forked from test0x101/EtwHookDbg
-
Notifications
You must be signed in to change notification settings - Fork 0
/
DriverMain.c
78 lines (66 loc) · 1.78 KB
/
DriverMain.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
#include<ntifs.h>
#include "Dbg.h"
#include "SearchFunc.h"
#include "hook\HookDebugApi.h"
#include "hook\Function.h"
#include "BEPatchDebug/etw/EtwControl.h"
#include "Pg\DisPg.h"
void SyscallCallback(_In_ unsigned int SystemCallIndex, _Inout_ void** SystemCallFunction)
{
if (GetNtCreateDebugObjectFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtCreateDebugObject;
}
else if (GetNtDebugActiveProcessFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtDebugActiveProcess;
}
else if (GetNtDebugContinueFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtDebugContinue;
}
else if (GetNtRemoveProcessDebugFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtRemoveProcessDebug;
}
else if (GetNtWaitForDebugEventFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtWaitForDebugEvent;
}
else if (GetNtReadVirtualMemoryFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtReadVirtualMemory;
}
else if (GetNtWriteVirtualMemoryFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtWriteVirtualMemory;
}
else if (GetNtProtectVirtualMemoryFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtProtectVirtualMemory;
}
else if (GetNtSetContextThreadFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtSetContextThread;
}
else if (GetNtGetContextThreadFunc() == *SystemCallFunction)
{
*SystemCallFunction = HotGeNtGetContextThread;
}
}
VOID DriverUnload(PDRIVER_OBJECT pDriver)
{
KdPrint(("DriverUnload\r\n"));
DestoryHookAll();
IfhOff();
}
NTSTATUS DriverEntry(PDRIVER_OBJECT pDriver, PUNICODE_STRING pReg)
{
GetKiRetireDpcList();
HotGetDbgkInitialize();
InitHook();
IfhOn(SyscallCallback);
pDriver->DriverUnload = DriverUnload;
KdPrint(("DriverEntry\r\n"));
return 0;
}