mirror of
https://github.com/Shinn-Home/KernelRuntimeImport
synced 2026-08-09 12:21:02 +00:00
Initial commit
This commit is contained in:
@@ -0,0 +1,2 @@
|
||||
# Auto detect text files and perform LF normalization
|
||||
* text=auto
|
||||
+356
@@ -0,0 +1,356 @@
|
||||
## Ignore Visual Studio temporary files, build results, and
|
||||
## files generated by popular Visual Studio add-ons.
|
||||
##
|
||||
## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore
|
||||
|
||||
# User-specific files
|
||||
*.rsuser
|
||||
*.suo
|
||||
*.user
|
||||
*.userosscache
|
||||
*.sln.docstates
|
||||
|
||||
# User-specific files (MonoDevelop/Xamarin Studio)
|
||||
*.userprefs
|
||||
|
||||
# Mono auto generated files
|
||||
mono_crash.*
|
||||
|
||||
# Build results
|
||||
[Dd]ebug/
|
||||
[Dd]ebugPublic/
|
||||
[Rr]elease/
|
||||
[Rr]eleases/
|
||||
x64/
|
||||
x86/
|
||||
[Aa][Rr][Mm]/
|
||||
[Aa][Rr][Mm]64/
|
||||
bld/
|
||||
[Bb]in/
|
||||
[Oo]bj/
|
||||
[Ll]og/
|
||||
[Ll]ogs/
|
||||
|
||||
# Visual Studio 2015/2017 cache/options directory
|
||||
.vs/
|
||||
# Uncomment if you have tasks that create the project's static files in wwwroot
|
||||
#wwwroot/
|
||||
|
||||
# Visual Studio 2017 auto generated files
|
||||
Generated\ Files/
|
||||
|
||||
# MSTest test Results
|
||||
[Tt]est[Rr]esult*/
|
||||
[Bb]uild[Ll]og.*
|
||||
|
||||
# NUnit
|
||||
*.VisualState.xml
|
||||
TestResult.xml
|
||||
nunit-*.xml
|
||||
|
||||
# Build Results of an ATL Project
|
||||
[Dd]ebugPS/
|
||||
[Rr]eleasePS/
|
||||
dlldata.c
|
||||
|
||||
# Benchmark Results
|
||||
BenchmarkDotNet.Artifacts/
|
||||
|
||||
# .NET Core
|
||||
project.lock.json
|
||||
project.fragment.lock.json
|
||||
artifacts/
|
||||
|
||||
# StyleCop
|
||||
StyleCopReport.xml
|
||||
|
||||
# Files built by Visual Studio
|
||||
*_i.c
|
||||
*_p.c
|
||||
*_h.h
|
||||
*.ilk
|
||||
*.meta
|
||||
*.obj
|
||||
*.iobj
|
||||
*.pch
|
||||
*.pdb
|
||||
*.ipdb
|
||||
*.pgc
|
||||
*.pgd
|
||||
*.rsp
|
||||
*.sbr
|
||||
*.tlb
|
||||
*.tli
|
||||
*.tlh
|
||||
*.tmp
|
||||
*.tmp_proj
|
||||
*_wpftmp.csproj
|
||||
*.log
|
||||
*.vspscc
|
||||
*.vssscc
|
||||
.builds
|
||||
*.pidb
|
||||
*.svclog
|
||||
*.scc
|
||||
|
||||
# Chutzpah Test files
|
||||
_Chutzpah*
|
||||
|
||||
# Visual C++ cache files
|
||||
ipch/
|
||||
*.aps
|
||||
*.ncb
|
||||
*.opendb
|
||||
*.opensdf
|
||||
*.sdf
|
||||
*.cachefile
|
||||
*.VC.db
|
||||
*.VC.VC.opendb
|
||||
|
||||
# Visual Studio profiler
|
||||
*.psess
|
||||
*.vsp
|
||||
*.vspx
|
||||
*.sap
|
||||
|
||||
# Visual Studio Trace Files
|
||||
*.e2e
|
||||
|
||||
# TFS 2012 Local Workspace
|
||||
$tf/
|
||||
|
||||
# Guidance Automation Toolkit
|
||||
*.gpState
|
||||
|
||||
# ReSharper is a .NET coding add-in
|
||||
_ReSharper*/
|
||||
*.[Rr]e[Ss]harper
|
||||
*.DotSettings.user
|
||||
|
||||
# TeamCity is a build add-in
|
||||
_TeamCity*
|
||||
|
||||
# DotCover is a Code Coverage Tool
|
||||
*.dotCover
|
||||
|
||||
# AxoCover is a Code Coverage Tool
|
||||
.axoCover/*
|
||||
!.axoCover/settings.json
|
||||
|
||||
# Visual Studio code coverage results
|
||||
*.coverage
|
||||
*.coveragexml
|
||||
|
||||
# NCrunch
|
||||
_NCrunch_*
|
||||
.*crunch*.local.xml
|
||||
nCrunchTemp_*
|
||||
|
||||
# MightyMoose
|
||||
*.mm.*
|
||||
AutoTest.Net/
|
||||
|
||||
# Web workbench (sass)
|
||||
.sass-cache/
|
||||
|
||||
# Installshield output folder
|
||||
[Ee]xpress/
|
||||
|
||||
# DocProject is a documentation generator add-in
|
||||
DocProject/buildhelp/
|
||||
DocProject/Help/*.HxT
|
||||
DocProject/Help/*.HxC
|
||||
DocProject/Help/*.hhc
|
||||
DocProject/Help/*.hhk
|
||||
DocProject/Help/*.hhp
|
||||
DocProject/Help/Html2
|
||||
DocProject/Help/html
|
||||
|
||||
# Click-Once directory
|
||||
publish/
|
||||
|
||||
# Publish Web Output
|
||||
*.[Pp]ublish.xml
|
||||
*.azurePubxml
|
||||
# Note: Comment the next line if you want to checkin your web deploy settings,
|
||||
# but database connection strings (with potential passwords) will be unencrypted
|
||||
*.pubxml
|
||||
*.publishproj
|
||||
|
||||
# Microsoft Azure Web App publish settings. Comment the next line if you want to
|
||||
# checkin your Azure Web App publish settings, but sensitive information contained
|
||||
# in these scripts will be unencrypted
|
||||
PublishScripts/
|
||||
|
||||
# NuGet Packages
|
||||
*.nupkg
|
||||
# NuGet Symbol Packages
|
||||
*.snupkg
|
||||
# The packages folder can be ignored because of Package Restore
|
||||
**/[Pp]ackages/*
|
||||
# except build/, which is used as an MSBuild target.
|
||||
!**/[Pp]ackages/build/
|
||||
# Uncomment if necessary however generally it will be regenerated when needed
|
||||
#!**/[Pp]ackages/repositories.config
|
||||
# NuGet v3's project.json files produces more ignorable files
|
||||
*.nuget.props
|
||||
*.nuget.targets
|
||||
|
||||
# Microsoft Azure Build Output
|
||||
csx/
|
||||
*.build.csdef
|
||||
|
||||
# Microsoft Azure Emulator
|
||||
ecf/
|
||||
rcf/
|
||||
|
||||
# Windows Store app package directories and files
|
||||
AppPackages/
|
||||
BundleArtifacts/
|
||||
Package.StoreAssociation.xml
|
||||
_pkginfo.txt
|
||||
*.appx
|
||||
*.appxbundle
|
||||
*.appxupload
|
||||
|
||||
# Visual Studio cache files
|
||||
# files ending in .cache can be ignored
|
||||
*.[Cc]ache
|
||||
# but keep track of directories ending in .cache
|
||||
!?*.[Cc]ache/
|
||||
|
||||
# Others
|
||||
ClientBin/
|
||||
~$*
|
||||
*~
|
||||
*.dbmdl
|
||||
*.dbproj.schemaview
|
||||
*.jfm
|
||||
*.pfx
|
||||
*.publishsettings
|
||||
orleans.codegen.cs
|
||||
|
||||
# Including strong name files can present a security risk
|
||||
# (https://github.com/github/gitignore/pull/2483#issue-259490424)
|
||||
#*.snk
|
||||
|
||||
# Since there are multiple workflows, uncomment next line to ignore bower_components
|
||||
# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622)
|
||||
#bower_components/
|
||||
|
||||
# RIA/Silverlight projects
|
||||
Generated_Code/
|
||||
|
||||
# Backup & report files from converting an old project file
|
||||
# to a newer Visual Studio version. Backup files are not needed,
|
||||
# because we have git ;-)
|
||||
_UpgradeReport_Files/
|
||||
Backup*/
|
||||
UpgradeLog*.XML
|
||||
UpgradeLog*.htm
|
||||
ServiceFabricBackup/
|
||||
*.rptproj.bak
|
||||
|
||||
# SQL Server files
|
||||
*.mdf
|
||||
*.ldf
|
||||
*.ndf
|
||||
|
||||
# Business Intelligence projects
|
||||
*.rdl.data
|
||||
*.bim.layout
|
||||
*.bim_*.settings
|
||||
*.rptproj.rsuser
|
||||
*- [Bb]ackup.rdl
|
||||
*- [Bb]ackup ([0-9]).rdl
|
||||
*- [Bb]ackup ([0-9][0-9]).rdl
|
||||
|
||||
# Microsoft Fakes
|
||||
FakesAssemblies/
|
||||
|
||||
# GhostDoc plugin setting file
|
||||
*.GhostDoc.xml
|
||||
|
||||
# Node.js Tools for Visual Studio
|
||||
.ntvs_analysis.dat
|
||||
node_modules/
|
||||
|
||||
# Visual Studio 6 build log
|
||||
*.plg
|
||||
|
||||
# Visual Studio 6 workspace options file
|
||||
*.opt
|
||||
|
||||
# Visual Studio 6 auto-generated workspace file (contains which files were open etc.)
|
||||
*.vbw
|
||||
|
||||
# Visual Studio LightSwitch build output
|
||||
**/*.HTMLClient/GeneratedArtifacts
|
||||
**/*.DesktopClient/GeneratedArtifacts
|
||||
**/*.DesktopClient/ModelManifest.xml
|
||||
**/*.Server/GeneratedArtifacts
|
||||
**/*.Server/ModelManifest.xml
|
||||
_Pvt_Extensions
|
||||
|
||||
# Paket dependency manager
|
||||
.paket/paket.exe
|
||||
paket-files/
|
||||
|
||||
# FAKE - F# Make
|
||||
.fake/
|
||||
|
||||
# CodeRush personal settings
|
||||
.cr/personal
|
||||
|
||||
# Python Tools for Visual Studio (PTVS)
|
||||
__pycache__/
|
||||
*.pyc
|
||||
|
||||
# Cake - Uncomment if you are using it
|
||||
# tools/**
|
||||
# !tools/packages.config
|
||||
|
||||
# Tabs Studio
|
||||
*.tss
|
||||
|
||||
# Telerik's JustMock configuration file
|
||||
*.jmconfig
|
||||
|
||||
# BizTalk build output
|
||||
*.btp.cs
|
||||
*.btm.cs
|
||||
*.odx.cs
|
||||
*.xsd.cs
|
||||
|
||||
# OpenCover UI analysis results
|
||||
OpenCover/
|
||||
|
||||
# Azure Stream Analytics local run output
|
||||
ASALocalRun/
|
||||
|
||||
# MSBuild Binary and Structured Log
|
||||
*.binlog
|
||||
|
||||
# NVidia Nsight GPU debugger configuration file
|
||||
*.nvuser
|
||||
|
||||
# MFractors (Xamarin productivity tool) working folder
|
||||
.mfractor/
|
||||
|
||||
# Local History for Visual Studio
|
||||
.localhistory/
|
||||
|
||||
# BeatPulse healthcheck temp database
|
||||
healthchecksdb
|
||||
|
||||
# Backup folder for Package Reference Convert tool in Visual Studio 2017
|
||||
MigrationBackup/
|
||||
|
||||
# Ionide (cross platform F# VS Code tools) working folder
|
||||
.ionide/
|
||||
imgui.ini
|
||||
*.zip
|
||||
*.log
|
||||
*.log
|
||||
*.log
|
||||
Injector/dll_mem.h
|
||||
@@ -0,0 +1,27 @@
|
||||
|
||||
Microsoft Visual Studio Solution File, Format Version 12.00
|
||||
# Visual Studio 15
|
||||
VisualStudioVersion = 15.0.36324.19
|
||||
MinimumVisualStudioVersion = 10.0.40219.1
|
||||
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "KernelRuntimeImport", "KernelRuntimeImport\KernelRuntimeImport.vcxproj", "{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}"
|
||||
EndProject
|
||||
Global
|
||||
GlobalSection(SolutionConfigurationPlatforms) = preSolution
|
||||
Debug|x64 = Debug|x64
|
||||
Release|x64 = Release|x64
|
||||
EndGlobalSection
|
||||
GlobalSection(ProjectConfigurationPlatforms) = postSolution
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.ActiveCfg = Debug|x64
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.Build.0 = Debug|x64
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Debug|x64.Deploy.0 = Debug|x64
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.ActiveCfg = Release|x64
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.Build.0 = Release|x64
|
||||
{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}.Release|x64.Deploy.0 = Release|x64
|
||||
EndGlobalSection
|
||||
GlobalSection(SolutionProperties) = preSolution
|
||||
HideSolutionNode = FALSE
|
||||
EndGlobalSection
|
||||
GlobalSection(ExtensibilityGlobals) = postSolution
|
||||
SolutionGuid = {2498DCDE-01D6-4B4C-BDC7-78315F0AF975}
|
||||
EndGlobalSection
|
||||
EndGlobal
|
||||
@@ -0,0 +1,86 @@
|
||||
#include "KernelRuntimeImport.h"
|
||||
|
||||
#include <intrin.h>
|
||||
#include <ntimage.h>
|
||||
|
||||
PVOID
|
||||
GetKernelBaseWithoutAPI(
|
||||
VOID
|
||||
)
|
||||
{
|
||||
static ULONG64 KernelBase = 0;
|
||||
if (KernelBase != 0)
|
||||
{
|
||||
return (PVOID)KernelBase;
|
||||
}
|
||||
|
||||
ULONG64 AddrAligned = __readmsr(0xC0000082) & ~(0xFFFull);
|
||||
while (AddrAligned > 0)
|
||||
{
|
||||
PIMAGE_DOS_HEADER Dos = (PIMAGE_DOS_HEADER)AddrAligned;
|
||||
if (Dos->e_magic == IMAGE_DOS_SIGNATURE)
|
||||
{
|
||||
LONG e_lfanew = Dos->e_lfanew;
|
||||
if (e_lfanew > 0 && e_lfanew <= 0x1000)
|
||||
{
|
||||
PIMAGE_NT_HEADERS64 Nt = (PIMAGE_NT_HEADERS64)(AddrAligned + (ULONG64)e_lfanew);
|
||||
if (Nt->Signature == IMAGE_NT_SIGNATURE &&
|
||||
Nt->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC &&
|
||||
Nt->OptionalHeader.ImageBase == AddrAligned &&
|
||||
Nt->OptionalHeader.SizeOfImage != 0)
|
||||
{
|
||||
KernelBase = AddrAligned;
|
||||
return (PVOID)KernelBase;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
AddrAligned -= PAGE_SIZE;
|
||||
}
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
PVOID
|
||||
GetntoskrnlExportAddressByHash(
|
||||
_In_ ULONG FunctionHash
|
||||
)
|
||||
{
|
||||
if (FunctionHash == 0)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
ULONG64 ModuleBase = (ULONG64)GetKernelBaseWithoutAPI();
|
||||
if (ModuleBase == NULL)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
PIMAGE_DOS_HEADER DosHeader = (PIMAGE_DOS_HEADER)ModuleBase;
|
||||
PIMAGE_NT_HEADERS NtHeader = (PIMAGE_NT_HEADERS)(ModuleBase + (ULONG)DosHeader->e_lfanew);
|
||||
IMAGE_DATA_DIRECTORY ExportDataDirectory = NtHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT];
|
||||
if (ExportDataDirectory.VirtualAddress == 0 ||
|
||||
ExportDataDirectory.Size < sizeof(IMAGE_EXPORT_DIRECTORY))
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
PIMAGE_EXPORT_DIRECTORY ExportDirectory = (PIMAGE_EXPORT_DIRECTORY)(ModuleBase + ExportDataDirectory.VirtualAddress);
|
||||
PULONG AddressOfFunctions = (PULONG)(ModuleBase + ExportDirectory->AddressOfFunctions);
|
||||
PULONG AddressOfNames = (PULONG)(ModuleBase + ExportDirectory->AddressOfNames);
|
||||
PUSHORT AddressOfNameOrdinals = (PUSHORT)(ModuleBase + ExportDirectory->AddressOfNameOrdinals);
|
||||
|
||||
for (ULONG i = 0; i < ExportDirectory->NumberOfNames; i++)
|
||||
{
|
||||
ULONG AddrOfName = AddressOfNames[i];
|
||||
PCHAR ExportName = (PCHAR)(ModuleBase + AddrOfName);
|
||||
if (KernelRuntimeImport::detail::StringHashConstexpr(ExportName) == FunctionHash)
|
||||
{
|
||||
USHORT OrdinalIndex = AddressOfNameOrdinals[i];
|
||||
return (PVOID)(ModuleBase + AddressOfFunctions[OrdinalIndex]);
|
||||
}
|
||||
}
|
||||
|
||||
return NULL;
|
||||
}
|
||||
@@ -0,0 +1,52 @@
|
||||
#pragma once
|
||||
|
||||
#include <ntifs.h>
|
||||
|
||||
namespace KernelRuntimeImport
|
||||
{
|
||||
namespace detail
|
||||
{
|
||||
constexpr ULONG StringHashMix(
|
||||
_In_ ULONG Hash,
|
||||
_In_ UCHAR Value
|
||||
)
|
||||
{
|
||||
return static_cast<ULONG>(
|
||||
(static_cast<ULONGLONG>(Hash ^ Value) * 16777619ull) & 0xffffffffull);
|
||||
}
|
||||
|
||||
constexpr ULONG StringHashConstexpr(
|
||||
_In_z_ const char* String,
|
||||
_In_ ULONG Hash = 215251764ul
|
||||
)
|
||||
{
|
||||
return (*String == '\0')
|
||||
? Hash
|
||||
: StringHashConstexpr(
|
||||
String + 1,
|
||||
StringHashMix(Hash, static_cast<UCHAR>(*String)));
|
||||
}
|
||||
|
||||
template <SIZE_T N>
|
||||
constexpr ULONG StringHashLiteral(
|
||||
_In_ const char(&String)[N]
|
||||
)
|
||||
{
|
||||
return StringHashConstexpr(String);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#define STRING_HASH(x) (KernelRuntimeImport::detail::StringHashLiteral(x))
|
||||
#define ROUTINE_TYPE(ReturnType, ...) ReturnType (NTAPI*)(__VA_ARGS__)
|
||||
#define CALL_ROUTINE(FuncAddr, RoutineType, ...) (reinterpret_cast<RoutineType>(FuncAddr)(__VA_ARGS__))
|
||||
|
||||
PVOID
|
||||
GetKernelBaseWithoutAPI(
|
||||
VOID
|
||||
);
|
||||
|
||||
PVOID
|
||||
GetntoskrnlExportAddressByHash(
|
||||
_In_ ULONG FunctionHash
|
||||
);
|
||||
@@ -0,0 +1,76 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project DefaultTargets="Build" ToolsVersion="12.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup Label="ProjectConfigurations">
|
||||
<ProjectConfiguration Include="Debug|x64">
|
||||
<Configuration>Debug</Configuration>
|
||||
<Platform>x64</Platform>
|
||||
</ProjectConfiguration>
|
||||
<ProjectConfiguration Include="Release|x64">
|
||||
<Configuration>Release</Configuration>
|
||||
<Platform>x64</Platform>
|
||||
</ProjectConfiguration>
|
||||
</ItemGroup>
|
||||
<PropertyGroup Label="Globals">
|
||||
<ProjectGuid>{5E2604B8-2CC4-47C4-9AE0-7D54994FD2C2}</ProjectGuid>
|
||||
<TemplateGuid>{1bc93793-694f-48fe-9372-81e2b05556fd}</TemplateGuid>
|
||||
<TargetFrameworkVersion>v4.5</TargetFrameworkVersion>
|
||||
<MinimumVisualStudioVersion>12.0</MinimumVisualStudioVersion>
|
||||
<Configuration>Debug</Configuration>
|
||||
<Platform Condition="'$(Platform)' == ''">Win32</Platform>
|
||||
<RootNamespace>KernelRuntimeImport</RootNamespace>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="Configuration">
|
||||
<TargetVersion>Windows10</TargetVersion>
|
||||
<UseDebugLibraries>true</UseDebugLibraries>
|
||||
<PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset>
|
||||
<ConfigurationType>Driver</ConfigurationType>
|
||||
<DriverType>KMDF</DriverType>
|
||||
<DriverTargetPlatform>Universal</DriverTargetPlatform>
|
||||
</PropertyGroup>
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
|
||||
<TargetVersion>Windows10</TargetVersion>
|
||||
<UseDebugLibraries>false</UseDebugLibraries>
|
||||
<PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset>
|
||||
<ConfigurationType>Driver</ConfigurationType>
|
||||
<DriverType>KMDF</DriverType>
|
||||
<DriverTargetPlatform>Universal</DriverTargetPlatform>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
||||
<ImportGroup Label="ExtensionSettings">
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="PropertySheets">
|
||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
||||
</ImportGroup>
|
||||
<PropertyGroup Label="UserMacros" />
|
||||
<PropertyGroup />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
|
||||
<DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor>
|
||||
</PropertyGroup>
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
|
||||
<DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor>
|
||||
</PropertyGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
|
||||
<ClCompile>
|
||||
<WarningLevel>Level4</WarningLevel>
|
||||
</ClCompile>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
|
||||
<ClCompile>
|
||||
<TreatWarningAsError>true</TreatWarningAsError>
|
||||
</ClCompile>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemGroup>
|
||||
<FilesToPackage Include="$(TargetPath)" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="KernelRuntimeImport.cpp" />
|
||||
<ClCompile Include="drv_main.cpp" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="KernelRuntimeImport.h" />
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,34 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup>
|
||||
<Filter Include="Source Files">
|
||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="Resource Files">
|
||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="Driver Files">
|
||||
<UniqueIdentifier>{8E41214B-6785-4CFE-B992-037D68949A14}</UniqueIdentifier>
|
||||
<Extensions>inf;inv;inx;mof;mc;</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="RuntimeImport">
|
||||
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
|
||||
<Extensions>h;hpp;hxx;hm;inl;inc;xsd</Extensions>
|
||||
</Filter>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="drv_main.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="KernelRuntimeImport.cpp">
|
||||
<Filter>RuntimeImport</Filter>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="KernelRuntimeImport.h">
|
||||
<Filter>RuntimeImport</Filter>
|
||||
</ClInclude>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,29 @@
|
||||
#include "KernelRuntimeImport.h"
|
||||
|
||||
EXTERN_C
|
||||
NTSTATUS
|
||||
DriverEntry(
|
||||
PDRIVER_OBJECT DrvObj,
|
||||
PUNICODE_STRING RegPath
|
||||
)
|
||||
{
|
||||
UNREFERENCED_PARAMETER(DrvObj);
|
||||
UNREFERENCED_PARAMETER(RegPath);
|
||||
|
||||
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
|
||||
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
|
||||
if (MmGetPhysicalAddressAddr == nullptr)
|
||||
{
|
||||
DbgBreakPoint();
|
||||
return STATUS_PROCEDURE_NOT_FOUND;
|
||||
}
|
||||
|
||||
ULONG Num = 0x12345678;
|
||||
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
|
||||
MmGetPhysicalAddressAddr,
|
||||
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
|
||||
&Num);
|
||||
UNREFERENCED_PARAMETER(PhyAddr);
|
||||
|
||||
return STATUS_UNSUCCESSFUL;
|
||||
}
|
||||
@@ -0,0 +1,112 @@
|
||||
# KernelRuntimeImport
|
||||
|
||||
[中文文档](README.zh-CN.md)
|
||||
|
||||
`KernelRuntimeImport` is a minimal Windows x64 kernel driver sample that demonstrates how to resolve and call exported functions from `ntoskrnl.exe` at runtime through function name hashing.
|
||||
|
||||
## Overview
|
||||
|
||||
This project demonstrates dynamic API importing and invocation at runtime:
|
||||
|
||||
- The target kernel function is not declared directly in the PE import table, so the IAT does not store the sensitive function and IAT hooks can be avoided.
|
||||
- The kernel image base is located at runtime.
|
||||
- The export table is traversed and export names are matched by hash.
|
||||
- After resolving the target function address, the function is invoked through a function pointer.
|
||||
|
||||
The current sample uses `MmGetPhysicalAddress` as an example to show the complete resolution and invocation flow.
|
||||
|
||||
## Features
|
||||
|
||||
- Uses `__readmsr(0xC0000082)` to help locate the base address of `ntoskrnl.exe` without relying on conventional kernel export lookup APIs.
|
||||
- Uses the compile-time string hash macro `STRING_HASH(...)` to generate the hash of the target export name.
|
||||
- Resolves the target function address at runtime by traversing the export table and comparing hashes.
|
||||
- Uses the `CALL_ROUTINE(...)` macro to cast the resolved address to the target function signature and invoke it directly.
|
||||
- Keeps the sample compact and easy to extend into a runtime resolver for multiple exported functions.
|
||||
|
||||
The minimal invocation example in `drv_main.cpp` is shown below:
|
||||
|
||||
```cpp
|
||||
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
|
||||
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
|
||||
if (MmGetPhysicalAddressAddr == nullptr)
|
||||
{
|
||||
DbgBreakPoint();
|
||||
return STATUS_PROCEDURE_NOT_FOUND;
|
||||
}
|
||||
|
||||
ULONG Num = 0x12345678;
|
||||
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
|
||||
MmGetPhysicalAddressAddr,
|
||||
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
|
||||
&Num);
|
||||
UNREFERENCED_PARAMETER(PhyAddr);
|
||||
```
|
||||
|
||||
This flow clearly shows the core purpose of the project: resolve a specified export by hash during driver runtime and call it directly, instead of linking through a static import entry.
|
||||
|
||||
## Supported Environment
|
||||
|
||||
The project has currently been tested only in the following environments:
|
||||
|
||||
| OS Version | Architecture | Status |
|
||||
| --- | --- | --- |
|
||||
| Windows 10 19044 | x64 | Tested |
|
||||
| Windows 11 22H2 | x64 | Tested |
|
||||
| Windows 11 24H2 | x64 | Tested |
|
||||
| Windows 11 25H2 | x64 | Tested |
|
||||
|
||||
Notes:
|
||||
|
||||
- Based on the implementation approach, it should theoretically be compatible with most Windows 10 / Windows 11 x64 versions.
|
||||
- The current repository targets x64 driver scenarios only and has not been validated on Win32, ARM, or ARM64.
|
||||
|
||||
## Build
|
||||
|
||||
The current build environment is:
|
||||
|
||||
- Visual Studio 2017
|
||||
- WDK 10
|
||||
- x64 Kernel-Mode Driver
|
||||
|
||||
Build steps:
|
||||
|
||||
1. Open `KernelRuntimeImport.sln` in Visual Studio 2017.
|
||||
2. Make sure WDK 10 is installed correctly and the `WindowsKernelModeDriver10.0` toolset is available.
|
||||
3. Switch the build platform to `x64`.
|
||||
4. Build with either the `Debug` or `Release` configuration.
|
||||
|
||||
Notes:
|
||||
|
||||
- The current project supports x64 drivers only.
|
||||
- Although the project file contains other platform configurations, the implementation and validation scope currently target x64 only.
|
||||
|
||||
## Debugging and Warnings
|
||||
|
||||
When export resolution fails, the current sample actively triggers `DbgBreakPoint()` and returns `STATUS_PROCEDURE_NOT_FOUND`:
|
||||
|
||||
```cpp
|
||||
if (MmGetPhysicalAddressAddr == nullptr)
|
||||
{
|
||||
DbgBreakPoint();
|
||||
return STATUS_PROCEDURE_NOT_FOUND;
|
||||
}
|
||||
```
|
||||
|
||||
This means:
|
||||
|
||||
- Run this sample in a test environment or virtual machine with a debugger attached.
|
||||
- If the target export cannot be resolved successfully, the driver will break in `DriverEntry` so the issue can be diagnosed immediately.
|
||||
|
||||
## Project Structure
|
||||
|
||||
- `KernelRuntimeImport/KernelRuntimeImport.h`: Hash helpers, function pointer invocation macros, and exported interface declarations.
|
||||
- `KernelRuntimeImport/KernelRuntimeImport.cpp`: Kernel base discovery and export table traversal / resolution logic.
|
||||
- `KernelRuntimeImport/drv_main.cpp`: Minimal driver entry and invocation example.
|
||||
|
||||
## Usage
|
||||
|
||||
This repository is better suited as a research and demonstration sample:
|
||||
|
||||
- If you want to understand the basic runtime import flow, start reading from `DriverEntry`.
|
||||
- If you want to extend it into a resolver for multiple APIs, continue building on top of `GetntoskrnlExportAddressByHash(...)`.
|
||||
- If you want to validate compatibility across different system versions, test them one by one in isolated virtual machines.
|
||||
+112
@@ -0,0 +1,112 @@
|
||||
# KernelRuntimeImport
|
||||
|
||||
[English](README.md)
|
||||
|
||||
`KernelRuntimeImport` 是教学性质的 Windows x64 内核驱动示例,用于展示如何在运行时通过函数名 Hash 解析 `ntoskrnl.exe` 的导出函数地址并调用。
|
||||
|
||||
## 概览
|
||||
|
||||
实现运行时动态导入API并调用:
|
||||
|
||||
- 不直接在 PE 导入表中声明目标内核函数(IAT表不保存敏感函数,可以避免IAT Hook)。
|
||||
- 在运行时定位内核镜像基址。
|
||||
- 遍历导出表,对导出函数名做 Hash 比对。
|
||||
- 解析到目标函数地址后,再通过函数指针完成调用。
|
||||
|
||||
当前示例以 `MmGetPhysicalAddress` 为例,演示完整的解析与调用流程。
|
||||
|
||||
## Features
|
||||
|
||||
- 通过 `__readmsr(0xC0000082)` 辅助定位 `ntoskrnl.exe` 基址,不依赖常规内核导出查询 API。
|
||||
- 使用编译期字符串 Hash 宏 `STRING_HASH(...)` 生成目标导出名 Hash。
|
||||
- 通过遍历导出表并比较 Hash,在运行时解析目标函数地址。
|
||||
- 使用 `CALL_ROUTINE(...)` 宏将地址转换为目标函数签名并直接调用。
|
||||
- 示例代码短小,便于二次扩展为多个导出函数的运行时解析器。
|
||||
|
||||
`drv_main.cpp` 中的最小调用示例如下:
|
||||
|
||||
```cpp
|
||||
constexpr ULONG MmGetPhysicalAddressHash = STRING_HASH("MmGetPhysicalAddress");
|
||||
PVOID MmGetPhysicalAddressAddr = GetntoskrnlExportAddressByHash(MmGetPhysicalAddressHash);
|
||||
if (MmGetPhysicalAddressAddr == nullptr)
|
||||
{
|
||||
DbgBreakPoint();
|
||||
return STATUS_PROCEDURE_NOT_FOUND;
|
||||
}
|
||||
|
||||
ULONG Num = 0x12345678;
|
||||
PHYSICAL_ADDRESS PhyAddr = CALL_ROUTINE(
|
||||
MmGetPhysicalAddressAddr,
|
||||
ROUTINE_TYPE(PHYSICAL_ADDRESS, _In_ PVOID),
|
||||
&Num);
|
||||
UNREFERENCED_PARAMETER(PhyAddr);
|
||||
```
|
||||
|
||||
上面的流程清楚说明了这个项目的核心功能:在驱动运行期间按 Hash 解析指定导出并直接调用,而不是通过静态导入项完成链接。
|
||||
|
||||
## Supported Environment
|
||||
|
||||
目前仅在以下环境完成过测试:
|
||||
|
||||
| 系统版本 | 架构 | 状态 |
|
||||
| --- | --- | --- |
|
||||
| Windows 10 19044 | x64 | 已测试 |
|
||||
| Windows 11 22H2 | x64 | 已测试 |
|
||||
| Windows 11 24H2 | x64 | 已测试 |
|
||||
| Windows 11 25H2 | x64 | 已测试 |
|
||||
|
||||
说明:
|
||||
|
||||
- 从实现方式来看,理论上应兼容大部分 Windows 10 / Windows 11 x64 版本。
|
||||
- 当前仓库只面向 x64 驱动场景,未验证 Win32、ARM 或 ARM64。
|
||||
|
||||
## Build
|
||||
|
||||
当前构建环境如下:
|
||||
|
||||
- Visual Studio 2017
|
||||
- WDK 10
|
||||
- x64 Kernel-Mode Driver
|
||||
|
||||
构建步骤:
|
||||
|
||||
1. 使用 Visual Studio 2017 打开 `KernelRuntimeImport.sln`。
|
||||
2. 确认已正确安装 WDK 10,并能使用 `WindowsKernelModeDriver10.0` 工具链。
|
||||
3. 将构建平台切换为 `x64`。
|
||||
4. 选择 `Debug` 或 `Release` 配置后执行编译。
|
||||
|
||||
说明:
|
||||
|
||||
- 当前项目仅支持 x64 驱动使用。
|
||||
- 虽然工程文件中包含其他平台配置项,但当前实现和验证范围都以 x64 为准。
|
||||
|
||||
## 调试与警告
|
||||
|
||||
当导出函数解析失败时,当前示例会主动触发 `DbgBreakPoint()`,并返回 `STATUS_PROCEDURE_NOT_FOUND`:
|
||||
|
||||
```cpp
|
||||
if (MmGetPhysicalAddressAddr == nullptr)
|
||||
{
|
||||
DbgBreakPoint();
|
||||
return STATUS_PROCEDURE_NOT_FOUND;
|
||||
}
|
||||
```
|
||||
|
||||
这意味着:
|
||||
|
||||
- 请在调试器连接的测试环境或虚拟机中运行本示例。
|
||||
- 如果目标导出未解析成功,驱动会在 `DriverEntry` 阶段中断,便于立刻定位问题。
|
||||
|
||||
## 项目结构
|
||||
|
||||
- `KernelRuntimeImport/KernelRuntimeImport.h`:Hash、函数指针调用宏以及导出接口声明。
|
||||
- `KernelRuntimeImport/KernelRuntimeImport.cpp`:内核基址定位与导出表遍历解析实现。
|
||||
- `KernelRuntimeImport/drv_main.cpp`:最小驱动入口与调用示例。
|
||||
|
||||
## 使用说明
|
||||
|
||||
这个仓库更适合作为研究和演示样例阅读:
|
||||
|
||||
- 如果你想了解运行时导入的基本实现流程,可以从 `DriverEntry` 入口开始读。
|
||||
- 如果你想扩展为多个 API 的解析器,可以在现有 `GetntoskrnlExportAddressByHash(...)` 基础上继续封装。
|
||||
- 如果你想验证不同系统版本上的兼容性,建议在独立虚拟机中逐个测试。
|
||||
Reference in New Issue
Block a user