AlpcpCaptureSecurityAttribute

INT64 __fastcall AlpcpCaptureSecurityAttribute(INT64 a1, INT64 a2, INT64 MessageAttributes){
  unsigned __int64 v5; 
  __int64 v6; 
  int v7; 
  INT64 result; 
  _SECURITY_QUALITY_OF_SERVICE *v9; 
  void *Object[2]; 
  _SECURITY_QUALITY_OF_SERVICE QualityOfService; 
  unsigned int Flags; 
  if( *((_BYTE *)KeGetCurrentThread() + 562) )
  {
    Flags = *(_DWORD *)a2;
    Object[0] = *(void **)(a2 + 16);
    v5 = *(_QWORD *)(a2 + 8);
    Object[1] = (void *)v5;
    if( v5 )
    {
      if( v5 >= 0x7FFFFFFF0000i64 )
        v5 = 0x7FFFFFFF0000i64;
      v6 = *(_QWORD *)v5;
      v7 = *(_DWORD *)(v5 + 8);
    }
    else
    {
      v6 = *(_QWORD *)(a1 + 260);
      v7 = *(_DWORD *)(a1 + 268);
    }
    *(_DWORD *)&QualityOfService.ContextTrackingMode = v7;
    *(_QWORD *)&QualityOfService.Length = v6;
    result = AlpcpCaptureSecurityAttributeInternal(
               (_ALPC_PORT *)a1,
               Flags,
               &QualityOfService,
               Object,
               (_KALPC_MESSAGE_ATTRIBUTES *)MessageAttributes);
    if( (int)result >= 0 )
      *(void **)(a2 + 16) = Object[0];
  }
  else
  {
    v9 = *(_SECURITY_QUALITY_OF_SERVICE **)(a2 + 8);
    if( !v9 )
      v9 = (_SECURITY_QUALITY_OF_SERVICE *)(a1 + 260);
    return AlpcpCaptureSecurityAttributeInternal(
             (_ALPC_PORT *)a1,
             *(unsigned int *)a2,
             v9,
             (VOID **)(a2 + 16),
             (_KALPC_MESSAGE_ATTRIBUTES *)MessageAttributes);
  }
  return result;
}

Referenced by:

AlpcpCaptureAttributes