SepAdtCloseObjectAuditAlarm

VOID __fastcall SepAdtCloseObjectAuditAlarm(
        _UNICODE_STRING *CapturedSubsystemName,
        VOID *HandleId,
        _SECURITY_SUBJECT_CONTEXT *SubjectSecurityContext,
        VOID *Object,
        UINT8 IsKernelObject){
  __int64 CurrentThreadProcess; 
  ULONG_PTR v9; 
  int AllocatedFullProcessImageName; 
  _UNICODE_STRING *v11; 
  ULONG_PTR *ClientToken; 
  _QWORD **PrimaryToken; 
  void *v14; 
  PVOID *v15; 
  ULONG v16; 
  ULONG_PTR v17; 
  UINT8 IsKernelHandle; 
  __int64 v19; 
  unsigned __int64 v20; 
  SE_ADT_PARAMETER_TYPE v21; 
  ULONG v22; 
  int v23; 
  UINT16 FlatSubCategoryId; 
  PVOID P; 
  _SE_ADT_PARAMETER_ARRAY Src; 
  LOBYTE(v23) = IsKernelObject;
  P = 0i64;
  FlatSubCategoryId = 0;
  if( SepAdtAuditObjectAccessWithContext(
         Object,
         CapturedSubsystemName,
         1u,
         0,
         SubjectSecurityContext,
         v23,
         &FlatSubCategoryId)
    && SepAdtAuditThisEventWithContext(0x7Bui64, 1u, 0, SubjectSecurityContext) )
  {
    CurrentThreadProcess = PsGetCurrentThreadProcess();
    v9 = *(_QWORD *)(CurrentThreadProcess + 1088);
    AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
    if( AllocatedFullProcessImageName < 0 )
    {
      SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
    }
    else
    {
      memset((INT64)&Src, 0i64);
      v11 = (_UNICODE_STRING *)&SeSubsystemName;
      ClientToken = (ULONG_PTR *)SubjectSecurityContext->ClientToken;
      Src.FlatSubCategoryId = FlatSubCategoryId;
      Src.CategoryId = 3;
      PrimaryToken = (_QWORD **)ClientToken;
      if( CapturedSubsystemName )
        v11 = CapturedSubsystemName;
      Src.AuditId = 4658;
      Src.Type = 8;
      Src.Parameters[0].Type = SeAdtParmTypeSid;
      if( !ClientToken )
        PrimaryToken = (_QWORD **)SubjectSecurityContext->PrimaryToken;
      Src.Parameters[0].Length = 4 * *(unsigned __int8 *)(*PrimaryToken[19] + 1i64) + 8;
      v14 = ClientToken;
      if( !ClientToken )
        v14 = SubjectSecurityContext->PrimaryToken;
      v15 = (PVOID *)*((_QWORD *)v14 + 19);
      Src.Parameters[1].Type = SeAdtParmTypeString;
      Src.Parameters[1].Address = v11;
      Src.Parameters[2].Type = SeAdtParmTypeLogonId;
      Src.Parameters[0].Address = *v15;
      v16 = v11->Length + 16;
      Src.Parameters[2].Length = 8;
      Src.Parameters[1].Length = v16;
      if( !ClientToken )
        ClientToken = (ULONG_PTR *)SubjectSecurityContext->PrimaryToken;
      v17 = ClientToken[3];
      Src.Parameters[3].Address = v11;
      Src.Parameters[3].Length = v16;
      Src.Parameters[4].Type = SeAdtParmTypePtr;
      Src.Parameters[2].Data[0] = v17;
      Src.Parameters[3].Type = SeAdtParmTypeString;
      Src.Parameters[4].Length = 8;
      IsKernelHandle = ObpIsKernelHandle(HandleId, 0);
      v20 = v19 ^ 0xFFFFFFFF80000000ui64;
      Src.Parameters[5].Type = v21;
      Src.Parameters[5].Length = v22;
      Src.Parameters[5].Data[0] = v9;
      if( !IsKernelHandle )
        v20 = (unsigned __int64)HandleId;
      Src.Parameters[6].Type = SeAdtParmTypeFileSpec;
      Src.ParameterCount = 7;
      Src.Parameters[4].Data[0] = v20 & 0xFFFFFFFFFFFFFFFCui64;
      Src.Parameters[6].Address = P;
      Src.Parameters[6].Length = *(unsigned __int16 *)P + 16;
      SepAdtLogAuditRecord(&Src);
    }
    if( P )
      ExFreePoolWithTag(P, 0);
  }
}

Referenced by:

NtCloseObjectAuditAlarm
SeCloseObjectAuditAlarm
SeCloseObjectAuditAlarmForNonObObject