KiTpBuildExcludedKernelTracepointRangeList

CHAR *__stdcall KiTpBuildExcludedKernelTracepointRangeList(){
  volatile INT64 *PoolWithTag; 
  volatile INT64 *v1; 
  void *v2; 
  __int64 v3; 
  int v4; 
  unsigned __int64 ImageBase; 
  PoolWithTag = (volatile INT64 *)ExAllocatePoolWithTag(PagedPool, 0x20ui64, 0x70727446ui64);
  v1 = PoolWithTag;
  if( PoolWithTag )
  {
    *((_DWORD *)PoolWithTag + 4) = 0;
    *((_DWORD *)PoolWithTag + 5) = 0;
    *((_DWORD *)PoolWithTag + 6) = 0;
    v2 = (void *)KiTpExcludedRoutines;
    LODWORD(v3) = 0;
    *((_QWORD *)PoolWithTag + 1) = PoolWithTag;
    *PoolWithTag = (volatile INT64)PoolWithTag;
    while( 1 )
    {
      ImageBase = 0i64;
      RtlLookupFunctionEntry(v2, &ImageBase, 0i64);
      RtlAddRange(v1);
      if( v4 < 0 )
        break;
      v3 = (unsigned int)(v3 + 1);
      v2 = (void *)*(&KiTpExcludedRoutines + v3);
      if( !v2 )
        return(CHAR *)v1;
    }
    RtlFreeRangeList((INT64)v1);
    ExFreePoolWithTag((PVOID)v1, 0x70727446u);
  }
  return 0i64;
}

Referenced by:

KiTpIsExcludedKernelTracepointLocation