Team Ai
Datasetpublic

MegaBites-AI/Windows-powershell

sourceHugging Facemitupdated 6mo agoView on Hugging Face
0likes372downloads
PSETWTracer.cs278 linesDownload Raw Back to common
1// Copyright (c) Microsoft Corporation.2// Licensed under the MIT License.3 4using Dbg = System.Management.Automation.Diagnostics;5 6namespace System.Management.Automation.Internal7{8    /// <summary>9    /// Defines enumerations for the keywords.10    /// </summary>11    [Flags]12    internal enum PSKeyword : ulong13    {14        Runspace = 0x1,15        Pipeline = 0x2,16        Protocol = 0x4,17        Transport = 0x8,18        Host = 0x10,19        Cmdlets = 0x20,20        Serializer = 0x40,21        Session = 0x80,22        ManagedPlugin = 0x100,23        UseAlwaysOperational = 0x8000000000000000,24        UseAlwaysAnalytic = 0x4000000000000000,25    }26 27    /// <summary>28    /// Define enumerations for levels.29    /// </summary>30    internal enum PSLevel : byte31    {32        LogAlways = 0x0,33        Critical = 0x1,34        Error = 0x2,35        Warning = 0x3,36        Informational = 0x4,37        Verbose = 0x5,38        Debug = 0x1439    }40 41    /// <summary>42    /// Defines enumerations for op codes.43    /// </summary>44    internal enum PSOpcode : byte45    {46        WinStart = 0x1,47        WinStop = 0x2,48        Open = 0xA,49        Close = 0xB,50        Connect = 0xC,51        Disconnect = 0xD,52        Negotiate = 0xE,53        Create = 0xF,54        Constructor = 0x10,55        Dispose = 0x11,56        EventHandler = 0x12,57        Exception = 0x13,58        Method = 0x14,59        Send = 0x15,60        Receive = 0x16,61        Rehydration = 0x17,62        SerializationSettings = 0x18,63        ShuttingDown = 0x19,64    }65 66    /// <summary>67    /// Defines enumerations for event ids.68    /// </summary>69    /// <remarks>add an entry for a new event that you70    /// add to the manifest. Set it to the same value71    /// that was set in the manifest</remarks>72    internal enum PSEventId : int73    {74        HostNameResolve = 0x1001,75        SchemeResolve = 0x1002,76        ShellResolve = 0x1003,77        RunspaceConstructor = 0x2001,78        RunspacePoolConstructor = 0x2002,79        RunspacePoolOpen = 0x2003,80        OperationalTransferEventRunspacePool = 0x2004,81        RunspaceStateChange = 0x2005,82        RetrySessionCreation = 0x2006,83        Port = 0x2F01,84        AppName = 0x2F02,85        ComputerName = 0x2F03,86        Scheme = 0x2F04,87        TestAnalytic = 0x2F05,88        WSManConnectionInfoDump = 0x2F06,89        AnalyticTransferEventRunspacePool = 0x2F07,90 91        // Start: Transport related events92        TransportReceivedObject = 0x8001,93        TransportSendingData = 0x8002,94        TransportReceivedData = 0x8003,95        AppDomainUnhandledException_Analytic = 0x8007,96        TransportError_Analytic = 0x8008,97        AppDomainUnhandledException = 0x8009,98        TransportError = 0x8010,99        WSManCreateShell = 0x8011,100        WSManCreateShellCallbackReceived = 0x8012,101        WSManCloseShell = 0x8013,102        WSManCloseShellCallbackReceived = 0x8014,103        WSManSendShellInputEx = 0x8015,104        WSManSendShellInputExCallbackReceived = 0x8016,105        WSManReceiveShellOutputEx = 0x8017,106        WSManReceiveShellOutputExCallbackReceived = 0x8018,107        WSManCreateCommand = 0x8019,108        WSManCreateCommandCallbackReceived = 0x8020,109        WSManCloseCommand = 0x8021,110        WSManCloseCommandCallbackReceived = 0x8022,111        WSManSignal = 0x8023,112        WSManSignalCallbackReceived = 0x8024,113        URIRedirection = 0x8025,114        ServerSendData = 0x8051,115        ServerCreateRemoteSession = 0x8052,116        ReportContext = 0x8053,117        ReportOperationComplete = 0x8054,118        ServerCreateCommandSession = 0x8055,119        ServerStopCommand = 0x8056,120        ServerReceivedData = 0x8057,121        ServerClientReceiveRequest = 0x8058,122        ServerCloseOperation = 0x8059,123        LoadingPSCustomShellAssembly = 0x8061,124        LoadingPSCustomShellType = 0x8062,125        ReceivedRemotingFragment = 0x8063,126        SentRemotingFragment = 0x8064,127        WSManPluginShutdown = 0x8065,128        // End: Transport related events129 130        // Start: Serialization related events131        Serializer_RehydrationSuccess = 0x7001,132        Serializer_RehydrationFailure = 0x7002,133        Serializer_DepthOverride = 0x7003,134        Serializer_ModeOverride = 0x7004,135        Serializer_ScriptPropertyWithoutRunspace = 0x7005,136        Serializer_PropertyGetterFailed = 0x7006,137        Serializer_EnumerationFailed = 0x7007,138        Serializer_ToStringFailed = 0x7008,139        Serializer_MaxDepthWhenSerializing = 0x700A,140        Serializer_XmlExceptionWhenDeserializing = 0x700B,141        Serializer_SpecificPropertyMissing = 0x700C,142        // End: Serialization related events143 144        // Start: Perftrack related events145        Perftrack_ConsoleStartupStart = 0xA001,146        Perftrack_ConsoleStartupStop = 0xA002,147        // End: Preftrack related events148 149        Command_Health = 0x1004,150        Engine_Health = 0x1005,151        Provider_Health = 0x1006,152        Pipeline_Detail = 0x1007,153        ScriptBlock_Compile_Detail = 0x1008,154        ScriptBlock_Invoke_Start_Detail = 0x1009,155        ScriptBlock_Invoke_Complete_Detail = 0x100A,156        Command_Lifecycle = 0x1F01,157        Engine_Lifecycle = 0x1F02,158        Provider_Lifecycle = 0x1F03,159        Settings = 0x1F04,160        Engine_Trace = 0x1F06,161        Amsi_Init = 0x4001,162        WDAC_Query = 0x4002,163        WDAC_Audit = 0x4003,164 165        // Experimental Features166        ExperimentalFeature_InvalidName = 0x3001,167        ExperimentalFeature_ReadConfig_Error = 0x3002,168 169        // Scheduled Jobs170        ScheduledJob_Start = 0xD001,171        ScheduledJob_Complete = 0xD002,172        ScheduledJob_Error = 0xD003,173 174        // PowerShell IPC Named Pipe Connection175        NamedPipeIPC_ServerListenerStarted = 0xD100,176        NamedPipeIPC_ServerListenerEnded = 0xD101,177        NamedPipeIPC_ServerListenerError = 0xD102,178        NamedPipeIPC_ServerConnect = 0xD103,179        NamedPipeIPC_ServerDisconnect = 0xD104,180 181        // Start: ISE related events182        ISEExecuteScript = 0x6001,183        ISEExecuteSelection = 0x6002,184        ISEStopCommand = 0x6003,185        ISEResumeDebugger = 0x6004,186        ISEStopDebugger = 0x6005,187        ISEDebuggerStepInto = 0x6006,188        ISEDebuggerStepOver = 0x6007,189        ISEDebuggerStepOut = 0x6008,190        ISEEnableAllBreakpoints = 0x6010,191        ISEDisableAllBreakpoints = 0x6011,192        ISERemoveAllBreakpoints = 0x6012,193        ISESetBreakpoint = 0x6013,194        ISERemoveBreakpoint = 0x6014,195        ISEEnableBreakpoint = 0x6015,196        ISEDisableBreakpoint = 0x6016,197        ISEHitBreakpoint = 0x6017,198        // End: ISE related events199    }200 201    /// <summary>202    /// Defines enumerations for channels.203    /// </summary>204    /// <remarks>205    /// On Windows, PSChannel is the numeric channel id value.206    /// On Non-Windows, PSChannel is used to filter events and207    /// the underlying channel bitmask values are used instead.208    /// The bit values are the same as used on Windows.209    /// </remarks>210#if UNIX211    [Flags]212    internal enum PSChannel : byte213    {214        Operational = 0x80,215        Analytic = 0x40216    }217#else218    internal enum PSChannel : byte219    {220        Operational = 0x10,221        Analytic = 0x11222    }223#endif224 225    /// <summary>226    /// Defines enumerations for tasks.227    /// </summary>228    internal enum PSTask : int229    {230        None = 0x0,231        CreateRunspace = 0x1,232        ExecuteCommand = 0x2,233        Serialization = 0x3,234        PowershellConsoleStartup = 0x4,235        EngineStart = 0x64,236        EngineStop = 0x65,237        CommandStart = 0x66,238        CommandStop = 0x67,239        ProviderStart = 0x68,240        ProviderStop = 0x69,241        ExecutePipeline = 0x6A,242        ExperimentalFeature = 0x6B,243        ScheduledJob = 0x6E,244        NamedPipe = 0x6F,245        ISEOperation = 0x78,246        Amsi = 0X82,247        WDAC = 0x83,248        WDACAudit = 0x84249    }250 251    /// <summary>252    /// Defines enumerations for version.253    /// </summary>254    /// <remarks>all messages in V2 timeframe255    /// should be of version 1</remarks>256    internal enum PSEventVersion : byte257    {258        One = 0x1,259    }260 261    /// <summary>262    /// Describes a binary blob to be used as a data item for ETW.263    /// </summary>264    internal sealed class PSETWBinaryBlob265    {266        public PSETWBinaryBlob(byte[] blob, int offset, int length)267        {268            this.blob = blob;269            this.offset = offset;270            this.length = length;271        }272 273        public readonly byte[] blob;274        public readonly int offset;275        public readonly int length;276    }277}278