NtQuerySecurityObject

NTSTATUS __stdcall NtQuerySecurityObject(
        VOID *Handle,
        UINT64 SecurityInformation,
        VOID *SecurityDescriptor,
        UINT64 Length,
        UINT64 *LengthNeeded){
  KPROCESSOR_MODE v7; 
  UINT64 *v8; 
  __int64 v9; 
  NTSTATUS result; 
  struct _DMA_ADAPTER *v11; 
  __int64 v12; 
  NTSTATUS v13; 
  UINT64 DesiredAccess; 
  PVOID Object; 
  struct _OBJECT_HANDLE_INFORMATION HandleInformation; 
  UINT64 SecurityInformationa; 
  SIZE_T Lengtha; 
  LODWORD(Lengtha) = Length;
  LODWORD(SecurityInformationa) = SecurityInformation;
  LODWORD(DesiredAccess) = 0;
  HandleInformation = 0i64;
  v7 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( v7 )
  {
    v8 = LengthNeeded;
    v9 = (__int64)LengthNeeded;
    if( (unsigned __int64)LengthNeeded >= 0x7FFFFFFF0000i64 )
      v9 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v9 = *(_DWORD *)v9;
    ProbeForWrite(SecurityDescriptor, (unsigned int)Lengtha, 4ui64);
  }
  else
  {
    v8 = LengthNeeded;
  }
  SeQuerySecurityAccessMask((unsigned int)SecurityInformationa, &DesiredAccess);
  Object = 0i64;
  result = ObReferenceObjectByHandle(Handle, DesiredAccess, 0i64, v7, &Object, &HandleInformation);
  if( result >= 0 )
  {
    v11 = (struct _DMA_ADAPTER *)Object;
    v12 = ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ (unsigned __int8)*((char *)Object - 24) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)Object - 48) >> 8)];
    v13 = (*(__int64(__fastcall **)(PVOID, __int64, UINT64 *, VOID *, SIZE_T *, char *, _DWORD, __int64, KPROCESSOR_MODE))(v12 + 152))(
            Object,
            1i64,
            &SecurityInformationa,
            SecurityDescriptor,
            &Lengtha,
            (char *)Object - 8,
            *(_DWORD *)(v12 + 100),
            v12 + 76,
            v7);
    *(_DWORD *)v8 = Lengtha;
    HalPutDmaAdapter(v11);
    return v13;
  }
  return result;
}

Referenced by:

RtlpSysVolCheckOwnerAndSecurity