SepAdtOpenEtwReadyEvent

NTSTATUS __stdcall SepAdtOpenEtwReadyEvent(VOID **EventHandle){
  NTSTATUS result; 
  _UNICODE_STRING v3; 
  INT64 v4; 
  __int64 v5; 
  _UNICODE_STRING *v6; 
  int v7; 
  int v8; 
  __int128 v9; 

  HIDWORD(v4) = 0;
  v8 = 0;
  v3 = 0i64;
  RtlInitUnicodeString(&v3, L"\\ADT_ETW_CHANNEL_INIT");
  v5 = 0i64;
  v6 = &v3;
  LODWORD(v4) = 48;
  v7 = 640;
  v9 = 0i64;
  result = NtCreateEvent((UINT64)EventHandle, 0x100003ui64, (INT64)&v4, 0i64, 0);
  if( result == 0x40000000 || result == -1073741771 )
    return 0;
  return result;
}

Referenced by:

SepAdtInitializeAuditingOptions
SepRmCallLsa