SepRegOpenKey
NTSTATUS __stdcall SepRegOpenKey(WCHAR *KeyName, UINT64 Attributes, VOID **pHandle){
unsigned int v3;
INT64 v5;
_UNICODE_STRING v7;
_OBJECT_ATTRIBUTES v8;
*(&v8.Length + 1) = 0;
v3 = Attributes;
*(&v8.Attributes + 1) = 0;
v7 = 0i64;
RtlInitUnicodeString(&v7, KeyName);
v8.RootDirectory = 0i64;
*pHandle = 0i64;
v8.ObjectName = &v7;
v8.Length = 48;
v8.Attributes = 576;
*(_OWORD *)&v8.SecurityDescriptor = 0i64;
return ZwOpenKey(
pHandle,
v3,
&v8,
v5,
*(INT64 *)&v7.Length,
(INT64)v7.Buffer,
*(INT64 *)&v8.Length,
(INT64)v8.RootDirectory);
}Referenced by:
SepAdtOpenRegAndSetupNotification
SepBuildCapPolicyTable
SepReadAndInsertCaps
SepReadAndPopulateCapes
SepRegQueryDwordValue
SepRmFetchGlobalSacl