SeGetTokenDeviceMap

NTSTATUS __fastcall SeGetTokenDeviceMap(__int64 a1, _QWORD *a2){
  __int64 v3; 
  __int64 v4; 
  NTSTATUS result; 
  WCHAR v6; 
  NTSTATUS v7; 
  WCHAR v8; 
  WCHAR v9; 
  PVOID P; 
  void *DirectoryHandle; 
  void *SymbolicLinkHandle; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  struct _UNICODE_STRING v15; 
  wchar_t Dst[64]; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  DirectoryHandle = 0i64;
  SymbolicLinkHandle = 0i64;
  P = 0i64;
  DestinationString = 0i64;
  v15 = 0i64;
  if( !a1 || !a2 )
    return -1073741811;
  if( (*(_DWORD *)(a1 + 200) & 0x20) != 0 )
    return -1073741729;
  v3 = *(_QWORD *)(a1 + 216);
  if( !v3 )
    return -1073741729;
  v4 = *(_QWORD *)(v3 + 40);
  if( v4 )
  {
    *a2 = v4;
    return 0;
  }
  else
  {
    PsGetServerSiloServiceSessionId(*(_EJOB **)(v3 + 160));
    swprintf_s(Dst, 0x40ui64, (WCHAR *)L"\\Sessions\\%d\\DosDevices\\%08x-%08x");
    RtlInitUnicodeString(&DestinationString, Dst, v6);
    ObjectAttributes.RootDirectory = 0i64;
    ObjectAttributes.ObjectName = &DestinationString;
    ObjectAttributes.Length = 48;
    ObjectAttributes.Attributes = 704;
    *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
    result = ZwCreateDirectoryObject(&DirectoryHandle, 0xF000Fui64, &ObjectAttributes);
    if( result >= 0 )
    {
      v7 = ObpSetDeviceMap(*(PVOID *)(v3 + 160), 0i64, DirectoryHandle, 0, 2, (__int64)&P);
      if( v7 >= 0 )
      {
        RtlInitUnicodeString(&v15, L"Global", v8);
        RtlInitUnicodeString(&DestinationString, L"\\Global??", v9);
        ObjectAttributes.RootDirectory = DirectoryHandle;
        ObjectAttributes.Length = 48;
        ObjectAttributes.ObjectName = &v15;
        ObjectAttributes.Attributes = 720;
        *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
        v7 = ZwCreateSymbolicLinkObject(&SymbolicLinkHandle, 0xF0001ui64, &ObjectAttributes, &DestinationString);
        if( v7 < 0 )
        {
          ObfDereferenceDeviceMap((_DEVICE_MAP *)P);
        }
        else
        {
          ZwClose(SymbolicLinkHandle);
          if( _InterlockedCompareExchange64((volatile signed __int64 *)(v3 + 40), (signed __int64)P, 0i64) )
            ObfDereferenceDeviceMap((_DEVICE_MAP *)P);
          *a2 = *(_QWORD *)(v3 + 40);
        }
      }
      ZwClose(DirectoryHandle);
      return v7;
    }
  }
  return result;
}

Referenced by:

ObSetCurrentProcessDeviceMap
ObpLookupObjectName
ObpReferenceDeviceMap