refactor: small ETWTI improvements

This commit is contained in:
2024-12-22 12:47:25 +01:00
parent 72d6b26c4e
commit ce6c920b9c
3 changed files with 6 additions and 1 deletions
+2
View File
@@ -33,6 +33,8 @@ void event_callback(const EVENT_RECORD& record, const krabs::trace_context& trac
if (!enabled_consumer) {
return;
}
// Check if we should follow this process
DWORD processId = record.EventHeader.ProcessId;
struct my_hashmap* obj = get_obj(processId);
if (!obj->value) {
+3
View File
@@ -25,17 +25,20 @@ krabs::user_trace trace_ppl(L"RedEdrPpl");
// Blocking
void StartEtwtiReader() {
LOG_A(LOG_INFO, "Preparing to read from ETW-TI");
krabs::provider<> ti_provider(L"Microsoft-Windows-Threat-Intelligence");
ti_provider.trace_flags(ti_provider.trace_flags() | EVENT_ENABLE_PROPERTY_STACK_TRACE);
ti_provider.add_on_event_callback(event_callback);
trace_ppl.enable(ti_provider);
LOG_A(LOG_INFO, "Start reading from ETW-TI");
// Blocking, stopped with trace.stop()
trace_ppl.start();
}
void ShutdownEtwtiReader() {
LOG_A(LOG_INFO, "Stop Reading from ETW-TI");
trace_ppl.stop();
}
+1 -1
View File
@@ -55,8 +55,8 @@ struct my_hashmap* get_obj(int pid) {
else {
//LOG_W(LOG_INFO, L"Failed to get executable path: %lu\n", GetLastError());
}
CloseHandle(hProcess);
}
CloseHandle(hProcess);
}
struct my_hashmap* res = add_obj(pid, observe);