SiOpenDevice
NTSTATUS __stdcall SiOpenDevice(PCWSTR SourceString, PHANDLE FileHandle){
WCHAR v2;
struct _UNICODE_STRING DestinationString;
struct _IO_STATUS_BLOCK IoStatusBlock;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
*FileHandle = 0i64;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, SourceString, v2);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
IoStatusBlock = 0i64;
return ZwOpenFile((UNICODE_STRING *)FileHandle, (PWCHAR)0x80100000i64);
}Referenced by:
SiGetDeviceNumberInformation
SiGetDiskPartitionInformation
SiGetDriveLayoutInformation
SiIssueSynchronousIoctl
SiQueryProperty