2023-02-16 16:01:21 +00:00
|
|
|
/***
|
|
|
|
Copyright (C) 2023 J Reece Wilson (a/k/a "Reece"). All rights reserved.
|
|
|
|
|
|
|
|
File: AuProcAddresses.NT.hpp
|
|
|
|
Date: 2023-2-16
|
|
|
|
Author: Reece
|
|
|
|
***/
|
|
|
|
#pragma once
|
|
|
|
|
2023-07-24 11:48:42 +00:00
|
|
|
struct _PROCESS_MEMORY_COUNTERS;
|
|
|
|
|
2023-02-16 16:01:21 +00:00
|
|
|
namespace Aurora
|
|
|
|
{
|
|
|
|
void InitNTAddresses();
|
|
|
|
|
2023-07-09 10:26:17 +00:00
|
|
|
static const wchar_t *kSyncDllName { L"API-MS-Win-Core-Synch-l1-2-0.dll" };
|
|
|
|
static const wchar_t *kNtDllName { L"NTDLL.dll" };
|
|
|
|
static const wchar_t *kKernel32DllName { L"Kernel32.dll" };
|
|
|
|
static const wchar_t *kKernelBaseDllName { L"KernelBase.dll" };
|
|
|
|
static const wchar_t *kWS2DllName { L"Ws2_32.dll" };
|
|
|
|
static const wchar_t *kAdvancedApiDllName { L"Advapi32.dll" };
|
|
|
|
static const wchar_t *kBCryptDllName { L"bcrypt.dll" };
|
2023-07-24 06:17:08 +00:00
|
|
|
static const wchar_t *kThemeDllName { L"UxTheme.dll" };
|
|
|
|
static const wchar_t *kShellDllName { L"Shell32.dll" };
|
2023-07-24 11:48:42 +00:00
|
|
|
static const wchar_t *kPSAPILegacyDllName { L"psapi.dll" };
|
2023-07-09 09:03:29 +00:00
|
|
|
|
|
|
|
struct WIN32_MEMORY_RANGE_ENTRY2
|
|
|
|
{
|
|
|
|
PVOID VirtualAddress;
|
|
|
|
SIZE_T NumberOfBytes;
|
|
|
|
};
|
|
|
|
|
|
|
|
enum class THREAD_INFORMATION_CLASS
|
|
|
|
{
|
|
|
|
ThreadMemoryPriority,
|
|
|
|
ThreadAbsoluteCpuPriority,
|
|
|
|
ThreadDynamicCodePolicy,
|
|
|
|
ThreadPowerThrottling,
|
|
|
|
ThreadInformationClassMax
|
|
|
|
};
|
2023-02-16 16:01:21 +00:00
|
|
|
|
2023-07-13 19:00:28 +00:00
|
|
|
inline BOOL(__stdcall *pWaitOnAddress)(
|
2023-07-09 09:03:29 +00:00
|
|
|
volatile VOID * Address,
|
|
|
|
PVOID CompareAddress,
|
|
|
|
SIZE_T AddressSize,
|
|
|
|
DWORD dwMilliseconds
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
2023-07-13 19:00:28 +00:00
|
|
|
inline void(__stdcall *pWakeByAddressSingle)(
|
2023-07-09 09:03:29 +00:00
|
|
|
PVOID Address
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
2023-07-13 19:00:28 +00:00
|
|
|
inline void(__stdcall *pWakeByAddressAll)(
|
2023-07-09 09:03:29 +00:00
|
|
|
PVOID Address
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
2023-07-13 19:00:28 +00:00
|
|
|
inline DWORD(__stdcall *pNtDelayExecution)(
|
2023-07-09 09:03:29 +00:00
|
|
|
BOOLEAN Alertable,
|
|
|
|
PLARGE_INTEGER DelayInterval
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline PVOID(__stdcall *pVirtualAlloc2)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Process,
|
|
|
|
PVOID BaseAddress,
|
|
|
|
SIZE_T Size,
|
|
|
|
ULONG AllocationType,
|
|
|
|
ULONG PageProtection,
|
|
|
|
MEM_EXTENDED_PARAMETER * ExtendedParameters,
|
|
|
|
ULONG ParameterCount
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline PVOID(__stdcall *pMapViewOfFile3)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE FileMapping,
|
|
|
|
HANDLE Process,
|
|
|
|
PVOID BaseAddress,
|
|
|
|
ULONG64 Offset,
|
|
|
|
SIZE_T ViewSize,
|
|
|
|
ULONG AllocationType,
|
|
|
|
ULONG PageProtection,
|
|
|
|
MEM_EXTENDED_PARAMETER * ExtendedParameters,
|
|
|
|
ULONG ParameterCount
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline PVOID(__stdcall *pUnmapViewOfFile2)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Process,
|
|
|
|
PVOID BaseAddress,
|
|
|
|
ULONG UnmapFlags
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
|
2023-03-15 00:35:29 +00:00
|
|
|
inline NTSTATUS(__stdcall *pNtWaitForKeyedEvent)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Handle,
|
|
|
|
PVOID Key,
|
|
|
|
BOOLEAN Alertable,
|
|
|
|
PLARGE_INTEGER NTTimeout
|
2023-03-15 00:35:29 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline NTSTATUS(__stdcall *pNtReleaseKeyedEvent)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Handle,
|
|
|
|
PVOID Key,
|
|
|
|
BOOLEAN Alertable,
|
|
|
|
PLARGE_INTEGER NTTimeout
|
2023-03-15 00:35:29 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline NTSTATUS(__stdcall *pNtCreateKeyedEvent)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Handle,
|
|
|
|
ACCESS_MASK Access,
|
|
|
|
POBJECT_ATTRIBUTES Attr,
|
|
|
|
ULONG Flags
|
2023-03-15 00:35:29 +00:00
|
|
|
);
|
|
|
|
|
|
|
|
inline NTSTATUS(__stdcall *pNtOpenKeyedEvent)(
|
2023-07-09 09:03:29 +00:00
|
|
|
HANDLE Handle,
|
|
|
|
ACCESS_MASK Access,
|
|
|
|
POBJECT_ATTRIBUTES Attr,
|
|
|
|
ULONG Flags
|
2023-03-15 00:35:29 +00:00
|
|
|
);
|
2023-06-15 19:44:27 +00:00
|
|
|
|
|
|
|
inline NTSTATUS(__stdcall *pRtlWaitOnAddress)(
|
2023-07-09 09:03:29 +00:00
|
|
|
const void * addr,
|
|
|
|
const void * cmp,
|
|
|
|
SIZE_T size,
|
|
|
|
const LARGE_INTEGER * timeout);
|
2023-03-15 00:35:29 +00:00
|
|
|
|
2023-02-16 16:01:21 +00:00
|
|
|
#if defined(AURORA_PLATFORM_WIN32)
|
2023-07-09 09:02:21 +00:00
|
|
|
inline NTSTATUS(__stdcall *pRtlGetVersion)(
|
2023-07-09 09:03:29 +00:00
|
|
|
PRTL_OSVERSIONINFOW lpVersionInformation
|
2023-02-16 16:01:21 +00:00
|
|
|
);
|
|
|
|
#endif
|
2023-06-15 19:44:27 +00:00
|
|
|
|
2023-07-28 13:09:23 +00:00
|
|
|
inline NTSTATUS(__stdcall *pNtNotifyChangeDirectoryFile)(
|
|
|
|
HANDLE FileHandle,
|
|
|
|
HANDLE Event,
|
|
|
|
PIO_APC_ROUTINE ApcRoutine,
|
|
|
|
PVOID ApcContext,
|
|
|
|
PIO_STATUS_BLOCK IoStatusBlock,
|
|
|
|
PVOID Buffer,
|
|
|
|
ULONG BufferSize,
|
|
|
|
ULONG CompletionFilter,
|
|
|
|
BOOLEAN WatchTree
|
|
|
|
);
|
|
|
|
|
2023-08-19 12:30:44 +00:00
|
|
|
inline NTSTATUS(__stdcall *pNtTerminateProcess)(
|
|
|
|
HANDLE ProcessHandle,
|
|
|
|
NTSTATUS ExitStatus
|
|
|
|
);
|
|
|
|
|
2023-07-09 09:02:21 +00:00
|
|
|
inline BOOL(__stdcall *pGetSystemCpuSetInformation)(
|
|
|
|
PSYSTEM_CPU_SET_INFORMATION Information,
|
2023-07-09 09:03:29 +00:00
|
|
|
ULONG BufferLength,
|
|
|
|
PULONG ReturnedLength,
|
|
|
|
HANDLE Process,
|
|
|
|
ULONG Flags
|
2023-07-09 09:02:21 +00:00
|
|
|
);
|
|
|
|
|
2023-07-09 09:03:29 +00:00
|
|
|
inline BOOL(__stdcall *pGetLogicalProcessorInformation)(
|
2023-07-09 09:02:21 +00:00
|
|
|
PSYSTEM_LOGICAL_PROCESSOR_INFORMATION Buffer,
|
2023-07-09 09:03:29 +00:00
|
|
|
PDWORD ReturnedLength
|
|
|
|
);
|
|
|
|
|
|
|
|
inline HRESULT(__stdcall *pSetThreadDescription)(
|
|
|
|
HANDLE hThread,
|
|
|
|
PCWSTR lpThreadDescription
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pSetThreadInformation)(
|
|
|
|
HANDLE hThread,
|
|
|
|
THREAD_INFORMATION_CLASS ThreadInformationClass,
|
|
|
|
LPVOID ThreadInformation,
|
|
|
|
DWORD ThreadInformationSize
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pSetThreadSelectedCpuSets)(
|
|
|
|
HANDLE Thread,
|
|
|
|
const ULONG * CpuSetIds,
|
|
|
|
ULONG CpuSetIdCount
|
|
|
|
);
|
2023-07-14 15:31:47 +00:00
|
|
|
|
|
|
|
#if defined(AURORA_PLATFORM_WIN32)
|
|
|
|
inline BOOL(__stdcall *pSetThreadGroupAffinity)(
|
|
|
|
HANDLE hThread,
|
|
|
|
GROUP_AFFINITY * GroupAffinity,
|
|
|
|
PGROUP_AFFINITY PreviousGroupAffinity
|
|
|
|
);
|
|
|
|
#endif
|
|
|
|
|
2023-07-09 09:03:29 +00:00
|
|
|
inline INT(__stdcall *pGetAddrInfoExCancel)(
|
|
|
|
LPHANDLE lpHandle
|
|
|
|
);
|
|
|
|
|
2023-07-24 06:17:08 +00:00
|
|
|
using LPLOOKUPSERVICE_COMPLETION_ROUTINE = void(__stdcall *)(
|
|
|
|
DWORD dwError,
|
|
|
|
DWORD dwBytes,
|
|
|
|
LPWSAOVERLAPPED lpOverlapped
|
|
|
|
);
|
|
|
|
|
|
|
|
inline INT(__stdcall *pGetAddrInfoExW)(
|
|
|
|
PCWSTR pName,
|
|
|
|
PCWSTR pServiceName,
|
|
|
|
DWORD dwNameSpace,
|
|
|
|
LPGUID lpNspId,
|
|
|
|
const ADDRINFOEXW * hints,
|
|
|
|
PADDRINFOEXW * ppResult,
|
|
|
|
struct timeval * timeout,
|
|
|
|
LPOVERLAPPED lpOverlapped,
|
|
|
|
LPLOOKUPSERVICE_COMPLETION_ROUTINE lpCompletionRoutine,
|
|
|
|
LPHANDLE lpHandle
|
|
|
|
);
|
|
|
|
|
|
|
|
inline void(__stdcall *pFreeAddrInfoExW)(
|
|
|
|
PADDRINFOEXW pAddrInfoEx
|
|
|
|
);
|
|
|
|
|
|
|
|
inline INT(__stdcall *pgetaddrinfo)(
|
|
|
|
PCSTR pNodeName,
|
|
|
|
PCSTR pServiceName,
|
|
|
|
const ADDRINFOA * pHints,
|
|
|
|
PADDRINFOA * ppResult
|
|
|
|
);
|
|
|
|
|
|
|
|
inline void(__stdcall *pfreeaddrinfo)(
|
|
|
|
PADDRINFOA pAddrInfo
|
|
|
|
);
|
|
|
|
|
2023-07-09 09:03:29 +00:00
|
|
|
inline BOOL(__stdcall *pPrefetchVirtualMemory)(
|
|
|
|
HANDLE hProcess,
|
|
|
|
ULONG_PTR NumberOfEntries,
|
|
|
|
WIN32_MEMORY_RANGE_ENTRY2 * VirtualAddresses,
|
|
|
|
ULONG Flags
|
2023-07-09 09:02:21 +00:00
|
|
|
);
|
|
|
|
|
2023-07-09 10:26:17 +00:00
|
|
|
inline NTSTATUS(__stdcall *pBCryptGenRandom)(
|
|
|
|
PVOID hAlgorithm,
|
|
|
|
PUCHAR pbBuffer,
|
|
|
|
ULONG cbBuffer,
|
|
|
|
ULONG dwFlags
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pCryptGenRandom)(
|
|
|
|
ULONG_PTR hProv,
|
|
|
|
DWORD dwLen,
|
|
|
|
BYTE *pbBuffer
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pCryptAcquireContextW)(
|
|
|
|
ULONG_PTR * hProv,
|
|
|
|
LPCWSTR szContainer,
|
|
|
|
LPCWSTR szProvider,
|
|
|
|
DWORD dwProvType,
|
|
|
|
DWORD dwFlags
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pCryptReleaseContext)(
|
|
|
|
ULONG_PTR hProvz,
|
|
|
|
DWORD dwFlags
|
|
|
|
);
|
|
|
|
|
2023-07-09 11:34:14 +00:00
|
|
|
inline NTSTATUS(__stdcall *pZwSetTimerResolution)(
|
|
|
|
ULONG RequestedResolution,
|
|
|
|
BOOLEAN Set,
|
|
|
|
PULONG ActualResolution
|
|
|
|
);
|
|
|
|
|
2023-07-11 16:58:20 +00:00
|
|
|
inline BOOLEAN(__stdcall *pRtlGenRandom)(
|
|
|
|
PVOID RandomBuffer,
|
|
|
|
ULONG RandomBufferLength
|
|
|
|
);
|
|
|
|
|
2023-07-24 06:17:08 +00:00
|
|
|
#if defined(AURORA_PLATFORM_WIN32)
|
|
|
|
inline NTSTATUS(__stdcall *pNtQueryInformationProcess)(
|
|
|
|
HANDLE ProcessHandle,
|
|
|
|
PROCESSINFOCLASS ProcessInformationClass,
|
|
|
|
PVOID ProcessInformation,
|
|
|
|
ULONG ProcessInformationLength,
|
|
|
|
PULONG ReturnLength
|
|
|
|
);
|
|
|
|
#endif
|
|
|
|
|
|
|
|
inline HRESULT(__stdcall *pSetWindowTheme)(
|
|
|
|
HWND hwnd,
|
|
|
|
LPCWSTR pszSubAppName,
|
|
|
|
LPCWSTR pszSubIdList
|
|
|
|
);
|
|
|
|
|
|
|
|
inline HANDLE(__stdcall *pFindFirstStreamW)(
|
|
|
|
LPCWSTR lpFileName,
|
|
|
|
STREAM_INFO_LEVELS InfoLevel,
|
|
|
|
LPVOID lpFindStreamData,
|
|
|
|
DWORD dwFlags
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pFindNextStreamW)(
|
|
|
|
HANDLE hFindStream,
|
|
|
|
LPVOID lpFindStreamData
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pFindClose)(
|
|
|
|
HANDLE hFindFile
|
|
|
|
);
|
|
|
|
|
2023-07-24 11:48:42 +00:00
|
|
|
inline BOOL(__stdcall *pCancelIoEx)(
|
|
|
|
HANDLE hFile,
|
|
|
|
LPOVERLAPPED lpOverlapped
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pCancelSynchronousIo)(
|
|
|
|
HANDLE hThread
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pGetProcessMemoryInfo)(
|
|
|
|
HANDLE Process,
|
|
|
|
::_PROCESS_MEMORY_COUNTERS *ppsmemCounters,
|
|
|
|
DWORD cb
|
|
|
|
);
|
|
|
|
|
|
|
|
inline BOOL(__stdcall *pSetFileInformationByHandle)(
|
|
|
|
HANDLE hFile,
|
|
|
|
FILE_INFO_BY_HANDLE_CLASS FileInformationClass,
|
|
|
|
LPVOID lpFileInformation,
|
|
|
|
DWORD dwBufferSize
|
|
|
|
);
|
|
|
|
|
|
|
|
inline int(__stdcall *pGetLocaleInfoEx)(
|
|
|
|
LPCWSTR lpLocaleName,
|
|
|
|
LCTYPE LCType,
|
|
|
|
LPWSTR lpLCData,
|
|
|
|
int cchData
|
|
|
|
);
|
|
|
|
|
|
|
|
inline int(__stdcall *pLCIDToLocaleName)(
|
|
|
|
LCID Locale,
|
|
|
|
LPWSTR lpName,
|
|
|
|
int cchName,
|
|
|
|
DWORD dwFlags
|
|
|
|
);
|
|
|
|
|
|
|
|
inline int(__stdcall *pGetLocaleInfoW)(
|
|
|
|
LCID Locale,
|
|
|
|
LCTYPE LCType,
|
|
|
|
LPWSTR lpLCData,
|
|
|
|
int cchData
|
|
|
|
);
|
|
|
|
|
|
|
|
inline DWORD(__stdcall *pGetThreadId)(
|
|
|
|
HANDLE hThread
|
|
|
|
);
|
|
|
|
|
2023-07-24 06:17:08 +00:00
|
|
|
inline HRESULT(__stdcall *pSHGetKnownFolderPath)(
|
|
|
|
const GUID & rfid,
|
|
|
|
DWORD dwFlags,
|
|
|
|
HANDLE hToken,
|
|
|
|
PWSTR * ppszPath
|
|
|
|
);
|
2023-07-24 11:48:42 +00:00
|
|
|
|
2023-06-15 19:44:27 +00:00
|
|
|
inline bool gUseNativeWaitMutex {};
|
|
|
|
inline bool gUseNativeWaitCondvar {};
|
2023-06-15 23:05:46 +00:00
|
|
|
inline bool gUseNativeWaitSemapahore {};
|
2023-07-09 11:34:14 +00:00
|
|
|
|
2023-07-11 14:21:55 +00:00
|
|
|
inline bool gUseFastFail {};
|
|
|
|
|
2023-07-09 12:51:05 +00:00
|
|
|
void Win32DropInit();
|
2023-07-09 11:34:14 +00:00
|
|
|
void Win32DropSchedulerResolution();
|
2023-07-11 14:21:55 +00:00
|
|
|
|
|
|
|
void Win32Terminate();
|
2023-02-16 16:01:21 +00:00
|
|
|
}
|