Import table
advapi32.dll
StartServiceW, UnregisterTraceGuids, TraceEvent, RegisterTraceGuidsW, ControlTraceW, StartTraceW, EnableTrace, ControlService, RegDeleteKeyW, RegSetValueExW, CreateServiceW, RegOpenKeyExW, RegCreateKeyExW, DeleteService, RegCloseKey, LookupPrivilegeValueW, AdjustTokenPrivileges, QueryServiceStatus, OpenSCManagerW, OpenServiceW, QueryServiceStatusEx, CloseServiceHandle, GetTraceEnableLevel, GetTraceLoggerHandle, OpenThreadToken, LookupAccountSidW, GetTokenInformation, OpenProcessToken, SetThreadToken
kernel32.dll
GetSystemDirectoryW, ExpandEnvironmentStringsW, CreateFileW, SetFilePointer, ReadFile, GetCurrentProcessId, InitializeCriticalSection, DeleteCriticalSection, TerminateThread, PostQueuedCompletionStatus, QueryDosDeviceW, CreateThread, CreateIoCompletionPort, Sleep, GetModuleFileNameW, CopyFileW, CreateProcessW, DeleteFileW, LeaveCriticalSection, EnterCriticalSection, DeviceIoControl, GetOverlappedResult, GetWindowsDirectoryW, FreeLibrary, LoadLibraryW, GetSystemWindowsDirectoryW, GetVersionExW, InterlockedDecrement, InterlockedCompareExchange, GetCurrentThreadId, GetQueuedCompletionStatus, GetModuleHandleA, GetVersionExA, CreateMutexA, ReleaseMutex, GetSystemTimeAsFileTime, InterlockedExchange, CreateSemaphoreA, ReleaseSemaphore, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, GetUserDefaultLangID, GetFileAttributesExW, OpenProcess, OpenThread, GetTickCount, WaitForMultipleObjects, GetLastError, GetCurrentProcess, GetSystemInfo, GetProcAddress, GetModuleHandleW, CreateWaitableTimerW, CancelWaitableTimer, SetWaitableTimer, WaitForSingleObject, SetEvent, CreateEventW, ResetEvent, CloseHandle, GetLocaleInfoW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, WriteFile, LoadLibraryA, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, WideCharToMultiByte, MultiByteToWideChar, InterlockedIncrement, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapFree, GetCommandLineA, HeapAlloc, GetProcessHeap, RtlUnwind, RaiseException, ExitThread, GetCPInfo, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, SetLastError, HeapSize, ExitProcess, GetStdHandle, GetModuleFileNameA, GetACP, GetOEMCP, IsValidCodePage, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter
ole32.dll
CoUninitialize, CoCreateGuid, CoInitializeEx
psapi.dll
EnumProcessModules, GetModuleFileNameExW
sbte.dll
SBCSScanFileTrace, SBCSScanRegistryTrace, SBCSQuarantineFile2W, SBCSAddUserKnownEntity, SBCSQueryThreatDataW
shell32.dll
SHGetFolderPathW
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
Export table
SBAPAddAllowedPid
SBAPAddBlockedPid
SBAPClearCache
SBAPGetAllAllowedPids
SBAPGetAllBlockedPids
SBAPGetCacheCount
SBAPGetMonitorAction
SBAPGetMonitorActive
SBAPIsAllowedPid
SBAPIsBlockedPid
SBAPIsETWRunning
SBAPIsStarted
SBAPRemoveAllAllowedPids
SBAPRemoveAllBlockedPids
SBAPRemoveAllowedPid
SBAPRemoveBlockedPid
SBAPSetExtensionList
SBAPSetLoggerCallback
SBAPSetMonitorAction
SBAPSetMonitorActive
SBAPSetNotifyCallback
SBAPSetPromptCallback
SBAPSetReportCallback
SBAPSetUserKnownEntityCallback
SBAPSimulateMessage
SBAPStart
SBAPStartETW
SBAPStop
SBAPStopETW
SBAPUninstallDriver