1LIBRARY "ADVAPI32.dll"
2EXPORTS
3
4; This file is a comprehensive documentation for 32-bit x86 advapi32.dll symbols.
5; It covers all 3 platforms (Win32s, Win9x and WinNT) and contains information
6; from native advapi32.dll libraries on 32-bit Windows systems and also from
7; 32-bit WoW64 advapi32.dll libraries on 64-bit Windows systems. Symbols in this
8; file are ordered by increasing Windows version in which they were introduced.
9; First are Win32s versions, then followed by Win9x versions and then WinNT
10; because logically Win32s symbols are a subset of Win9x symbols which are a
11; subset of WinNT symbols. Comments contains additional information with exceptions.
12;
13; BEWARE that this file contains only information about symbol availability and
14; whether it is possible to load an application or library which references these
15; symbols. It does not contain information if the particular Windows version
16; supports or implements corresponding API functions. Lots of -W functions are
17; unimplemented on Win32s and Win9x platforms and simply signal
18; ERROR_CALL_NOT_IMPLEMENTED.
19
20; This is list of symbols available in all Windows versions (Win32s since Win32s 1.1;
21; Win9x since Windows 95; WinNT since Windows NT 3.1)
22AbortSystemShutdownA@4
23AbortSystemShutdownW@4
24AccessCheck@32
25AccessCheckAndAuditAlarmA@44
26AccessCheckAndAuditAlarmW@44
27AddAccessAllowedAce@16
28AddAccessDeniedAce@16
29AddAce@20
30AddAuditAccessAce@24
31AdjustTokenGroups@24
32AdjustTokenPrivileges@24
33AllocateAndInitializeSid@44
34AllocateLocallyUniqueId@4
35AreAllAccessesGranted@8
36AreAnyAccessesGranted@8
37BackupEventLogA@8
38BackupEventLogW@8
39ChangeServiceConfigA@44
40ChangeServiceConfigW@44
41ClearEventLogA@8
42ClearEventLogW@8
43CloseEventLog@4
44CloseServiceHandle@4
45ControlService@12
46CopySid@12
47CreatePrivateObjectSecurity@24
48CreateServiceA@52
49CreateServiceW@52
50DeleteAce@8
51DeleteService@4
52DeregisterEventSource@4
53DestroyPrivateObjectSecurity@4
54DuplicateToken@12
55EnumDependentServicesA@24
56EnumDependentServicesW@24
57EnumServicesStatusA@32
58EnumServicesStatusW@32
59EqualPrefixSid@8
60EqualSid@8
61FindFirstFreeAce@8
62FreeSid@4
63GetAce@12
64GetAclInformation@16
65GetFileSecurityA@20
66GetFileSecurityW@20
67GetKernelObjectSecurity@20
68GetLengthSid@4
69GetNumberOfEventLogRecords@8
70GetOldestEventLogRecord@8
71GetPrivateObjectSecurity@20
72GetSecurityDescriptorControl@12
73GetSecurityDescriptorDacl@16
74GetSecurityDescriptorGroup@12
75GetSecurityDescriptorLength@4
76GetSecurityDescriptorOwner@12
77GetSecurityDescriptorSacl@16
78GetServiceDisplayNameA@16
79GetServiceDisplayNameW@16
80GetServiceKeyNameA@16
81GetServiceKeyNameW@16
82GetSidIdentifierAuthority@4
83GetSidLengthRequired@4
84GetSidSubAuthority@8
85GetSidSubAuthorityCount@4
86GetTokenInformation@20
87GetUserNameA@8
88GetUserNameW@8
89ImpersonateNamedPipeClient@4
90ImpersonateSelf@4
91InitializeAcl@12
92InitializeSecurityDescriptor@8
93InitializeSid@12
94InitiateSystemShutdownA@20
95InitiateSystemShutdownW@20
96IsValidAcl@4
97IsValidSecurityDescriptor@4
98IsValidSid@4
99LockServiceDatabase@4
100LookupAccountNameA@28
101LookupAccountNameW@28
102LookupAccountSidA@28
103LookupAccountSidW@28
104LookupPrivilegeDisplayNameA@20
105LookupPrivilegeDisplayNameW@20
106LookupPrivilegeNameA@16
107LookupPrivilegeNameW@16
108LookupPrivilegeValueA@12
109LookupPrivilegeValueW@12
110MakeAbsoluteSD@44
111MakeSelfRelativeSD@12
112MapGenericMask@8
113NotifyBootConfigStatus@4
114ObjectCloseAuditAlarmA@12
115ObjectCloseAuditAlarmW@12
116ObjectOpenAuditAlarmA@48
117ObjectOpenAuditAlarmW@48
118ObjectPrivilegeAuditAlarmA@24
119ObjectPrivilegeAuditAlarmW@24
120OpenBackupEventLogA@8
121OpenBackupEventLogW@8
122OpenEventLogA@8
123OpenEventLogW@8
124OpenProcessToken@12
125OpenSCManagerA@12
126OpenSCManagerW@12
127OpenServiceA@12
128OpenServiceW@12
129OpenThreadToken@16
130PrivilegeCheck@12
131PrivilegedServiceAuditAlarmA@20
132PrivilegedServiceAuditAlarmW@20
133QueryServiceConfigA@16
134QueryServiceConfigW@16
135QueryServiceLockStatusA@16
136QueryServiceLockStatusW@16
137QueryServiceObjectSecurity@20
138QueryServiceStatus@8
139ReadEventLogA@28
140ReadEventLogW@28
141RegCloseKey@4
142RegConnectRegistryA@12
143RegConnectRegistryW@12
144RegCreateKeyA@12
145RegCreateKeyExA@36
146RegCreateKeyExW@36
147RegCreateKeyW@12
148RegDeleteKeyA@8
149RegDeleteKeyW@8
150RegDeleteValueA@8
151RegDeleteValueW@8
152RegEnumKeyA@16
153RegEnumKeyExA@32
154RegEnumKeyExW@32
155RegEnumKeyW@16
156RegEnumValueA@32
157RegEnumValueW@32
158RegFlushKey@4
159RegGetKeySecurity@16
160RegLoadKeyA@12
161RegLoadKeyW@12
162RegNotifyChangeKeyValue@20
163RegOpenKeyA@12
164RegOpenKeyExA@20
165RegOpenKeyExW@20
166RegOpenKeyW@12
167RegQueryInfoKeyA@48
168RegQueryInfoKeyW@48
169RegQueryValueA@16
170RegQueryValueExA@24
171RegQueryValueExW@24
172RegQueryValueW@16
173RegReplaceKeyA@16
174RegReplaceKeyW@16
175RegRestoreKeyA@12
176RegRestoreKeyW@12
177RegSaveKeyA@12
178RegSaveKeyW@12
179RegSetKeySecurity@12
180RegSetValueA@20
181RegSetValueExA@24
182RegSetValueExW@24
183RegSetValueW@20
184RegUnLoadKeyA@8
185RegUnLoadKeyW@8
186RegisterEventSourceA@8
187RegisterEventSourceW@8
188RegisterServiceCtrlHandlerA@8
189RegisterServiceCtrlHandlerW@8
190ReportEventA@36
191ReportEventW@36
192RevertToSelf@0
193SetAclInformation@16
194SetFileSecurityA@12
195SetFileSecurityW@12
196SetKernelObjectSecurity@12
197SetPrivateObjectSecurity@20
198SetSecurityDescriptorDacl@16
199SetSecurityDescriptorGroup@12
200SetSecurityDescriptorOwner@12
201SetSecurityDescriptorSacl@16
202SetServiceObjectSecurity@12
203SetServiceStatus@8
204SetTokenInformation@16
205StartServiceA@12
206StartServiceCtrlDispatcherA@4
207StartServiceCtrlDispatcherW@4
208StartServiceW@12
209UnlockServiceDatabase@4
210
211; This is list of symbols added in Win32s 1.20 and available in all Win9x and WinNT versions
212SetThreadToken@8
213
214; This is list of symbols added in Win32s 1.20 and available in all WinNT versions, but not in Win9x
215ElfBackupEventLogFileA@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
216ElfBackupEventLogFileW@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
217ElfChangeNotify@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
218ElfClearEventLogFileA@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
219ElfClearEventLogFileW@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
220ElfCloseEventLog@4 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
221ElfDeregisterEventSource@4 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
222ElfNumberOfRecords@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
223ElfOldestRecord@8 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
224ElfOpenBackupEventLogA@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
225ElfOpenBackupEventLogW@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
226ElfOpenEventLogA@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
227ElfOpenEventLogW@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
228ElfReadEventLogA@28 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
229ElfReadEventLogW@28 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
230ElfRegisterEventSourceA@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
231ElfRegisterEventSourceW@12 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
232ElfReportEventA@48 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
233ElfReportEventW@48 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
234I_ScSetServiceBitsA@20
235I_ScSetServiceBitsW@20
236LsaAddPrivilegesToAccount@8
237LsaClearAuditLog@4
238LsaClose@4
239LsaCreateAccount@16
240LsaCreateSecret@16
241LsaCreateTrustedDomain@16
242LsaDelete@4
243LsaEnumerateAccounts@20
244LsaEnumeratePrivileges@20
245LsaEnumeratePrivilegesOfAccount@8
246LsaEnumerateTrustedDomains@20
247LsaFreeMemory@4
248LsaGetQuotasForAccount@8
249LsaGetSystemAccessAccount@8
250LsaICLookupNames@40 ; Win32s has ABI "LsaICLookupNames@40", Windows NT 3.1-4.0 has ABI "LsaICLookupNames@28", Windows 2000 has ABI "LsaICLookupNames@32", Windows XP and new has ABI "LsaICLookupNames@40"
251LsaICLookupSids@36 ; Win32s has ABI "LsaICLookupSids@36", Windows NT 3.1-4.0 has ABI "LsaICLookupSids@28", Windows 2000 has ABI "LsaICLookupSids@32", Windows XP and new has ABI "LsaICLookupSids@36"
252LsaLookupNames@20
253LsaLookupPrivilegeDisplayName@16
254LsaLookupPrivilegeName@12
255LsaLookupPrivilegeValue@12
256LsaLookupSids@20
257LsaOpenAccount@16
258LsaOpenPolicy@16
259LsaOpenSecret@16
260LsaOpenTrustedDomain@16
261LsaQueryInfoTrustedDomain@12
262LsaQueryInformationPolicy@12
263LsaQuerySecret@20
264LsaQuerySecurityObject@12
265LsaRemovePrivilegesFromAccount@12
266LsaSetInformationPolicy@12
267LsaSetInformationTrustedDomain@12
268LsaSetQuotasForAccount@8
269LsaSetSecret@12
270LsaSetSecurityObject@12
271LsaSetSystemAccessAccount@8
272QueryWindows31FilesMigration@4 ; removed in Windows Server 2003
273SynchronizeWindows31FilesAndWindowsNTRegistry@16 ; removed in Windows Server 2003
274SystemFunction001@12
275SystemFunction002@12
276SystemFunction003@8
277SystemFunction004@12
278SystemFunction005@12
279SystemFunction006@8
280SystemFunction007@8
281SystemFunction008@12
282SystemFunction009@12
283SystemFunction010@12
284SystemFunction011@12
285SystemFunction012@12
286SystemFunction013@12
287SystemFunction014@12
288SystemFunction015@12
289SystemFunction016@12
290SystemFunction017@12
291SystemFunction018@12
292SystemFunction019@12
293SystemFunction020@12
294SystemFunction021@12
295SystemFunction022@12
296SystemFunction023@12
297SystemFunction024@12
298SystemFunction025@12
299SystemFunction026@12
300SystemFunction027@12
301SystemFunction028@8
302SystemFunction029@8
303SystemFunction030@8
304SystemFunction031@8
305
306; This is list of symbols added in Win32s 1.20, available in all Win9x versions and since Windows NT 3.5
307IsTextUnicode@12
308NotifyChangeEventLog@8
309SetServiceBits@16
310
311; This is list of symbols added in Win32s 1.20, available since Windows NT 3.5, but not available in Win9x
312SystemFunction032@8
313SystemFunction033@8
314
315; This is list of symbols added in Win32s 1.25, available in all Win9x versions and since Windows NT 3.51
316CreateProcessAsUserA@44
317CreateProcessAsUserW@44
318ImpersonateLoggedOnUser@4
319LogonUserA@24
320LogonUserW@24
321
322; This is list of symbols added in Win32s 1.25, available since Windows NT 3.51, but not available in Win9x
323LsaAddAccountRights@16
324LsaDeleteTrustedDomain@8
325LsaEnumerateAccountRights@16
326LsaEnumerateAccountsWithUserRight@16
327LsaQueryTrustedDomainInfo@16
328LsaRemoveAccountRights@20
329LsaRetrievePrivateData@12
330LsaSetTrustedDomainInformation@16
331LsaStorePrivateData@12
332
333; This is list of symbols added in Win32s 1.30, available in all Win9x versions and since Windows NT 3.51
334RegQueryMultipleValuesA@20
335RegQueryMultipleValuesW@20
336
337; This is list of symbols added in Win32s 1.30, available since Windows NT 3.51, but not available in Win9x
338LsaNtStatusToWinError@4
339
340;; This is end of Win32s symbols ;;
341
342; This is list of symbols available in all Win9x versions, but not available in Win32s and WinNT
343; RegRemapPreDefKey@8
344
345; This is list of symbols added in Windows 95 OSR2 and also since Windows NT 4.0, but not available in Win32s
346CryptAcquireContextA@20
347CryptCreateHash@20
348CryptDecrypt@24
349CryptDeriveKey@20
350CryptDestroyHash@4
351CryptDestroyKey@4
352CryptEncrypt@28
353CryptExportKey@24
354CryptGenKey@16
355CryptGenRandom@12
356CryptGetHashParam@20
357CryptGetKeyParam@20
358CryptGetProvParam@20
359CryptGetUserKey@12
360CryptHashData@16
361CryptHashSessionKey@12
362CryptImportKey@24
363CryptReleaseContext@8
364CryptSetHashParam@16
365CryptSetKeyParam@16
366CryptSetProvParam@16
367CryptSetProviderA@8
368CryptSignHashA@24
369CryptVerifySignatureA@24
370
371; This is list of symbols added in Windows 98 and also since Windows NT 4.0, but not available in Win32s
372BuildExplicitAccessWithNameA@20
373BuildExplicitAccessWithNameW@20
374BuildImpersonateExplicitAccessWithNameA@24
375BuildImpersonateExplicitAccessWithNameW@24
376BuildImpersonateTrusteeA@8
377BuildImpersonateTrusteeW@8
378BuildSecurityDescriptorA@36
379BuildSecurityDescriptorW@36
380BuildTrusteeWithNameA@8
381BuildTrusteeWithNameW@8
382BuildTrusteeWithSidA@8
383BuildTrusteeWithSidW@8
384CryptAcquireContextW@20
385CryptSetProviderW@8
386CryptSignHashW@24
387CryptVerifySignatureW@24
388DuplicateTokenEx@24
389GetAuditedPermissionsFromAclA@16
390GetAuditedPermissionsFromAclW@16
391GetCurrentHwProfileA@4
392GetCurrentHwProfileW@4
393GetEffectiveRightsFromAclA@12
394GetEffectiveRightsFromAclW@12
395GetExplicitEntriesFromAclA@12
396GetExplicitEntriesFromAclW@12
397GetMultipleTrusteeA@4
398GetMultipleTrusteeOperationA@4
399GetMultipleTrusteeOperationW@4
400GetMultipleTrusteeW@4
401GetNamedSecurityInfoA@32
402GetNamedSecurityInfoW@32
403GetSecurityInfo@32
404GetTrusteeNameA@4
405GetTrusteeNameW@4
406GetTrusteeTypeA@4
407GetTrusteeTypeW@4
408LookupSecurityDescriptorPartsA@28
409LookupSecurityDescriptorPartsW@28
410ObjectDeleteAuditAlarmA@12
411ObjectDeleteAuditAlarmW@12
412SetEntriesInAclA@16
413SetEntriesInAclW@16
414SetNamedSecurityInfoA@28
415SetNamedSecurityInfoW@28
416SetSecurityInfo@28
417
418; This is list of symbols added in Windows 98 and also since Windows NT 4.0 SP4, but not available in Win32s
419CancelOverlappedAccess@4
420ConvertAccessToSecurityDescriptorA@20
421ConvertAccessToSecurityDescriptorW@20
422ConvertSecurityDescriptorToAccessA@28
423ConvertSecurityDescriptorToAccessNamedA@28
424ConvertSecurityDescriptorToAccessNamedW@28
425ConvertSecurityDescriptorToAccessW@28
426GetAccessPermissionsForObjectA@36
427GetAccessPermissionsForObjectW@36
428GetNamedSecurityInfoExA@36
429GetNamedSecurityInfoExW@36
430GetOverlappedAccessResults@16
431GetSecurityInfoExA@36
432GetSecurityInfoExW@36
433SetEntriesInAccessListA@24
434SetEntriesInAccessListW@24
435SetEntriesInAuditListA@24
436SetEntriesInAuditListW@24
437SetNamedSecurityInfoExA@36
438SetNamedSecurityInfoExW@36
439SetSecurityInfoExA@36
440SetSecurityInfoExW@36
441TrusteeAccessToObjectA@24
442TrusteeAccessToObjectW@24
443
444; This is list of symbols added in Windows 98 and also since Windows 2000, but not available in Win32s
445CryptContextAddRef@12
446CryptDuplicateHash@16
447CryptDuplicateKey@16
448CryptEnumProviderTypesA@24
449CryptEnumProviderTypesW@24
450CryptEnumProvidersA@24
451CryptEnumProvidersW@24
452CryptGetDefaultProviderA@20
453CryptGetDefaultProviderW@20
454CryptSetProviderExA@16
455CryptSetProviderExW@16
456
457; This is list of symbols added in Windows ME, but not available in Win32s and WinNT
458; CryptGetLocalKeyLimits@16
459
460;; This is end of Win9x symbols ;;
461
462; This is list of symbols (not mentioned in previous sections) added in Windows NT 4.0, but not available in Win32s and Win9x
463; BuildAccessRequestA@12 ; removed in Windows NT 4.0 SP4
464; BuildAccessRequestW@12 ; removed in Windows NT 4.0 SP4
465; DenyAccessRightsA@16 ; removed in Windows NT 4.0 SP4
466; DenyAccessRightsW@16 ; removed in Windows NT 4.0 SP4
467EnumServiceGroupW@36
468; GetAuditedPermissionsFromSDA@16 ; removed in Windows NT 4.0 SP4
469; GetAuditedPermissionsFromSDW@16 ; removed in Windows NT 4.0 SP4
470; GetEffectiveAccessRightsA@16 ; removed in Windows NT 4.0 SP4
471; GetEffectiveAccessRightsW@16 ; removed in Windows NT 4.0 SP4
472; GetEffectiveRightsFromSDA@12 ; removed in Windows NT 4.0 SP4
473; GetEffectiveRightsFromSDW@12 ; removed in Windows NT 4.0 SP4
474; GetExplicitAccessRightsA@16 ; removed in Windows NT 4.0 SP4
475; GetExplicitAccessRightsW@16 ; removed in Windows NT 4.0 SP4
476; GrantAccessRightsA@16 ; removed in Windows NT 4.0 SP4
477; GrantAccessRightsW@16 ; removed in Windows NT 4.0 SP4
478I_ScGetCurrentGroupStateW@12
479; IsAccessPermittedA@20 ; removed in Windows NT 4.0 SP4
480; IsAccessPermittedW@20 ; removed in Windows NT 4.0 SP4
481LsaGetUserName@8
482; NTAccessMaskToProvAccessRights@12 ; removed in Windows NT 4.0 SP4
483; ProvAccessRightsToNTAccessMask@8 ; removed in Windows NT 4.0 SP4
484; ReplaceAllAccessRightsA@16 ; removed in Windows NT 4.0 SP4
485; ReplaceAllAccessRightsW@16 ; removed in Windows NT 4.0 SP4
486; RevokeExplicitAccessRightsA@16 ; removed in Windows NT 4.0 SP4
487; RevokeExplicitAccessRightsW@16 ; removed in Windows NT 4.0 SP4
488; SetAccessRightsA@16 ; removed in Windows NT 4.0 SP4
489; SetAccessRightsW@16 ; removed in Windows NT 4.0 SP4
490
491; This is list of symbols (not mentioned in previous sections) added in Windows NT 4.0 SP4, but not available in Win32s and Win9x
492EnumServicesStatusExA@40
493EnumServicesStatusExW@40
494LsaGetRemoteUserName@12
495QueryServiceStatusEx@20
496
497; This is list of symbols added in Windows 2000
498AccessCheckByType@44
499AccessCheckByTypeAndAuditAlarmA@64
500AccessCheckByTypeAndAuditAlarmW@64
501AccessCheckByTypeResultList@44
502AccessCheckByTypeResultListAndAuditAlarmA@64
503AccessCheckByTypeResultListAndAuditAlarmByHandleA@68
504AccessCheckByTypeResultListAndAuditAlarmByHandleW@68
505AccessCheckByTypeResultListAndAuditAlarmW@64
506AddAccessAllowedAceEx@20
507AddAccessAllowedObjectAce@28
508AddAccessDeniedAceEx@20
509AddAccessDeniedObjectAce@28
510AddAuditAccessAceEx@28
511AddAuditAccessObjectAce@36
512AddUsersToEncryptedFile@8
513BuildTrusteeWithObjectsAndNameA@24
514BuildTrusteeWithObjectsAndNameW@24
515BuildTrusteeWithObjectsAndSidA@20
516BuildTrusteeWithObjectsAndSidW@20
517ChangeServiceConfig2A@12
518ChangeServiceConfig2W@12
519CheckTokenMembership@12
520CloseEncryptedFileRaw@4
521CloseTrace@8
522CommandLineFromMsiDescriptor@12
523ControlTraceA@20
524ControlTraceW@20
525ConvertSDToStringSDRootDomainA@24
526ConvertSDToStringSDRootDomainW@24
527ConvertSecurityDescriptorToStringSecurityDescriptorA@20
528ConvertSecurityDescriptorToStringSecurityDescriptorW@20
529ConvertSidToStringSidA@8
530ConvertSidToStringSidW@8
531ConvertStringSDToSDRootDomainA@20
532ConvertStringSDToSDRootDomainW@20
533ConvertStringSecurityDescriptorToSecurityDescriptorA@16
534ConvertStringSecurityDescriptorToSecurityDescriptorW@16
535ConvertStringSidToSidA@8
536ConvertStringSidToSidW@8
537ConvertToAutoInheritPrivateObjectSecurity@24
538CreatePrivateObjectSecurityEx@32
539CreateProcessWithLogonW@44
540CreateRestrictedToken@36
541CreateTraceInstanceId@8
542DecryptFileA@8
543DecryptFileW@8
544DuplicateEncryptionInfoFile@20 ; Windows 2000 has ABI "DuplicateEncryptionInfoFile@8", Windows XP and new has ABI "DuplicateEncryptionInfoFile@20"
545EnableTrace@24
546EncryptFileA@4
547EncryptFileW@4
548EncryptionDisable@8
549FileEncryptionStatusA@8
550FileEncryptionStatusW@8
551FreeEncryptionCertificateHashList@4
552GetEventLogInformation@20
553GetLocalManagedApplications@12
554GetManagedApplications@20
555GetMangledSiteSid@12 ; removed in Windows XP
556GetSecurityDescriptorRMControl@8
557GetSiteDirectoryA@12 ; removed in Windows XP
558GetSiteDirectoryW@12 ; removed in Windows XP
559GetSiteNameFromSid@8 ; removed in Windows XP
560GetSiteSidFromToken@4 ; removed in Windows XP
561GetSiteSidFromUrl@4 ; removed in Windows XP
562GetTraceEnableFlags@8
563GetTraceEnableLevel@8
564GetTraceLoggerHandle@4
565GetTrusteeFormA@4
566GetTrusteeFormW@4
567I_ScIsSecurityProcess@0
568I_ScPnPGetServiceName@12
569ImpersonateAnonymousToken@4
570InitiateSystemShutdownExA@24
571InitiateSystemShutdownExW@24
572InstallApplication@4
573; IsInSandbox@0 ; removed in Windows XP
574IsProcessRestricted@0 ; removed in Windows XP
575IsTokenRestricted@4
576LsaCreateTrustedDomainEx@20
577LsaEnumerateTrustedDomainsEx@20
578LsaOpenTrustedDomainByName@16
579LsaQueryDomainInformationPolicy@12
580LsaQueryTrustedDomainInfoByName@16
581LsaSetDomainInformationPolicy@12
582LsaSetTrustedDomainInfoByName@16
583MakeAbsoluteSD2@8
584OpenEncryptedFileRawA@12
585OpenEncryptedFileRawW@12
586OpenTraceA@4
587OpenTraceW@4
588ProcessTrace@16
589QueryAllTracesA@12
590QueryAllTracesW@12
591QueryRecoveryAgentsOnEncryptedFile@8
592QueryServiceConfig2A@20
593QueryServiceConfig2W@20
594QueryUsersOnEncryptedFile@8
595ReadEncryptedFileRaw@12
596RegDisablePredefinedCache@0
597RegOpenCurrentUser@8
598RegOpenUserClassesRoot@16
599RegOverridePredefKey@8
600RegisterServiceCtrlHandlerExA@12
601RegisterServiceCtrlHandlerExW@12
602RegisterTraceGuidsA@32
603RegisterTraceGuidsW@32
604RemoveTraceCallback@4
605RemoveUsersFromEncryptedFile@8
606SetPrivateObjectSecurityEx@24
607SetSecurityDescriptorControl@12
608SetSecurityDescriptorRMControl@8
609SetTraceCallback@8
610SetUserFileEncryptionKey@4
611StartTraceA@12
612StartTraceW@12
613SystemFunction034@12
614SystemFunction035@4
615TraceEvent@12
616TraceEventInstance@20
617UninstallApplication@8 ; Windows 2000 has ABI "UninstallApplication@4", Windows XP and new has ABI "UninstallApplication@8"
618UnregisterTraceGuids@8
619WmiCloseBlock@4
620WmiDevInstToInstanceNameA@16
621WmiDevInstToInstanceNameW@16
622WmiEnumerateGuids@8
623WmiExecuteMethodA@28
624WmiExecuteMethodW@28
625WmiFileHandleToInstanceNameA@16
626WmiFileHandleToInstanceNameW@16
627WmiFreeBuffer@4
628WmiMofEnumerateResourcesA@12
629WmiMofEnumerateResourcesW@12
630WmiNotificationRegistrationA@20
631WmiNotificationRegistrationW@20
632WmiOpenBlock@12
633WmiQueryAllDataA@12
634WmiQueryAllDataW@12
635WmiQueryGuidInformation@8
636WmiQuerySingleInstanceA@16
637WmiQuerySingleInstanceW@16
638WmiSetSingleInstanceA@20
639WmiSetSingleInstanceW@20
640WmiSetSingleItemA@24
641WmiSetSingleItemW@24
642WriteEncryptedFileRaw@12
643
644; In Windows 2000 SP1 there was no new symbol
645
646; This is list of symbols added in Windows 2000 SP2
647EqualDomainSid@12
648
649; This is list of symbols added in Windows 2000 SP3
650CreateWellKnownSid@16
651GetWindowsAccountDomainSid@12
652IsWellKnownSid@8
653LsaOpenPolicySce@16
654SystemFunction040@12
655SystemFunction041@12
656
657; This is list of symbols added in Windows 2000 SP4 and Windows XP SP2 (not available in Windows XP and Windows XP SP1)
658; CreateProcessAsUserSecure@0 ; removed in Windows Server 2003
659ElfFlushEventLog@4 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
660
661; This is list of symbols added in Windows XP
662A_SHAFinal@8
663A_SHAInit@4
664A_SHAUpdate@12
665CloseCodeAuthzLevel@4
666ComputeAccessTokenFromCodeAuthzLevel@20
667ConvertStringSDToSDDomainA@24
668ConvertStringSDToSDDomainW@24
669CreateCodeAuthzLevel@20
670CreatePrivateObjectSecurityWithMultipleInheritance@36
671CredDeleteA@12
672CredDeleteW@12
673CredEnumerateA@16
674CredEnumerateW@16
675CredFree@4
676CredGetSessionTypes@8
677CredGetTargetInfoA@12
678CredGetTargetInfoW@12
679CredIsMarshaledCredentialA@4
680CredIsMarshaledCredentialW@4
681CredMarshalCredentialA@12
682CredMarshalCredentialW@12
683CredProfileLoaded@0
684CredReadA@16
685CredReadDomainCredentialsA@16
686CredReadDomainCredentialsW@16
687CredReadW@16
688CredRenameA@16
689CredRenameW@16
690CredUnmarshalCredentialA@12
691CredUnmarshalCredentialW@12
692CredWriteA@8
693CredWriteDomainCredentialsA@12
694CredWriteDomainCredentialsW@12
695CredWriteW@8
696CredpConvertCredential@16
697CredpConvertTargetInfo@16
698CredpDecodeCredential@4
699CredpEncodeCredential@4
700EncryptedFileKeyInfo@12
701EnumerateTraceGuids@12
702FlushTraceA@16
703FlushTraceW@16
704FreeEncryptedFileKeyInfo@4
705FreeInheritedFromArray@12
706GetInformationCodeAuthzLevelW@20
707GetInformationCodeAuthzPolicyW@24
708GetInheritanceSourceA@40
709GetInheritanceSourceW@40
710GetLocalManagedApplicationData@12
711GetManagedApplicationCategories@8
712I_ScSendTSMessage@16
713IdentifyCodeAuthzLevelW@16
714IsTokenUntrusted@4
715LogonUserExA@40
716LogonUserExW@40
717LsaICLookupNamesWithCreds@48
718LsaICLookupSidsWithCreds@48
719LsaLookupNames2@24
720LsaQueryForestTrustInformation@12
721LsaSetForestTrustInformation@20
722MD4Final@4
723MD4Init@4
724MD4Update@12
725MD5Final@4
726MD5Init@4
727MD5Update@12
728MSChapSrvChangePassword2@28
729MSChapSrvChangePassword@28
730ProcessIdleTasks@0
731QueryTraceA@16
732QueryTraceW@16
733RegSaveKeyExA@16
734RegSaveKeyExW@16
735RegisterIdleTask@16
736SaferCloseLevel@4
737SaferComputeTokenFromLevel@20
738SaferCreateLevel@20
739SaferGetLevelInformation@20
740SaferGetPolicyInformation@24
741SaferIdentifyLevel@16
742SaferRecordEventLogEntry@12
743SaferSetLevelInformation@16
744SaferSetPolicyInformation@20
745SaferiChangeRegistryScope@8
746SaferiCompareTokenLevels@12
747SaferiIsExecutableFileType@8
748SaferiPopulateDefaultsInRegistry@8
749SaferiRecordEventLogEntry@12
750; SaferiReplaceProcessThreadTokens@12 ; removed in Windows 7
751SaferiSearchMatchingHashRules@24
752SetInformationCodeAuthzLevelW@16
753SetInformationCodeAuthzPolicyW@20
754StopTraceA@16
755StopTraceW@16
756SystemFunction036@8
757TraceMessage ; cdecl
758TraceMessageVa@24
759TreeResetNamedSecurityInfoA@44
760TreeResetNamedSecurityInfoW@44
761UnregisterIdleTask@12
762UpdateTraceA@16
763UpdateTraceW@16
764; WdmWmiServiceMain@8 ; removed in Windows Vista
765; WmiGetFirstTraceOffset@4 ; removed in Windows Vista
766; WmiGetTraceHeader@12 ; removed in Windows Vista
767; WmiParseTraceEvent@20 ; removed in Windows Vista
768WmiQueryAllDataMultipleA@16
769WmiQueryAllDataMultipleW@16
770WmiQuerySingleInstanceMultipleA@20
771WmiQuerySingleInstanceMultipleW@20
772WmiReceiveNotificationsA@16
773WmiReceiveNotificationsW@16
774; Wow64Win32ApiEntry@12 ; removed in Windows 7
775
776; This is list of symbols added in Windows XP SP1
777; WmiCloseTraceWithCursor@4 ; removed in Windows Vista
778; WmiConvertTimestamp@12 ; removed in Windows Vista
779; WmiGetNextEvent@4 ; removed in Windows Vista
780; WmiOpenTraceWithCursor@4 ; removed in Windows Vista
781
782; In Windows XP SP2 there was no new symbol
783
784; This is list of symbols added in Windows XP SP3 and Windows Vista (not available in any version of Windows Server 2003)
785RegDisablePredefinedCacheEx@0
786
787; This is list of symbols added in Windows Server 2003
788CreateProcessWithTokenW@36
789
790; This is list of symbols added in Windows Server 2003 SP1 and Windows XP x64 SP1 (WoW64 version)
791ElfReportEventAndSourceW@60 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
792I_QueryTagInformation@12
793RegConnectRegistryExA@16
794RegConnectRegistryExW@16
795RegDeleteKeyExA@16
796RegDeleteKeyExW@16
797RegDisableReflectionKey@4
798RegEnableReflectionKey@4
799RegGetValueA@28
800RegGetValueW@28
801RegQueryReflectionKey@8
802
803; In Windows Server 2003 SP2 and Windows XP x64 SP2 (WoW64 version) there was no new symbol
804
805; This is list of symbols added in Windows Vista
806AddMandatoryAce@20
807AddUsersToEncryptedFileEx@16
808AuditComputeEffectivePolicyBySid@16
809AuditComputeEffectivePolicyByToken@16
810AuditEnumerateCategories@8
811AuditEnumeratePerUserPolicy@4
812AuditEnumerateSubCategories@16
813AuditFree@4
814AuditLookupCategoryGuidFromCategoryId@8
815AuditLookupCategoryIdFromCategoryGuid@8
816AuditLookupCategoryNameA@8
817AuditLookupCategoryNameW@8
818AuditLookupSubCategoryNameA@8
819AuditLookupSubCategoryNameW@8
820AuditQueryPerUserPolicy@16
821AuditQuerySecurity@8
822AuditQuerySystemPolicy@12
823AuditSetPerUserPolicy@12
824AuditSetSecurity@8
825AuditSetSystemPolicy@8
826; CheckAppInitBlockedServiceIdentity@4 ; removed in Windows 7
827CloseThreadWaitChainSession@4
828ControlServiceExA@16
829ControlServiceExW@16
830CredBackupCredentials@20
831CredEncryptAndMarshalBinaryBlob@12
832CredFindBestCredentialA@16
833CredFindBestCredentialW@16
834CredIsProtectedA@8
835CredIsProtectedW@8
836CredProfileUnloaded@0
837CredProtectA@24
838CredProtectW@24
839CredReadByTokenHandle@20
840CredRestoreCredentials@16
841CredUnprotectA@20
842CredUnprotectW@20
843CredpConvertOneCredentialSize@8
844CredpEncodeSecret@20
845EnableTraceEx@48
846EnumerateTraceGuidsEx@24
847EventAccessControl@20
848EventAccessQuery@12
849EventAccessRemove@4
850EventActivityIdControl@8
851EventEnabled@12
852EventProviderEnabled@20
853EventRegister@16
854EventUnregister@8
855EventWrite@20
856EventWriteEndScenario@20
857EventWriteStartScenario@20
858EventWriteString@24
859EventWriteTransfer@28
860FlushEfsCache@4
861FreeEncryptedFileMetadata@4
862GetEncryptedFileMetadata@12
863GetThreadWaitChain@28
864I_ScQueryServiceConfig@12
865I_ScSendPnPMessage@24
866I_ScValidatePnPService@12
867InitiateShutdownA@20
868InitiateShutdownW@20
869IsValidRelativeSecurityDescriptor@12
870LogonUserExExW@44
871LsaManageSidNameMapping@12
872NotifyServiceStatusChange@12
873NotifyServiceStatusChangeA@12
874NotifyServiceStatusChangeW@12
875OpenThreadWaitChainSession@8
876PerfAddCounters@12
877PerfCloseQueryHandle@4
878PerfCreateInstance@16
879PerfDecrementULongCounterValue@16
880PerfDecrementULongLongCounterValue@20
881PerfDeleteCounters@12
882PerfDeleteInstance@8
883PerfEnumerateCounterSet@16
884PerfEnumerateCounterSetInstances@20
885PerfIncrementULongCounterValue@16
886PerfIncrementULongLongCounterValue@20
887PerfOpenQueryHandle@8
888PerfQueryCounterData@16
889PerfQueryCounterInfo@16
890PerfQueryCounterSetRegistrationInfo@28
891PerfQueryInstance@16
892PerfSetCounterRefValue@16
893PerfSetCounterSetInfo@12
894PerfSetULongCounterValue@16
895PerfSetULongLongCounterValue@20
896PerfStartProvider@12
897PerfStartProviderEx@12
898PerfStopProvider@4
899ProcessIdleTasksW@16
900QuerySecurityAccessMask@8
901RegCopyTreeA@12
902RegCopyTreeW@12
903RegCreateKeyTransactedA@44
904RegCreateKeyTransactedW@44
905RegDeleteKeyTransactedA@24
906RegDeleteKeyTransactedW@24
907RegDeleteKeyValueA@12
908RegDeleteKeyValueW@12
909RegDeleteTreeA@8
910RegDeleteTreeW@8
911RegLoadAppKeyA@20
912RegLoadAppKeyW@20
913RegLoadMUIStringA@28
914RegLoadMUIStringW@28
915RegOpenKeyTransactedA@28
916RegOpenKeyTransactedW@28
917RegRenameKey@12
918RegSetKeyValueA@24
919RegSetKeyValueW@24
920RegisterWaitChainCOMCallback@8
921SetEncryptedFileMetadata@24
922SetSecurityAccessMask@8
923SetUserFileEncryptionKeyEx@16
924TreeSetNamedSecurityInfoA@44
925TreeSetNamedSecurityInfoW@44
926UsePinForEncryptedFilesA@12
927UsePinForEncryptedFilesW@12
928
929; In Windows Vista SP1 there was no new symbol
930
931; In Windows Vista SP2 there was no new symbol
932
933; This is list of symbols added in Windows 7
934AddConditionalAce@32
935AuditQueryGlobalSaclA@8
936AuditQueryGlobalSaclW@8
937AuditSetGlobalSaclA@8
938AuditSetGlobalSaclW@8
939EnableTraceEx2@44
940EventWriteEx@40
941SaferiIsDllAllowed@8 ; Windows 7 has ABI "SaferiIsDllAllowed@12", Windows 8 and new has ABI "SaferiIsDllAllowed@8"
942TraceSetInformation@20
943
944; This is list of ordinal-only symbols added in Windows 7
945; Symbol names are taken from:
946; https://www.geoffchappell.com/studies/windows/win32/advapi32/history/ords61.htm
947SaferiRegisterExtensionDll@8 @1000 NONAME
948
949; In Windows 7 SP1 there was no new symbol
950
951; This is list of symbols added in Windows 8
952BaseRegCloseKey@4
953BaseRegCreateKey@32
954BaseRegDeleteKeyEx@16
955BaseRegDeleteValue@8
956BaseRegFlushKey@4
957BaseRegGetVersion@8
958BaseRegLoadKey@12
959BaseRegOpenKey@20
960BaseRegRestoreKey@12
961BaseRegSaveKeyEx@16
962BaseRegSetKeySecurity@12
963BaseRegSetValue@20
964BaseRegUnLoadKey@8
965CheckForHiberboot@8
966ConvertSDToStringSDDomainW@28
967; CredProfileLoadedEx@4
968EnumDynamicTimeZoneInformation@8
969; EtwLogSysConfigExtension@8 ; removed in Windows 10 Anniversary Update (Redstone / 1607)
970EventSetInformation@20
971GetDynamicTimeZoneInformationEffectiveYears@12
972GetStringConditionFromBinary@16
973; I_ScRegisterPreshutdownRestart@8
974LsaGetAppliedCAPIDs@12
975LsaLookupSids2@24
976LsaQueryCAPs@16
977LsaSetCAPs@12
978; MIDL_user_free_Ext@4
979OperationEnd@4
980OperationStart@4
981PerfRegCloseKey@4
982PerfRegEnumKey@24
983PerfRegEnumValue@32
984PerfRegQueryInfoKey@44
985PerfRegQueryValue@28
986PerfRegSetValue@24
987; PsmActivateApplication@12 ; removed in Windows 8.1
988; PsmAdjustActivationToken@24 ; removed in Windows 8.1
989; PsmQueryBackgroundActivationType@8 ; removed in Windows 8.1
990; PsmRegisterApplicationProcess@8 ; removed in Windows 8.1
991QueryServiceDynamicInformation@12
992RemoteRegEnumKeyWrapper@20
993RemoteRegEnumValueWrapper@28
994RemoteRegQueryInfoKeyWrapper@40
995RemoteRegQueryValueWrapper@24
996SafeBaseRegGetKeySecurity@16
997TraceQueryInformation@24
998WaitServiceState@16
999
1000; In Windows 8.1 there was no new symbol
1001
1002; This is list of symbols added in Windows 10 (Threshold / 1507)
1003NpGetUserName@12
1004
1005; This is list of symbols added in Windows 10 November Update (Threshold 2 / 1511)
1006; I_ScReparseServiceDatabase@4
1007; QueryLocalUserServiceName@12
1008; QueryUserServiceName@20
1009
1010; This is list of symbols added in Windows 10 Anniversary Update (Redstone / 1607)
1011CveEventWrite@8
1012
1013; This is list of symbols added in Windows 10 Creators Update (Redstone 2 / 1703)
1014; QueryUserServiceNameForContext@20
1015
1016; This is list of symbols added in Windows 10 Fall Creators Update (Redstone 3 / 1709)
1017; CreateServiceEx@56
1018QueryTraceProcessingHandle@32
1019RemoteRegQueryMultipleValues2Wrapper@24
1020RemoteRegQueryMultipleValuesWrapper@20
1021
1022; In Windows 10 April 2018 Update (Redstone 4 / 1803) there was no new symbol
1023
1024; In Windows 10 October 2018 Update (Redstone 5 / 1809) there was no new symbl
1025
1026; In Windows 10 May 2019 Update (19H1 / 1903) there was no new symbol
1027
1028; In Windows 10 November 2019 Update (19H2 /1909) there was no new symbol
1029
1030; In Windows 10 May 2020 Update (20H1 / 2004) there was no new symbol
1031
1032; In Windows 10 October 2020 Update (20H2) there was no new symbol
1033
1034; In Windows 10 May 2021 Update (21H1) there was no new symbol
1035
1036; In Windows 10 November 2021 Update (21H2) there was no new symbol
1037
1038; This is list of symbols added in Windows 10 2022 Update (22H2) and Windows 11 2022 Update (Sun Valley 2 / 22H2) (WoW64 version) (not available in Windows 11 (Sun Valley / 21H2))
1039LsaInvokeTrustScanner@16
1040LsaQueryForestTrustInformation2@16
1041LsaSetForestTrustInformation2@24
1042
1043; This is list of symbols added in Windows 11 (Sun Valley / 21H2) (WoW64 version)
1044LsaConfigureAutoLogonCredentials@0
1045; LsaDisablePasswordLessCurrentUser@0 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
1046LsaDisableUserArso@4
1047; LsaEnablePasswordLessCurrentUser@0 ; removed in Windows 11 2022 Update (Sun Valley 2 / 22H2)
1048LsaEnableUserArso@4
1049LsaGetDeviceRegistrationInfo@4
1050LsaIsUserArsoAllowed@4
1051LsaIsUserArsoEnabled@8
1052LsaProfileDeleted@4
1053LsaValidateProcUniqueLuid@4
1054
1055; In Windows 11 2022 Update (Sun Valley 2 / 22H2) (WoW64 version) there was no new symbol
1056
1057; In Windows 11 2023 Update (Sun Valley 3 / 23H2) (WoW64 version) there was no new symbol
1058
1059; This is list of symbols added in Windows 11 2024 Update (Hudson Valley / 24H2) (WoW64 version)
1060; LsaIOpenPolicyWithCreds@24 ; removed in Windows 11 2025 Update (Hudson Valley 2 / 25H2)
1061
1062; This is list of symbols added in Windows 11 2025 Update (Hudson Valley 2 / 25H2) (WoW64 version)
1063; LogonSecondaryUserIntoSessionW@20
1064; LsaPurgeLocalSystemAccessTable@0
1065LsaQueryLocalSystemAccess@8
1066LsaQueryLocalSystemAccessAll@4
1067LsaSetLocalSystemAccess@4