SepAssemblePrivileges

VOID __stdcall SepAssemblePrivileges(
        UINT64 PrivilegeCount,
        UINT8 SystemSecurity,
        UINT8 WriteOwner,
        UINT8 Relabel,
        PRIVILEGE_SET **Privileges){
  unsigned int *PoolWithTag; 
  unsigned int *v9; 
  __int64 v10; 
  if( Privileges )
  {
    if( (_DWORD)PrivilegeCount )
    {
      PoolWithTag = (unsigned int *)ExAllocatePoolWithTag(
                                      PagedPool,
                                      (unsigned int)(12 * (PrivilegeCount - 1) + 20),
                                      0x72506553ui64);
      v9 = PoolWithTag;
      if( PoolWithTag )
      {
        *PoolWithTag = 0;
        PoolWithTag[1] = 0;
        v10 = 0i64;
        if( SystemSecurity )
        {
          *((_QWORD *)v9 + 1) = *(_QWORD *)SeSecurityPrivilege;
          v9[3 * (*v9)++ + 4] = 0x80000000;
          v10 = *v9;
        }
        if( WriteOwner )
        {
          *(_QWORD *)&v9[3 * v10 + 2] = SeTakeOwnershipPrivilege;
          v9[3 * (*v9)++ + 4] = 0x80000000;
          v10 = *v9;
        }
        if( Relabel )
        {
          *(_QWORD *)&v9[3 * v10 + 2] = SeRelabelPrivilege;
          v9[3 * (*v9)++ + 4] = 0x80000000;
        }
        *Privileges = (PRIVILEGE_SET *)v9;
      }
    }
  }
}

Referenced by:

SepAccessCheck
SepAccessCheckEx