SepAdtPrivilegedServiceAuditAlarm
VOID __fastcall SepAdtPrivilegedServiceAuditAlarm(
_SECURITY_SUBJECT_CONTEXT *SubjectSecurityContext,
_UNICODE_STRING *CapturedSubsystemName,
_UNICODE_STRING *CapturedServiceName,
_TOKEN *ClientToken,
_TOKEN *PrimaryToken,
_PRIVILEGE_SET *CapturedPrivileges,
UINT8 AccessGranted){
UINT16 *v8;
_UNICODE_STRING *v9;
__int64 CurrentThreadProcess;
int AllocatedFullProcessImageName;
_SID_AND_ATTRIBUTES *UserAndGroups;
unsigned __int8 *Sid;
_UNICODE_STRING *v14;
_LUID AuthenticationId;
int v16;
ULONG v17;
int Length;
unsigned int PrivilegeCount;
ULONG v20;
UINT16 FlatSubCategoryId[4];
PVOID P;
_UNICODE_STRING *v23;
ULONG_PTR v24;
_SE_ADT_PARAMETER_ARRAY Src;
v23 = CapturedSubsystemName;
v8 = FlatSubCategoryId;
P = 0i64;
v9 = CapturedServiceName;
FlatSubCategoryId[0] = 0;
LOBYTE(CapturedServiceName) = AccessGranted == 0;
LOBYTE(v8) = AccessGranted;
if( (unsigned __int8)SepAdtAuditPrivilegeUseWithContext(
CapturedPrivileges,
(INT64)v8,
(INT64)CapturedServiceName,
SubjectSecurityContext,
FlatSubCategoryId) )
{
CurrentThreadProcess = PsGetCurrentThreadProcess();
v24 = *(_QWORD *)(CurrentThreadProcess + 1088);
AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
if( AllocatedFullProcessImageName >= 0 )
{
if( ClientToken )
UserAndGroups = ClientToken->UserAndGroups;
else
UserAndGroups = PrimaryToken->UserAndGroups;
Sid = (unsigned __int8 *)UserAndGroups->Sid;
v14 = (_UNICODE_STRING *)&SeSubsystemName;
AuthenticationId = PrimaryToken->AuthenticationId;
if( v23 )
v14 = v23;
memset((INT64)&Src, 0i64);
Src.CategoryId = 4;
Src.FlatSubCategoryId = FlatSubCategoryId[0];
Src.AuditId = 4673;
Src.Type = 8;
if( !AccessGranted )
Src.Type = 16;
v16 = Sid[1];
Src.Parameters[0].Type = SeAdtParmTypeSid;
v17 = v14->Length + 16;
Src.Parameters[0].Address = Sid;
Src.Parameters[1].Type = SeAdtParmTypeString;
Src.Parameters[0].Length = 4 * v16 + 8;
Src.Parameters[1].Length = v17;
Src.Parameters[1].Address = v14;
Src.Parameters[2].Type = SeAdtParmTypeLogonId;
Src.Parameters[2].Length = 8;
if( ClientToken )
Src.Parameters[2].Data[0] = (ULONG_PTR)ClientToken->AuthenticationId;
else
Src.Parameters[2].Data[0] = (ULONG_PTR)AuthenticationId;
Src.Parameters[3].Type = SeAdtParmTypeString;
Src.Parameters[3].Length = v17;
Src.Parameters[3].Address = v14;
if( v9 )
{
Length = v9->Length;
Src.Parameters[4].Type = SeAdtParmTypeString;
Src.Parameters[4].Length = Length + 16;
Src.Parameters[4].Address = v9;
}
if( CapturedPrivileges )
{
PrivilegeCount = CapturedPrivileges->PrivilegeCount;
if( CapturedPrivileges->PrivilegeCount )
{
Src.Parameters[5].Type = SeAdtParmTypePrivs;
Src.Parameters[5].Address = CapturedPrivileges;
Src.Parameters[5].Length = 12 * PrivilegeCount + 8;
}
}
Src.Parameters[6].Data[0] = v24;
Src.Parameters[7].Address = P;
v20 = *(unsigned __int16 *)P + 16;
Src.Parameters[6].Type = SeAdtParmTypePtr;
Src.Parameters[7].Length = v20;
Src.Parameters[6].Length = 8;
Src.Parameters[7].Type = SeAdtParmTypeFileSpec;
Src.ParameterCount = 8;
SepAdtLogAuditRecord(&Src);
}
if( P )
ExFreePoolWithTag(P, 0);
if( AllocatedFullProcessImageName < 0 )
SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
}
}Referenced by:
NtPrivilegedServiceAuditAlarm
PfQuerySuperfetchInformation
SePrivilegedServiceAuditAlarm