SeOperationAuditAlarm

VOID __stdcall SeOperationAuditAlarm(
        VOID *Object,
        VOID *HandleId,
        UNICODE_STRING *ObjectTypeName,
        UINT64 AuditMask,
        VOID *SecurityDescriptor){
  SECURITY_DESCRIPTOR *v5; 
  int v9; 
  __int64 CurrentThreadProcess; 
  ULONG_PTR v11; 
  int AllocatedFullProcessImageName; 
  void *PrimaryToken; 
  int v14; 
  ULONG_PTR v15; 
  ULONG v16; 
  int v17; 
  ULONG v18; 
  SE_ADT_PARAMETER_TYPE v19; 
  int v20; 
  SE_ADT_PARAMETER_TYPE v21; 
  ULONG v22; 
  NTSTATUS v23; 
  ULONG v24; 
  char NeedToFree[4]; 
  char SDLength[12]; 
  PVOID P; 
  PVOID v28; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectContext; 
  _SE_ADT_PARAMETER_ARRAY Src; 
  SECURITY_DESCRIPTOR *SecurityDescriptorIn; 
  v5 = SecurityDescriptorIn;
  *(_QWORD *)&SDLength[4] = SecurityDescriptorIn;
  P = 0i64;
  v28 = 0i64;
  *(_DWORD *)SDLength = 0;
  NeedToFree[0] = 0;
  memset(&SubjectContext, 0, sizeof(SubjectContext));
  v9 = SepAdtClassifyObjectIntoSubCategory(HandleId, (_UNICODE_STRING *)AuditMask, 1u, 0);
  CurrentThreadProcess = PsGetCurrentThreadProcess();
  v11 = *(_QWORD *)(CurrentThreadProcess + 1088);
  AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
  if( AllocatedFullProcessImageName < 0 )
  {
LABEL_24:
    SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
    goto LABEL_25;
  }
  memset((INT64)&Src, 0i64);
  Src.CategoryId = 3;
  Src.Type = 8;
  Src.FlatSubCategoryId = v9;
  Src.AuditId = 4663;
  SeCaptureSubjectContext(&SubjectContext);
  PrimaryToken = SubjectContext.PrimaryToken;
  Src.Parameters[0].Type = SeAdtParmTypeSid;
  if( SubjectContext.ClientToken )
    PrimaryToken = SubjectContext.ClientToken;
  Src.Parameters[1].Length = 32;
  Src.Parameters[1].Address = &SeSubsystemName;
  Src.Parameters[2].Type = SeAdtParmTypeLogonId;
  Src.Parameters[2].Length = 8;
  Src.Parameters[0].Address = (PVOID)**((_QWORD **)PrimaryToken + 19);
  v14 = *((unsigned __int8 *)Src.Parameters[0].Address + 1);
  Src.Parameters[1].Type = SeAdtParmTypeString;
  Src.Parameters[0].Length = 4 * v14 + 8;
  if( SubjectContext.ClientToken )
    v15 = *((_QWORD *)SubjectContext.ClientToken + 3);
  else
    v15 = *((_QWORD *)SubjectContext.PrimaryToken + 3);
  Src.Parameters[2].Data[0] = v15;
  v16 = *(unsigned __int16 *)AuditMask + 16;
  Src.Parameters[3].Type = SeAdtParmTypeString;
  Src.Parameters[4].Type = SeAdtParmTypeString;
  Src.Parameters[4].Length = v16;
  Src.Parameters[3].Length = 32;
  Src.Parameters[3].Address = &SeSubsystemName;
  Src.Parameters[4].Address = (PVOID)AuditMask;
  SepQueryNameString(HandleId, (_OBJECT_NAME_INFORMATION **)&v28);
  if( v28 )
  {
    if( (_WORD)v9 == 116 || (Src.Parameters[5].Type = SeAdtParmTypeString, (_WORD)v9 == 128) )
      Src.Parameters[5].Type = SeAdtParmTypeFileSpec;
    v17 = *(unsigned __int16 *)v28;
    Src.Parameters[5].Address = v28;
    Src.Parameters[5].Length = v17 + 16;
  }
  Src.Parameters[6].Type = SeAdtParmTypePtr;
  Src.Parameters[6].Length = 8;
  if( ObpIsKernelHandle(ObjectTypeName, 0) )
    ObjectTypeName = (UNICODE_STRING *)((unsigned __int64)ObjectTypeName ^ 0xFFFFFFFF80000000ui64);
  Src.Parameters[7].Length = 4;
  Src.Parameters[7].Data[1] = 4i64;
  Src.Parameters[8].Length = 4;
  Src.Parameters[7].Data[0] = (unsigned int)SecurityDescriptor;
  Src.Parameters[8].Data[0] = (unsigned int)SecurityDescriptor;
  Src.Parameters[10].Address = P;
  v22 = *(unsigned __int16 *)P + 16;
  Src.Parameters[6].Data[0] = (unsigned __int64)ObjectTypeName & 0xFFFFFFFFFFFFFFFCui64;
  Src.Parameters[7].Type = SeAdtParmTypeAccessMask;
  Src.Parameters[8].Type = SeAdtParmTypeHexUlong;
  Src.Parameters[9].Type = v19;
  Src.Parameters[9].Length = v18;
  Src.Parameters[9].Data[0] = v11;
  Src.Parameters[10].Type = v21;
  Src.Parameters[10].Length = v22;
  if( v9 != v20 && v9 - v20 != 12 || !SecurityDescriptorIn )
    goto LABEL_19;
  v23 = SepCheckAndCopySelfRelativeSD(
          SecurityDescriptorIn,
          (SECURITY_DESCRIPTOR **)&SDLength[4],
          (UINT64 *)SDLength,
          (UINT8 *)NeedToFree);
  v5 = *(SECURITY_DESCRIPTOR **)&SDLength[4];
  AllocatedFullProcessImageName = v23;
  if( v23 >= 0 )
  {
    Src.Parameters[11].Type = SeAdtParmTypeResourceAttribute;
    v24 = SepSecurityDescriptorStrictLength(*(VOID **)&SDLength[4]);
    Src.Parameters[11].Data[1] = 0i64;
    Src.Parameters[11].Length = v24;
    Src.Parameters[11].Address = v5;
    Src.Parameters[11].Data[0] = 32i64;
LABEL_19:
    Src.ParameterCount = 12;
    SepAdtLogAuditRecord(&Src);
    SeReleaseSubjectContext(&SubjectContext);
  }
  if( NeedToFree[0] && v5 )
    ExFreePoolWithTag(v5, 0);
  if( AllocatedFullProcessImageName < 0 )
    goto LABEL_24;
LABEL_25:
  if( P )
    ExFreePoolWithTag(P, 0);
  if( v28 )
    ExFreePoolWithTag(v28, 0);
}

Referenced by:

ObpAuditObjectAccess