SepAdtOpenObjectAuditAlarm

bool __fastcall SepAdtOpenObjectAuditAlarm(
        unsigned __int16 a1,
        __int64 a2,
        unsigned __int64 *a3,
        unsigned __int16 *a4,
        __int64 a5,
        PVOID a6,
        __int64 a7,
        __int64 a8,
        int a9,
        int a10,
        __int64 a11,
        char a12,
        __int64 a13,
        int a14,
        __int64 a15,
        int a16,
        __int64 a17,
        __int64 a18,
        __int64 a19){
  SECURITY_DESCRIPTOR *v19; 
  ULONG_PTR v21; 
  void *v22; 
  __int128 *v24; 
  __int64 CurrentThreadProcess; 
  int AllocatedFullProcessImageName; 
  unsigned __int8 **v27; 
  ULONG_PTR v28; 
  char v29; 
  ULONG v30; 
  unsigned __int16 *v31; 
  ULONG_PTR v32; 
  int v33; 
  ULONG v34; 
  ULONG v35; 
  int v36; 
  UINT8 IsKernelHandle; 
  unsigned __int64 v38; 
  __int64 v39; 
  unsigned __int64 v40; 
  ULONG_PTR v41; 
  __int64 v42; 
  __int64 v43; 
  UINT8 *v44; 
  int v45; 
  UINT64 v46; 
  char *PoolWithTag; 
  char *v48; 
  int v49; 
  __int64 v50; 
  ULONG_PTR v51; 
  int v52; 
  unsigned int v53; 
  unsigned int v54; 
  __int64 v55; 
  unsigned __int16 v56; 
  _WORD *v57; 
  char *v58; 
  _OWORD *v59; 
  __int64 v60; 
  unsigned int v61; 
  _DWORD *v62; 
  void *v63; 
  __int64 v64; 
  int v65; 
  __int64 v66; 
  unsigned __int16 *v67; 
  int v68; 
  ULONG ParameterCount; 
  int v70; 
  NTSTATUS v71; 
  SECURITY_DESCRIPTOR *v72; 
  ULONG v73; 
  UINT8 NeedToFree[8]; 
  void *Src; 
  size_t Size; 
  PVOID v77; 
  unsigned __int16 *v78; 
  __int64 v79; 
  SECURITY_DESCRIPTOR *SecurityDescriptorOut; 
  PVOID v81; 
  PVOID P; 
  __int64 v83; 
  unsigned __int8 *v84; 
  unsigned __int64 *v85; 
  __int128 *v86; 
  SECURITY_DESCRIPTOR *v87; 
  SECURITY_SUBJECT_CONTEXT SubjectSecurityContext; 
  _SE_ADT_PARAMETER_ARRAY result; 
  __int128 v90; 
  v19 = (SECURITY_DESCRIPTOR *)a6;
  *(_WORD *)&NeedToFree[4] = a1;
  v21 = 0i64;
  v83 = a19;
  v22 = 0i64;
  v85 = a3;
  v78 = (unsigned __int16 *)a2;
  v79 = a8;
  SubjectSecurityContext.PrimaryToken = (void *)a8;
  v87 = (SECURITY_DESCRIPTOR *)a6;
  SecurityDescriptorOut = (SECURITY_DESCRIPTOR *)a6;
  v81 = 0i64;
  P = 0i64;
  *(_QWORD *)&SubjectSecurityContext.ImpersonationLevel = 0i64;
  SubjectSecurityContext.ProcessAuditId = 0i64;
  v90 = 0i64;
  Size = 0i64;
  Src = 0i64;
  v77 = 0i64;
  NeedToFree[1] = 0;
  NeedToFree[2] = 0;
  NeedToFree[0] = 0;
  SubjectSecurityContext.ClientToken = (void *)a7;
  if( !SepAdtAuditThisEventWithContext(0x7Bui64, a12, a12 == 0, &SubjectSecurityContext) )
    return 1;
  v24 = &v90;
  if( a18 )
    v24 = (__int128 *)a18;
  v86 = v24;
  CurrentThreadProcess = PsGetCurrentThreadProcess();
  AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
  if( AllocatedFullProcessImageName >= 0 )
  {
    if( a7 )
    {
      v21 = *(_QWORD *)(a7 + 24);
      v27 = *(unsigned __int8 ***)(a7 + 152);
    }
    else
    {
      v27 = *(unsigned __int8 ***)(v79 + 152);
    }
    v28 = *(_QWORD *)(v79 + 24);
    v84 = *v27;
    memset((INT64)&result, 0i64);
    v29 = a12;
    v30 = 8;
    result.AuditId = 4656;
    result.FlatSubCategoryId = *(_WORD *)&NeedToFree[4];
    result.Type = 8;
    if( a14 == 2 )
      v30 = 3;
    result.CategoryId = v30;
    if( !a12 )
      result.Type = 16;
    v31 = (unsigned __int16 *)&SeSubsystemName;
    v32 = 4i64;
    result.Parameters[0].Address = v84;
    if( v78 )
      v31 = v78;
    result.Parameters[0].Type = SeAdtParmTypeSid;
    result.Parameters[1].Type = SeAdtParmTypeString;
    v33 = v84[1];
    result.Parameters[1].Address = v31;
    result.Parameters[2].Type = SeAdtParmTypeLogonId;
    result.Parameters[2].Length = 8;
    result.Parameters[2].Data[0] = v21;
    result.Parameters[0].Length = 4 * v33 + 8;
    v34 = *v31 + 16;
    result.Parameters[1].Length = v34;
    if( !a7 )
      result.Parameters[2].Data[0] = v28;
    result.Parameters[3].Type = SeAdtParmTypeString;
    result.Parameters[3].Length = v34;
    result.Parameters[3].Address = v31;
    if( !a4 )
    {
      AllocatedFullProcessImageName = -1073741811;
LABEL_19:
      v22 = Src;
      goto LABEL_20;
    }
    v35 = *a4 + 16;
    result.Parameters[4].Address = a4;
    result.Parameters[4].Length = v35;
    result.Parameters[4].Type = SeAdtParmTypeString;
    if( a5 )
    {
      if( *(_WORD *)&NeedToFree[4] == 116
        || (result.Parameters[5].Type = SeAdtParmTypeString, *(_WORD *)&NeedToFree[4] == 128) )
      {
        result.Parameters[5].Type = SeAdtParmTypeFileSpec;
      }
      v36 = *(unsigned __int16 *)a5;
      result.Parameters[5].Address = (PVOID)a5;
      result.Parameters[5].Length = v36 + 16;
    }
    result.Parameters[6].Type = SeAdtParmTypePtr;
    result.Parameters[6].Length = 8;
    if( v85 )
    {
      IsKernelHandle = ObpIsKernelHandle((PVOID)*v85, 0);
      v40 = v39 ^ 0xFFFFFFFF80000000ui64;
      if( !IsKernelHandle )
        v40 = v38;
      result.Parameters[6].Data[0] = v40 & 0xFFFFFFFFFFFFFFFCui64;
    }
    else
    {
      result.Parameters[6].Data[0] = 0i64;
    }
    result.Parameters[7].Address = v86;
    v41 = (unsigned int)a10;
    result.Parameters[7].Type = SeAdtParmTypeGuid;
    result.Parameters[7].Length = 16;
    result.Parameters[8].Type = SeAdtParmTypeAccessMask;
    result.Parameters[8].Length = v32;
    result.Parameters[8].Data[1] = v32;
    if( !v29 )
      v41 = (unsigned int)a9;
    v42 = v83;
    result.Parameters[8].Data[0] = v41;
    if( v83 && (v43 = *(_QWORD *)(v83 + 72)) != 0 )
    {
      AllocatedFullProcessImageName = SepCheckAndCopySelfRelativeSD(
                                        *(SECURITY_DESCRIPTOR **)(v43 + 56),
                                        (SECURITY_DESCRIPTOR **)&Src,
                                        (size_t *)((char *)&Size + 4),
                                        &NeedToFree[1]);
      if( AllocatedFullProcessImageName < 0 )
        goto LABEL_102;
      AllocatedFullProcessImageName = SepCheckAndCopySelfRelativeSD(
                                        *(SECURITY_DESCRIPTOR **)(*(_QWORD *)(v42 + 72) + 64i64),
                                        (SECURITY_DESCRIPTOR **)&v77,
                                        &Size,
                                        &NeedToFree[2]);
      if( AllocatedFullProcessImageName < 0 )
        goto LABEL_102;
      v44 = (UINT8 *)Src;
      if( Src || v77 )
      {
        v45 = 8;
        goto LABEL_55;
      }
    }
    else
    {
      v44 = (UINT8 *)Src;
    }
    v45 = 0;
LABEL_55:
    v46 = HIDWORD(Size);
    LODWORD(v78) = HIDWORD(Size) + Size - v45 + 152;
    PoolWithTag = (char *)ExAllocatePoolWithTag(PagedPool, (unsigned int)v78, 0x70416553ui64);
    v48 = PoolWithTag;
    if( !PoolWithTag )
    {
      AllocatedFullProcessImageName = -1073741670;
      goto LABEL_19;
    }
    memset((INT64)PoolWithTag, 0i64);
    v49 = a10;
    *((_DWORD *)v48 + 34) = (unsigned __int8)a12;
    if( !a12 )
      v49 = a9;
    *((_DWORD *)v48 + 33) = 4;
    *(_DWORD *)v48 = v49 & 0xFDFFFFFF;
    if( v83 )
    {
      v50 = *(_QWORD *)(v83 + 72);
      if( v50 )
      {
        *(_OWORD *)(v48 + 4) = *(_OWORD *)(v50 + 88);
        *(_OWORD *)(v48 + 20) = *(_OWORD *)(v50 + 104);
        *(_OWORD *)(v48 + 36) = *(_OWORD *)(v50 + 120);
        *(_OWORD *)(v48 + 52) = *(_OWORD *)(v50 + 136);
        *(_OWORD *)(v48 + 68) = *(_OWORD *)(v50 + 152);
        *(_OWORD *)(v48 + 84) = *(_OWORD *)(v50 + 168);
        *(_OWORD *)(v48 + 100) = *(_OWORD *)(v50 + 184);
        *(_OWORD *)(v48 + 116) = *(_OWORD *)(v50 + 200);
      }
    }
    if( v44 )
      memmove((UINT8 *)v48 + 144, v44, v46);
    if( v77 )
      memmove((UINT8 *)&v48[v46 + 144], (UINT8 *)v77, (unsigned int)Size);
    result.Parameters[9].Length = (unsigned int)v78;
    v51 = (unsigned int)a10;
    result.Parameters[9].Type = SeAdtParmTypeAccessReason;
    result.Parameters[9].Address = v48;
    result.Parameters[10].Type = SeAdtParmTypeHexUlong;
    result.Parameters[10].Length = 4;
    if( !a12 )
      v51 = (unsigned int)a9;
    result.Parameters[10].Data[0] = v51;
    if( a11 )
    {
      v52 = *(_DWORD *)a11;
      if( *(_DWORD *)a11 )
      {
        result.Parameters[11].Type = SeAdtParmTypePrivs;
        result.Parameters[11].Address = (PVOID)a11;
        result.Parameters[11].Length = 12 * v52 + 8;
      }
    }
    v53 = 12;
    result.ParameterCount = 12;
    if( a16 )
    {
      v54 = 0;
      v55 = 0i64;
      v56 = 2 - (a12 != 0);
      v57 = (_WORD *)(a15 + 2);
      do
      {
        if( !v54 || (v56 & *v57) != 0 )
          v55 = (unsigned int)(v55 + 1);
        ++v54;
        v57 += 24;
      }
      while( v54 < a16 );
      if( (_DWORD)v55 )
      {
        v58 = (char *)ExAllocatePoolWithTag(PagedPool, 24 * v55, 0x70416553ui64);
        v81 = v58;
        if( !v58 )
        {
          AllocatedFullProcessImageName = -1073741670;
LABEL_101:
          ExFreePoolWithTag(v48, 0);
LABEL_102:
          v22 = Src;
          goto LABEL_20;
        }
        v59 = (_OWORD *)(a15 + 4);
        v60 = 0i64;
        v61 = 0;
        v62 = (_DWORD *)a17;
        v63 = v58;
        do
        {
          if( !v61 || (v56 & *((_WORD *)v59 - 1)) != 0 )
          {
            v64 = 3 * v60;
            *(_OWORD *)&v58[8 * v64] = *v59;
            *(_WORD *)&v58[8 * v64 + 18] = *((_WORD *)v59 - 2);
            if( v61 )
            {
              *(_WORD *)&v58[24 * v60 + 16] = 0;
              if( a17 && a12 )
                *(_DWORD *)&v58[24 * v60 + 20] = *v62;
            }
            else
            {
              *(_WORD *)&v58[24 * v60 + 16] = 1;
              *(_DWORD *)&v58[24 * v60 + 20] = 0;
            }
            v60 = (unsigned int)(v60 + 1);
          }
          ++v61;
          v59 += 3;
          ++v62;
        }
        while( v61 < a16 );
        v65 = 3 * v60;
        result.Parameters[12].Address = v63;
        v19 = v87;
        v53 = 13;
        result.Parameters[12].Length = 8 * v65;
        result.Parameters[12].Type = SeAdtParmTypeObjectTypes;
        result.Parameters[12].Data[1] = 4i64;
        result.ParameterCount = 13;
        result.AuditId = 4661;
      }
    }
    v66 = v53;
    v67 = (unsigned __int16 *)P;
    result.Parameters[v66].Type = SeAdtParmTypeUlongNoConv;
    result.Parameters[result.ParameterCount].Length = 4;
    result.Parameters[result.ParameterCount++].Data[0] = *(unsigned int *)(v79 + 128);
    result.Parameters[result.ParameterCount].Type = SeAdtParmTypePtr;
    result.Parameters[result.ParameterCount].Length = 8;
    result.Parameters[result.ParameterCount++].Data[0] = a13;
    result.Parameters[result.ParameterCount].Type = SeAdtParmTypeFileSpec;
    result.Parameters[result.ParameterCount].Length = *v67 + 16;
    v68 = *(unsigned __int16 *)&NeedToFree[4];
    result.Parameters[result.ParameterCount].Address = v67;
    ParameterCount = ++result.ParameterCount;
    v70 = v68 - 116;
    if( (!v70 || v70 == 12) && v19 && result.AuditId == 4656 && SepSDContainsAttributeACE(v19) )
    {
      v71 = SepCheckAndCopySelfRelativeSD(v19, &SecurityDescriptorOut, (size_t *)((char *)&Size + 4), NeedToFree);
      v19 = SecurityDescriptorOut;
      AllocatedFullProcessImageName = v71;
      if( v71 < 0 )
        goto LABEL_99;
      v72 = SecurityDescriptorOut;
      result.Parameters[ParameterCount].Type = SeAdtParmTypeResourceAttribute;
      v73 = SepSecurityDescriptorStrictLength(v72);
      result.Parameters[result.ParameterCount].Length = v73;
      result.Parameters[result.ParameterCount].Address = v19;
      result.Parameters[result.ParameterCount].Data[0] = 32i64;
      result.Parameters[result.ParameterCount].Data[1] = 0i64;
      ParameterCount = result.ParameterCount;
    }
    result.ParameterCount = ParameterCount + 1;
    SepAdtLogAuditRecord(&result);
LABEL_99:
    if( v81 )
      ExFreePoolWithTag(v81, 0);
    goto LABEL_101;
  }
LABEL_20:
  if( P )
    ExFreePoolWithTag(P, 0);
  if( NeedToFree[0] && v19 )
    ExFreePoolWithTag(v19, 0);
  if( NeedToFree[1] && v22 )
    ExFreePoolWithTag(v22, 0);
  if( NeedToFree[2] && v77 )
    ExFreePoolWithTag(v77, 0);
  if( AllocatedFullProcessImageName < 0 )
    SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
  return AllocatedFullProcessImageName >= 0;
}

Referenced by:

NtOpenObjectAuditAlarm
ObpCreateHandle
SeAuditHandleCreation
SeOpenObjectAuditAlarmForNonObObject
SeOpenObjectAuditAlarmWithTransaction
SeOpenObjectForDeleteAuditAlarmWithTransaction
SepAccessCheckAndAuditAlarmWithAdminlessChecks