MacriumImageGuardian
16 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 3 | Blocked unauthorised process (processName) from deleting file (fileName). | Unknown | N |
| 4 | Blocked unauthorised process (processName) from renaming file (fileName). | Unknown | N |
| 5 | Blocked unauthorised process (processName) accessing file (fileName). | Unknown | N |
| 90 | MIG protection enabled | Unknown | N |
| 91 | MIG protection disabled | Unknown | N |
| 92 | MIG protection disabled until the next reboot | Unknown | N |
| 100 | Driver Loaded version. | Unknown | N |
| 200 | Driver Unloaded | Unknown | N |
| 320 | Blocked unauthorised process (processName) accessing file (fileName). | Unknown | N |
| 330 | User has enabled Image Guardian on volume (volumePath). | Unknown | N |
| 340 | User has disabled Image Guardian on volume (volumePath). | Unknown | N |
| 510 | Error protecting volume (volumePath). | Unknown | N |
| 520 | Error unprotecting volume (volumePath). | Unknown | N |
| 600 | Attribute error sourceFile sourceLine. | Unknown | N |
| 601 | A cryptographic function failed with status status. | Unknown | N |
| 602 | Blocked Operation Stack Trace:stackBackTrace. | Unknown | N |
Event ID 3: Blocked unauthorised process (processName) from deleting file (fileName).
#Event ID 4: Blocked unauthorised process (processName) from renaming file (fileName).
#Event ID 5: Blocked unauthorised process (processName) accessing file (fileName).
#Event ID 92: MIG protection disabled until the next reboot
#Description
MIG protection disabled until the next reboot.
Message #
Event ID 100: Driver Loaded version.
#Event ID 320: Blocked unauthorised process (processName) accessing file (fileName).
#Event ID 330: User has enabled Image Guardian on volume (volumePath).
#Event ID 340: User has disabled Image Guardian on volume (volumePath).
#Event ID 510: Error protecting volume (volumePath).
#Event ID 520: Error unprotecting volume (volumePath).
#Event ID 600: Attribute error sourceFile sourceLine.
#Event ID 601: A cryptographic function failed with status status.
#Description
A cryptographic function failed with status status.
Message #
Fields #
| Name | Description |
|---|---|
status UInt32 | NTSTATUS reference |
sourceFile AnsiString | |
sourceLine UInt32 |