KiStackAttachProcess
VOID __stdcall KiStackAttachProcess(_EPROCESS *Process, UINT64 Force, _KAPC_STATE *ApcState){
_ETHREAD *CurrentThread;
unsigned __int8 CurrentIrql;
_KAPC_STATE *v5;
char v6;
int v8;
struct _KPRCB *CurrentPrcb;
_QWORD *v10;
__int64 v11;
__int64 v12;
_QWORD *v13;
__int64 v14;
struct _KPRCB *v15;
struct _KPRCB *v16;
__int64 v17;
unsigned __int64 v18;
__int64 v19;
unsigned __int64 v20;
unsigned __int64 v21;
struct _KPRCB *v22;
_QWORD *v23;
_QWORD *v24;
__int64 v25;
__int64 v26;
unsigned __int64 v27;
unsigned __int64 v28;
UINT64 v29[2];
UINT64 SpinCount;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
CurrentIrql = 0;
v5 = ApcState;
v6 = Force;
if( (*((_DWORD *)KeGetPcr() + 3243) & 0x10001) != 0 && (Force & 2) == 0 || (*((_DWORD *)Process + 158) & 0x400) != 0 )
KeBugCheckEx(
5u,
(ULONG_PTR)Process,
*((_QWORD *)CurrentThread + 23),
*((unsigned __int8 *)CurrentThread + 586),
*((_DWORD *)KeGetPcr() + 3243) & 0x10001);
if( *((_EPROCESS **)CurrentThread + 23) == Process )
{
ApcState->Process = (_EPROCESS *)1;
}
else
{
v8 = Force & 2;
if( (Force & 2) == 0 )
{
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
CurrentPrcb = KeGetCurrentPrcb();
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)CurrentThread + 16, 0i64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( *((_QWORD *)CurrentThread + 8) );
v25 = *((_QWORD *)CurrentPrcb + 4247);
if( v25 && *((_BYTE *)CurrentPrcb + 32) <= 1u )
++*(_DWORD *)(v25 + 24);
}
v5 = ApcState;
}
if( *((_BYTE *)CurrentThread + 586) )
{
KiAttachProcess((__int64)CurrentThread, (__int64)Process, CurrentIrql, v6, (__int64)v5);
}
else
{
v10 = (_QWORD *)((char *)CurrentThread + 600);
*((_QWORD *)CurrentThread + 79) = *((_QWORD *)CurrentThread + 23);
*((_BYTE *)CurrentThread + 640) = *((_BYTE *)CurrentThread + 192);
*((_BYTE *)CurrentThread + 641) = *((_BYTE *)CurrentThread + 193);
*((_BYTE *)CurrentThread + 642) = *((_BYTE *)CurrentThread + 194);
v11 = *((_QWORD *)CurrentThread + 19);
if( (_ETHREAD *)v11 == (_ETHREAD *)((char *)CurrentThread + 152) )
{
*((_QWORD *)CurrentThread + 76) = (char *)CurrentThread + 600;
*v10 = v10;
*((_BYTE *)CurrentThread + 641) = 0;
}
else
{
v23 = (_QWORD *)*((_QWORD *)CurrentThread + 20);
*v10 = v11;
*((_QWORD *)CurrentThread + 76) = v23;
*(_QWORD *)(v11 + 8) = v10;
*v23 = v10;
}
v12 = *((_QWORD *)CurrentThread + 21);
v13 = (_QWORD *)((char *)CurrentThread + 616);
if( (_ETHREAD *)v12 == (_ETHREAD *)((char *)CurrentThread + 168) )
{
*((_QWORD *)CurrentThread + 78) = (char *)CurrentThread + 616;
*v13 = v13;
*((_BYTE *)CurrentThread + 642) = 0;
}
else
{
v24 = (_QWORD *)*((_QWORD *)CurrentThread + 22);
*v13 = v12;
*((_QWORD *)CurrentThread + 78) = v24;
*(_QWORD *)(v12 + 8) = v13;
*v24 = v13;
}
*((_QWORD *)CurrentThread + 20) = (char *)CurrentThread + 152;
LODWORD(v14) = (_DWORD)CurrentThread + 168;
*((_QWORD *)CurrentThread + 22) = (char *)CurrentThread + 168;
*((_QWORD *)CurrentThread + 21) = (char *)CurrentThread + 168;
*((_QWORD *)CurrentThread + 19) = (char *)CurrentThread + 152;
*((_BYTE *)CurrentThread + 586) = 1;
*((_WORD *)CurrentThread + 96) = 0;
*((_BYTE *)CurrentThread + 194) = 0;
if( (v6 & 1) == 0 )
{
LODWORD(v14) = _InterlockedExchangeAdd((volatile signed __int32 *)Process + 210, 8u);
if( (v14 & 7) != 0 )
{
KiReleaseThreadLockSafe((INT64)CurrentThread);
KiInSwapSingleProcess((_KTHREAD *)CurrentThread, (_KPROCESS *)Process, CurrentIrql);
KeGetCurrentIrql();
__writecr8(2ui64);
LODWORD(v14) = KiIrqlFlags;
v22 = KeGetCurrentPrcb();
LODWORD(v29[0]) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)CurrentThread + 16, 0i64) )
{
do
{
KeYieldProcessorEx(v29);
v14 = *((_QWORD *)CurrentThread + 8);
}
while( v14 );
v26 = *((_QWORD *)v22 + 4247);
if( v26 && *((_BYTE *)v22 + 32) <= 1u )
{
LODWORD(v14) = *(_DWORD *)(v26 + 24) + 1;
*(_DWORD *)(v26 + 24) = v14;
}
}
v5 = ApcState;
}
}
*((_DWORD *)CurrentThread + 29) |= 0x800u;
*((_QWORD *)CurrentThread + 23) = Process;
if( !v8 )
{
*((_QWORD *)CurrentThread + 8) = 0i64;
v15 = KeGetCurrentPrcb();
if( *((_QWORD *)v15 + 4247) )
{
if( *((_BYTE *)v15 + 32) <= 1u && !(_DWORD)v14 )
v5 = ApcState;
}
}
v16 = KeGetCurrentPrcb();
v17 = *((_QWORD *)CurrentThread + 79);
v18 = *((unsigned __int8 *)v16 + 209);
v19 = 8i64 * *((unsigned __int8 *)v16 + 208) + 376;
_interlockedbittestandset64((volatile signed __int32 *)((char *)Process + v19), v18);
v20 = *((_QWORD *)Process + 5);
if( (_BYTE)KiKvaShadow )
{
v21 = *((_QWORD *)Process + 5);
if( (v20 & 2) != 0 )
v21 = v20 | 0x8000000000000000ui64;
__writegsqword(0x9000u, v21);
KiSetAddressPolicy(*((_BYTE *)Process + 912));
v5 = ApcState;
}
__writecr3(v20);
if( !KiFlushPcid && (_BYTE)KiKvaShadow )
{
v27 = __readcr4();
if( (v27 & 0x20080) != 0 )
{
__writecr4(v27 ^ 0x80);
__writecr4(v27);
}
else
{
v28 = __readcr3();
__writecr3(v28);
}
}
_interlockedbittestandreset64((volatile signed __int32 *)(v19 + v17), v18);
*((_DWORD *)CurrentThread + 29) &= ~0x800u;
if( !v8 )
__writecr8(CurrentIrql);
v5->Process = 0i64;
}
}
}Referenced by:
AlpcViewDestroyProcedure
AlpcpExposeViewAttributeInSenderContext
AlpcpForceUnlinkSecureView
AlpcpPrepareViewForDelivery
AlpcpRestoreWriteAccess
CmEnumerateValueKey
CmpAddRemoveContainerToCLFSLog
CmpAttachToRegistryProcess
CmpFinishSystemHivesLoad
CmpMountPreloadedHives
CmpWalkOneLevel
DbgkQueueUserExceptionReport
DbgkSendSystemDllMessages
DbgkUserReportWorkRoutine
DbgkpMarkProcessPeb
DbgkpPostFakeProcessCreateMessages
EmpMapPhysicalAddress
EtwQueryProcessTelemetryInfo
EtwTraceAppStateChange
EtwpAddRegEntryToGroup
EtwpCovSampEnumerateProcess
EtwpProcessEnumCallback
EtwpPsProvProcessEnumCallback
EtwpRealtimeInjectEtwBuffer
EtwpTiQueryVad
EtwpTrackGuidEntryRegistrations
EtwpUMGLEnabled
EtwpUpdateProcessTracingCallback
EtwpWriteProcessEvent
ExSweepHandleTable
ExpDebuggerWorker
ExpSvmServicePageFault
ExpWnfWriteStateData
IoRaiseHardError
IoRemoveIoCompletion
IopIsNotNativeDriverImage
IopRaiseHardError
KeForceAttachProcess
KeSecureProcess
KiTpReadImageData
KiTpWriteMemory
MiAllocateChildVads
MiAllocateVirtualMemory
MiCloneProcessAddressSpace
MiCombineIdenticalPages
MiCopyLargeVad
MiCopyPagesIntoEnclave
MiDeleteFinalPageTables
MiDeleteInsertedCloneVads
MiEmptyAccessLogs
MiFindNextEnclaveBoundary
MiFlushAllPages
MiGetWorkingSetInfoEx
MiGetWorkingSetInfoList
MiHotPatchAllProcesses
MiInSwapSharedWorkingSetWorker
MiInSwapStoreWorker
MiInsertChildVads
MiIssueHardFault
MiLoadDataIntoVsmEnclave
MiLockDownWorkingSet
MiLogHotPatchRundown
MiMapImageForEnclaveUse
MiMapImageInSystemSpace
MiMapViewOfSection
MiQueryMemoryPhysicalContiguity
MiQueryProcessActivePatches
MiScrubProcesses
MiUnmapImageForEnclaveUse
MiUnmapViewOfSection
MmAssignProcessToJob
MmAttachSession
MmCopyVirtualMemory
MmCreatePeb
MmCreateShadowMapping
MmCreateTeb
MmDeleteShadowMapping
MmDeleteTeb
MmEnforceWorkingSetLimit
MmEnumerateAddressSpaceAndReferenceImages
MmFlushVirtualMemory
MmFreeVirtualMemory
MmInitializeHandBuiltProcess2
MmInitializeProcessAddressSpace
MmIsFileMapped
MmNewProcessInitialized
MmPrefetchVirtualMemory
MmProbeAndLockProcessPages
MmProcessWorkingSetControl
MmSecureVirtualMemoryAgainstWrites
MmSetCommitReleaseEligibility
MmUpdateOldWorkingSetPages
NtCreateEnclave
ObCloseHandleTableEntry
ObSetHandleAttributes
ObpDecrementHandleCount
ObpIncrementHandleCountEx
PfSnAsyncPrefetchWorker
PfSnPopulateReadList
PoEnergyContextStart
PsDispatchIumService
PsMapSystemDlls
PsQueryProcessCommandLine
PsQueryProcessExceptionFlags
PsStartSiloMonitor
PsUnregisterSiloMonitor
PspAllocatePartition
PspAllocateThread
PspApplyWorkingSetLimitsToProcess
PspChangeProcessExecutionState
PspCreateSecureThread
PspDeleteUserStack
PspInitPhase3
PspIsProcessReadyForRemoteThread
PspIumGetPhysicalPage
PspProcessDynamicEHContinuationTargets
PspRundownSingleProcess
PspSetupReservedUserMappings
PspSetupUserProcessAddressSpace
PspSetupUserShadowStack
PspSetupUserStack
PspShutdownCsrProcess
PspTrySetProcessPebThrottlingFlags
PspWow64InitThread
PspWow64ReadOrWriteThreadCpuArea
PspWow64SetupUserStack
PspWritePebAffinityInfo
PspWriteTebIdealProcessor
PspWriteTebImpersonationInfo
SMKM_STORE::SmStCleanup
SMKM_STORE::SmStDirectRead
SMKM_STORE::SmStPrioritizeRegionsStore
SMKM_STORE::SmStSwapStore
SMKM_STORE::SmStTrimWsStore
SepAdtLogAuditRecord
SepCleanupLUIDDeviceMapDirectory
SepRmCallLsa
SmFirstTimeInit
SmProcessStoreMemoryPriorityRequest
VmpPrefetchWorker