2023-08-20 16:12:04 +02:00
|
|
|
#ifndef CALLBACKS_H
|
|
|
|
#define CALLBACKS_H
|
|
|
|
|
|
|
|
#include <ntifs.h>
|
|
|
|
#include <wdftypes.h>
|
|
|
|
#include <wdf.h>
|
2023-08-29 19:36:58 +02:00
|
|
|
#include "common.h"
|
2023-08-20 16:12:04 +02:00
|
|
|
|
2023-08-20 17:04:53 +02:00
|
|
|
#define HANDLE_REPORT_PROCESS_NAME_MAX_LENGTH 64
|
|
|
|
|
2023-08-20 16:12:04 +02:00
|
|
|
typedef struct _OPEN_HANDLE_FAILURE_REPORT
|
|
|
|
{
|
|
|
|
INT report_code;
|
|
|
|
INT is_kernel_handle;
|
|
|
|
LONG process_id;
|
|
|
|
LONG thread_id;
|
2023-08-22 10:51:52 +02:00
|
|
|
LONG access;
|
2023-10-05 08:27:17 +02:00
|
|
|
CHAR process_name[HANDLE_REPORT_PROCESS_NAME_MAX_LENGTH];
|
2023-08-20 16:12:04 +02:00
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
}OPEN_HANDLE_FAILURE_REPORT, * POPEN_HANDLE_FAILURE_REPORT;
|
2023-08-20 16:12:04 +02:00
|
|
|
|
|
|
|
//handle access masks
|
|
|
|
//https://learn.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights
|
|
|
|
#define PROCESS_CREATE_PROCESS 0x0080
|
|
|
|
#define PROCESS_TERMINATE 0x0001
|
|
|
|
#define PROCESS_CREATE_THREAD 0x0002
|
|
|
|
#define PROCESS_DUP_HANDLE 0x0040
|
|
|
|
#define PROCESS_QUERY_INFORMATION 0x0400
|
|
|
|
#define PROCESS_QUERY_LIMITED_INFORMATION 0x1000
|
|
|
|
#define PROCESS_SET_INFORMATION 0x0200
|
|
|
|
#define PROCESS_SET_QUOTA 0x0100
|
|
|
|
#define PROCESS_SUSPEND_RESUME 0x0800
|
|
|
|
#define PROCESS_VM_OPERATION 0x0008
|
|
|
|
#define PROCESS_VM_READ 0x0010
|
|
|
|
#define PROCESS_VM_WRITE 0x0020
|
|
|
|
|
2023-08-22 10:51:52 +02:00
|
|
|
//https://www.sysnative.com/forums/threads/object-headers-handles-and-types.34987/
|
|
|
|
#define GET_OBJECT_HEADER_FROM_HANDLE(x) ((x << 4) | 0xffff000000000000)
|
|
|
|
|
|
|
|
static const uintptr_t EPROCESS_IMAGE_FILE_NAME_OFFSET = 0x5a8;
|
|
|
|
static const uintptr_t EPROCESS_HANDLE_TABLE_OFFSET = 0x570;
|
|
|
|
static const uintptr_t EPROCESS_PLIST_ENTRY_OFFSET = 0x448;
|
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
static UNICODE_STRING OBJECT_TYPE_PROCESS = RTL_CONSTANT_STRING(L"Process");
|
|
|
|
static UNICODE_STRING OBJECT_TYPE_THREAD = RTL_CONSTANT_STRING(L"Thread");
|
2023-08-29 19:36:58 +02:00
|
|
|
|
2023-10-09 09:34:30 +02:00
|
|
|
typedef struct _THREAD_LIST_ENTRY
|
|
|
|
{
|
|
|
|
SINGLE_LIST_ENTRY list;
|
|
|
|
PKTHREAD thread;
|
|
|
|
PKPROCESS owning_process;
|
|
|
|
BOOLEAN apc_queued;
|
|
|
|
PKAPC apc;
|
|
|
|
|
|
|
|
}THREAD_LIST_ENTRY, * PTHREAD_LIST_ENTRY;
|
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
VOID
|
|
|
|
NTAPI
|
2023-09-27 06:22:14 +02:00
|
|
|
ExUnlockHandleTableEntry(
|
2023-08-29 19:36:58 +02:00
|
|
|
IN PHANDLE_TABLE HandleTable,
|
|
|
|
IN PHANDLE_TABLE_ENTRY HandleTableEntry
|
|
|
|
);
|
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
VOID
|
2023-09-27 06:22:14 +02:00
|
|
|
ObPostOpCallbackRoutine(
|
2023-08-20 16:12:04 +02:00
|
|
|
_In_ PVOID RegistrationContext,
|
|
|
|
_In_ POB_POST_OPERATION_INFORMATION OperationInformation
|
|
|
|
);
|
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
OB_PREOP_CALLBACK_STATUS
|
2023-09-27 06:22:14 +02:00
|
|
|
ObPreOpCallbackRoutine(
|
2023-08-20 16:12:04 +02:00
|
|
|
_In_ PVOID RegistrationContext,
|
|
|
|
_In_ POB_PRE_OPERATION_INFORMATION OperationInformation
|
|
|
|
);
|
|
|
|
|
2023-09-02 10:54:04 +02:00
|
|
|
//VOID ProcessCreateNotifyRoutine(
|
|
|
|
// _In_ HANDLE ParentId,
|
|
|
|
// _In_ HANDLE ProcessId,
|
|
|
|
// _In_ BOOLEAN Create
|
|
|
|
//);
|
2023-08-21 11:45:00 +02:00
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
VOID
|
2023-09-27 06:22:14 +02:00
|
|
|
EnumerateProcessListWithCallbackFunction(
|
2023-09-13 12:06:25 +02:00
|
|
|
_In_ PVOID Function,
|
2023-09-13 12:25:32 +02:00
|
|
|
_In_opt_ PVOID Context
|
2023-08-22 10:51:52 +02:00
|
|
|
);
|
|
|
|
|
2023-10-05 08:27:17 +02:00
|
|
|
NTSTATUS
|
2023-09-27 06:22:14 +02:00
|
|
|
EnumerateProcessHandles(
|
2023-08-22 10:51:52 +02:00
|
|
|
_In_ PEPROCESS Process
|
|
|
|
);
|
|
|
|
|
2023-10-08 16:07:49 +02:00
|
|
|
NTSTATUS
|
|
|
|
InitialiseThreadList();
|
|
|
|
|
|
|
|
VOID
|
|
|
|
ThreadCreateNotifyRoutine(
|
|
|
|
_In_ HANDLE ProcessId,
|
|
|
|
_In_ HANDLE ThreadId,
|
|
|
|
_In_ BOOLEAN Create
|
|
|
|
);
|
|
|
|
|
|
|
|
VOID
|
|
|
|
CleanupThreadListOnDriverUnload();
|
|
|
|
|
2023-10-09 09:34:30 +02:00
|
|
|
VOID
|
|
|
|
FindThreadListEntryByThreadAddress(
|
|
|
|
_In_ PKTHREAD Thread,
|
|
|
|
_Inout_ PTHREAD_LIST_ENTRY* Entry
|
|
|
|
);
|
|
|
|
|
2023-08-20 16:12:04 +02:00
|
|
|
#endif
|