PsSetCreateProcessNotifyRoutineEx进程监控框架

vs设置:“项目-属性-链接器-命令行”位置添加 /INTEGRITYCHECK 即可,不然注册回调的时候会失败
参考:https://xiaodaozhi.com/kernel/18.html

#include <ntddk.h>

typedef NTSTATUS (*PPsSetCreateProcessNotifyRoutineEx)(
_In_ PCREATE_PROCESS_NOTIFY_ROUTINE_EX NotifyRoutine,
_In_ BOOLEAN Remove
);

PPsSetCreateProcessNotifyRoutineEx pPsSetCreateProcessNotifyRoutineEx = NULL;
BOOLEAN	bRegister = FALSE;

VOID CreateProcessNotifyEx(
	_Inout_  PEPROCESS              Process,
	_In_     HANDLE                 ProcessId,
	_In_opt_ PPS_CREATE_NOTIFY_INFO CreateInfo
	)
{
	HANDLE	hParentId = NULL;
	HANDLE	hParentThreadId = NULL;
	HANDLE	hCurrentThreadId = NULL;
	hCurrentThreadId = PsGetCurrentThreadId();
	if (CreateInfo == NULL){
		DbgPrint("ProcessDestory ThreadID[%d]", hCurrentThreadId);
		return;
	}
	hParentId = CreateInfo->CreatingThreadId.UniqueProcess;
	hParentThreadId = CreateInfo->CreatingThreadId.UniqueThread;
	DbgPrint("CreateProcess ParentID[%d] Name:%wZ", hParentId, CreateInfo->ImageFileName);
	return;

}

NTSTATUS	Unload(PDRIVER_OBJECT driver)
{
	DbgPrint("unload driver");
	if (bRegister && pPsSetCreateProcessNotifyRoutineEx){
		pPsSetCreateProcessNotifyRoutineEx(CreateProcessNotifyEx, TRUE);
		bRegister = FALSE;
	}
	return STATUS_SUCCESS;
}



NTSTATUS	DriverEntry(PDRIVER_OBJECT	driver, PUNICODE_STRING	RegPath)
{
	DbgPrint("Driver Entry");
	driver->DriverUnload = Unload;
	do{
		UNICODE_STRING	uFunName = { 0 };
		RtlInitUnicodeString(&uFunName, L"PsSetCreateProcessNotifyRoutineEx");

		pPsSetCreateProcessNotifyRoutineEx = (PPsSetCreateProcessNotifyRoutineEx)MmGetSystemRoutineAddress(&uFunName);
		if (pPsSetCreateProcessNotifyRoutineEx == NULL){
			DbgPrint("GetSetCreateProcessNotif Failed");
			break;
		}
		if (STATUS_SUCCESS != pPsSetCreateProcessNotifyRoutineEx(CreateProcessNotifyEx, FALSE)){
			DbgPrint("Register Process Notify Failed");
			break;
		}
		bRegister = TRUE;
		DbgPrint("Register Process Notify Success");

	} while (FALSE);
	return STATUS_SUCCESS;
}

在这里插入图片描述

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值