SepAdtOpenObjectAuditAlarm
bool __fastcall SepAdtOpenObjectAuditAlarm(
unsigned __int16 a1,
__int64 a2,
unsigned __int64 *a3,
unsigned __int16 *a4,
__int64 a5,
PVOID a6,
__int64 a7,
__int64 a8,
int a9,
int a10,
__int64 a11,
char a12,
__int64 a13,
int a14,
__int64 a15,
int a16,
__int64 a17,
__int64 a18,
__int64 a19){
SECURITY_DESCRIPTOR *v19;
ULONG_PTR v21;
void *v22;
__int128 *v24;
__int64 CurrentThreadProcess;
int AllocatedFullProcessImageName;
unsigned __int8 **v27;
ULONG_PTR v28;
char v29;
ULONG v30;
unsigned __int16 *v31;
ULONG_PTR v32;
int v33;
ULONG v34;
ULONG v35;
int v36;
UINT8 IsKernelHandle;
unsigned __int64 v38;
__int64 v39;
unsigned __int64 v40;
ULONG_PTR v41;
__int64 v42;
__int64 v43;
UINT8 *v44;
int v45;
UINT64 v46;
char *PoolWithTag;
char *v48;
int v49;
__int64 v50;
ULONG_PTR v51;
int v52;
unsigned int v53;
unsigned int v54;
__int64 v55;
unsigned __int16 v56;
_WORD *v57;
char *v58;
_OWORD *v59;
__int64 v60;
unsigned int v61;
_DWORD *v62;
void *v63;
__int64 v64;
int v65;
__int64 v66;
unsigned __int16 *v67;
int v68;
ULONG ParameterCount;
int v70;
NTSTATUS v71;
SECURITY_DESCRIPTOR *v72;
ULONG v73;
UINT8 NeedToFree[8];
void *Src;
size_t Size;
PVOID v77;
unsigned __int16 *v78;
__int64 v79;
SECURITY_DESCRIPTOR *SecurityDescriptorOut;
PVOID v81;
PVOID P;
__int64 v83;
unsigned __int8 *v84;
unsigned __int64 *v85;
__int128 *v86;
SECURITY_DESCRIPTOR *v87;
SECURITY_SUBJECT_CONTEXT SubjectSecurityContext;
_SE_ADT_PARAMETER_ARRAY result;
__int128 v90;
v19 = (SECURITY_DESCRIPTOR *)a6;
*(_WORD *)&NeedToFree[4] = a1;
v21 = 0i64;
v83 = a19;
v22 = 0i64;
v85 = a3;
v78 = (unsigned __int16 *)a2;
v79 = a8;
SubjectSecurityContext.PrimaryToken = (void *)a8;
v87 = (SECURITY_DESCRIPTOR *)a6;
SecurityDescriptorOut = (SECURITY_DESCRIPTOR *)a6;
v81 = 0i64;
P = 0i64;
*(_QWORD *)&SubjectSecurityContext.ImpersonationLevel = 0i64;
SubjectSecurityContext.ProcessAuditId = 0i64;
v90 = 0i64;
Size = 0i64;
Src = 0i64;
v77 = 0i64;
NeedToFree[1] = 0;
NeedToFree[2] = 0;
NeedToFree[0] = 0;
SubjectSecurityContext.ClientToken = (void *)a7;
if( !SepAdtAuditThisEventWithContext(0x7Bui64, a12, a12 == 0, &SubjectSecurityContext) )
return 1;
v24 = &v90;
if( a18 )
v24 = (__int128 *)a18;
v86 = v24;
CurrentThreadProcess = PsGetCurrentThreadProcess();
AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
if( AllocatedFullProcessImageName >= 0 )
{
if( a7 )
{
v21 = *(_QWORD *)(a7 + 24);
v27 = *(unsigned __int8 ***)(a7 + 152);
}
else
{
v27 = *(unsigned __int8 ***)(v79 + 152);
}
v28 = *(_QWORD *)(v79 + 24);
v84 = *v27;
memset((INT64)&result, 0i64);
v29 = a12;
v30 = 8;
result.AuditId = 4656;
result.FlatSubCategoryId = *(_WORD *)&NeedToFree[4];
result.Type = 8;
if( a14 == 2 )
v30 = 3;
result.CategoryId = v30;
if( !a12 )
result.Type = 16;
v31 = (unsigned __int16 *)&SeSubsystemName;
v32 = 4i64;
result.Parameters[0].Address = v84;
if( v78 )
v31 = v78;
result.Parameters[0].Type = SeAdtParmTypeSid;
result.Parameters[1].Type = SeAdtParmTypeString;
v33 = v84[1];
result.Parameters[1].Address = v31;
result.Parameters[2].Type = SeAdtParmTypeLogonId;
result.Parameters[2].Length = 8;
result.Parameters[2].Data[0] = v21;
result.Parameters[0].Length = 4 * v33 + 8;
v34 = *v31 + 16;
result.Parameters[1].Length = v34;
if( !a7 )
result.Parameters[2].Data[0] = v28;
result.Parameters[3].Type = SeAdtParmTypeString;
result.Parameters[3].Length = v34;
result.Parameters[3].Address = v31;
if( !a4 )
{
AllocatedFullProcessImageName = -1073741811;
LABEL_19:
v22 = Src;
goto LABEL_20;
}
v35 = *a4 + 16;
result.Parameters[4].Address = a4;
result.Parameters[4].Length = v35;
result.Parameters[4].Type = SeAdtParmTypeString;
if( a5 )
{
if( *(_WORD *)&NeedToFree[4] == 116
|| (result.Parameters[5].Type = SeAdtParmTypeString, *(_WORD *)&NeedToFree[4] == 128) )
{
result.Parameters[5].Type = SeAdtParmTypeFileSpec;
}
v36 = *(unsigned __int16 *)a5;
result.Parameters[5].Address = (PVOID)a5;
result.Parameters[5].Length = v36 + 16;
}
result.Parameters[6].Type = SeAdtParmTypePtr;
result.Parameters[6].Length = 8;
if( v85 )
{
IsKernelHandle = ObpIsKernelHandle((PVOID)*v85, 0);
v40 = v39 ^ 0xFFFFFFFF80000000ui64;
if( !IsKernelHandle )
v40 = v38;
result.Parameters[6].Data[0] = v40 & 0xFFFFFFFFFFFFFFFCui64;
}
else
{
result.Parameters[6].Data[0] = 0i64;
}
result.Parameters[7].Address = v86;
v41 = (unsigned int)a10;
result.Parameters[7].Type = SeAdtParmTypeGuid;
result.Parameters[7].Length = 16;
result.Parameters[8].Type = SeAdtParmTypeAccessMask;
result.Parameters[8].Length = v32;
result.Parameters[8].Data[1] = v32;
if( !v29 )
v41 = (unsigned int)a9;
v42 = v83;
result.Parameters[8].Data[0] = v41;
if( v83 && (v43 = *(_QWORD *)(v83 + 72)) != 0 )
{
AllocatedFullProcessImageName = SepCheckAndCopySelfRelativeSD(
*(SECURITY_DESCRIPTOR **)(v43 + 56),
(SECURITY_DESCRIPTOR **)&Src,
(size_t *)((char *)&Size + 4),
&NeedToFree[1]);
if( AllocatedFullProcessImageName < 0 )
goto LABEL_102;
AllocatedFullProcessImageName = SepCheckAndCopySelfRelativeSD(
*(SECURITY_DESCRIPTOR **)(*(_QWORD *)(v42 + 72) + 64i64),
(SECURITY_DESCRIPTOR **)&v77,
&Size,
&NeedToFree[2]);
if( AllocatedFullProcessImageName < 0 )
goto LABEL_102;
v44 = (UINT8 *)Src;
if( Src || v77 )
{
v45 = 8;
goto LABEL_55;
}
}
else
{
v44 = (UINT8 *)Src;
}
v45 = 0;
LABEL_55:
v46 = HIDWORD(Size);
LODWORD(v78) = HIDWORD(Size) + Size - v45 + 152;
PoolWithTag = (char *)ExAllocatePoolWithTag(PagedPool, (unsigned int)v78, 0x70416553ui64);
v48 = PoolWithTag;
if( !PoolWithTag )
{
AllocatedFullProcessImageName = -1073741670;
goto LABEL_19;
}
memset((INT64)PoolWithTag, 0i64);
v49 = a10;
*((_DWORD *)v48 + 34) = (unsigned __int8)a12;
if( !a12 )
v49 = a9;
*((_DWORD *)v48 + 33) = 4;
*(_DWORD *)v48 = v49 & 0xFDFFFFFF;
if( v83 )
{
v50 = *(_QWORD *)(v83 + 72);
if( v50 )
{
*(_OWORD *)(v48 + 4) = *(_OWORD *)(v50 + 88);
*(_OWORD *)(v48 + 20) = *(_OWORD *)(v50 + 104);
*(_OWORD *)(v48 + 36) = *(_OWORD *)(v50 + 120);
*(_OWORD *)(v48 + 52) = *(_OWORD *)(v50 + 136);
*(_OWORD *)(v48 + 68) = *(_OWORD *)(v50 + 152);
*(_OWORD *)(v48 + 84) = *(_OWORD *)(v50 + 168);
*(_OWORD *)(v48 + 100) = *(_OWORD *)(v50 + 184);
*(_OWORD *)(v48 + 116) = *(_OWORD *)(v50 + 200);
}
}
if( v44 )
memmove((UINT8 *)v48 + 144, v44, v46);
if( v77 )
memmove((UINT8 *)&v48[v46 + 144], (UINT8 *)v77, (unsigned int)Size);
result.Parameters[9].Length = (unsigned int)v78;
v51 = (unsigned int)a10;
result.Parameters[9].Type = SeAdtParmTypeAccessReason;
result.Parameters[9].Address = v48;
result.Parameters[10].Type = SeAdtParmTypeHexUlong;
result.Parameters[10].Length = 4;
if( !a12 )
v51 = (unsigned int)a9;
result.Parameters[10].Data[0] = v51;
if( a11 )
{
v52 = *(_DWORD *)a11;
if( *(_DWORD *)a11 )
{
result.Parameters[11].Type = SeAdtParmTypePrivs;
result.Parameters[11].Address = (PVOID)a11;
result.Parameters[11].Length = 12 * v52 + 8;
}
}
v53 = 12;
result.ParameterCount = 12;
if( a16 )
{
v54 = 0;
v55 = 0i64;
v56 = 2 - (a12 != 0);
v57 = (_WORD *)(a15 + 2);
do
{
if( !v54 || (v56 & *v57) != 0 )
v55 = (unsigned int)(v55 + 1);
++v54;
v57 += 24;
}
while( v54 < a16 );
if( (_DWORD)v55 )
{
v58 = (char *)ExAllocatePoolWithTag(PagedPool, 24 * v55, 0x70416553ui64);
v81 = v58;
if( !v58 )
{
AllocatedFullProcessImageName = -1073741670;
LABEL_101:
ExFreePoolWithTag(v48, 0);
LABEL_102:
v22 = Src;
goto LABEL_20;
}
v59 = (_OWORD *)(a15 + 4);
v60 = 0i64;
v61 = 0;
v62 = (_DWORD *)a17;
v63 = v58;
do
{
if( !v61 || (v56 & *((_WORD *)v59 - 1)) != 0 )
{
v64 = 3 * v60;
*(_OWORD *)&v58[8 * v64] = *v59;
*(_WORD *)&v58[8 * v64 + 18] = *((_WORD *)v59 - 2);
if( v61 )
{
*(_WORD *)&v58[24 * v60 + 16] = 0;
if( a17 && a12 )
*(_DWORD *)&v58[24 * v60 + 20] = *v62;
}
else
{
*(_WORD *)&v58[24 * v60 + 16] = 1;
*(_DWORD *)&v58[24 * v60 + 20] = 0;
}
v60 = (unsigned int)(v60 + 1);
}
++v61;
v59 += 3;
++v62;
}
while( v61 < a16 );
v65 = 3 * v60;
result.Parameters[12].Address = v63;
v19 = v87;
v53 = 13;
result.Parameters[12].Length = 8 * v65;
result.Parameters[12].Type = SeAdtParmTypeObjectTypes;
result.Parameters[12].Data[1] = 4i64;
result.ParameterCount = 13;
result.AuditId = 4661;
}
}
v66 = v53;
v67 = (unsigned __int16 *)P;
result.Parameters[v66].Type = SeAdtParmTypeUlongNoConv;
result.Parameters[result.ParameterCount].Length = 4;
result.Parameters[result.ParameterCount++].Data[0] = *(unsigned int *)(v79 + 128);
result.Parameters[result.ParameterCount].Type = SeAdtParmTypePtr;
result.Parameters[result.ParameterCount].Length = 8;
result.Parameters[result.ParameterCount++].Data[0] = a13;
result.Parameters[result.ParameterCount].Type = SeAdtParmTypeFileSpec;
result.Parameters[result.ParameterCount].Length = *v67 + 16;
v68 = *(unsigned __int16 *)&NeedToFree[4];
result.Parameters[result.ParameterCount].Address = v67;
ParameterCount = ++result.ParameterCount;
v70 = v68 - 116;
if( (!v70 || v70 == 12) && v19 && result.AuditId == 4656 && SepSDContainsAttributeACE(v19) )
{
v71 = SepCheckAndCopySelfRelativeSD(v19, &SecurityDescriptorOut, (size_t *)((char *)&Size + 4), NeedToFree);
v19 = SecurityDescriptorOut;
AllocatedFullProcessImageName = v71;
if( v71 < 0 )
goto LABEL_99;
v72 = SecurityDescriptorOut;
result.Parameters[ParameterCount].Type = SeAdtParmTypeResourceAttribute;
v73 = SepSecurityDescriptorStrictLength(v72);
result.Parameters[result.ParameterCount].Length = v73;
result.Parameters[result.ParameterCount].Address = v19;
result.Parameters[result.ParameterCount].Data[0] = 32i64;
result.Parameters[result.ParameterCount].Data[1] = 0i64;
ParameterCount = result.ParameterCount;
}
result.ParameterCount = ParameterCount + 1;
SepAdtLogAuditRecord(&result);
LABEL_99:
if( v81 )
ExFreePoolWithTag(v81, 0);
goto LABEL_101;
}
LABEL_20:
if( P )
ExFreePoolWithTag(P, 0);
if( NeedToFree[0] && v19 )
ExFreePoolWithTag(v19, 0);
if( NeedToFree[1] && v22 )
ExFreePoolWithTag(v22, 0);
if( NeedToFree[2] && v77 )
ExFreePoolWithTag(v77, 0);
if( AllocatedFullProcessImageName < 0 )
SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
return AllocatedFullProcessImageName >= 0;
}Referenced by:
NtOpenObjectAuditAlarm
ObpCreateHandle
SeAuditHandleCreation
SeOpenObjectAuditAlarmForNonObObject
SeOpenObjectAuditAlarmWithTransaction
SeOpenObjectForDeleteAuditAlarmWithTransaction
SepAccessCheckAndAuditAlarmWithAdminlessChecks