EtwpTiFillThreadIdentity
NTSTATUS __stdcall EtwpTiFillThreadIdentity(INT64 a1, INT64 a2){
NTSTATUS result;
*(_DWORD *)(a1 + 12) = 0;
*(_DWORD *)(a1 + 28) = 0;
*(_QWORD *)a1 = a2 + 1152;
*(_QWORD *)(a1 + 16) = a2 + 1072;
result = 2;
*(_DWORD *)(a1 + 8) = 4;
*(_DWORD *)(a1 + 24) = 8;
return result;
}Referenced by:
EtwTiLogAllocExecVm
EtwTiLogMapExecView
EtwTiLogProtectExecVm
EtwTiLogReadWriteVm
EtwTiLogSetContextThread
EtwTiLogSuspendResumeProcess
EtwTiLogSuspendResumeThread
EtwTimLogProhibitChildProcessCreation
EtwTimLogProhibitLowILImageMap
EtwTimLogProhibitNonMicrosoftBinaries
EtwpTimLogMitigationForProcess