Elastic Windows Event Explorer


Publisher - Microsoft-Windows-WinINet

Event ID 101

Message:

Session handle %{HINTERNET} created: UserAgent=%{UserAgent}, AccessType=%{AccessType}, ProxyList=%{ProxyList}, ProxyBypassList=%{ProxyBypassList}, Flags=%{Flags}

Event Data:

# Name In Type
Out Type
1 HINTERNET win:Pointer win:HexInt64
2 _UserAgentLength win:UInt16 xs:unsignedShort
3 UserAgent win:AnsiString xs:string
4 _AccessTypeLength win:UInt16 xs:unsignedShort
5 AccessType win:AnsiString xs:string
6 _ProxyListLength win:UInt16 xs:unsignedShort
7 ProxyList win:AnsiString xs:string
8 _ProxyBypassListLength win:UInt16 xs:unsignedShort
9 ProxyBypassList win:AnsiString xs:string
10 Flags win:UInt32 win:HexInt32

Observed Windows Versions:

Version: 0

Fingerprint: K4NPW2GOIVS62