mirror of
https://github.com/dobin/RedEdr
synced 2026-08-09 12:30:51 +00:00
refactor: add "etw_time -> event_time" to all subsystems
This commit is contained in:
@@ -41,7 +41,7 @@ void EventProcessor::init() {
|
||||
nlohmann::json j;
|
||||
j["type"] = "meta";
|
||||
j["func"] = "init";
|
||||
j["date"] = get_time_for_file();
|
||||
j["event_time"] = get_time();
|
||||
j["version"] = REDEDR_VERSION;
|
||||
j["trace_id"] = trace_id;
|
||||
|
||||
@@ -50,6 +50,8 @@ void EventProcessor::init() {
|
||||
j["do_kernel"] = g_Config.do_kernel;
|
||||
j["do_hook"] = g_Config.do_hook;
|
||||
j["do_hook_callstack"] = g_Config.do_dllinjection_ucallstack;
|
||||
j["do_defendertrace"] = g_Config.do_defendertrace;
|
||||
j["do_antimalwareengine"] = g_Config.do_antimalwareengine;
|
||||
|
||||
j["targets"] = g_Config.targetProcessNames;
|
||||
json_entries.push_back(j);
|
||||
@@ -65,7 +67,7 @@ void EventProcessor::LogInitialProcessInfo(Process *process) {
|
||||
j["pid"] = process->id;
|
||||
j["type"] = "process_query";
|
||||
j["func"] = "peb";
|
||||
j["time"] = get_time();
|
||||
j["event_time"] = get_time();
|
||||
j["id"] = process->id;
|
||||
j["parent_pid"] = processPebInfoRet.parent_pid;
|
||||
j["image_path"] = processPebInfoRet.image_path;
|
||||
@@ -89,7 +91,7 @@ void EventProcessor::LogInitialProcessInfo(Process *process) {
|
||||
nlohmann::json jDlls;
|
||||
jDlls["func"] = "loaded_dll";
|
||||
jDlls["type"] = "process_query";
|
||||
jDlls["time"] = get_time();
|
||||
jDlls["event_time"] = get_time();
|
||||
jDlls["pid"] = process->id;
|
||||
jDlls["process_name"] = process->processPebInfoRet.image_path;
|
||||
jDlls["dlls"] = {};
|
||||
|
||||
@@ -411,7 +411,7 @@ void CreateProcessNotifyRoutine(PEPROCESS process, HANDLE pid, PPS_CREATE_NOTIFY
|
||||
JsonEscape(processName, PROC_NAME_LEN);
|
||||
JsonEscape(parentName, PROC_NAME_LEN);
|
||||
|
||||
RtlStringCbPrintfA(ProcessLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"time\":%llu,\"func\":\"process_create\",\"krn_pid\":%llu,\"pid\":%llu,\"name\":\"%s\",\"ppid\":%llu,\"parent_name\":\"%s\"}",
|
||||
RtlStringCbPrintfA(ProcessLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"event_time\":%llu,\"func\":\"process_create\",\"krn_pid\":%llu,\"pid\":%llu,\"name\":\"%s\",\"ppid\":%llu,\"parent_name\":\"%s\"}",
|
||||
systemTime,
|
||||
(unsigned __int64)PsGetCurrentProcessId(),
|
||||
(unsigned __int64)pid,
|
||||
@@ -452,7 +452,7 @@ void CreateThreadNotifyRoutine(HANDLE ProcessId, HANDLE ThreadId, BOOLEAN Create
|
||||
KeQuerySystemTime(&systemTime);
|
||||
|
||||
char ThreadLine[DATA_BUFFER_SIZE];
|
||||
RtlStringCbPrintfA(ThreadLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"time\":%llu,\"func\":\"thread_create\",\"krn_pid\":%llu,\"pid\":%llu,\"threadid\":%llu,\"create\":%d}",
|
||||
RtlStringCbPrintfA(ThreadLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"event_time\":%llu,\"func\":\"thread_create\",\"krn_pid\":%llu,\"pid\":%llu,\"threadid\":%llu,\"create\":%d}",
|
||||
systemTime,
|
||||
(unsigned __int64)PsGetCurrentProcessId(),
|
||||
(unsigned __int64)ProcessId,
|
||||
@@ -487,7 +487,7 @@ void LoadImageNotifyRoutine(PUNICODE_STRING FullImageName, HANDLE ProcessId, PIM
|
||||
WcharToAscii(ImageName, sizeof(ImageName), AsciiImageName, sizeof(AsciiImageName));
|
||||
JsonEscape(AsciiImageName, sizeof(AsciiImageName));
|
||||
char ImageLine[DATA_BUFFER_SIZE];
|
||||
RtlStringCbPrintfA(ImageLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"time\":%llu,\"func\":\"image_load\",\"krn_pid\":%llu,\"pid\":%llu,\"image\":\"%s\"}",
|
||||
RtlStringCbPrintfA(ImageLine, DATA_BUFFER_SIZE, "{\"type\":\"kernel\",\"event_time\":%llu,\"func\":\"image_load\",\"krn_pid\":%llu,\"pid\":%llu,\"image\":\"%s\"}",
|
||||
systemTime,
|
||||
(unsigned __int64)PsGetCurrentProcessId(),
|
||||
(unsigned __int64)ProcessId,
|
||||
|
||||
@@ -155,6 +155,7 @@ void SendDefenderInfos() {
|
||||
modules_event["event"] = "process_modules";
|
||||
modules_event["type"] = "meta";
|
||||
modules_event["pid"] = pid;
|
||||
modules_event["event_time"] = get_time();
|
||||
modules_event["process_name"] = wchar2string(process_name);
|
||||
modules_event["modules"] = modules_array;
|
||||
|
||||
@@ -174,6 +175,7 @@ void SendDefenderInfos() {
|
||||
platform_event["event"] = "defender_platform_info";
|
||||
platform_event["type"] = "meta";
|
||||
platform_event["pid"] = msmpeng_pid;
|
||||
platform_event["event_time"] = get_time();
|
||||
nlohmann::json platform_info = GetDefenderPlatformInfo();
|
||||
platform_event["as_signature_version"] = platform_info["as_signature_version"];
|
||||
platform_event["av_signature_version"] = platform_info["av_signature_version"];
|
||||
|
||||
@@ -18,7 +18,7 @@ nlohmann::json KrabsEtwEventToJsonStr(const EVENT_RECORD& record, krabs::schema
|
||||
nlohmann::json j;
|
||||
|
||||
j["type"] = "etw";
|
||||
j["etw_time"] = static_cast<__int64>(record.EventHeader.TimeStamp.QuadPart);
|
||||
j["event_time"] = static_cast<__int64>(record.EventHeader.TimeStamp.QuadPart);
|
||||
j["etw_pid"] = record.EventHeader.ProcessId;
|
||||
j["etw_tid"] = record.EventHeader.ThreadId;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user