EtwpTiFillThreadIdentity

NTSTATUS __stdcall EtwpTiFillThreadIdentity(INT64 a1, INT64 a2){
  NTSTATUS result; 

  *(_DWORD *)(a1 + 12) = 0;
  *(_DWORD *)(a1 + 28) = 0;
  *(_QWORD *)a1 = a2 + 1152;
  *(_QWORD *)(a1 + 16) = a2 + 1072;
  result = 2;
  *(_DWORD *)(a1 + 8) = 4;
  *(_DWORD *)(a1 + 24) = 8;
  return result;
}

Referenced by:

EtwTiLogAllocExecVm
EtwTiLogMapExecView
EtwTiLogProtectExecVm
EtwTiLogReadWriteVm
EtwTiLogSetContextThread
EtwTiLogSuspendResumeProcess
EtwTiLogSuspendResumeThread
EtwTimLogProhibitChildProcessCreation
EtwTimLogProhibitLowILImageMap
EtwTimLogProhibitNonMicrosoftBinaries
EtwpTimLogMitigationForProcess