SepAdtCloseObjectAuditAlarm
VOID __fastcall SepAdtCloseObjectAuditAlarm(
_UNICODE_STRING *CapturedSubsystemName,
VOID *HandleId,
_SECURITY_SUBJECT_CONTEXT *SubjectSecurityContext,
VOID *Object,
UINT8 IsKernelObject){
__int64 CurrentThreadProcess;
ULONG_PTR v9;
int AllocatedFullProcessImageName;
_UNICODE_STRING *v11;
ULONG_PTR *ClientToken;
_QWORD **PrimaryToken;
void *v14;
PVOID *v15;
ULONG v16;
ULONG_PTR v17;
UINT8 IsKernelHandle;
__int64 v19;
unsigned __int64 v20;
SE_ADT_PARAMETER_TYPE v21;
ULONG v22;
int v23;
UINT16 FlatSubCategoryId;
PVOID P;
_SE_ADT_PARAMETER_ARRAY Src;
LOBYTE(v23) = IsKernelObject;
P = 0i64;
FlatSubCategoryId = 0;
if( SepAdtAuditObjectAccessWithContext(
Object,
CapturedSubsystemName,
1u,
0,
SubjectSecurityContext,
v23,
&FlatSubCategoryId)
&& SepAdtAuditThisEventWithContext(0x7Bui64, 1u, 0, SubjectSecurityContext) )
{
CurrentThreadProcess = PsGetCurrentThreadProcess();
v9 = *(_QWORD *)(CurrentThreadProcess + 1088);
AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
if( AllocatedFullProcessImageName < 0 )
{
SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
}
else
{
memset((INT64)&Src, 0i64);
v11 = (_UNICODE_STRING *)&SeSubsystemName;
ClientToken = (ULONG_PTR *)SubjectSecurityContext->ClientToken;
Src.FlatSubCategoryId = FlatSubCategoryId;
Src.CategoryId = 3;
PrimaryToken = (_QWORD **)ClientToken;
if( CapturedSubsystemName )
v11 = CapturedSubsystemName;
Src.AuditId = 4658;
Src.Type = 8;
Src.Parameters[0].Type = SeAdtParmTypeSid;
if( !ClientToken )
PrimaryToken = (_QWORD **)SubjectSecurityContext->PrimaryToken;
Src.Parameters[0].Length = 4 * *(unsigned __int8 *)(*PrimaryToken[19] + 1i64) + 8;
v14 = ClientToken;
if( !ClientToken )
v14 = SubjectSecurityContext->PrimaryToken;
v15 = (PVOID *)*((_QWORD *)v14 + 19);
Src.Parameters[1].Type = SeAdtParmTypeString;
Src.Parameters[1].Address = v11;
Src.Parameters[2].Type = SeAdtParmTypeLogonId;
Src.Parameters[0].Address = *v15;
v16 = v11->Length + 16;
Src.Parameters[2].Length = 8;
Src.Parameters[1].Length = v16;
if( !ClientToken )
ClientToken = (ULONG_PTR *)SubjectSecurityContext->PrimaryToken;
v17 = ClientToken[3];
Src.Parameters[3].Address = v11;
Src.Parameters[3].Length = v16;
Src.Parameters[4].Type = SeAdtParmTypePtr;
Src.Parameters[2].Data[0] = v17;
Src.Parameters[3].Type = SeAdtParmTypeString;
Src.Parameters[4].Length = 8;
IsKernelHandle = ObpIsKernelHandle(HandleId, 0);
v20 = v19 ^ 0xFFFFFFFF80000000ui64;
Src.Parameters[5].Type = v21;
Src.Parameters[5].Length = v22;
Src.Parameters[5].Data[0] = v9;
if( !IsKernelHandle )
v20 = (unsigned __int64)HandleId;
Src.Parameters[6].Type = SeAdtParmTypeFileSpec;
Src.ParameterCount = 7;
Src.Parameters[4].Data[0] = v20 & 0xFFFFFFFFFFFFFFFCui64;
Src.Parameters[6].Address = P;
Src.Parameters[6].Length = *(unsigned __int16 *)P + 16;
SepAdtLogAuditRecord(&Src);
}
if( P )
ExFreePoolWithTag(P, 0);
}
}Referenced by:
NtCloseObjectAuditAlarm
SeCloseObjectAuditAlarm
SeCloseObjectAuditAlarmForNonObObject