Import table
advapi32.dll
OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceW, LookupPrivilegeValueW, PrivilegeCheck, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, RegOpenKeyA, RegQueryValueExA, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, QueryServiceStatus
kernel32.dll
GetCurrentProcessId, TlsGetValue, TerminateProcess, ExitThread, HeapUnlock, SetLastError, HeapWalk, HeapLock, GetProcessHeaps, GetModuleHandleW, InterlockedCompareExchange, VirtualQuery, LeaveCriticalSection, EnterCriticalSection, GetModuleHandleExW, InitializeCriticalSection, DeleteCriticalSection, ResumeThread, GetSystemInfo, MultiByteToWideChar, SetEvent, LoadLibraryW, IsBadReadPtr, GetCurrentThreadId, WaitForSingleObject, GetCurrentThread, WaitForMultipleObjects, CreateEventW, Sleep, SetFilePointer, CreateFileW, GetModuleFileNameA, CreateFileA, DuplicateHandle, VirtualAlloc, VirtualFree, InterlockedIncrement, InterlockedDecrement, DeviceIoControl, CreateThread, TlsAlloc, TlsSetValue, WriteFile, FlushFileBuffers, QueryPerformanceCounter, RaiseException, DebugBreak, DisableThreadLibraryCalls, GetModuleHandleA, GetLastError, LoadLibraryA, GetProcAddress, FreeLibrary, GetCurrentProcess, ReadProcessMemory, GetModuleFileNameW, SetStdHandle, WriteConsoleW, CloseHandle, GetStdHandle, DecodePointer, EncodePointer, RtlUnwind, HeapFree, HeapAlloc, GetCommandLineA, HeapReAlloc, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, TlsFree, LCMapStringW, GetStringTypeW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapSize, ExitProcess, HeapCreate, HeapDestroy, IsProcessorFeaturePresent, WideCharToMultiByte, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetTickCount, GetSystemTimeAsFileTime, GetConsoleCP, GetConsoleMode
rpcrt4.dll
UuidToStringA, RpcStringFreeA
Export table
BaseHostedKevlarPostHandler
BaseHostedKevlarPreHandler
Exp_ClientDll_Register
exp_DetachHandlers
Exp_GetAgentVersion
Exp_HookAddress
Exp_HookAddress_000
Exp_HookAPI
Finalize
GetUnStubInterface
HIDPreADMCOMConnect
HIDPreLsarLookupNames
HIDPreLsarLookupSids
HipArmorQueryV1GetReference
HipArmorQueryV1ReleaseReference
HookSwhDirective_PreSetWindowsHookEx
Initialize
RegPermDirective_PreNtSetSecurityObject
RpcAddApiToList