AdtpWriteToEtwEx

NTSTATUS __stdcall AdtpWriteToEtwEx(_SE_ADT_PARAMETER_ARRAY_EX *AuditParameters, UINT8 *pbPreventCoaf){
  unsigned int v4; 
  int v5; 
  USHORT Type; 
  UINT64 FlatSubCategoryId; 
  UINT64 v8; 
  unsigned __int64 v9; 
  unsigned __int16 v10; 
  unsigned int *p_Size; 
  UINT8 FreeWhenDone[4]; 
  UINT64 CategoryId; 
  EVENT_DESCRIPTOR EventDescriptor; 
  EVENT_DATA_DESCRIPTOR EtwDataDescriptors[20]; 
  EVENT_DATA_DESCRIPTOR DescriptorIndex[48]; 
  UINT8 v18[16]; 
  __int128 v19; 
  __int128 v20; 
  UNICODE_STRING result[128]; 
  v4 = 0;
  *(_WORD *)FreeWhenDone = 0;
  memset((INT64)result, 0i64);
  memset((INT64)EtwDataDescriptors, 0i64);
  *pbPreventCoaf = 0;
  *(_OWORD *)v18 = 0i64;
  v19 = 0i64;
  v20 = 0i64;
  AdtpNormalizeAuditInfoHelper(0i64, AuditParameters);
  if( !AuditParameters->Parameters[0].Address )
  {
    v5 = -1073741811;
LABEL_17:
    v10 = *(_WORD *)FreeWhenDone;
    goto LABEL_18;
  }
  Type = AuditParameters->Type;
  v5 = AdtpPackageParameters(
         0i64,
         AuditParameters,
         (PWCHAR)2,
         result,
         EtwDataDescriptors,
         (UINT16 *)DescriptorIndex,
         FreeWhenDone);
  if( v5 < 0 )
    goto LABEL_17;
  if( AuditParameters->FlatSubCategoryId
    && (FlatSubCategoryId = AuditParameters->FlatSubCategoryId,
        CategoryId = 0i64,
        (int)AdtpGetCategoryAndSubCategoryId(FlatSubCategoryId, &CategoryId, (UINT64 *)((char *)&CategoryId + 4)) >= 0) )
  {
    v8 = (unsigned __int16)(CategoryId + 48) << 8;
    LOWORD(v8) = WORD2(CategoryId) + (((_WORD)CategoryId + 48) << 8);
  }
  else
  {
    v8 = 65280i64;
  }
  EventDescriptor.Id = AuditParameters->AuditId;
  EventDescriptor.Version = AuditParameters->Version;
  v9 = 0x8020000000000000ui64;
  if( Type != 8 )
    v9 = 0x8010000000000000ui64;
  *(_WORD *)&EventDescriptor.Channel = 10;
  v10 = *(_WORD *)FreeWhenDone;
  EventDescriptor.Task = v8;
  EventDescriptor.Opcode = 0;
  EventDescriptor.Keyword = v9;
  if( !*(_WORD *)FreeWhenDone )
    goto LABEL_15;
  p_Size = &DescriptorIndex[0].Size;
  v8 = *(unsigned __int16 *)FreeWhenDone;
  do
  {
    v4 += *p_Size;
    p_Size += 4;
    --v8;
  }
  while( v8 );
  if( v4 <= 0xDC00 )
  {
LABEL_15:
    v5 = EtwWriteKMSecurityEvent(&EventDescriptor, v8, (EVENT_DATA_DESCRIPTOR *)*(unsigned __int16 *)FreeWhenDone);
    if( v5 == -1073741058 )
      *pbPreventCoaf = 1;
    goto LABEL_17;
  }
  *pbPreventCoaf = 1;
  v5 = -2147483643;
LABEL_18:
  AdtpCleanupParameterAllocations(v18, DescriptorIndex, v10);
  return v5;
}

Referenced by:

SeAuditPlugAndPlay