Elastic Windows Event Explorer


Publisher - Microsoft-Antimalware-Scan-Interface

Event ID 1101

Message:

AmsiScanBuffer

Event Data:

# Name In Type
Out Type
1 session win:Pointer win:HexInt64
2 scanStatus win:UInt8 xs:unsignedByte
3 scanResult win:UInt32 xs:unsignedInt
4 appname win:UnicodeString xs:string
5 contentname win:UnicodeString xs:string
6 contentsize win:UInt32 xs:unsignedInt
7 originalsize win:UInt32 xs:unsignedInt
8 content win:Binary xs:hexBinary
9 hash win:Binary xs:hexBinary
10 contentFiltered win:Boolean xs:boolean

Observed Windows Versions:

Version: 0

Fingerprint: 4KIHV72DYPSEG