DrvDbGetSecurityDescriptor

VOID *__fastcall DrvDbGetSecurityDescriptor(){
  VOID *v0; 
  VOID *PoolWithTag; 
  UINT64 v2; 
  void *v3; 
  VOID *v4; 
  UINT64 v5; 
  void *v6; 
  VOID *v7; 
  UINT64 v8; 
  void *v9; 
  VOID *v10; 
  UINT64 v11; 
  void *v12; 
  int v13; 
  int v14; 
  UINT32 v15; 
  struct _ACL *v16; 
  ACL *v17; 
  unsigned int v18; 
  VOID *v19; 
  VOID *v20; 
  __int128 SecurityDescriptor[2]; 
  __int64 v23; 
  struct _SID_IDENTIFIER_AUTHORITY IdentifierAuthority; 
  SID_IDENTIFIER_AUTHORITY v25; 
  SID_IDENTIFIER_AUTHORITY v26; 
  VOID *v27; 
  *(_WORD *)&IdentifierAuthority.Value[4] = 1280;
  v27 = 0i64;
  *(_DWORD *)IdentifierAuthority.Value = 0;
  *(_DWORD *)v25.Value = 0;
  *(_WORD *)&v25.Value[4] = 768;
  *(_DWORD *)v26.Value = 0;
  *(_WORD *)&v26.Value[4] = 256;
  v23 = 0i64;
  v0 = 0i64;
  memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
  PoolWithTag = ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x42444450ui64);
  v3 = PoolWithTag;
  if( PoolWithTag )
  {
    LOBYTE(v2) = 1;
    if( (int)RtlInitializeSid(PoolWithTag, &IdentifierAuthority, v2) >= 0 )
    {
      *RtlSubAuthoritySid(v3, 0i64) = 18;
      if( RtlValidSid(v3) )
      {
        v4 = ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x42444450ui64);
        v6 = v4;
        if( v4 )
        {
          LOBYTE(v5) = 1;
          if( (int)RtlInitializeSid(v4, &v25, v5) >= 0 )
          {
            *RtlSubAuthoritySid(v6, 0i64) = 4;
            if( RtlValidSid(v6) )
            {
              v7 = ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x42444450ui64);
              v9 = v7;
              if( v7 )
              {
                LOBYTE(v8) = 1;
                if( (int)RtlInitializeSid(v7, &v26, v8) >= 0 )
                {
                  *RtlSubAuthoritySid(v9, 0i64) = 0;
                  if( RtlValidSid(v9) )
                  {
                    v10 = ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x42444450ui64);
                    v12 = v10;
                    if( v10 )
                    {
                      LOBYTE(v11) = 2;
                      if( (int)RtlInitializeSid(v10, &IdentifierAuthority, v11) >= 0 )
                      {
                        *RtlSubAuthoritySid(v12, 0i64) = 32;
                        *RtlSubAuthoritySid(v12, 1ui64) = 544;
                        if( RtlValidSid(v12) )
                        {
                          v13 = RtlLengthSid(v9);
                          v14 = RtlLengthSid(v6) + v13;
                          v15 = RtlLengthSid(v3) + 32 + v14;
                          v16 = (struct _ACL *)ExAllocatePoolWithTag(PagedPool, v15, 0x42444450ui64);
                          v17 = v16;
                          if( v16 )
                          {
                            if( RtlCreateAcl(v16, v15, 2u) >= 0
                              && (int)RtlpAddKnownAce(v17, 2ui64, 2ui64, 0xF003Fui64, v3, 0) >= 0
                              && (int)RtlpAddKnownAce(v17, 2ui64, 2ui64, 0x20000ui64, v6, 0) >= 0
                              && (int)RtlpAddKnownAce(v17, 2ui64, 2ui64, 0x20019ui64, v9, 0) >= 0
                              && RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64) >= 0
                              && RtlSetDaclSecurityDescriptor(SecurityDescriptor, 1u, v17, 0) >= 0
                              && RtlSetOwnerSecurityDescriptor(SecurityDescriptor, v12, 1u) >= 0
                              && (int)RtlSetGroupSecurityDescriptor(SecurityDescriptor, v12, 1u) >= 0 )
                            {
                              WORD1(SecurityDescriptor[0]) |= 0x1400u;
                              if( RtlValidSecurityDescriptor(SecurityDescriptor) )
                              {
                                v18 = RtlLengthSecurityDescriptor(SecurityDescriptor);
                                *(_DWORD *)IdentifierAuthority.Value = v18;
                                if( v18 >= 0x28 )
                                {
                                  v19 = ExAllocatePoolWithTag(PagedPool, v18, 0x42444450ui64);
                                  v20 = v19;
                                  if( v19 )
                                  {
                                    memset((INT64)v19, 0i64);
                                    if( (int)RtlAbsoluteToSelfRelativeSD(
                                                SecurityDescriptor,
                                                v20,
                                                (UINT64 *)IdentifierAuthority.Value) < 0 )
                                    {
                                      v0 = v27;
                                    }
                                    else
                                    {
                                      v0 = v20;
                                      v20 = 0i64;
                                    }
                                    if( v20 )
                                      ExFreePoolWithTag(v20, 0);
                                  }
                                  else
                                  {
                                    v0 = v27;
                                  }
                                }
                              }
                            }
                            ExFreePoolWithTag(v17, 0);
                          }
                        }
                      }
                      ExFreePoolWithTag(v12, 0);
                    }
                  }
                }
                ExFreePoolWithTag(v9, 0);
              }
            }
          }
          ExFreePoolWithTag(v6, 0);
        }
      }
    }
    ExFreePoolWithTag(v3, 0);
  }
  return v0;
}

Referenced by:

DrvDbLoadDatabaseNode