FD3 |
Block |
1 |
|
Registry Write |
|
1/18/2010 9:24 |
1/18/2010 9:24 |
|
Client services_Write Registry |
2008 |
C:/WINDOWS/system32/wbem/wmiprvse.exe |
0 |
No Module Name |
/REGISTRY/MACHINE/SYSTEM/CurrentControlSet/Services/SRTSPX/Performance |
0 |
0 |
NETWORK SERVICE |
Default |
STFCONSULTING MSP |
STF |
My Company\STF_MSP\\Workstations 32bit |
DOOLEY-FD3 |