KiTpBuildExcludedKernelTracepointRangeList

_RTL_RANGE_LIST *__stdcall KiTpBuildExcludedKernelTracepointRangeList(INT64 a1, INT64 a2, UINT64 a3){
  VOID **PoolWithTag; 
  _RTL_RANGE_LIST *v4; 
  UINT64 v5; 
  __int64 v6; 
  ULONGLONG v7; 
  _IMAGE_ARM64_RUNTIME_FUNCTION_ENTRY *v8; 
  UINT64 Flags; 
  UINT64 ImageBase; 

  PoolWithTag = ExAllocatePoolWithTag(1ui64, 0x20ui64, 1886549062i64);
  v4 = (_RTL_RANGE_LIST *)PoolWithTag;
  if( PoolWithTag )
  {
    *((_DWORD *)PoolWithTag + 4) = 0;
    *((_DWORD *)PoolWithTag + 5) = 0;
    *((_DWORD *)PoolWithTag + 6) = 0;
    v5 = KiTpExcludedRoutines;
    LODWORD(v6) = 0;
    PoolWithTag[1] = PoolWithTag;
    *PoolWithTag = PoolWithTag;
    while( 1 )
    {
      ImageBase = 0i64;
      v7 = v5;
      v8 = RtlLookupFunctionEntry(v5, &ImageBase, 0i64);
      if( v8 )
        v7 = ImageBase + v8->UnwindData;
      LODWORD(Flags) = 1;
      if( RtlAddRange(v4, v5, v7, 0, Flags, 0i64, 0i64) < 0 )
        break;
      v6 = (unsigned int)(v6 + 1);
      v5 = *(&KiTpExcludedRoutines + v6);
      if( !v5 )
        return v4;
    }
    RtlFreeRangeList(v4);
    ExFreePoolWithTag(v4, 0x70727446u);
  }
  return 0i64;
}

Referenced by:

KiTpIsExcludedKernelTracepointLocation