KeQueryKvaShadowRegion
NTSTATUS __stdcall KeQueryKvaShadowRegion(INT64 a1, UINT64 **a2, UINT64 *a3){
INT64 v5;
unsigned __int64 v6;
_DWORD *v7;
unsigned int v8;
unsigned int v9;
struct _KPRCB *CurrentPrcb;
KPCR *Pcr;
if( !a1 )
{
Pcr = KeGetPcr();
*a3 = 20480i64;
*a2 = (UINT64 *)&Pcr->NtTib.ExceptionList[-763];
return 1;
}
v5 = a1 - 1;
if( !v5 )
{
CurrentPrcb = KeGetCurrentPrcb();
*a3 = 4096i64;
*a2 = &CurrentPrcb->KernelDirectoryTableBase;
return 1;
}
if( v5 == 1 )
{
LODWORD(v6) = RtlImageNtHeader(0x140000000ui64);
v7 = (_DWORD *)RtlSectionTableFromVirtualAddress(
v6,
0x140000000i64,
(unsigned int)KiDivideErrorFaultShadow - 0x40000000);
*a2 = (UINT64 *)(0x140000000i64 + (unsigned int)v7[3]);
v8 = v7[2];
v9 = v7[4];
if( v8 <= v9 )
v8 = v9;
*a3 = (v8 + 4095i64) & 0xFFFFFFFFFFFFF000ui64;
return 1;
}
return 0;
}Referenced by:
MiCheckRelevantKernelShadows