KeQueryKvaShadowRegion

NTSTATUS __stdcall KeQueryKvaShadowRegion(INT64 a1, UINT64 **a2, UINT64 *a3){
  INT64 v5; 
  unsigned __int64 v6; 
  _DWORD *v7; 
  unsigned int v8; 
  unsigned int v9; 
  struct _KPRCB *CurrentPrcb; 
  KPCR *Pcr; 

  if( !a1 )
  {
    Pcr = KeGetPcr();
    *a3 = 20480i64;
    *a2 = (UINT64 *)&Pcr->NtTib.ExceptionList[-763];
    return 1;
  }
  v5 = a1 - 1;
  if( !v5 )
  {
    CurrentPrcb = KeGetCurrentPrcb();
    *a3 = 4096i64;
    *a2 = &CurrentPrcb->KernelDirectoryTableBase;
    return 1;
  }
  if( v5 == 1 )
  {
    LODWORD(v6) = RtlImageNtHeader(0x140000000ui64);
    v7 = (_DWORD *)RtlSectionTableFromVirtualAddress(
                     v6,
                     0x140000000i64,
                     (unsigned int)KiDivideErrorFaultShadow - 0x40000000);
    *a2 = (UINT64 *)(0x140000000i64 + (unsigned int)v7[3]);
    v8 = v7[2];
    v9 = v7[4];
    if( v8 <= v9 )
      v8 = v9;
    *a3 = (v8 + 4095i64) & 0xFFFFFFFFFFFFF000ui64;
    return 1;
  }
  return 0;
}

Referenced by:

MiCheckRelevantKernelShadows