Initial commit

This commit is contained in:
__Shinn
2026-04-20 18:42:48 +08:00
commit 21d4c67e93
10 changed files with 886 additions and 0 deletions
+2
View File
@@ -0,0 +1,2 @@
# Auto detect text files and perform LF normalization
* text=auto
+356
View File
@@ -0,0 +1,356 @@
## Ignore Visual Studio temporary files, build results, and
## files generated by popular Visual Studio add-ons.
##
## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore
# User-specific files
*.rsuser
*.suo
*.user
*.userosscache
*.sln.docstates
# User-specific files (MonoDevelop/Xamarin Studio)
*.userprefs
# Mono auto generated files
mono_crash.*
# Build results
[Dd]ebug/
[Dd]ebugPublic/
[Rr]elease/
[Rr]eleases/
x64/
x86/
[Aa][Rr][Mm]/
[Aa][Rr][Mm]64/
bld/
[Bb]in/
[Oo]bj/
[Ll]og/
[Ll]ogs/
# Visual Studio 2015/2017 cache/options directory
.vs/
# Uncomment if you have tasks that create the project's static files in wwwroot
#wwwroot/
# Visual Studio 2017 auto generated files
Generated\ Files/
# MSTest test Results
[Tt]est[Rr]esult*/
[Bb]uild[Ll]og.*
# NUnit
*.VisualState.xml
TestResult.xml
nunit-*.xml
# Build Results of an ATL Project
[Dd]ebugPS/
[Rr]eleasePS/
dlldata.c
# Benchmark Results
BenchmarkDotNet.Artifacts/
# .NET Core
project.lock.json
project.fragment.lock.json
artifacts/
# StyleCop
StyleCopReport.xml
# Files built by Visual Studio
*_i.c
*_p.c
*_h.h
*.ilk
*.meta
*.obj
*.iobj
*.pch
*.pdb
*.ipdb
*.pgc
*.pgd
*.rsp
*.sbr
*.tlb
*.tli
*.tlh
*.tmp
*.tmp_proj
*_wpftmp.csproj
*.log
*.vspscc
*.vssscc
.builds
*.pidb
*.svclog
*.scc
# Chutzpah Test files
_Chutzpah*
# Visual C++ cache files
ipch/
*.aps
*.ncb
*.opendb
*.opensdf
*.sdf
*.cachefile
*.VC.db
*.VC.VC.opendb
# Visual Studio profiler
*.psess
*.vsp
*.vspx
*.sap
# Visual Studio Trace Files
*.e2e
# TFS 2012 Local Workspace
$tf/
# Guidance Automation Toolkit
*.gpState
# ReSharper is a .NET coding add-in
_ReSharper*/
*.[Rr]e[Ss]harper
*.DotSettings.user
# TeamCity is a build add-in
_TeamCity*
# DotCover is a Code Coverage Tool
*.dotCover
# AxoCover is a Code Coverage Tool
.axoCover/*
!.axoCover/settings.json
# Visual Studio code coverage results
*.coverage
*.coveragexml
# NCrunch
_NCrunch_*
.*crunch*.local.xml
nCrunchTemp_*
# MightyMoose
*.mm.*
AutoTest.Net/
# Web workbench (sass)
.sass-cache/
# Installshield output folder
[Ee]xpress/
# DocProject is a documentation generator add-in
DocProject/buildhelp/
DocProject/Help/*.HxT
DocProject/Help/*.HxC
DocProject/Help/*.hhc
DocProject/Help/*.hhk
DocProject/Help/*.hhp
DocProject/Help/Html2
DocProject/Help/html
# Click-Once directory
publish/
# Publish Web Output
*.[Pp]ublish.xml
*.azurePubxml
# Note: Comment the next line if you want to checkin your web deploy settings,
# but database connection strings (with potential passwords) will be unencrypted
*.pubxml
*.publishproj
# Microsoft Azure Web App publish settings. Comment the next line if you want to
# checkin your Azure Web App publish settings, but sensitive information contained
# in these scripts will be unencrypted
PublishScripts/
# NuGet Packages
*.nupkg
# NuGet Symbol Packages
*.snupkg
# The packages folder can be ignored because of Package Restore
**/[Pp]ackages/*
# except build/, which is used as an MSBuild target.
!**/[Pp]ackages/build/
# Uncomment if necessary however generally it will be regenerated when needed
#!**/[Pp]ackages/repositories.config
# NuGet v3's project.json files produces more ignorable files
*.nuget.props
*.nuget.targets
# Microsoft Azure Build Output
csx/
*.build.csdef
# Microsoft Azure Emulator
ecf/
rcf/
# Windows Store app package directories and files
AppPackages/
BundleArtifacts/
Package.StoreAssociation.xml
_pkginfo.txt
*.appx
*.appxbundle
*.appxupload
# Visual Studio cache files
# files ending in .cache can be ignored
*.[Cc]ache
# but keep track of directories ending in .cache
!?*.[Cc]ache/
# Others
ClientBin/
~$*
*~
*.dbmdl
*.dbproj.schemaview
*.jfm
*.pfx
*.publishsettings
orleans.codegen.cs
# Including strong name files can present a security risk
# (https://github.com/github/gitignore/pull/2483#issue-259490424)
#*.snk
# Since there are multiple workflows, uncomment next line to ignore bower_components
# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622)
#bower_components/
# RIA/Silverlight projects
Generated_Code/
# Backup & report files from converting an old project file
# to a newer Visual Studio version. Backup files are not needed,
# because we have git ;-)
_UpgradeReport_Files/
Backup*/
UpgradeLog*.XML
UpgradeLog*.htm
ServiceFabricBackup/
*.rptproj.bak
# SQL Server files
*.mdf
*.ldf
*.ndf
# Business Intelligence projects
*.rdl.data
*.bim.layout
*.bim_*.settings
*.rptproj.rsuser
*- [Bb]ackup.rdl
*- [Bb]ackup ([0-9]).rdl
*- [Bb]ackup ([0-9][0-9]).rdl
# Microsoft Fakes
FakesAssemblies/
# GhostDoc plugin setting file
*.GhostDoc.xml
# Node.js Tools for Visual Studio
.ntvs_analysis.dat
node_modules/
# Visual Studio 6 build log
*.plg
# Visual Studio 6 workspace options file
*.opt
# Visual Studio 6 auto-generated workspace file (contains which files were open etc.)
*.vbw
# Visual Studio LightSwitch build output
**/*.HTMLClient/GeneratedArtifacts
**/*.DesktopClient/GeneratedArtifacts
**/*.DesktopClient/ModelManifest.xml
**/*.Server/GeneratedArtifacts
**/*.Server/ModelManifest.xml
_Pvt_Extensions
# Paket dependency manager
.paket/paket.exe
paket-files/
# FAKE - F# Make
.fake/
# CodeRush personal settings
.cr/personal
# Python Tools for Visual Studio (PTVS)
__pycache__/
*.pyc
# Cake - Uncomment if you are using it
# tools/**
# !tools/packages.config
# Tabs Studio
*.tss
# Telerik's JustMock configuration file
*.jmconfig
# BizTalk build output
*.btp.cs
*.btm.cs
*.odx.cs
*.xsd.cs
# OpenCover UI analysis results
OpenCover/
# Azure Stream Analytics local run output
ASALocalRun/
# MSBuild Binary and Structured Log
*.binlog
# NVidia Nsight GPU debugger configuration file
*.nvuser
# MFractors (Xamarin productivity tool) working folder
.mfractor/
# Local History for Visual Studio
.localhistory/
# BeatPulse healthcheck temp database
healthchecksdb
# Backup folder for Package Reference Convert tool in Visual Studio 2017
MigrationBackup/
# Ionide (cross platform F# VS Code tools) working folder
.ionide/
imgui.ini
*.zip
*.log
*.log
*.log
Injector/dll_mem.h
+27
View File
@@ -0,0 +1,27 @@
Microsoft Visual Studio Solution File, Format Version 12.00
# Visual Studio 15
VisualStudioVersion = 15.0.36324.19
MinimumVisualStudioVersion = 10.0.40219.1
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "KernelRuntimeImport", "KernelRuntimeImport\KernelRuntimeImport.vcxproj", "{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}"
EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Debug|x64 = Debug|x64
Release|x64 = Release|x64
EndGlobalSection
GlobalSection(ProjectConfigurationPlatforms) = postSolution
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.ActiveCfg = Debug|x64
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.Build.0 = Debug|x64
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.Deploy.0 = Debug|x64
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.ActiveCfg = Release|x64
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.Build.0 = Release|x64
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.Deploy.0 = Release|x64
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
EndGlobalSection
GlobalSection(ExtensibilityGlobals) = postSolution
SolutionGuid = {2498DCDE-01D6-4B4C-BDC7-78315F0AF975}
EndGlobalSection
EndGlobal
@@ -0,0 +1,86 @@
#include "KernelRuntimeImport.h"
#include <intrin.h>
#include <ntimage.h>
PVOID
GetKernelBaseWithoutAPI(
VOID
)
{
static ULONG64 KernelBase = 0;
if (KernelBase != 0)
{
return (PVOID)KernelBase;
}
ULONG64 AddrAligned = __readmsr(0xC0000082) & ~(0xFFFull);
while (AddrAligned > 0)
{
PIMAGE_DOS_HEADER Dos = (PIMAGE_DOS_HEADER)AddrAligned;
if (Dos->e_magic == IMAGE_DOS_SIGNATURE)
{
LONG e_lfanew = Dos->e_lfanew;
if (e_lfanew > 0 && e_lfanew <= 0x1000)
{
PIMAGE_NT_HEADERS64 Nt = (PIMAGE_NT_HEADERS64)(AddrAligned + (ULONG64)e_lfanew);
if (Nt->Signature == IMAGE_NT_SIGNATURE &&
Nt->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC &&
Nt->OptionalHeader.ImageBase == AddrAligned &&
Nt->OptionalHeader.SizeOfImage != 0)
{
KernelBase = AddrAligned;
return (PVOID)KernelBase;
}
}
}
AddrAligned -= PAGE_SIZE;
}
return NULL;
}
PVOID
GetntoskrnlExportAddressByHash(
_In_ ULONG FunctionHash
)
{
if (FunctionHash == 0)
{
return NULL;
}
ULONG64 ModuleBase = (ULONG64)GetKernelBaseWithoutAPI();
if (ModuleBase == NULL)
{
return NULL;
}
PIMAGE_DOS_HEADER DosHeader = (PIMAGE_DOS_HEADER)ModuleBase;
PIMAGE_NT_HEADERS NtHeader = (PIMAGE_NT_HEADERS)(ModuleBase + (ULONG)DosHeader->e_lfanew);
IMAGE_DATA_DIRECTORY ExportDataDirectory = NtHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT];
if (ExportDataDirectory.VirtualAddress == 0 ||
ExportDataDirectory.Size < sizeof(IMAGE_EXPORT_DIRECTORY))
{
return NULL;
}
PIMAGE_EXPORT_DIRECTORY ExportDirectory = (PIMAGE_EXPORT_DIRECTORY)(ModuleBase + ExportDataDirectory.VirtualAddress);
PULONG AddressOfFunctions = (PULONG)(ModuleBase + ExportDirectory->AddressOfFunctions);
PULONG AddressOfNames = (PULONG)(ModuleBase + ExportDirectory->AddressOfNames);
PUSHORT AddressOfNameOrdinals = (PUSHORT)(ModuleBase + ExportDirectory->AddressOfNameOrdinals);
for (ULONG i = 0; i < ExportDirectory->NumberOfNames; i++)
{
ULONG AddrOfName = AddressOfNames[i];
PCHAR ExportName = (PCHAR)(ModuleBase + AddrOfName);
if (KernelRuntimeImport::detail::StringHashConstexpr(ExportName) == FunctionHash)
{
USHORT OrdinalIndex = AddressOfNameOrdinals[i];
return (PVOID)(ModuleBase + AddressOfFunctions[OrdinalIndex]);
}
}
return NULL;
}
+52
View File
@@ -0,0 +1,52 @@
#pragma once
#include <ntifs.h>
namespace KernelRuntimeImport
{
namespace detail
{
constexpr ULONG StringHashMix(
_In_ ULONG Hash,
_In_ UCHAR Value
)
{
return static_cast<ULONG>(
(static_cast<ULONGLONG>(Hash ^ Value) * 16777619ull) & 0xffffffffull);
}
constexpr ULONG StringHashConstexpr(
_In_z_ const char* String,
_In_ ULONG Hash = 215251764ul
)
{
return (*String == '\0')
? Hash
: StringHashConstexpr(
String + 1,
StringHashMix(Hash, static_cast<UCHAR>(*String)));
}
template <SIZE_T N>
constexpr ULONG StringHashLiteral(
_In_ const char(&String)[N]
)
{
return StringHashConstexpr(String);
}
}
}
#define STRING_HASH(x) (KernelRuntimeImport::detail::StringHashLiteral(x))
#define ROUTINE_TYPE(ReturnType, ...) ReturnType (NTAPI*)(__VA_ARGS__)
#define CALL_ROUTINE(FuncAddr, RoutineType, ...) (reinterpret_cast<RoutineType>(FuncAddr)(__VA_ARGS__))
PVOID
GetKernelBaseWithoutAPI(
VOID
);
PVOID
GetntoskrnlExportAddressByHash(
_In_ ULONG FunctionHash
);
@@ -0,0 +1,76 @@
<?xml version="1.0" encoding="utf-8"?>
<Project DefaultTargets="Build" ToolsVersion="12.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup Label="ProjectConfigurations">
<ProjectConfiguration Include="Debug|x64">
<Configuration>Debug</Configuration>
<Platform>x64</Platform>
</ProjectConfiguration>
<ProjectConfiguration Include="Release|x64">
<Configuration>Release</Configuration>
<Platform>x64</Platform>
</ProjectConfiguration>
</ItemGroup>
<PropertyGroup Label="Globals">
<ProjectGuid>{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}</ProjectGuid>
<TemplateGuid>{1bc93793-694f-48fe-9372-81e2b05556fd}</TemplateGuid>
<TargetFrameworkVersion>v4.5</TargetFrameworkVersion>
<MinimumVisualStudioVersion>12.0</MinimumVisualStudioVersion>
<Configuration>Debug</Configuration>
<Platform Condition="'$(Platform)' == ''">Win32</Platform>
<RootNamespace>KernelRuntimeImport</RootNamespace>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="Configuration">
<TargetVersion>Windows10</TargetVersion>
<UseDebugLibraries>true</UseDebugLibraries>
<PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset>
<ConfigurationType>Driver</ConfigurationType>
<DriverType>KMDF</DriverType>
<DriverTargetPlatform>Universal</DriverTargetPlatform>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
<TargetVersion>Windows10</TargetVersion>
<UseDebugLibraries>false</UseDebugLibraries>
<PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset>
<ConfigurationType>Driver</ConfigurationType>
<DriverType>KMDF</DriverType>
<DriverTargetPlatform>Universal</DriverTargetPlatform>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
<ImportGroup Label="ExtensionSettings">
</ImportGroup>
<ImportGroup Label="PropertySheets">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<PropertyGroup Label="UserMacros" />
<PropertyGroup />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
<DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor>
</PropertyGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
<ClCompile>
<WarningLevel>Level4</WarningLevel>
</ClCompile>
</ItemDefinitionGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
<ClCompile>
<TreatWarningAsError>true</TreatWarningAsError>
</ClCompile>
</ItemDefinitionGroup>
<ItemGroup>
<FilesToPackage Include="$(TargetPath)" />
</ItemGroup>
<ItemGroup>
<ClCompile Include="KernelRuntimeImport.cpp" />
<ClCompile Include="drv_main.cpp" />
</ItemGroup>
<ItemGroup>
<ClInclude Include="KernelRuntimeImport.h" />
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
</ImportGroup>
</Project>
@@ -0,0 +1,34 @@
<?xml version="1.0" encoding="utf-8"?>
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup>
<Filter Include="Source Files">
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
</Filter>
<Filter Include="Resource Files">
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
</Filter>
<Filter Include="Driver Files">
<UniqueIdentifier>{8E41214B-6785-4CFE-B992-037D68949A14}</UniqueIdentifier>
<Extensions>inf;inv;inx;mof;mc;</Extensions>
</Filter>
<Filter Include="RuntimeImport">
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
<Extensions>h;hpp;hxx;hm;inl;inc;xsd</Extensions>
</Filter>
</ItemGroup>
<ItemGroup>
<ClCompile Include="drv_main.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="KernelRuntimeImport.cpp">
<Filter>RuntimeImport</Filter>
</ClCompile>
</ItemGroup>
<ItemGroup>
<ClInclude Include="KernelRuntimeImport.h">
<Filter>RuntimeImport</Filter>
</ClInclude>
</ItemGroup>
</Project>
+29
View File
@@ -0,0 +1,29 @@
#include "KernelRuntimeImport.h"
EXTERN_C
NTSTATUS
DriverEntry(
PDRIVER_OBJECT DrvObj,
PUNICODE_STRING RegPath
)
{
UNREFERENCED_PARAMETER(DrvObj);
UNREFERENCED_PARAMETER(RegPath);
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
if (MmGetPhysicalAddressAddr == nullptr)
{
DbgBreakPoint();
return STATUS_PROCEDURE_NOT_FOUND;
}
ULONG Num = 0x12345678;
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
MmGetPhysicalAddressAddr,
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
&Num);
UNREFERENCED_PARAMETER(PhyAddr);
return STATUS_UNSUCCESSFUL;
}
+112
View File
@@ -0,0 +1,112 @@
# KernelRuntimeImport
[中文文档](README.zh-CN.md)
`KernelRuntimeImport` is a minimal Windows x64 kernel driver sample that demonstrates how to resolve and call exported functions from `ntoskrnl.exe` at runtime through function name hashing.
## Overview
This project demonstrates dynamic API importing and invocation at runtime:
- The target kernel function is not declared directly in the PE import table, so the IAT does not store the sensitive function and IAT hooks can be avoided.
- The kernel image base is located at runtime.
- The export table is traversed and export names are matched by hash.
- After resolving the target function address, the function is invoked through a function pointer.
The current sample uses `MmGetPhysicalAddress` as an example to show the complete resolution and invocation flow.
## Features
- Uses `__readmsr(0xC0000082)` to help locate the base address of `ntoskrnl.exe` without relying on conventional kernel export lookup APIs.
- Uses the compile-time string hash macro `STRING_HASH(...)` to generate the hash of the target export name.
- Resolves the target function address at runtime by traversing the export table and comparing hashes.
- Uses the `CALL_ROUTINE(...)` macro to cast the resolved address to the target function signature and invoke it directly.
- Keeps the sample compact and easy to extend into a runtime resolver for multiple exported functions.
The minimal invocation example in `drv_main.cpp` is shown below:
```cpp
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
if (MmGetPhysicalAddressAddr == nullptr)
{
DbgBreakPoint();
return STATUS_PROCEDURE_NOT_FOUND;
}
ULONG Num = 0x12345678;
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
MmGetPhysicalAddressAddr,
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
&Num);
UNREFERENCED_PARAMETER(PhyAddr);
```
This flow clearly shows the core purpose of the project: resolve a specified export by hash during driver runtime and call it directly, instead of linking through a static import entry.
## Supported Environment
The project has currently been tested only in the following environments:
| OS Version | Architecture | Status |
| --- | --- | --- |
| Windows 10 19044 | x64 | Tested |
| Windows 11 22H2 | x64 | Tested |
| Windows 11 24H2 | x64 | Tested |
| Windows 11 25H2 | x64 | Tested |
Notes:
- Based on the implementation approach, it should theoretically be compatible with most Windows 10 / Windows 11 x64 versions.
- The current repository targets x64 driver scenarios only and has not been validated on Win32, ARM, or ARM64.
## Build
The current build environment is:
- Visual Studio 2017
- WDK 10
- x64 Kernel-Mode Driver
Build steps:
1. Open `KernelRuntimeImport.sln` in Visual Studio 2017.
2. Make sure WDK 10 is installed correctly and the `WindowsKernelModeDriver10.0` toolset is available.
3. Switch the build platform to `x64`.
4. Build with either the `Debug` or `Release` configuration.
Notes:
- The current project supports x64 drivers only.
- Although the project file contains other platform configurations, the implementation and validation scope currently target x64 only.
## Debugging and Warnings
When export resolution fails, the current sample actively triggers `DbgBreakPoint()` and returns `STATUS_PROCEDURE_NOT_FOUND`:
```cpp
if (MmGetPhysicalAddressAddr == nullptr)
{
DbgBreakPoint();
return STATUS_PROCEDURE_NOT_FOUND;
}
```
This means:
- Run this sample in a test environment or virtual machine with a debugger attached.
- If the target export cannot be resolved successfully, the driver will break in `DriverEntry` so the issue can be diagnosed immediately.
## Project Structure
- `KernelRuntimeImport/KernelRuntimeImport.h`: Hash helpers, function pointer invocation macros, and exported interface declarations.
- `KernelRuntimeImport/KernelRuntimeImport.cpp`: Kernel base discovery and export table traversal / resolution logic.
- `KernelRuntimeImport/drv_main.cpp`: Minimal driver entry and invocation example.
## Usage
This repository is better suited as a research and demonstration sample:
- If you want to understand the basic runtime import flow, start reading from `DriverEntry`.
- If you want to extend it into a resolver for multiple APIs, continue building on top of `GetntoskrnlExportAddressByHash(...)`.
- If you want to validate compatibility across different system versions, test them one by one in isolated virtual machines.
+112
View File
@@ -0,0 +1,112 @@
# KernelRuntimeImport
[English](README.md)
`KernelRuntimeImport` 是教学性质的 Windows x64 内核驱动示例,用于展示如何在运行时通过函数名 Hash 解析 `ntoskrnl.exe` 的导出函数地址并调用。
## 概览
实现运行时动态导入API并调用:
- 不直接在 PE 导入表中声明目标内核函数(IAT表不保存敏感函数,可以避免IAT Hook)。
- 在运行时定位内核镜像基址。
- 遍历导出表,对导出函数名做 Hash 比对。
- 解析到目标函数地址后,再通过函数指针完成调用。
当前示例以 `MmGetPhysicalAddress` 为例,演示完整的解析与调用流程。
## Features
- 通过 `__readmsr(0xC0000082)` 辅助定位 `ntoskrnl.exe` 基址,不依赖常规内核导出查询 API。
- 使用编译期字符串 Hash 宏 `STRING_HASH(...)` 生成目标导出名 Hash。
- 通过遍历导出表并比较 Hash,在运行时解析目标函数地址。
- 使用 `CALL_ROUTINE(...)` 宏将地址转换为目标函数签名并直接调用。
- 示例代码短小,便于二次扩展为多个导出函数的运行时解析器。
`drv_main.cpp` 中的最小调用示例如下:
```cpp
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
if (MmGetPhysicalAddressAddr == nullptr)
{
DbgBreakPoint();
return STATUS_PROCEDURE_NOT_FOUND;
}
ULONG Num = 0x12345678;
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
MmGetPhysicalAddressAddr,
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
&Num);
UNREFERENCED_PARAMETER(PhyAddr);
```
上面的流程清楚说明了这个项目的核心功能:在驱动运行期间按 Hash 解析指定导出并直接调用,而不是通过静态导入项完成链接。
## Supported Environment
目前仅在以下环境完成过测试:
| 系统版本 | 架构 | 状态 |
| --- | --- | --- |
| Windows 10 19044 | x64 | 已测试 |
| Windows 11 22H2 | x64 | 已测试 |
| Windows 11 24H2 | x64 | 已测试 |
| Windows 11 25H2 | x64 | 已测试 |
说明:
- 从实现方式来看,理论上应兼容大部分 Windows 10 / Windows 11 x64 版本。
- 当前仓库只面向 x64 驱动场景,未验证 Win32、ARM 或 ARM64。
## Build
当前构建环境如下:
- Visual Studio 2017
- WDK 10
- x64 Kernel-Mode Driver
构建步骤:
1. 使用 Visual Studio 2017 打开 `KernelRuntimeImport.sln`。
2. 确认已正确安装 WDK 10,并能使用 `WindowsKernelModeDriver10.0` 工具链。
3. 将构建平台切换为 `x64`。
4. 选择 `Debug` 或 `Release` 配置后执行编译。
说明:
- 当前项目仅支持 x64 驱动使用。
- 虽然工程文件中包含其他平台配置项,但当前实现和验证范围都以 x64 为准。
## 调试与警告
当导出函数解析失败时,当前示例会主动触发 `DbgBreakPoint()`,并返回 `STATUS_PROCEDURE_NOT_FOUND`:
```cpp
if (MmGetPhysicalAddressAddr == nullptr)
{
DbgBreakPoint();
return STATUS_PROCEDURE_NOT_FOUND;
}
```
这意味着:
- 请在调试器连接的测试环境或虚拟机中运行本示例。
- 如果目标导出未解析成功,驱动会在 `DriverEntry` 阶段中断,便于立刻定位问题。
## 项目结构
- `KernelRuntimeImport/KernelRuntimeImport.h`:Hash、函数指针调用宏以及导出接口声明。
- `KernelRuntimeImport/KernelRuntimeImport.cpp`:内核基址定位与导出表遍历解析实现。
- `KernelRuntimeImport/drv_main.cpp`:最小驱动入口与调用示例。
## 使用说明
这个仓库更适合作为研究和演示样例阅读:
- 如果你想了解运行时导入的基本实现流程,可以从 `DriverEntry` 入口开始读。
- 如果你想扩展为多个 API 的解析器,可以在现有 `GetntoskrnlExportAddressByHash(...)` 基础上继续封装。
- 如果你想验证不同系统版本上的兼容性,建议在独立虚拟机中逐个测试。