EtwpBuildProcessEvent

__int64 __fastcall EtwpBuildProcessEvent(
        _EPROCESS *Process,
        __int16 a2,
        char a3,
        __int64 a4,
        __int64 a5,
        __int64 a6,
        __int64 a7,
        __int64 a8,
        PSTRING DestinationString,
        __int64 a10,
        __int64 a11){
  PSTRING v11; 
  _QWORD *v14; 
  int v15; 
  int *v16; 
  unsigned int v17; 
  unsigned __int64 v18; 
  __int64 v19; 
  int v20; 
  int v21; 
  __int64 v22; 
  struct DMA_ADAPTER *v23; 
  int *v24; 
  struct DMA_ADAPTER *v25; 
  int v26; 
  __int64 *v27; 
  int v28; 
  char *v29; 
  __int64 Length; 
  char v31; 
  _UNICODE_STRING *v32; 
  int v33; 
  __int64 v34; 
  __int64 v35; 
  unsigned int v36; 
  int v37; 
  unsigned int v38; 
  __int64 v39; 
  unsigned int v40; 
  __int64 result; 
  UNICODE_STRING *v42; 
  char *Buffer; 
  __int16 v44; 
  __int64 v45; 
  PVOID TokenInformation; 
  __int16 v47; 
  char v48; 
  v48 = a3;
  v47 = a2;
  v11 = DestinationString;
  TokenInformation = 0i64;
  RtlInitAnsiString(DestinationString, 0i64, a3);
  v14 = (_QWORD *)a11;
  *(_QWORD *)a4 = Process;
  *(_DWORD *)(a4 + 8) = *((_DWORD *)Process + 272);
  v15 = *((_DWORD *)Process + 336);
  *v14 = 0i64;
  *(_DWORD *)(a4 + 12) = v15;
  *(_DWORD *)(a4 + 16) = MmGetSessionIdEx((INT64)Process);
  v16 = (int *)(a4 + 32);
  v17 = 4;
  *(_DWORD *)(a4 + 20) = *((_DWORD *)Process + 501);
  v18 = *((_QWORD *)Process + 5) & 0xFFFFFFFFFFFFF000ui64;
  *(_DWORD *)(a4 + 32) = 0;
  *(_QWORD *)(a4 + 24) = v18;
  v19 = *((_QWORD *)Process + 176);
  if( v19 && ((v44 = *(_WORD *)(v19 + 8), v44 == 332) || v44 == 452) )
  {
    *v16 = 2;
    v20 = 6;
  }
  else
  {
    v20 = 4;
  }
  v21 = *v16;
  v22 = a6;
  if( (*((_BYTE *)Process + 2170) & 7) != 0 )
    v21 = v20;
  *v16 = v21;
  *(_QWORD *)v22 = a4;
  *(_QWORD *)(v22 + 8) = 36i64;
  v23 = (struct DMA_ADAPTER *)PsReferencePrimaryToken((PEPROCESS)Process);
  v24 = (int *)a8;
  v25 = v23;
  EtwpQueryTokenPackageInfo((__int64)v23, a8, (_DWORD *)(a4 + 32));
  v26 = SeQueryInformationToken(v25, TokenUser, &TokenInformation);
  ObFastDereferenceObject((INT64 *)Process + 151, v25);
  if( v26 < 0 )
  {
    v28 = 4;
    TokenInformation = &EtwpNull;
    v27 = &EtwpNull;
  }
  else
  {
    v27 = (__int64 *)TokenInformation;
    *v14 = TokenInformation;
    v28 = 4 * *(unsigned __int8 *)(*v27 + 1) + 24;
  }
  *(_QWORD *)(v22 + 16) = v27;
  *(_DWORD *)(v22 + 28) = 0;
  v29 = (char *)Process + 1448;
  Length = -1i64;
  *(_DWORD *)(v22 + 24) = v28;
  do
    ++Length;
  while( v29[Length] );
  if( (_DWORD)Length == 14 )
  {
    v42 = (UNICODE_STRING *)*((_QWORD *)Process + 184);
    if( v42 )
    {
      if( v42->Length && RtlUnicodeStringToAnsiString(v11, v42, 1u) >= 0 )
      {
        Length = v11->Length;
        Buffer = v11->Buffer;
        v29 = &Buffer[Length];
        while( v29 != Buffer )
        {
          if( *--v29 == 92 )
          {
            ++v29;
            break;
          }
        }
        LODWORD(Length) = (_DWORD)Buffer - (_DWORD)v29 + Length;
      }
    }
  }
  *(_DWORD *)(v22 + 40) = Length;
  v31 = v48;
  *(_QWORD *)(v22 + 32) = v29;
  *(_DWORD *)(v22 + 44) = 0;
  *(_QWORD *)(v22 + 48) = &EtwpNull;
  *(_QWORD *)(v22 + 56) = 1i64;
  if( v31 )
    EtwpQueryProcessOtherInfo((__int64)Process, a5);
  else
    *(_QWORD *)a5 = 0i64;
  v32 = (_UNICODE_STRING *)a10;
  *(_WORD *)a10 = 0;
  if( *((_QWORD *)Process + 170) )
  {
    if( v31 )
    {
      EtwpQueryProcessCommandLine(Process, v32);
      v33 = v32->Length;
      if( (_WORD)v33 )
      {
        v17 = 5;
        *(_QWORD *)(v22 + 64) = v32->Buffer;
        *(_DWORD *)(v22 + 72) = v33;
        *(_DWORD *)(v22 + 76) = 0;
      }
    }
  }
  v34 = 2i64 * v17;
  v35 = v17 + 1;
  v36 = v17 + 2;
  v35 *= 2i64;
  *(_QWORD *)(v22 + 8 * v34) = &EtwpNull;
  *(_QWORD *)(v22 + 8 * v34 + 8) = 2i64;
  v37 = *v24;
  *(_QWORD *)(v22 + 8 * v35) = v24 + 4;
  *(_DWORD *)(v22 + 8 * v35 + 8) = v37;
  *(_DWORD *)(v22 + 8 * v35 + 12) = 0;
  v38 = v24[2];
  v39 = v36;
  v40 = v36 + 1;
  v39 *= 2i64;
  *(_QWORD *)(v22 + 8 * v39) = v24 + 68;
  *(_QWORD *)(v22 + 8 * v39 + 8) = v38;
  if( v47 == 807 )
  {
    v45 = 2i64 * v40++;
    *(_QWORD *)(v22 + 8 * v45) = (char *)Process + 2112;
    *(_QWORD *)(v22 + 8 * v45 + 8) = 8i64;
  }
  result = a7;
  *(_DWORD *)a7 = v40;
  return result;
}

Referenced by:

EtwpTraceProcessRundown
EtwpWriteProcessEvent