mirror of
https://github.com/dobin/RedEdr
synced 2026-08-09 12:30:51 +00:00
refactor: small ETWTI improvements
This commit is contained in:
@@ -33,6 +33,8 @@ void event_callback(const EVENT_RECORD& record, const krabs::trace_context& trac
|
||||
if (!enabled_consumer) {
|
||||
return;
|
||||
}
|
||||
|
||||
// Check if we should follow this process
|
||||
DWORD processId = record.EventHeader.ProcessId;
|
||||
struct my_hashmap* obj = get_obj(processId);
|
||||
if (!obj->value) {
|
||||
|
||||
@@ -25,17 +25,20 @@ krabs::user_trace trace_ppl(L"RedEdrPpl");
|
||||
|
||||
// Blocking
|
||||
void StartEtwtiReader() {
|
||||
LOG_A(LOG_INFO, "Preparing to read from ETW-TI");
|
||||
krabs::provider<> ti_provider(L"Microsoft-Windows-Threat-Intelligence");
|
||||
ti_provider.trace_flags(ti_provider.trace_flags() | EVENT_ENABLE_PROPERTY_STACK_TRACE);
|
||||
ti_provider.add_on_event_callback(event_callback);
|
||||
trace_ppl.enable(ti_provider);
|
||||
|
||||
LOG_A(LOG_INFO, "Start reading from ETW-TI");
|
||||
// Blocking, stopped with trace.stop()
|
||||
trace_ppl.start();
|
||||
}
|
||||
|
||||
|
||||
void ShutdownEtwtiReader() {
|
||||
LOG_A(LOG_INFO, "Stop Reading from ETW-TI");
|
||||
trace_ppl.stop();
|
||||
}
|
||||
|
||||
|
||||
@@ -55,8 +55,8 @@ struct my_hashmap* get_obj(int pid) {
|
||||
else {
|
||||
//LOG_W(LOG_INFO, L"Failed to get executable path: %lu\n", GetLastError());
|
||||
}
|
||||
CloseHandle(hProcess);
|
||||
}
|
||||
CloseHandle(hProcess);
|
||||
}
|
||||
|
||||
struct my_hashmap* res = add_obj(pid, observe);
|
||||
|
||||
Reference in New Issue
Block a user