|
23 | 23 |
|
24 | 24 | #include <ph.h>
|
25 | 25 | #include <hndlinfo.h>
|
| 26 | +#include <json.h> |
26 | 27 |
|
27 | 28 | #include <kphuser.h>
|
28 | 29 | #include <lsasup.h>
|
@@ -416,6 +417,122 @@ NTSTATUS PhpGetEtwObjectName(
|
416 | 417 | return status;
|
417 | 418 | }
|
418 | 419 |
|
| 420 | +typedef struct _PH_ETW_TRACEGUID_ENTRY |
| 421 | +{ |
| 422 | + PPH_STRING Name; |
| 423 | + PGUID Guid; |
| 424 | +} PH_ETW_TRACEGUID_ENTRY, *PPH_ETW_TRACEGUID_ENTRY; |
| 425 | + |
| 426 | +VOID PhInitializeEtwTraceGuidCache( |
| 427 | + _Inout_ PPH_ARRAY EtwTraceGuidArrayList |
| 428 | + ) |
| 429 | +{ |
| 430 | + PPH_STRING applicationDirectory; |
| 431 | + PPH_BYTES capabilityListString = NULL; |
| 432 | + PVOID jsonObject; |
| 433 | + ULONG arrayLength; |
| 434 | + |
| 435 | + if (applicationDirectory = PhGetApplicationDirectory()) |
| 436 | + { |
| 437 | + PPH_STRING capabilityListFileName; |
| 438 | + |
| 439 | + capabilityListFileName = PhConcatStringRefZ(&applicationDirectory->sr, L"etwguids.txt"); |
| 440 | + PhDereferenceObject(applicationDirectory); |
| 441 | + |
| 442 | + capabilityListString = PhFileReadAllText(capabilityListFileName->Buffer, FALSE); |
| 443 | + PhDereferenceObject(capabilityListFileName); |
| 444 | + } |
| 445 | + |
| 446 | + if (!capabilityListString) |
| 447 | + return; |
| 448 | + |
| 449 | + PhInitializeArray(EtwTraceGuidArrayList, sizeof(PH_ETW_TRACEGUID_ENTRY), 2000); |
| 450 | + |
| 451 | + if (!(jsonObject = PhCreateJsonParser(capabilityListString->Buffer))) |
| 452 | + return; |
| 453 | + |
| 454 | + if (!(arrayLength = PhGetJsonArrayLength(jsonObject))) |
| 455 | + { |
| 456 | + PhFreeJsonParser(jsonObject); |
| 457 | + return; |
| 458 | + } |
| 459 | + |
| 460 | + for (ULONG i = 0; i < arrayLength; i++) |
| 461 | + { |
| 462 | + PVOID jsonArrayObject; |
| 463 | + PPH_STRING guidString; |
| 464 | + PPH_STRING guidName; |
| 465 | + UNICODE_STRING guidStringUs; |
| 466 | + GUID guid; |
| 467 | + PH_ETW_TRACEGUID_ENTRY result; |
| 468 | + |
| 469 | + if (!(jsonArrayObject = PhGetJsonArrayIndexObject(jsonObject, i))) |
| 470 | + continue; |
| 471 | + |
| 472 | + guidString = PhGetJsonValueAsString(jsonArrayObject, "guid"); |
| 473 | + guidName = PhGetJsonValueAsString(jsonArrayObject, "name"); |
| 474 | + //guidGroup = PhGetJsonValueAsString(jsonArrayObject, "group"); |
| 475 | + |
| 476 | + if (!PhStringRefToUnicodeString(&guidString->sr, &guidStringUs)) |
| 477 | + { |
| 478 | + PhDereferenceObject(guidName); |
| 479 | + PhDereferenceObject(guidString); |
| 480 | + continue; |
| 481 | + } |
| 482 | + |
| 483 | + if (!NT_SUCCESS(RtlGUIDFromString( |
| 484 | + &guidStringUs, |
| 485 | + &guid |
| 486 | + ))) |
| 487 | + { |
| 488 | + PhDereferenceObject(guidName); |
| 489 | + PhDereferenceObject(guidString); |
| 490 | + continue; |
| 491 | + } |
| 492 | + |
| 493 | + result.Name = guidName; |
| 494 | + result.Guid = PhAllocateCopy(&guid, sizeof(GUID)); |
| 495 | + |
| 496 | + PhAddItemArray(EtwTraceGuidArrayList, &result); |
| 497 | + |
| 498 | + PhDereferenceObject(guidString); |
| 499 | + } |
| 500 | + |
| 501 | + PhDereferenceObject(capabilityListString); |
| 502 | + PhFreeJsonParser(jsonObject); |
| 503 | +} |
| 504 | + |
| 505 | +PPH_STRING PhGetEtwTraceGuidName( |
| 506 | + _In_ PGUID Guid |
| 507 | + ) |
| 508 | +{ |
| 509 | + static PH_INITONCE initOnce = PH_INITONCE_INIT; |
| 510 | + static PH_ARRAY etwTraceGuidArrayList; |
| 511 | + PPH_ETW_TRACEGUID_ENTRY entry; |
| 512 | + SIZE_T i; |
| 513 | + |
| 514 | + if (WindowsVersion < WINDOWS_8) |
| 515 | + return NULL; |
| 516 | + |
| 517 | + if (PhBeginInitOnce(&initOnce)) |
| 518 | + { |
| 519 | + PhInitializeEtwTraceGuidCache(&etwTraceGuidArrayList); |
| 520 | + PhEndInitOnce(&initOnce); |
| 521 | + } |
| 522 | + |
| 523 | + for (i = 0; i < etwTraceGuidArrayList.Count; i++) |
| 524 | + { |
| 525 | + entry = PhItemArray(&etwTraceGuidArrayList, i); |
| 526 | + |
| 527 | + if (IsEqualGUID(entry->Guid, Guid)) |
| 528 | + { |
| 529 | + return PhReferenceObject(entry->Name); |
| 530 | + } |
| 531 | + } |
| 532 | + |
| 533 | + return NULL; |
| 534 | +} |
| 535 | + |
419 | 536 | PPH_STRING PhGetEtwPublisherName(
|
420 | 537 | _In_ PGUID Guid
|
421 | 538 | )
|
@@ -456,11 +573,16 @@ PPH_STRING PhGetEtwPublisherName(
|
456 | 573 | if (publisherName)
|
457 | 574 | {
|
458 | 575 | PhDereferenceObject(guidString);
|
459 |
| - |
460 | 576 | return publisherName;
|
461 | 577 | }
|
462 | 578 | else
|
463 | 579 | {
|
| 580 | + if (publisherName = PhGetEtwTraceGuidName(Guid)) |
| 581 | + { |
| 582 | + PhDereferenceObject(guidString); |
| 583 | + return publisherName; |
| 584 | + } |
| 585 | + |
464 | 586 | return guidString;
|
465 | 587 | }
|
466 | 588 | }
|
|
0 commit comments