KeQueryKvaShadowRegion
INT64 __fastcall KeQueryKvaShadowRegion(INT64 a1, UINT64 **a2, UINT64 *a3){
INT64 v5;
IMAGE_NT_HEADERS *v6;
_DWORD *v7;
unsigned int v8;
unsigned int v9;
struct _KPRCB *CurrentPrcb;
KPCR *Pcr;
if( !a1 )
{
Pcr = KeGetPcr();
*a3 = 20480i64;
*a2 = (UINT64 *)(*(_QWORD *)Pcr - 12208i64);
return 1i64;
}
v5 = a1 - 1;
if( !v5 )
{
CurrentPrcb = KeGetCurrentPrcb();
*a3 = 4096i64;
*a2 = (UINT64 *)((char *)CurrentPrcb + 36480);
return 1i64;
}
if( v5 == 1 )
{
v6 = RtlImageNtHeader((PVOID)0x140000000i64);
RtlSectionTableFromVirtualAddress(v6, 0x140000000ui64);
*a2 = (UINT64 *)(0x140000000i64 + (unsigned int)v7[3]);
v8 = v7[2];
v9 = v7[4];
if( v8 <= v9 )
v8 = v9;
*a3 = (v8 + 4095i64) & 0xFFFFFFFFFFFFF000ui64;
return 1i64;
}
return 0i64;
}Referenced by:
MiCheckRelevantKernelShadows