Min version78 Pre RTM
Max version7 SP110 TH2
x64 offset
offset:bitpos
Field Name
0x0000struct _PRIVILEGE_SET *
PrivilegesUsed
0x0008struct _GENERIC_MAPPING
GenericMapping
0x0018unsigned long
AccessesToAudit
0x001Cunsigned long
MaximumAuditMask
0x0020struct _GUID
TransactionId
0x0030void *
NewSecurityDescriptor
0x0038void *
ExistingSecurityDescriptor
0x0040void *
ParentSecurityDescriptor
0x0048function *
DeRefSecurityDescriptor
0x0050void *
SDLock
0x0058struct _ACCESS_REASONS
AccessReasons
0x00D8uint8_t
GenerateStagingEvents