EtwpUpdateProcessTracingCallback

INT64 __fastcall EtwpUpdateProcessTracingCallback(_EPROCESS *Process, VOID *Context){
  __int64 v4; 
  struct _EX_RUNDOWN_REF *v5; 
  char v6; 
  unsigned int v7; 
  __int64 v8; 
  __int64 *v9; 
  _KAPC_STATE ApcState; 
  memset(&ApcState, 0, sizeof(ApcState));
  v4 = *((_QWORD *)Process + 170);
  if( v4 )
  {
    v5 = (struct _EX_RUNDOWN_REF *)((char *)Process + 1112);
    if( ExAcquireRundownProtection((PEX_RUNDOWN_REF)Process + 139) )
    {
      KiStackAttachProcess((_KPROCESS *)Process, 0i64, &ApcState);
      v6 = *((_BYTE *)Context + 4);
      v7 = *(_DWORD *)Context;
      if( v6 )
        _interlockedbittestandset((volatile signed __int32 *)(v4 + 888), v7);
      else
        _interlockedbittestandreset((volatile signed __int32 *)(v4 + 888), v7);
      v8 = 0i64;
      v9 = (__int64 *)*((_QWORD *)Process + 176);
      if( v9 )
        v8 = *v9;
      if( v8 )
      {
        if( v6 )
          _interlockedbittestandset((volatile signed __int32 *)(v8 + 576), v7);
        else
          _interlockedbittestandreset((volatile signed __int32 *)(v8 + 576), v7);
      }
      KiUnstackDetachProcess(&ApcState, 0i64);
      ExReleaseRundownProtection(v5);
    }
  }
  return 0i64;
}

Referenced by:

EtwpUpdatePerProcessTracing