EtwQueryProcessTelemetryInfo

__int64 __fastcall EtwQueryProcessTelemetryInfo(
        ULONG_PTR BugCheckParameter1,
        volatile void *Address,
        SIZE_T Length,
        char a4,
        __int64 a5){
  UINT64 v5; 
  int v8; 
  __int64 *v9; 
  struct DMA_ADAPTER *v10; 
  int v11; 
  unsigned int v12; 
  __int64 v13; 
  __int64 v14; 
  UINT8 *v15; 
  unsigned __int16 *v16; 
  UINT8 *v17; 
  UINT8 *v18; 
  UINT8 *v19; 
  UINT64 Size; 
  int v23; 
  __int64 v24; 
  PVOID P[2]; 
  _DWORD *v26; 
  UINT8 **v27; 
  struct DMA_ADAPTER *v28; 
  ULONG_PTR v29; 
  size_t v30; 
  size_t v31; 
  UINT8 v32[256]; 
  UINT8 v33[144]; 
  _KAPC_STATE ApcState; 
  UINT8 Src[80]; 
  v5 = (unsigned int)Length;
  v29 = BugCheckParameter1;
  v26 = (_DWORD *)a5;
  memset(&ApcState, 0, sizeof(ApcState));
  memset((INT64)&v30, 0i64);
  memset((INT64)Src, 0i64);
  LODWORD(Size) = 0;
  *(_OWORD *)P = 0i64;
  v8 = 0;
  v24 = 0i64;
  v9 = &EmptyUnicodeString;
  if( *(_QWORD *)(BugCheckParameter1 + 1472) )
    v9 = *(__int64 **)(BugCheckParameter1 + 1472);
  v27 = (UINT8 **)v9;
  v10 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)BugCheckParameter1);
  v28 = v10;
  v23 = 0;
  EtwpQueryTokenPackageInfo((__int64)v10, (__int64)&v30, &v23);
  v11 = SeQueryUserSidToken(v10, Src, 0x44ui64, &Size);
  if( v11 >= 0 )
  {
    if( (int)PsAcquireProcessExitSynchronization((struct _EX_RUNDOWN_REF *)BugCheckParameter1) >= 0 )
    {
      KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
      EtwpQueryProcessOtherInfo(BugCheckParameter1, (__int64)&v24);
      EtwpQueryProcessCommandLine((_EPROCESS *)BugCheckParameter1, (_UNICODE_STRING *)P);
      KiUnstackDetachProcess(&ApcState, 0i64);
      ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
      v8 = v24;
    }
    v12 = Size + 100 + v30 + v31 + *(unsigned __int16 *)v9 + LOWORD(P[0]);
    if( v26 )
      *v26 = v12;
    if( a4 )
      ProbeForWrite((VOID *)Address, v5, 4ui64);
    memset((INT64)Address, 0i64);
    if( (unsigned int)v5 < 0x60 )
    {
      v11 = -1073741820;
      HIDWORD(Size) = -1073741820;
    }
    else
    {
      *(_DWORD *)Address = 96;
      *((_DWORD *)Address + 1) = *(_DWORD *)(BugCheckParameter1 + 1088);
      *((_QWORD *)Address + 1) = PsGetProcessStartKey(BugCheckParameter1);
      *((_QWORD *)Address + 2) = *(_QWORD *)(BugCheckParameter1 + 1128);
      *((_QWORD *)Address + 3) = *(_QWORD *)(BugCheckParameter1 + 2304);
      *((_QWORD *)Address + 4) = *(_QWORD *)(BugCheckParameter1 + 2312);
      *((_QWORD *)Address + 5) = *(_QWORD *)(BugCheckParameter1 + 2296);
      *((_QWORD *)Address + 6) = MmGetSessionCreateTime(v13);
      *((_DWORD *)Address + 14) = PsGetProcessSessionId(BugCheckParameter1);
      *((_DWORD *)Address + 15) = KUSER_SHARED_DATA.BootId;
      *((_DWORD *)Address + 16) = v8;
      *((_DWORD *)Address + 17) = HIDWORD(v24);
      if( (unsigned int)v5 >= v12 )
      {
        *((_DWORD *)Address + 18) = 96;
        v14 = (unsigned int)Size;
        memmove((UINT8 *)Address + 96, Src, (unsigned int)Size);
        v15 = (UINT8 *)Address + v14 + 96;
        *((_DWORD *)Address + 19) = v14 + 96;
        v16 = (unsigned __int16 *)v27;
        memmove(v15, v27[1], *(unsigned __int16 *)v27);
        v17 = &v15[*v16 + 2];
        *((_DWORD *)Address + 20) = (_DWORD)v17 - (_DWORD)Address;
        memmove(v17, v32, v30);
        v18 = &v17[v30];
        *((_DWORD *)Address + 21) = (_DWORD)v18 - (_DWORD)Address;
        memmove(v18, v33, v31);
        v19 = &v18[v31];
        *((_DWORD *)Address + 22) = (_DWORD)v19 - (_DWORD)Address;
        memmove(v19, (UINT8 *)P[1], LOWORD(P[0]));
        v11 = 0;
      }
      else
      {
        v11 = -2147483643;
        HIDWORD(Size) = -2147483643;
      }
    }
  }
  if( P[1] )
    ExFreePoolWithTag(P[1], 0);
  if( v10 )
    ObFastDereferenceObject((INT64 *)(BugCheckParameter1 + 1208), v10);
  return(unsigned int)v11;
}

Referenced by:

NtQueryInformationProcess