SepAdtPrivilegedServiceAuditAlarm

VOID __fastcall SepAdtPrivilegedServiceAuditAlarm(
        _SECURITY_SUBJECT_CONTEXT *SubjectSecurityContext,
        _UNICODE_STRING *CapturedSubsystemName,
        _UNICODE_STRING *CapturedServiceName,
        _TOKEN *ClientToken,
        _TOKEN *PrimaryToken,
        _PRIVILEGE_SET *CapturedPrivileges,
        UINT8 AccessGranted){
  UINT16 *v8; 
  _UNICODE_STRING *v9; 
  __int64 CurrentThreadProcess; 
  int AllocatedFullProcessImageName; 
  _SID_AND_ATTRIBUTES *UserAndGroups; 
  unsigned __int8 *Sid; 
  _UNICODE_STRING *v14; 
  _LUID AuthenticationId; 
  int v16; 
  ULONG v17; 
  int Length; 
  unsigned int PrivilegeCount; 
  ULONG v20; 
  UINT16 FlatSubCategoryId[4]; 
  PVOID P; 
  _UNICODE_STRING *v23; 
  ULONG_PTR v24; 
  _SE_ADT_PARAMETER_ARRAY Src; 
  v23 = CapturedSubsystemName;
  v8 = FlatSubCategoryId;
  P = 0i64;
  v9 = CapturedServiceName;
  FlatSubCategoryId[0] = 0;
  LOBYTE(CapturedServiceName) = AccessGranted == 0;
  LOBYTE(v8) = AccessGranted;
  if( (unsigned __int8)SepAdtAuditPrivilegeUseWithContext(
                          CapturedPrivileges,
                          (INT64)v8,
                          (INT64)CapturedServiceName,
                          SubjectSecurityContext,
                          FlatSubCategoryId) )
  {
    CurrentThreadProcess = PsGetCurrentThreadProcess();
    v24 = *(_QWORD *)(CurrentThreadProcess + 1088);
    AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
    if( AllocatedFullProcessImageName >= 0 )
    {
      if( ClientToken )
        UserAndGroups = ClientToken->UserAndGroups;
      else
        UserAndGroups = PrimaryToken->UserAndGroups;
      Sid = (unsigned __int8 *)UserAndGroups->Sid;
      v14 = (_UNICODE_STRING *)&SeSubsystemName;
      AuthenticationId = PrimaryToken->AuthenticationId;
      if( v23 )
        v14 = v23;
      memset((INT64)&Src, 0i64);
      Src.CategoryId = 4;
      Src.FlatSubCategoryId = FlatSubCategoryId[0];
      Src.AuditId = 4673;
      Src.Type = 8;
      if( !AccessGranted )
        Src.Type = 16;
      v16 = Sid[1];
      Src.Parameters[0].Type = SeAdtParmTypeSid;
      v17 = v14->Length + 16;
      Src.Parameters[0].Address = Sid;
      Src.Parameters[1].Type = SeAdtParmTypeString;
      Src.Parameters[0].Length = 4 * v16 + 8;
      Src.Parameters[1].Length = v17;
      Src.Parameters[1].Address = v14;
      Src.Parameters[2].Type = SeAdtParmTypeLogonId;
      Src.Parameters[2].Length = 8;
      if( ClientToken )
        Src.Parameters[2].Data[0] = (ULONG_PTR)ClientToken->AuthenticationId;
      else
        Src.Parameters[2].Data[0] = (ULONG_PTR)AuthenticationId;
      Src.Parameters[3].Type = SeAdtParmTypeString;
      Src.Parameters[3].Length = v17;
      Src.Parameters[3].Address = v14;
      if( v9 )
      {
        Length = v9->Length;
        Src.Parameters[4].Type = SeAdtParmTypeString;
        Src.Parameters[4].Length = Length + 16;
        Src.Parameters[4].Address = v9;
      }
      if( CapturedPrivileges )
      {
        PrivilegeCount = CapturedPrivileges->PrivilegeCount;
        if( CapturedPrivileges->PrivilegeCount )
        {
          Src.Parameters[5].Type = SeAdtParmTypePrivs;
          Src.Parameters[5].Address = CapturedPrivileges;
          Src.Parameters[5].Length = 12 * PrivilegeCount + 8;
        }
      }
      Src.Parameters[6].Data[0] = v24;
      Src.Parameters[7].Address = P;
      v20 = *(unsigned __int16 *)P + 16;
      Src.Parameters[6].Type = SeAdtParmTypePtr;
      Src.Parameters[7].Length = v20;
      Src.Parameters[6].Length = 8;
      Src.Parameters[7].Type = SeAdtParmTypeFileSpec;
      Src.ParameterCount = 8;
      SepAdtLogAuditRecord(&Src);
    }
    if( P )
      ExFreePoolWithTag(P, 0);
    if( AllocatedFullProcessImageName < 0 )
      SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
  }
}

Referenced by:

NtPrivilegedServiceAuditAlarm
PfQuerySuperfetchInformation
SePrivilegedServiceAuditAlarm