Import table
advapi32.dll
UnregisterTraceGuids, TraceEvent, ConvertStringSecurityDescriptorToSecurityDescriptorW, ControlTraceW, StartTraceW, EnableTrace, ControlService, RegDeleteKeyW, RegSetValueExW, CreateServiceW, RegOpenKeyExW, RegCreateKeyExW, DeleteService, RegCloseKey, LookupPrivilegeValueW, AdjustTokenPrivileges, QueryServiceStatus, OpenSCManagerW, OpenServiceW, StartServiceW, QueryServiceStatusEx, CloseServiceHandle, GetTraceEnableLevel, GetTraceLoggerHandle, LookupAccountSidW, GetTokenInformation, OpenProcessToken, OpenThreadToken, SetThreadToken, RegisterTraceGuidsW
kernel32.dll
OpenThread, OpenProcess, GetWindowsDirectoryW, GetSystemDirectoryW, ExpandEnvironmentStringsW, CreateFileW, SetFilePointer, ReadFile, GetFileAttributesExW, GetUserDefaultLangID, InitializeCriticalSection, Sleep, InterlockedCompareExchange, EnterCriticalSection, LeaveCriticalSection, GetCurrentProcessId, DeleteCriticalSection, TerminateThread, PostQueuedCompletionStatus, QueryDosDeviceW, CreateThread, CreateIoCompletionPort, GetModuleFileNameW, CopyFileW, CreateProcessW, DeleteFileW, CreateWaitableTimerW, DeviceIoControl, GetOverlappedResult, WriteFile, FreeLibrary, LoadLibraryW, GetSystemWindowsDirectoryW, GetVersionExW, InterlockedDecrement, GetQueuedCompletionStatus, MultiByteToWideChar, LocalAlloc, LocalFree, GetLongPathNameA, UnmapViewOfFile, InterlockedIncrement, MapViewOfFile, CreateFileMappingW, GetSystemTimeAsFileTime, TlsAlloc, TlsFree, TlsGetValue, OpenEventA, TlsSetValue, FlushFileBuffers, CancelWaitableTimer, SetWaitableTimer, GetTickCount, WaitForMultipleObjects, GetLastError, GetCurrentProcess, GetSystemInfo, GetProcAddress, GetModuleHandleW, HeapFree, GetProcessHeap, HeapAlloc, ResetEvent, GetCurrentThreadId, CreateEventW, CloseHandle, SetEvent, WaitForSingleObject, CreateEventA, GetEnvironmentStringsW, QueryPerformanceCounter, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, HeapReAlloc, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleW, ResumeThread, FreeEnvironmentStringsW, GetModuleFileNameA, GetStartupInfoW, GetFileType, InitializeCriticalSectionAndSpinCount, SetHandleCount, WideCharToMultiByte, InterlockedExchange, GetStringTypeW, GetCommandLineA, RtlUnwind, RaiseException, ExitThread, LCMapStringW, GetCPInfo, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, IsProcessorFeaturePresent, HeapSize, ExitProcess, GetStdHandle, GetLocaleInfoW, GetACP, GetOEMCP, IsValidCodePage, SetLastError, HeapCreate, HeapDestroy
ole32.dll
CoUninitialize, CoCreateGuid, CoInitializeEx
psapi.dll
GetModuleFileNameExW
sbte.dll
SBCSScanFileTrace, SBCSQueryThreatDataW, SBCSScanRegistryTrace, SBCSQuarantineFile2W, SBCSAddUserKnownEntity, SBCSRemoveFileCacheEntry
shell32.dll
SHGetFolderPathW
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
Export table
SBAPAddAllowedPid
SBAPAddBlockedPid
SBAPClearCache
SBAPGetAllAllowedPids
SBAPGetAllBlockedPids
SBAPGetCacheCount
SBAPGetMonitorAction
SBAPGetMonitorActive
SBAPIsAllowedPid
SBAPIsBlockedPid
SBAPIsETWRunning
SBAPIsStarted
SBAPRemoveAllAllowedPids
SBAPRemoveAllBlockedPids
SBAPRemoveAllowedPid
SBAPRemoveBlockedPid
SBAPSetExtensionList
SBAPSetLoggerCallback
SBAPSetMonitorAction
SBAPSetMonitorActive
SBAPSetNotifyCallback
SBAPSetPromptCallback
SBAPSetReportCallback
SBAPSetUserKnownEntityCallback
SBAPSimulateMessage
SBAPStart
SBAPStartETW
SBAPStartVolumeWatcher
SBAPStop
SBAPStopETW
SBAPStopVolumeWatcher
SBAPUninstallDriver