Created
July 9, 2016 15:07
-
-
Save mgeeky/505be4959e91ea133418dc2baa3a4064 to your computer and use it in GitHub Desktop.
API Filters list for Rohitab API Monitor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<?xml version="1.0"?> | |
<!-- | |
API Monitor Filter | |
(c) 2010-2013, Rohitab Batra <[email protected]> | |
http://www.rohitab.com/apimonitor/ | |
--> | |
<ApiMonitor> | |
<CaptureFilter> | |
<Module Name="Advapi32.dll"> | |
<Api Name="ControlService"/> | |
<Api Name="ControlServiceExA"/> | |
<Api Name="ControlServiceExW"/> | |
<Api Name="CreateProcessAsUserA"/> | |
<Api Name="CreateProcessAsUserW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CreateProcessWithLogonW"/> | |
<Api Name="CreateProcessWithTokenW"/> | |
<Api Name="CreateServiceA"/> | |
<Api Name="CreateServiceW"/> | |
<Api Name="DeleteService"/> | |
<Api Name="OpenSCManagerA"/> | |
<Api Name="OpenSCManagerW"/> | |
<Api Name="OpenServiceA"/> | |
<Api Name="OpenServiceW"/> | |
<Api Name="RegDeleteKeyA"/> | |
<Api Name="RegDeleteKeyExW"/> | |
<Api Name="RegOpenKeyExA"/> | |
<Api Name="RegOpenKeyExW"/> | |
<Api Name="RegQueryValueExA"/> | |
<Api Name="RegQueryValueExW"/> | |
<Api Name="RegSetValueExA"/> | |
<Api Name="RegSetValueExW"/> | |
<Api Name="StartServiceA"/> | |
<Api Name="StartServiceW"/> | |
</Module> | |
<Module Name="Kernel32.dll"> | |
<Api Name="CheckRemoteDebuggerPresent"/> | |
<Api Name="CopyFileA"/> | |
<Api Name="CopyFileExA"/> | |
<Api Name="CopyFileExW"/> | |
<Api Name="CopyFileW"/> | |
<Api Name="CreateFileW"/> | |
<Api Name="CreateProcessA"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CreateProcessW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CreateRemoteThread"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CreateRemoteThreadEx"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CreateToolhelp32Snapshot"/> | |
<Api Name="DeleteFileA"/> | |
<Api Name="DeleteFileW"/> | |
<Api Name="DeviceIoControl"/> | |
<Api Name="FindFirstFileA"/> | |
<Api Name="FindFirstFileExA"/> | |
<Api Name="FindFirstFileExW"/> | |
<Api Name="FindFirstFileW"/> | |
<Api Name="FindNextFileA"/> | |
<Api Name="FindNextFileW"/> | |
<Api Name="FindResourceA"/> | |
<Api Name="FindResourceW"/> | |
<Api Name="GetThreadContext"/> | |
<Api Name="IsDebuggerPresent"/> | |
<Api Name="LoadResource"/> | |
<Api Name="Module32First"/> | |
<Api Name="Module32FirstW"/> | |
<Api Name="Module32Next"/> | |
<Api Name="Module32NextW"/> | |
<Api Name="MoveFileA"/> | |
<Api Name="MoveFileExA"/> | |
<Api Name="MoveFileExW"/> | |
<Api Name="OpenProcess"/> | |
<Api Name="OutputDebugStringW"/> | |
<Api Name="Process32First"/> | |
<Api Name="Process32FirstW"/> | |
<Api Name="Process32Next"/> | |
<Api Name="Process32NextW"/> | |
<Api Name="ReadFile"/> | |
<Api Name="ReadFileEx"/> | |
<Api Name="ReadProcessMemory"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="SetThreadContext"/> | |
<Api Name="VirtualAllocEx"/> | |
<Api Name="WinExec"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="Wow64GetThreadContext"/> | |
<Api Name="Wow64GetThreadSelectorEntry"/> | |
<Api Name="Wow64SetThreadContext"/> | |
<Api Name="WriteFile"/> | |
<Api Name="WriteFileEx"/> | |
<Api Name="WriteProcessMemory"> | |
<Breakpoint Before="True"/> | |
</Api> | |
</Module> | |
<Module Name="Ntdll.dll"> | |
<Api Name="LdrLoadDll"/> | |
<Api Name="NtOpenFile"/> | |
<Api Name="NtQueryDirectoryFile"/> | |
<Api Name="NtQuerySystemInformation"/> | |
<Api Name="NtQueryVirtualMemory"/> | |
<Api Name="NtReadFile"/> | |
<Api Name="NtReadVirtualMemory"/> | |
<Api Name="NtSetSystemInformation"/> | |
<Api Name="NtWriteFile"/> | |
<Api Name="NtWriteVirtualMemory"/> | |
</Module> | |
<Module Name="Ole32.dll"> | |
<Api Name="CoCreateInstance"/> | |
<Api Name="CoCreateInstanceEx"/> | |
<Api Name="OleInitialize"/> | |
</Module> | |
<Module Name="Psapi.dll"> | |
<Api Name="EnumProcesses"/> | |
</Module> | |
<Module Name="Shell32.dll"> | |
<Api Name="ShellExecuteA"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="ShellExecuteExA"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="ShellExecuteExW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="ShellExecuteW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
</Module> | |
<Module Name="urlmon.dll"> | |
<Api Name="URLDownloadToCacheFileA"/> | |
<Api Name="URLDownloadToCacheFileW"/> | |
<Api Name="URLDownloadToFileA"/> | |
<Api Name="URLDownloadToFileW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
</Module> | |
<Module Name="User32.dll"> | |
<Api Name="AttachThreadInput"/> | |
<Api Name="BlockInput"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="CallNextHookEx"/> | |
<Api Name="GetAsyncKeyState"/> | |
<Api Name="GetKeyState"/> | |
<Api Name="GetKeyboardState"/> | |
<Api Name="SetWindowsHookExA"> | |
<Breakpoint Before="True"/> | |
</Api> | |
<Api Name="SetWindowsHookExW"> | |
<Breakpoint Before="True"/> | |
</Api> | |
</Module> | |
<Module Name="Wininet.dll"> | |
<Api Name="AppCacheCheckManifest"/> | |
<Api Name="AppCacheCloseHandle"/> | |
<Api Name="AppCacheDeleteGroup"/> | |
<Api Name="AppCacheDeleteIEGroup"/> | |
<Api Name="AppCacheDuplicateHandle"/> | |
<Api Name="AppCacheFinalize"/> | |
<Api Name="AppCacheFreeDownloadList"/> | |
<Api Name="AppCacheFreeGroupList"/> | |
<Api Name="AppCacheFreeIESpace"/> | |
<Api Name="AppCacheGetDownloadList"/> | |
<Api Name="AppCacheGetFallbackUrl"/> | |
<Api Name="AppCacheGetGroupList"/> | |
<Api Name="AppCacheGetIEGroupList"/> | |
<Api Name="AppCacheGetInfo"/> | |
<Api Name="AppCacheGetManifestUrl"/> | |
<Api Name="AppCacheLookup"/> | |
<Api Name="CommitUrlCacheEntryA"/> | |
<Api Name="CommitUrlCacheEntryBinaryBlob"/> | |
<Api Name="CommitUrlCacheEntryW"/> | |
<Api Name="CreateMD5SSOHash"/> | |
<Api Name="CreateUrlCacheContainerA"/> | |
<Api Name="CreateUrlCacheContainerW"/> | |
<Api Name="CreateUrlCacheEntryA"/> | |
<Api Name="CreateUrlCacheEntryExW"/> | |
<Api Name="CreateUrlCacheEntryW"/> | |
<Api Name="CreateUrlCacheGroup"/> | |
<Api Name="DeleteIE3Cache"/> | |
<Api Name="DeleteUrlCacheContainerA"/> | |
<Api Name="DeleteUrlCacheContainerW"/> | |
<Api Name="DeleteUrlCacheEntry"/> | |
<Api Name="DeleteUrlCacheEntryA"/> | |
<Api Name="DeleteUrlCacheEntryW"/> | |
<Api Name="DeleteUrlCacheGroup"/> | |
<Api Name="DeleteWpadCacheForNetworks"/> | |
<Api Name="DetectAutoProxyUrl"/> | |
<Api Name="DoConnectoidsExist"/> | |
<Api Name="ExportCookieFileA"/> | |
<Api Name="ExportCookieFileW"/> | |
<Api Name="FindCloseUrlCache"/> | |
<Api Name="FindFirstUrlCacheContainerA"/> | |
<Api Name="FindFirstUrlCacheContainerW"/> | |
<Api Name="FindFirstUrlCacheEntryA"/> | |
<Api Name="FindFirstUrlCacheEntryExA"/> | |
<Api Name="FindFirstUrlCacheEntryExW"/> | |
<Api Name="FindFirstUrlCacheEntryW"/> | |
<Api Name="FindFirstUrlCacheGroup"/> | |
<Api Name="FindNextUrlCacheContainerA"/> | |
<Api Name="FindNextUrlCacheContainerW"/> | |
<Api Name="FindNextUrlCacheEntryA"/> | |
<Api Name="FindNextUrlCacheEntryExA"/> | |
<Api Name="FindNextUrlCacheEntryExW"/> | |
<Api Name="FindNextUrlCacheEntryW"/> | |
<Api Name="FindNextUrlCacheGroup"/> | |
<Api Name="FindP3PPolicySymbol"/> | |
<Api Name="FreeP3PObject"/> | |
<Api Name="FreeUrlCacheSpaceA"/> | |
<Api Name="FreeUrlCacheSpaceW"/> | |
<Api Name="FtpCommandA"/> | |
<Api Name="FtpCommandW"/> | |
<Api Name="FtpCreateDirectoryA"/> | |
<Api Name="FtpCreateDirectoryW"/> | |
<Api Name="FtpDeleteFileA"/> | |
<Api Name="FtpDeleteFileW"/> | |
<Api Name="FtpFindFirstFileA"/> | |
<Api Name="FtpFindFirstFileW"/> | |
<Api Name="FtpGetCurrentDirectoryA"/> | |
<Api Name="FtpGetCurrentDirectoryW"/> | |
<Api Name="FtpGetFileA"/> | |
<Api Name="FtpGetFileEx"/> | |
<Api Name="FtpGetFileSize"/> | |
<Api Name="FtpGetFileW"/> | |
<Api Name="FtpOpenFileA"/> | |
<Api Name="FtpOpenFileW"/> | |
<Api Name="FtpPutFileA"/> | |
<Api Name="FtpPutFileEx"/> | |
<Api Name="FtpPutFileW"/> | |
<Api Name="FtpRemoveDirectoryA"/> | |
<Api Name="FtpRemoveDirectoryW"/> | |
<Api Name="FtpRenameFileA"/> | |
<Api Name="FtpRenameFileW"/> | |
<Api Name="FtpSetCurrentDirectoryA"/> | |
<Api Name="FtpSetCurrentDirectoryW"/> | |
<Api Name="GetDiskInfoA"/> | |
<Api Name="GetP3PPolicy"/> | |
<Api Name="GetP3PRequestStatus"/> | |
<Api Name="GetUrlCacheConfigInfoA"/> | |
<Api Name="GetUrlCacheConfigInfoW"/> | |
<Api Name="GetUrlCacheContainerInfoA"/> | |
<Api Name="GetUrlCacheContainerInfoW"/> | |
<Api Name="GetUrlCacheEntryBinaryBlob"/> | |
<Api Name="GetUrlCacheEntryInfoA"/> | |
<Api Name="GetUrlCacheEntryInfoExA"/> | |
<Api Name="GetUrlCacheEntryInfoExW"/> | |
<Api Name="GetUrlCacheEntryInfoW"/> | |
<Api Name="GetUrlCacheGroupAttributeA"/> | |
<Api Name="GetUrlCacheGroupAttributeW"/> | |
<Api Name="GetUrlCacheHeaderData"/> | |
<Api Name="GopherCreateLocatorA"/> | |
<Api Name="GopherCreateLocatorW"/> | |
<Api Name="GopherFindFirstFileA"/> | |
<Api Name="GopherFindFirstFileW"/> | |
<Api Name="GopherGetAttributeA"/> | |
<Api Name="GopherGetAttributeW"/> | |
<Api Name="GopherGetLocatorTypeA"/> | |
<Api Name="GopherGetLocatorTypeW"/> | |
<Api Name="GopherOpenFileA"/> | |
<Api Name="GopherOpenFileW"/> | |
<Api Name="HttpAddRequestHeadersA"/> | |
<Api Name="HttpAddRequestHeadersW"/> | |
<Api Name="HttpCheckDavCompliance"/> | |
<Api Name="HttpCheckDavComplianceA"/> | |
<Api Name="HttpCheckDavComplianceW"/> | |
<Api Name="HttpCloseDependencyHandle"/> | |
<Api Name="HttpDuplicateDependencyHandle"/> | |
<Api Name="HttpEndRequestA"/> | |
<Api Name="HttpEndRequestW"/> | |
<Api Name="HttpOpenDependencyHandle"/> | |
<Api Name="HttpOpenRequestA"/> | |
<Api Name="HttpOpenRequestW"/> | |
<Api Name="HttpPushClose"/> | |
<Api Name="HttpPushEnable"/> | |
<Api Name="HttpPushWait"/> | |
<Api Name="HttpQueryInfoA"/> | |
<Api Name="HttpQueryInfoW"/> | |
<Api Name="HttpSendRequestA"/> | |
<Api Name="HttpSendRequestExA"/> | |
<Api Name="HttpSendRequestExW"/> | |
<Api Name="HttpSendRequestW"/> | |
<Api Name="ImportCookieFileA"/> | |
<Api Name="ImportCookieFileW"/> | |
<Api Name="IncrementUrlCacheHeaderData"/> | |
<Api Name="InternalInternetGetCookie"/> | |
<Api Name="InternetAlgIdToStringA"/> | |
<Api Name="InternetAlgIdToStringW"/> | |
<Api Name="InternetAttemptConnect"/> | |
<Api Name="InternetAutodial"/> | |
<Api Name="InternetAutodialHangup"/> | |
<Api Name="InternetCanonicalizeUrlA"/> | |
<Api Name="InternetCanonicalizeUrlW"/> | |
<Api Name="InternetCheckConnectionA"/> | |
<Api Name="InternetCheckConnectionW"/> | |
<Api Name="InternetCloseHandle"/> | |
<Api Name="InternetCombineUrlA"/> | |
<Api Name="InternetCombineUrlW"/> | |
<Api Name="InternetConfirmZoneCrossing"/> | |
<Api Name="InternetConfirmZoneCrossingA"/> | |
<Api Name="InternetConfirmZoneCrossingW"/> | |
<Api Name="InternetConnectA"/> | |
<Api Name="InternetConnectW"/> | |
<Api Name="InternetCrackUrlA"/> | |
<Api Name="InternetCrackUrlW"/> | |
<Api Name="InternetCreateUrlA"/> | |
<Api Name="InternetCreateUrlW"/> | |
<Api Name="InternetDebugGetLocalTime"/> | |
<Api Name="InternetDial"/> | |
<Api Name="InternetDialA"/> | |
<Api Name="InternetDialW"/> | |
<Api Name="InternetErrorDlg"/> | |
<Api Name="InternetFindNextFileA"/> | |
<Api Name="InternetFindNextFileW"/> | |
<Api Name="InternetFortezzaCommand"/> | |
<Api Name="InternetFreeProxyInfoList"/> | |
<Api Name="InternetGetCertByURL"/> | |
<Api Name="InternetGetCertByURLA"/> | |
<Api Name="InternetGetConnectedState"/> | |
<Api Name="InternetGetConnectedStateEx"/> | |
<Api Name="InternetGetConnectedStateExA"/> | |
<Api Name="InternetGetConnectedStateExW"/> | |
<Api Name="InternetGetCookieA"/> | |
<Api Name="InternetGetCookieExA"/> | |
<Api Name="InternetGetCookieExW"/> | |
<Api Name="InternetGetCookieW"/> | |
<Api Name="InternetGetDialBrandingW"/> | |
<Api Name="InternetGetDialEngineW"/> | |
<Api Name="InternetGetLastResponseInfoA"/> | |
<Api Name="InternetGetLastResponseInfoW"/> | |
<Api Name="InternetGetProxyForUrl"/> | |
<Api Name="InternetGetSecurityInfoByURL"/> | |
<Api Name="InternetGetSecurityInfoByURLA"/> | |
<Api Name="InternetGetSecurityInfoByURLW"/> | |
<Api Name="InternetGoOnline"/> | |
<Api Name="InternetGoOnlineA"/> | |
<Api Name="InternetGoOnlineW"/> | |
<Api Name="InternetHangUp"/> | |
<Api Name="InternetLockRequestFile"/> | |
<Api Name="InternetOpenA"/> | |
<Api Name="InternetOpenUrlA"/> | |
<Api Name="InternetOpenUrlW"/> | |
<Api Name="InternetOpenW"/> | |
<Api Name="InternetQueryDataAvailable"/> | |
<Api Name="InternetQueryFortezzaStatus"/> | |
<Api Name="InternetQueryOptionA"/> | |
<Api Name="InternetQueryOptionW"/> | |
<Api Name="InternetReadFile"/> | |
<Api Name="InternetReadFileExA"/> | |
<Api Name="InternetReadFileExW"/> | |
<Api Name="InternetSecurityProtocolToStringA"/> | |
<Api Name="InternetSecurityProtocolToStringW"/> | |
<Api Name="InternetSetCookieA"/> | |
<Api Name="InternetSetCookieExA"/> | |
<Api Name="InternetSetCookieExW"/> | |
<Api Name="InternetSetCookieW"/> | |
<Api Name="InternetSetDialState"/> | |
<Api Name="InternetSetDialStateA"/> | |
<Api Name="InternetSetDialStateW"/> | |
<Api Name="InternetSetFilePointer"/> | |
<Api Name="InternetSetOptionA"/> | |
<Api Name="InternetSetOptionExA"/> | |
<Api Name="InternetSetOptionExW"/> | |
<Api Name="InternetSetOptionW"/> | |
<Api Name="InternetSetStatusCallback"/> | |
<Api Name="InternetSetStatusCallbackA"/> | |
<Api Name="InternetSetStatusCallbackW"/> | |
<Api Name="InternetShowSecurityInfoByURL"/> | |
<Api Name="InternetShowSecurityInfoByURLA"/> | |
<Api Name="InternetShowSecurityInfoByURLW"/> | |
<Api Name="InternetTimeFromSystemTime"/> | |
<Api Name="InternetTimeFromSystemTimeA"/> | |
<Api Name="InternetTimeFromSystemTimeW"/> | |
<Api Name="InternetTimeToSystemTime"/> | |
<Api Name="InternetTimeToSystemTimeA"/> | |
<Api Name="InternetTimeToSystemTimeW"/> | |
<Api Name="InternetUnlockRequestFile"/> | |
<Api Name="InternetWriteFile"/> | |
<Api Name="InternetWriteFileExA"/> | |
<Api Name="InternetWriteFileExW"/> | |
<Api Name="IsDomainLegalCookieDomainA"/> | |
<Api Name="IsDomainLegalCookieDomainW"/> | |
<Api Name="IsHostInProxyBypassList"/> | |
<Api Name="IsProfilesEnabled"/> | |
<Api Name="IsUrlCacheEntryExpiredA"/> | |
<Api Name="IsUrlCacheEntryExpiredW"/> | |
<Api Name="LoadUrlCacheContent"/> | |
<Api Name="MapResourceToPolicy"/> | |
<Api Name="ParseX509EncodedCertificateForListBoxEntry"/> | |
<Api Name="PerformOperationOverUrlCacheA"/> | |
<Api Name="ReadGuidsForConnectedNetworks"/> | |
<Api Name="ReadUrlCacheEntryStream"/> | |
<Api Name="ReadUrlCacheEntryStreamEx"/> | |
<Api Name="RegisterUrlCacheNotification"/> | |
<Api Name="ResumeSuspendedDownload"/> | |
<Api Name="RetrieveUrlCacheEntryFileA"/> | |
<Api Name="RetrieveUrlCacheEntryFileW"/> | |
<Api Name="RetrieveUrlCacheEntryStreamA"/> | |
<Api Name="RetrieveUrlCacheEntryStreamW"/> | |
<Api Name="RunOnceUrlCache"/> | |
<Api Name="SetUrlCacheConfigInfoA"/> | |
<Api Name="SetUrlCacheConfigInfoW"/> | |
<Api Name="SetUrlCacheEntryGroup"/> | |
<Api Name="SetUrlCacheEntryGroupA"/> | |
<Api Name="SetUrlCacheEntryGroupW"/> | |
<Api Name="SetUrlCacheEntryInfoA"/> | |
<Api Name="SetUrlCacheEntryInfoW"/> | |
<Api Name="SetUrlCacheGroupAttributeA"/> | |
<Api Name="SetUrlCacheGroupAttributeW"/> | |
<Api Name="SetUrlCacheHeaderData"/> | |
<Api Name="ShowClientAuthCerts"/> | |
<Api Name="ShowSecurityInfo"/> | |
<Api Name="ShowX509EncodedCertificate"/> | |
<Api Name="UnlockUrlCacheEntryFile"/> | |
<Api Name="UnlockUrlCacheEntryFileA"/> | |
<Api Name="UnlockUrlCacheEntryFileW"/> | |
<Api Name="UnlockUrlCacheEntryStream"/> | |
<Api Name="UpdateUrlCacheContentPath"/> | |
<Api Name="UrlCacheCheckEntriesExist"/> | |
<Api Name="UrlCacheCloseEntryHandle"/> | |
<Api Name="UrlCacheContainerSetEntryMaximumAge"/> | |
<Api Name="UrlCacheCreateContainer"/> | |
<Api Name="UrlCacheFreeEntryInfo"/> | |
<Api Name="UrlCacheGetContentPaths"/> | |
<Api Name="UrlCacheGetEntryInfo"/> | |
<Api Name="UrlCacheGetGlobalLimit"/> | |
<Api Name="UrlCacheReadEntryStream"/> | |
<Api Name="UrlCacheReloadSettings"/> | |
<Api Name="UrlCacheRetrieveEntryFile"/> | |
<Api Name="UrlCacheRetrieveEntryStream"/> | |
<Api Name="UrlCacheSetGlobalLimit"/> | |
<Api Name="UrlCacheUpdateEntryExtraData"/> | |
<Api Name="UrlZonesDetach"/> | |
<Api Name="_GetFileExtensionFromUrl"/> | |
</Module> | |
<Module Name="Ws2_32.dll"> | |
<Api Name="WSARecv"/> | |
<Api Name="WSASend"/> | |
<Api Name="WSASocketA"/> | |
<Api Name="WSAStartup"/> | |
<Api Name="accept"/> | |
<Api Name="bind"/> | |
<Api Name="connect"/> | |
<Api Name="getaddrinfo"/> | |
<Api Name="gethostbyaddr"/> | |
<Api Name="gethostbyname"/> | |
<Api Name="getprotobynumber"/> | |
<Api Name="getservbyname"/> | |
<Api Name="getservbyport"/> | |
<Api Name="getsockname"/> | |
<Api Name="listen"/> | |
<Api Name="recv"/> | |
<Api Name="send"/> | |
<Api Name="socket"/> | |
</Module> | |
</CaptureFilter> | |
</ApiMonitor> |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment