SeOperationAuditAlarm
VOID __stdcall SeOperationAuditAlarm(
VOID *Object,
VOID *HandleId,
UNICODE_STRING *ObjectTypeName,
UINT64 AuditMask,
VOID *SecurityDescriptor){
SECURITY_DESCRIPTOR *v5;
int v9;
__int64 CurrentThreadProcess;
ULONG_PTR v11;
int AllocatedFullProcessImageName;
void *PrimaryToken;
int v14;
ULONG_PTR v15;
ULONG v16;
int v17;
ULONG v18;
SE_ADT_PARAMETER_TYPE v19;
int v20;
SE_ADT_PARAMETER_TYPE v21;
ULONG v22;
NTSTATUS v23;
ULONG v24;
char NeedToFree[4];
char SDLength[12];
PVOID P;
PVOID v28;
struct _SECURITY_SUBJECT_CONTEXT SubjectContext;
_SE_ADT_PARAMETER_ARRAY Src;
SECURITY_DESCRIPTOR *SecurityDescriptorIn;
v5 = SecurityDescriptorIn;
*(_QWORD *)&SDLength[4] = SecurityDescriptorIn;
P = 0i64;
v28 = 0i64;
*(_DWORD *)SDLength = 0;
NeedToFree[0] = 0;
memset(&SubjectContext, 0, sizeof(SubjectContext));
v9 = SepAdtClassifyObjectIntoSubCategory(HandleId, (_UNICODE_STRING *)AuditMask, 1u, 0);
CurrentThreadProcess = PsGetCurrentThreadProcess();
v11 = *(_QWORD *)(CurrentThreadProcess + 1088);
AllocatedFullProcessImageName = PsGetAllocatedFullProcessImageNameEx(CurrentThreadProcess, &P);
if( AllocatedFullProcessImageName < 0 )
{
LABEL_24:
SepAuditFailed((unsigned int)AllocatedFullProcessImageName);
goto LABEL_25;
}
memset((INT64)&Src, 0i64);
Src.CategoryId = 3;
Src.Type = 8;
Src.FlatSubCategoryId = v9;
Src.AuditId = 4663;
SeCaptureSubjectContext(&SubjectContext);
PrimaryToken = SubjectContext.PrimaryToken;
Src.Parameters[0].Type = SeAdtParmTypeSid;
if( SubjectContext.ClientToken )
PrimaryToken = SubjectContext.ClientToken;
Src.Parameters[1].Length = 32;
Src.Parameters[1].Address = &SeSubsystemName;
Src.Parameters[2].Type = SeAdtParmTypeLogonId;
Src.Parameters[2].Length = 8;
Src.Parameters[0].Address = (PVOID)**((_QWORD **)PrimaryToken + 19);
v14 = *((unsigned __int8 *)Src.Parameters[0].Address + 1);
Src.Parameters[1].Type = SeAdtParmTypeString;
Src.Parameters[0].Length = 4 * v14 + 8;
if( SubjectContext.ClientToken )
v15 = *((_QWORD *)SubjectContext.ClientToken + 3);
else
v15 = *((_QWORD *)SubjectContext.PrimaryToken + 3);
Src.Parameters[2].Data[0] = v15;
v16 = *(unsigned __int16 *)AuditMask + 16;
Src.Parameters[3].Type = SeAdtParmTypeString;
Src.Parameters[4].Type = SeAdtParmTypeString;
Src.Parameters[4].Length = v16;
Src.Parameters[3].Length = 32;
Src.Parameters[3].Address = &SeSubsystemName;
Src.Parameters[4].Address = (PVOID)AuditMask;
SepQueryNameString(HandleId, (_OBJECT_NAME_INFORMATION **)&v28);
if( v28 )
{
if( (_WORD)v9 == 116 || (Src.Parameters[5].Type = SeAdtParmTypeString, (_WORD)v9 == 128) )
Src.Parameters[5].Type = SeAdtParmTypeFileSpec;
v17 = *(unsigned __int16 *)v28;
Src.Parameters[5].Address = v28;
Src.Parameters[5].Length = v17 + 16;
}
Src.Parameters[6].Type = SeAdtParmTypePtr;
Src.Parameters[6].Length = 8;
if( ObpIsKernelHandle(ObjectTypeName, 0) )
ObjectTypeName = (UNICODE_STRING *)((unsigned __int64)ObjectTypeName ^ 0xFFFFFFFF80000000ui64);
Src.Parameters[7].Length = 4;
Src.Parameters[7].Data[1] = 4i64;
Src.Parameters[8].Length = 4;
Src.Parameters[7].Data[0] = (unsigned int)SecurityDescriptor;
Src.Parameters[8].Data[0] = (unsigned int)SecurityDescriptor;
Src.Parameters[10].Address = P;
v22 = *(unsigned __int16 *)P + 16;
Src.Parameters[6].Data[0] = (unsigned __int64)ObjectTypeName & 0xFFFFFFFFFFFFFFFCui64;
Src.Parameters[7].Type = SeAdtParmTypeAccessMask;
Src.Parameters[8].Type = SeAdtParmTypeHexUlong;
Src.Parameters[9].Type = v19;
Src.Parameters[9].Length = v18;
Src.Parameters[9].Data[0] = v11;
Src.Parameters[10].Type = v21;
Src.Parameters[10].Length = v22;
if( v9 != v20 && v9 - v20 != 12 || !SecurityDescriptorIn )
goto LABEL_19;
v23 = SepCheckAndCopySelfRelativeSD(
SecurityDescriptorIn,
(SECURITY_DESCRIPTOR **)&SDLength[4],
(UINT64 *)SDLength,
(UINT8 *)NeedToFree);
v5 = *(SECURITY_DESCRIPTOR **)&SDLength[4];
AllocatedFullProcessImageName = v23;
if( v23 >= 0 )
{
Src.Parameters[11].Type = SeAdtParmTypeResourceAttribute;
v24 = SepSecurityDescriptorStrictLength(*(VOID **)&SDLength[4]);
Src.Parameters[11].Data[1] = 0i64;
Src.Parameters[11].Length = v24;
Src.Parameters[11].Address = v5;
Src.Parameters[11].Data[0] = 32i64;
LABEL_19:
Src.ParameterCount = 12;
SepAdtLogAuditRecord(&Src);
SeReleaseSubjectContext(&SubjectContext);
}
if( NeedToFree[0] && v5 )
ExFreePoolWithTag(v5, 0);
if( AllocatedFullProcessImageName < 0 )
goto LABEL_24;
LABEL_25:
if( P )
ExFreePoolWithTag(P, 0);
if( v28 )
ExFreePoolWithTag(v28, 0);
}Referenced by:
ObpAuditObjectAccess