Winlogon

GPTKB entity

Statements (50)
Predicate Object
gptkbp:instanceOf Windows API
gptkbp:category Process
Windows security
Windows authentication
gptkbp:developedBy gptkb:Microsoft
gptkbp:documentation gptkb:Microsoft_Docs
gptkbp:executableName winlogon.exe
gptkbp:hasRole authentication
session management
https://www.w3.org/2000/01/rdf-schema#label Winlogon
gptkbp:interactsWith gptkb:GINA
gptkb:LSASS
credential providers
msgina.dll
userinit.exe
gptkbp:introducedIn gptkb:Windows_NT_3.1
gptkbp:location C:\\Windows\\System32
gptkbp:monitors mouse input
keyboard input
gptkbp:operatingSystem gptkb:Microsoft_Windows
gptkbp:processor critical system process
gptkbp:relatedTo gptkb:Windows_security_subsystem
user authentication
session management
Windows logon process
gptkbp:replacedGINAIn gptkb:Windows_Vista
gptkbp:responsibleFor user logon
Ctrl+Alt+Del handling
loading user profile
locking workstation
screen saver activation
secure attention sequence
user logoff
gptkbp:runsOn gptkb:Windows_8
gptkb:Windows_10
gptkb:Windows_11
gptkb:Windows_7
gptkb:Windows_Vista
gptkb:Windows_XP
gptkb:Windows_2000
gptkb:Windows_Server_2003
Process
gptkbp:target malware
gptkbp:terminationEffect system crash
automatic reboot
gptkbp:uses WinSta0 desktop
gptkbp:vulnerableTo Winlogon Helper DLL injection
gptkbp:bfsParent gptkb:Windows_NT_operating_system
gptkb:LSASS
gptkbp:bfsLayer 7