feature: augment etw callstacks

This commit is contained in:
2024-12-22 13:14:01 +01:00
parent b0e9fb20cd
commit f733495a75
2 changed files with 21 additions and 1 deletions
+19
View File
@@ -19,6 +19,7 @@ void AugmentEvent(nlohmann::json& j) {
void AugmentEventWithMemAddrInfo(nlohmann::json& j) {
// InjectedDLL: callstack
if (j.contains("callstack") && j["callstack"].is_array()) {
for (auto& callstack_entry : j["callstack"]) {
if (callstack_entry.contains("addr")) {
@@ -35,6 +36,24 @@ void AugmentEventWithMemAddrInfo(nlohmann::json& j) {
}
}
}
// ETW: stack_trace
if (j.contains("stack_trace") && j["stack_trace"].is_array()) {
for (auto& callstack_entry : j["stack_trace"]) {
if (callstack_entry.contains("addr")) {
uint64_t addr = callstack_entry["addr"].get<uint64_t>();
std::string symbol = g_MemStatic.ResolveStr(addr);
callstack_entry["addr_info"] = symbol;
// log
if (1) {
LOG_A(LOG_INFO, "Addr 0x%llx Symbol: %s",
addr,
symbol.c_str());
}
}
}
}
}
+2 -1
View File
@@ -135,11 +135,12 @@ void event_callback(const EVENT_RECORD& record, const krabs::trace_context& trac
// Callstack
auto stack_trace = schema.stack_trace();
j["stack_trace"] = {};
for (auto& return_address : stack_trace)
{
// Only add non-kernelspace addresses
if (return_address < 0xFFFF080000000000) {
j["stack_trace"] += return_address;
j["stack_trace"] += { {"addr", return_address} };
}
}