????

Your IP : 18.224.184.62


Current Path : C:/Program Files/Windows Defender Advanced Threat Protection/en-US/
Upload File :
Current File : C:/Program Files/Windows Defender Advanced Threat Protection/en-US/MsSense.exe.mui

MZ����@���	�!�L�!This program cannot be run in DOS mode.

$9%=�}DS�}DS�}DS�j���|DS�j�Q�|DS�Rich}DS�PEL%W���!(�

���@ X�8.rdata�@@.rsrcX� �@@%W��
lPP%W��$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg @.rsrc$01@!�.rsrc$02 �>�F[I�٧Iמ!;�l�s�q��{#%W��0�0�H�`�x���?������	�			 ���е�@%��@!�MUI�4VS_VERSION_INFO��X"
�slX"
�sl?ZStringFileInfo6040904B0LCompanyNameMicrosoft Corporation�?FileDescriptionWindows Defender Advanced Threat Protection Service Executablet*FileVersion10.8792.27763.1022 (WinBuild.160101.0800)8InternalNameMsSense.exe�.LegalCopyright� Microsoft Corporation. All rights reserved.HOriginalFilenameMsSense.exe.muij%ProductNameMicrosoft� Windows� Operating SystemJProductVersion10.8792.27763.1022DVarFileInfo$Translation	�
00�PP�����h�!��
#�9�h;���H-3�5�]�����_�����j����8l����8o�3��pInfo

Error

Warning

 Information

Verbose

LService is starting (Version %1).

<Service is shutting down.

�Windows Defender Advanced Threat Protection service failed to start. Failure code: %1

pContacted server %1 times, all succeeded, URI: %2.

�Contacted server %1 times, all failed, URI: %2. Last HTTP error code: %3

�Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found.

�Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: %1

hService failed to clean configuration settings.

�Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: %1

�Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: %1

�Onboarding or re-onboarding of Windows Defender Advanced Threat Protection service completed.

TNew cloud configuration failed to apply, version: %1. Also failed to apply last known good configuration, version %2. Also failed to apply the default configuration.

�Windows Defender Advanced Threat Protection machine ID calculated: %1

�Windows Defender Advanced Threat Protection cannot calculate machine ID. Failure code: %1

�Windows Defender Advanced Threat Protection cannot start command channel with URL: %1

4Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: %1

TOOBE (Windows Welcome) is completed.

dOOBE (Windows Welcome) has not yet completed.

�Cannot wait for OOBE (Windows Welcome) to complete. Failure code: %1

�Service failed to reset health status in the registry. Failure code: %1

�Windows Defender Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: %1

Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: %1

PConnected User Experiences and Telemetry service registration failed with failure code: %1. Requested disk quota in MB: %2, Requested daily upload quota in MB: %3

�Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3

�Failed to disable Windows Defender Advanced Threat Protection mode in Windows Defender. Failure code: %1

Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: %1

Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: %1

�Windows Defender Advanced Threat Protection service failed to persist SENSE GUID. Failure code: %1

�Communication quotas are updated. Disk quota in MB: %1, daily upload quota in MB: %2

\Connected User Experiences and Telemetry service registration succeeded with completion code: %1. Requested disk quota in MB: %2, requested daily upload quota in MB: %3

�Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4.

�Network connection is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. Metered connection: %2, internet available: %3, free network available: %4, proxy is defined by GP: %5.

�Network connection is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. Metered connection: %2, internet available: %3, free network available: %4, proxy is defined by GP: %5.

�Battery state is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. AC state: %2, battery saver mode : %3, battery low state: %4, battery critical state: %5

�Battery state is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. AC state: %2, battery saver mode : %3, battery low state: %4, battery critical state: %5

�Component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception message: %4

Component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception Error: %4, Exception message: %5

�Offboarding of Windows Defender Advanced Threat Protection service completed.

�Failed to register and to start the event trace session [%1]. Error code: %2

�Failed to register and start the event trace session [%1] due to lack of resources. Error code: %2. This is most likely because there are too many active event trace sessions. The service will retry in 1 minute.

�Successfully registered and started the event trace session - recovered after previous failed attempts.

 Failed to add a provider [%1] to event trace session [%2]. Error code: %3. This means that events from this provider will not be reported.

�Invalid cloud configuration command received and ignored. Version: %1, status: %2, error code: %3, message: %4

�New cloud configuration applied successfully. Version: %1.

�New cloud configuration failed to apply, version: %1. Successfully applied the last known good configuration, version %2.

TNew cloud configuration failed to apply, version: %1. Also failed to apply last known good configuration, version %2. Successfully applied the default configuration.

�Cloud configuration loaded from persistent storage, version: %1.

�Global (per-pattern) state changed. State: %1, pattern: %2

�Failed to create the Secure ETW autologger. Failure code: %1

�Failed to remove the Secure ETW autologger. Failure code: %1

�Capturing a snapshot of the machine for troubleshooting purposes.

4Starting command: %1

TFailed to run command %1, error: %2.

�Data collection command parameters are invalid: SasUri: %1, compressionLevel: %2.

�Failed to start Connected User Experiences and Telemetry service. Failure code: %1

�Updating the start type of external service. Name: %1, actual start type: %2, expected start type: %3, exit code: %4

�Starting stopped external service. Name: %1, exit code: %2

�Failed to load Microsoft Security Events Component Minifilter driver. Failure code: %1

LPolicy update: Latency mode - %1

�Contacted server %1 times, failed %2 times and succeeded %3 times. URI: %4. Last HTTP error code: %5

�The start type of the service is unexpected. Service name: %1, actual start type: %2, expected start type: %3

\The service is stopped. Service name: %1

`Policy update: Allow sample collection - %1

DSucceeded to run command: %1

�Tried to send first full machine profile report. Result code: %1

HSense starting for platform: %1

�Device tag in registry exceeds length limit. Tag name: %2. Length limit: %1.

�Device tag name in registry exceeds length limit. Tag name: %2. Length limit: %1.

�Number of customer tags in registry exceeds limit. Limit: %1 tags.

�Successfully applied protection on Connected User Experiences and Telemetry service

�Successfully removed protection from Connected User Experiences and Telemetry service

�Failed to apply protection on Connected User Experiences and Telemetry service. Failure code: %1

�Failed to remove protection from Connected User Experiences and Telemetry service. Failure code: %1

�Failed to create Windows Defender Advanced Threat Protection ETW autologger. Failure code: %1

�Failed to remove Windows Defender Advanced Threat Protection ETW autologger. Failure code: %1

�Cyber event may be dropped because its size [%1 bytes] exceeded max size [%2 bytes] or close to it.

�Set Windows Defender Antivirus running mode. Force passive mode: %1, result code: %2.

�Failed to trigger Windows Defender Advanced Threat Protection Incident Response executable. Failure code: %1

�Starting again stopped external service that should be up. Name: %1, exit code: %2

`Cannot start the external service. Name: %1

Updating the start type of external service again. Name: %1, actual start type: %2, expected start type: %3, exit code: %4

�Cannot update the start type of external service. Name: %1, actual start type: %2, expected start type: %3

�Failed to configure System Guard Runtime Monitor to connect to cloud service in geo-region %1. Failure code: %2

�Failed to remove System Guard Runtime Monitor geo-region information. Failure code: %1

Stopping sending sensor cyber data quota because data quota is exceed. Will resume sending once quota period passes. State Mask: %1

pResuming sending sensor cyber data. State Mask: %1

�Windows Defender Advanced Threat Protection Classification Engine executable has started

�Windows Defender Advanced Threat Protection Classification Engine executable has ended

�Windows Defender Advanced Threat Protection Classification Engine Init has called. Result code: %1

�There are connectivity issues to the Cloud for the DLP scenario

�The connectivity to the Cloud for the DLP scenario has been restored

�Sense has encoutered the following error while communicating with server: (%1). Result: (%2)

�Windows Defender Advanced Threat Protection Classification Engine executable failed to start. Failure code: %1

�Windows Defender Advanced Threat Protection Network Detection and Response executable failed to start. Failure code: %1

�Windows Defender Advanced Threat Protection Network Detection and Response executable has started

�Windows Defender Advanced Threat Protection Network Detection and Response executable has ended

�Failed to queue asynchronous driver unload. Failure code: %1

LFailed to wait for driver unload.

�Windows Defender Advanced Threat Protection service failed to start. Failure code %1 ; Failed to load MsSense DLL Module

�Windows Defender Advanced Threat Protection service failed to start. Failure code %1 ; Issue with MsSense DLL Module

xUpdate phase:%1, new platform version: %2, message: %3

�Update phase:%1 new platform version: %2, failure message: %3, error: %4

XFailed to remove MDEContain WFP filters

tFailed to Leave SecurityManagement. Failure code: %1

�MsSecFlt.sys kernel service failed to request to stop itself after offboarding process. Failure code: %1

tMsSecFlt.sys kernel service has successfully started.

dMsSecFlt.sys kernel service failed to start.

tMsSecWfp.sys kernel service has successfully started.

dMsSecWfp.sys kernel service failed to start.

�%1: Failed to modify service object trust label. Failure code: %2

�Update phase:%1, new platform version: %2, success message: %3

�Windows Defender Advanced Threat Protection service failed to remove its failure actions. Failure code: %1

DEventTraker Event data: (%1)

,Info message: %1

�Update phase:%1 new platform version: %2, warning message: %3

�Update error message: %5, Additional parameters: %1: %2, %3: %4, error message: %6

�Windows Defender Advanced Threat Protection Trace Event Monitor executable has started

�Windows Defender Advanced Threat Protection Trace Event Monitor executable has ended

�Windows Defender Advanced Threat Protection Trace Event Monitor executable failed to start. Failure code: %1

�Windows Defender Advanced Threat Protection Dlp Processor executable failed to start. Failure code: %1

�Windows Defender Advanced Threat Protection Dlp Processor executable has started

�Windows Defender Advanced Threat Protection Dlp Processor executable has ended

dReceived DLP policy type: %1. Policy Hash: %2

|Completed processing DLP policy type: %1. Policy Hash: %2

�Failed to process DLP policy type: %1. Policy Hash: %2, Exception: %4 [%5]

�Ignore DLP policy type: %1 due to Data Loss Prevention feature currently disabled.

tFailed to update driver permissions Failure code: %1

`Failed to ACL on Folder %1 Failure code: %2

�Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id %1 of event log channel: %2, with provider: %3. Event data will not be collected until next reboot.

�Windows Defender Advanced Threat Protection service failed to create certificate. Failure code: %1

�Windows Defender Advanced Threat Protection service failed to generate key. Failure code: %1

�Windows Defender Advanced Threat Protection service failed to persist authentication state. State: %1, Failure code: %2

�Registration of device by Windows Defender Advanced Threat Protection service completed.

�Windows Defender Advanced Threat Protection service successfully generated a key.

�Failed to communicate with authentication service. %1 request failed, hresult: %2,  HTTP error code: %3 .

�Request for %1 rejected by authentication service. Hresult: %2, error code: %3 .

�Windows Defender Advanced Threat Protection service failed to sign message (authentication). Failure code: %1

Windows Defender Advanced Threat Protection service failed to remove persist authentication state. State: %1, Failure code: %2

�Windows Defender Advanced Threat Protection service failed to open key. Failure code: %1

�Registration is required as part of re-onboarding of Windows Defender Advanced Threat Protection service.

Cyber telemetry upload has been suspended for Windows Defender Advanced Threat Protection service due to invalid/expired token.

�Cyber telemetry upload been resumed for Windows Defender Advanced Threat Protection service due to newly refreshed token.

�Key rotation of device by Windows Defender Advanced Threat Protection service completed.

�Authentication initialization for Windows Defender Advanced Threat Protection service completed successfully.

�Windows Defender Advanced Threat Protection service opened key successfully.

�Windows Defender Advanced Threat Protection service certificate creation completed successfully.

�Windows Defender Advanced Threat Protection service authentication request signing completed successfully.

�Rename of device by Windows Defender Advanced Threat Protection service completed.

�Windows Defender Advanced Threat Protection orchestrator failed to perform: %1. Identifier: %2. HRESULT: %3.

�Windows Defender Advanced Threat Protection orchestrator performed: %1 successfully. Identifier: %2.

tCSP: Get Node's Value. NodeId: (%1), TokenName: (%2).

�CSP: Failed to Get Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3).

�CSP: Get Node's Value complete. NodeId: (%1), TokenName: (%2), Result: (%3).

�CSP: Get Last Connected value complete. Result (%1), IsDefault: (%2).

�CSP: Get Org ID value complete. Result: (%1), IsDefault: (%2).

xCSP: Get Sense Is Running value complete. Result: (%1).

�CSP: Get Onboarding State value complete. Result: (%1), IsDefault: (%2).

CSP: Get Onboarding value complete. Onboarding Blob Hash: (%1), IsDefault: (%2), Onboarding State: (%3), Onboarding State IsDefault: (%4)

�CSP: Get Offboarding value complete. Offboarding Blob Hash: (%1), IsDefault: (%2).

�CSP: Get Sample Sharing value complete. Result: (%1), IsDefault: (%2).

LCSP: Onboarding process. Started.

�CSP: Onboarding process. Delete Offboarding blob complete. Result: (%1).

�CSP: Onboarding process. Write Onboarding blob complete. Result: (%1)

�CSP: Onboarding process. The service started successfully.

�CSP: Onboarding process. Pending service running state complete. Result: (%1).

�CSP: Set Sample Sharing value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

�CSP: Offboarding process. Delete Onboarding blob complete. Result (%1).

�CSP: Offboarding process. Write Offboarding blob complete. Result (%1).

�CSP: Set Node's Value started. NodeId: (%1), TokenName: (%2).

�CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3).

�CSP: Set Node's Value complete. NodeId: (%1), TokenName: (%2), Result: (%3).

�CSP: Set Telemetry Reporting Frequency started. New value: (%1).

�CSP: Set Telemetry Reporting Frequency complete. Previous value: (%1), IsDefault: (%2), New value: (%3), Result: (%4).

�CSP: Get Telemetry Reporting Frequency complete. Value: (%1), Registry Value: (%2), IsDefault: (%3).

�CSP: Get Group Ids complete. Value: (%1), IsDefault: (%2).

�CSP: Set Group Ids exceeded allowed limit. Allowed: (%1), Actual: (%2).

xCSP: Set Group Ids complete. Value: (%1), Result: (%2).

�CSP: Onboarding process. Service is running: (%1), Previous Onboarding Blob Hash: (%2), IsDefault: (%3), Onboarding State: (%4), Onboarding State IsDefault: (%5), New Onboarding Blob Hash: (%6)

�CSP: Onboarding process. Service is running: (%1), Previous Offboarding Blob Hash: (%2), IsDefault: (%3), Onboarding State: (%4), Onboarding State IsDefault: (%5), New Offboarding Blob Hash: (%6)

�CSP: Failed to Set Sample Sharing Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

�CSP: Failed to Set Telemetry Reporting Frequency Value. Requested Value: (%1)

�CSP: Get Sense is running. Service is configured as delay-start, and hasn't started yet.

�CSP: Get Device Tagging Group complete. Value: (%1), IsDefault: (%2).

CSP: Get Device Tagging Criticality value complete. In Registry: (%1), IsDefault: (%2), Conversion Succeeded: (%3), Result: (%4).

 CSP: Get Device Tagging Identification Method value complete. In Registry: (%1), IsDefault: (%2), Conversion Succeeded: (%3), Result: (%4).

�CSP: Set Device Tagging Group complete. Value: (%1), Result: (%2).

�CSP: Set Device Tagging Group exceeded allowed limit. Allowed: (%1), Actual: (%2).

�CSP: Set Device Tagging Criticality value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

�CSP: Failed to Set Device Tagging Criticality Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

CSP: Set Device Tagging Identification Method value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

CSP: Failed to Set Device Tagging Identification Method Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

�CSP: Get AadDeviceId complete. Value: (%1), IsDefault: (%2).

|CSP: Set AadDeviceId complete. Value: (%1), Result: (%2).

�CSP: Set AadDeviceId exceeded allowed limit. Allowed: (%1), Actual: (%2).

3Windows Defender Advanced Threat Protection Service�Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer.���2��\C�o2����^�����ʬ�æ�����lw���MUIen-US