diff --git a/JonMon-Lite/DefaultBinaries/JonMon-Lite-Provider.man b/JonMon-Lite/DefaultBinaries/JonMon-Lite-Provider.man
new file mode 100644
index 0000000..d953964
--- /dev/null
+++ b/JonMon-Lite/DefaultBinaries/JonMon-Lite-Provider.man
@@ -0,0 +1,601 @@
+
+
+
+
+
+
+
+
+ 67112660
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/DefaultBinaries/JonMon-Lite.json b/JonMon-Lite/DefaultBinaries/JonMon-Lite.json
new file mode 100644
index 0000000..0d4e1a6
--- /dev/null
+++ b/JonMon-Lite/DefaultBinaries/JonMon-Lite.json
@@ -0,0 +1,10 @@
+{
+ "XMLFilePath": "C:\\Path\\To\\JonMon-Lite.xml",
+ "ETLFilePath": "C:\\PerfLogs\\Admin\\JonMon-Lite\\",
+ "RootPath": "C:\\PerfLogs\\Admin\\JonMon-Lite\\",
+ "TraceName": "JonMon-Lite",
+ "WorkstationName": ["WorkstationName"],
+ "User": "",
+ "Password": ""
+
+}
\ No newline at end of file
diff --git a/JonMon-Lite/DefaultBinaries/JonMon-Lite.xml b/JonMon-Lite/DefaultBinaries/JonMon-Lite.xml
new file mode 100644
index 0000000..e4ef4d8
--- /dev/null
+++ b/JonMon-Lite/DefaultBinaries/JonMon-Lite.xml
@@ -0,0 +1,1303 @@
+
+
+ 3
+ 25
+ O:BAD:AI(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1200a9;;;LU)(A;;0x1301ff;;;S-1-5-80-2661322625-712705077-2999183737-3043590567-590698655)(A;ID;0x1f019f;;;BA)(A;ID;0x1f019f;;;SY)(A;ID;FR;;;AU)(A;ID;FR;;;LS)(A;ID;FR;;;NS)(A;ID;FA;;;BA)
+
+ 1
+ JonMon-Lite
+ JonMon-Lite
+ 0
+
+
+ 0
+ -1
+ 0
+ {00000000-0000-0000-0000-000000000000}
+ 8
+ 0
+ 0
+ 2
+ 0
+ 0
+ 2
+ 0
+ 0
+ 0
+ 0
+ 0
+ 0
+ 0
+ JonMon-Lite
+ 0
+ 1
+
+ Microsoft-Windows-RPC
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Error
+ Error
+ 0
+ 0x2
+
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+ win:Verbose
+ Verbose
+ 0
+ 0x5
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x0
+
+ Microsoft-Windows-RPC/EEInfo
+ EEInfo
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-RPC/Debug
+ Debug
+ 0
+ 0x4000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ Microsoft-Windows-RPC/EEInfo
+ EEInfo
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-RPC/Debug
+ Debug
+ 0
+ 0x4000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {6AD52B32-D609-4BE9-AE07-CE8DAE937E39}
+
+
+ Microsoft-Antimalware-Scan-Interface
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x0
+
+ Event1
+
+
+ 0
+ 0x1
+
+
+ AMSI/Debug
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ Event1
+
+
+ 0
+ 0x1
+
+
+ AMSI/Debug
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {2A576B87-09A7-520E-C21A-4942F0271D67}
+
+
+ Microsoft-Windows-DotNETRuntime
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:LogAlways
+ Log Always
+ -1
+ 0x0
+
+
+ win:Error
+ Error
+ 0
+ 0x2
+
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+ win:Verbose
+ Verbose
+ 0
+ 0x5
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x8
+
+ GCKeyword
+ GC
+ 0
+ 0x1
+
+
+ GCHandleKeyword
+ GCHandle
+ 0
+ 0x2
+
+
+ FusionKeyword
+ Binder
+ 0
+ 0x4
+
+
+ LoaderKeyword
+ Loader
+ -1
+ 0x8
+
+
+ JitKeyword
+ Jit
+ 0
+ 0x10
+
+
+ NGenKeyword
+ NGen
+ 0
+ 0x20
+
+
+ StartEnumerationKeyword
+ StartEnumeration
+ 0
+ 0x40
+
+
+ EndEnumerationKeyword
+ StopEnumeration
+ 0
+ 0x80
+
+
+ SecurityKeyword
+ Security
+ 0
+ 0x400
+
+
+ AppDomainResourceManagementKeyword
+ AppDomainResourceManagement
+ 0
+ 0x800
+
+
+ JitTracingKeyword
+ JitTracing
+ 0
+ 0x1000
+
+
+ InteropKeyword
+ Interop
+ 0
+ 0x2000
+
+
+ ContentionKeyword
+ Contention
+ 0
+ 0x4000
+
+
+ ExceptionKeyword
+ Exception
+ 0
+ 0x8000
+
+
+ ThreadingKeyword
+ Threading
+ 0
+ 0x10000
+
+
+ JittedMethodILToNativeMapKeyword
+ JittedMethodILToNativeMap
+ 0
+ 0x20000
+
+
+ OverrideAndSuppressNGenEventsKeyword
+ OverrideAndSuppressNGenEvents
+ 0
+ 0x40000
+
+
+ TypeKeyword
+ Type
+ 0
+ 0x80000
+
+
+ GCHeapDumpKeyword
+ GCHeapDump
+ 0
+ 0x100000
+
+
+ GCSampledObjectAllocationHighKeyword
+ GCSampledObjectAllocationHigh
+ 0
+ 0x200000
+
+
+ GCHeapSurvivalAndMovementKeyword
+ GCHeapSurvivalAndMovement
+ 0
+ 0x400000
+
+
+ GCHeapCollectKeyword
+ GCHeapCollect
+ 0
+ 0x800000
+
+
+ GCHeapAndTypeNamesKeyword
+ GCHeapAndTypeNames
+ 0
+ 0x1000000
+
+
+ GCSampledObjectAllocationLowKeyword
+ GCSampledObjectAllocationLow
+ 0
+ 0x2000000
+
+
+ PerfTrackKeyword
+ PerfTrack
+ 0
+ 0x20000000
+
+
+ StackKeyword
+ Stack
+ 0
+ 0x40000000
+
+
+ ThreadTransferKeyword
+ ThreadTransfer
+ 0
+ 0x80000000
+
+
+ DebuggerKeyword
+ Debugger
+ 0
+ 0x100000000
+
+
+ MonitoringKeyword
+ Monitoring
+ 0
+ 0x200000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ GCKeyword
+ GC
+ 0
+ 0x1
+
+
+ GCHandleKeyword
+ GCHandle
+ 0
+ 0x2
+
+
+ FusionKeyword
+ Binder
+ 0
+ 0x4
+
+
+ LoaderKeyword
+ Loader
+ 0
+ 0x8
+
+
+ JitKeyword
+ Jit
+ 0
+ 0x10
+
+
+ NGenKeyword
+ NGen
+ 0
+ 0x20
+
+
+ StartEnumerationKeyword
+ StartEnumeration
+ 0
+ 0x40
+
+
+ EndEnumerationKeyword
+ StopEnumeration
+ 0
+ 0x80
+
+
+ SecurityKeyword
+ Security
+ 0
+ 0x400
+
+
+ AppDomainResourceManagementKeyword
+ AppDomainResourceManagement
+ 0
+ 0x800
+
+
+ JitTracingKeyword
+ JitTracing
+ 0
+ 0x1000
+
+
+ InteropKeyword
+ Interop
+ 0
+ 0x2000
+
+
+ ContentionKeyword
+ Contention
+ 0
+ 0x4000
+
+
+ ExceptionKeyword
+ Exception
+ 0
+ 0x8000
+
+
+ ThreadingKeyword
+ Threading
+ 0
+ 0x10000
+
+
+ JittedMethodILToNativeMapKeyword
+ JittedMethodILToNativeMap
+ 0
+ 0x20000
+
+
+ OverrideAndSuppressNGenEventsKeyword
+ OverrideAndSuppressNGenEvents
+ 0
+ 0x40000
+
+
+ TypeKeyword
+ Type
+ 0
+ 0x80000
+
+
+ GCHeapDumpKeyword
+ GCHeapDump
+ 0
+ 0x100000
+
+
+ GCSampledObjectAllocationHighKeyword
+ GCSampledObjectAllocationHigh
+ 0
+ 0x200000
+
+
+ GCHeapSurvivalAndMovementKeyword
+ GCHeapSurvivalAndMovement
+ 0
+ 0x400000
+
+
+ GCHeapCollectKeyword
+ GCHeapCollect
+ 0
+ 0x800000
+
+
+ GCHeapAndTypeNamesKeyword
+ GCHeapAndTypeNames
+ 0
+ 0x1000000
+
+
+ GCSampledObjectAllocationLowKeyword
+ GCSampledObjectAllocationLow
+ 0
+ 0x2000000
+
+
+ PerfTrackKeyword
+ PerfTrack
+ 0
+ 0x20000000
+
+
+ StackKeyword
+ Stack
+ 0
+ 0x40000000
+
+
+ ThreadTransferKeyword
+ ThreadTransfer
+ 0
+ 0x80000000
+
+
+ DebuggerKeyword
+ Debugger
+ 0
+ 0x100000000
+
+
+ MonitoringKeyword
+ Monitoring
+ 0
+ 0x200000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {E13C0D23-CCBC-4E12-931B-D9CC2EEE27E4}
+
+
+ Microsoft-Windows-WMI-Activity
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Error
+ Error
+ 0
+ 0x2
+
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x0
+
+ Microsoft-Windows-WMI-Activity/Trace
+
+
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-WMI-Activity/Operational
+
+
+ 0
+ 0x4000000000000000
+
+
+ Microsoft-Windows-WMI-Activity/Debug
+
+
+ 0
+ 0x2000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ Microsoft-Windows-WMI-Activity/Trace
+
+
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-WMI-Activity/Operational
+
+
+ 0
+ 0x4000000000000000
+
+
+ Microsoft-Windows-WMI-Activity/Debug
+
+
+ 0
+ 0x2000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}
+
+
+ Microsoft-Windows-Crypto-DPAPI
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Error
+ Error
+ 0
+ 0x2
+
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x40
+
+ ETW_TASK_BACKUPSERVICE_OPERATION
+ BackUp Service Operation
+ 0
+ 0x1
+
+
+ ETW_TASK_MASTERKEY_OPERATION
+ Master Key Operation
+ 0
+ 0x2
+
+
+ ETW_TASK_DATAPROTECTION_OPERATION
+ Data Protection Operation
+ 0
+ 0x4
+
+
+ ETW_TASK_CREDKEY_OPERATION
+ Credential Key Operation
+ 0
+ 0x8
+
+
+ ETW_TASK_DEF_INFORMATION
+ DPAPIDefInformationKeywordMessage
+ -1
+ 0x40
+
+
+ ETW_TASK_RC4_FALLBACK
+ DPAPIRC4FallbackKeywordMessage
+ 0
+ 0x80
+
+
+ ETW_TASK_MASTER_KEY_BACKUP
+ DPAPIMasterKeyBackupKeywordMessage
+ 0
+ 0x100
+
+
+ Microsoft-Windows-Crypto-DPAPI/Operational
+ Microsoft-Windows-Crypto-DPAPI/Operational
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
+ Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
+ 0
+ 0x4000000000000000
+
+
+ Microsoft-Windows-Crypto-DPAPI/Debug
+ Microsoft-Windows-Crypto-DPAPI/Debug
+ 0
+ 0x2000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ ETW_TASK_BACKUPSERVICE_OPERATION
+ BackUp Service Operation
+ 0
+ 0x1
+
+
+ ETW_TASK_MASTERKEY_OPERATION
+ Master Key Operation
+ 0
+ 0x2
+
+
+ ETW_TASK_DATAPROTECTION_OPERATION
+ Data Protection Operation
+ 0
+ 0x4
+
+
+ ETW_TASK_CREDKEY_OPERATION
+ Credential Key Operation
+ 0
+ 0x8
+
+
+ ETW_TASK_DEF_INFORMATION
+ DPAPIDefInformationKeywordMessage
+ 0
+ 0x40
+
+
+ ETW_TASK_RC4_FALLBACK
+ DPAPIRC4FallbackKeywordMessage
+ 0
+ 0x80
+
+
+ ETW_TASK_MASTER_KEY_BACKUP
+ DPAPIMasterKeyBackupKeywordMessage
+ 0
+ 0x100
+
+
+ Microsoft-Windows-Crypto-DPAPI/Operational
+ Microsoft-Windows-Crypto-DPAPI/Operational
+ 0
+ 0x8000000000000000
+
+
+ Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
+ Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
+ 0
+ 0x4000000000000000
+
+
+ Microsoft-Windows-Crypto-DPAPI/Debug
+ Microsoft-Windows-Crypto-DPAPI/Debug
+ 0
+ 0x2000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {89FE8F40-CDCE-464E-8217-15EF97D4C7C3}
+
+
+ Microsoft-Windows-Kernel-Process
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x10
+
+ WINEVENT_KEYWORD_PROCESS
+
+
+ -1
+ 0x10
+
+
+ WINEVENT_KEYWORD_THREAD
+
+
+ 0
+ 0x20
+
+
+ WINEVENT_KEYWORD_IMAGE
+
+
+ 0
+ 0x40
+
+
+ WINEVENT_KEYWORD_CPU_PRIORITY
+
+
+ 0
+ 0x80
+
+
+ WINEVENT_KEYWORD_OTHER_PRIORITY
+
+
+ 0
+ 0x100
+
+
+ WINEVENT_KEYWORD_PROCESS_FREEZE
+
+
+ 0
+ 0x200
+
+
+ WINEVENT_KEYWORD_JOB
+
+
+ 0
+ 0x400
+
+
+ WINEVENT_KEYWORD_ENABLE_PROCESS_TRACING_CALLBACKS
+
+
+ 0
+ 0x800
+
+
+ WINEVENT_KEYWORD_JOB_IO
+
+
+ 0
+ 0x1000
+
+
+ WINEVENT_KEYWORD_WORK_ON_BEHALF
+
+
+ 0
+ 0x2000
+
+
+ WINEVENT_KEYWORD_JOB_SILO
+
+
+ 0
+ 0x4000
+
+
+ Microsoft-Windows-Kernel-Process/Analytic
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ WINEVENT_KEYWORD_PROCESS
+
+
+ 0
+ 0x10
+
+
+ WINEVENT_KEYWORD_THREAD
+
+
+ 0
+ 0x20
+
+
+ WINEVENT_KEYWORD_IMAGE
+
+
+ 0
+ 0x40
+
+
+ WINEVENT_KEYWORD_CPU_PRIORITY
+
+
+ 0
+ 0x80
+
+
+ WINEVENT_KEYWORD_OTHER_PRIORITY
+
+
+ 0
+ 0x100
+
+
+ WINEVENT_KEYWORD_PROCESS_FREEZE
+
+
+ 0
+ 0x200
+
+
+ WINEVENT_KEYWORD_JOB
+
+
+ 0
+ 0x400
+
+
+ WINEVENT_KEYWORD_ENABLE_PROCESS_TRACING_CALLBACKS
+
+
+ 0
+ 0x800
+
+
+ WINEVENT_KEYWORD_JOB_IO
+
+
+ 0
+ 0x1000
+
+
+ WINEVENT_KEYWORD_WORK_ON_BEHALF
+
+
+ 0
+ 0x2000
+
+
+ WINEVENT_KEYWORD_JOB_SILO
+
+
+ 0
+ 0x4000
+
+
+ Microsoft-Windows-Kernel-Process/Analytic
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {22FB2CD6-0E7B-422B-A0C7-2FAD1FD0E716}
+
+
+ Microsoft-Windows-Kernel-File
+ 0
+ 0
+
+ Events up to this level are enabled
+ 1
+ 0
+
+ win:Informational
+ Information
+ 0
+ 0x4
+
+
+
+
+
+
+ -1
+ 0x0
+
+
+
+ Events with any of these keywords are enabled
+ 2
+ 0x1000
+
+ KERNEL_FILE_KEYWORD_FILENAME
+
+
+ 0
+ 0x10
+
+
+ KERNEL_FILE_KEYWORD_FILEIO
+
+
+ 0
+ 0x20
+
+
+ KERNEL_FILE_KEYWORD_OP_END
+
+
+ 0
+ 0x40
+
+
+ KERNEL_FILE_KEYWORD_CREATE
+
+
+ 0
+ 0x80
+
+
+ KERNEL_FILE_KEYWORD_READ
+
+
+ 0
+ 0x100
+
+
+ KERNEL_FILE_KEYWORD_WRITE
+
+
+ 0
+ 0x200
+
+
+ KERNEL_FILE_KEYWORD_DELETE_PATH
+
+
+ 0
+ 0x400
+
+
+ KERNEL_FILE_KEYWORD_RENAME_SETLINK_PATH
+
+
+ 0
+ 0x800
+
+
+ KERNEL_FILE_KEYWORD_CREATE_NEW_FILE
+
+
+ -1
+ 0x1000
+
+
+ Microsoft-Windows-Kernel-File/Analytic
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ Events with all of these keywords are enabled
+ 2
+ 0x0
+
+ KERNEL_FILE_KEYWORD_FILENAME
+
+
+ 0
+ 0x10
+
+
+ KERNEL_FILE_KEYWORD_FILEIO
+
+
+ 0
+ 0x20
+
+
+ KERNEL_FILE_KEYWORD_OP_END
+
+
+ 0
+ 0x40
+
+
+ KERNEL_FILE_KEYWORD_CREATE
+
+
+ 0
+ 0x80
+
+
+ KERNEL_FILE_KEYWORD_READ
+
+
+ 0
+ 0x100
+
+
+ KERNEL_FILE_KEYWORD_WRITE
+
+
+ 0
+ 0x200
+
+
+ KERNEL_FILE_KEYWORD_DELETE_PATH
+
+
+ 0
+ 0x400
+
+
+ KERNEL_FILE_KEYWORD_RENAME_SETLINK_PATH
+
+
+ 0
+ 0x800
+
+
+ KERNEL_FILE_KEYWORD_CREATE_NEW_FILE
+
+
+ 0
+ 0x1000
+
+
+ Microsoft-Windows-Kernel-File/Analytic
+
+
+ 0
+ 0x8000000000000000
+
+
+
+ These additional data fields will be collected with each event
+ 2
+ 0
+
+ sid
+ Security Identifier
+ 0
+ 0x1
+
+
+ sessionid
+ Session Identifier
+ 0
+ 0x2
+
+
+ {EDD08927-9CC4-4E65-B970-C2560FB5C289}
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.h b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.h
new file mode 100644
index 0000000..4bb315a
--- /dev/null
+++ b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.h
@@ -0,0 +1,1642 @@
+//**********************************************************************`
+//* This is an include file generated by Message Compiler. *`
+//* *`
+//* Copyright (c) Microsoft Corporation. All Rights Reserved. *`
+//**********************************************************************`
+#pragma once
+
+//*****************************************************************************
+//
+// Notes on the ETW event code generated by MC:
+//
+// - Structures and arrays of structures are treated as an opaque binary blob.
+// The caller is responsible for packing the data for the structure into a
+// single region of memory, with no padding between values. The macro will
+// have an extra parameter for the length of the blob.
+// - Arrays of nul-terminated strings must be packed by the caller into a
+// single binary blob containing the correct number of strings, with a nul
+// after each string. The size of the blob is specified in characters, and
+// includes the final nul.
+// - Arrays of SID are treated as a single binary blob. The caller is
+// responsible for packing the SID values into a single region of memory with
+// no padding.
+// - The length attribute on the data element in the manifest is significant
+// for values with intype win:UnicodeString, win:AnsiString, or win:Binary.
+// The length attribute must be specified for win:Binary, and is optional for
+// win:UnicodeString and win:AnsiString (if no length is given, the strings
+// are assumed to be nul-terminated). For win:UnicodeString, the length is
+// measured in characters, not bytes.
+// - For an array of win:UnicodeString, win:AnsiString, or win:Binary, the
+// length attribute applies to every value in the array, so every value in
+// the array must have the same length. The values in the array are provided
+// to the macro via a single pointer -- the caller is responsible for packing
+// all of the values into a single region of memory with no padding between
+// values.
+// - Values of type win:CountedUnicodeString, win:CountedAnsiString, and
+// win:CountedBinary can be generated and collected on Vista or later.
+// However, they may not decode properly without the Windows 10 2018 Fall
+// Update.
+// - Arrays of type win:CountedUnicodeString, win:CountedAnsiString, and
+// win:CountedBinary must be packed by the caller into a single region of
+// memory. The format for each item is a UINT16 byte-count followed by that
+// many bytes of data. When providing the array to the generated macro, you
+// must provide the total size of the packed array data, including the UINT16
+// sizes for each item. In the case of win:CountedUnicodeString, the data
+// size is specified in WCHAR (16-bit) units. In the case of
+// win:CountedAnsiString and win:CountedBinary, the data size is specified in
+// bytes.
+//
+//*****************************************************************************
+
+#include
+#include
+#include
+
+#ifndef ETW_INLINE
+ #ifdef _ETW_KM_
+ // In kernel mode, save stack space by never inlining templates.
+ #define ETW_INLINE DECLSPEC_NOINLINE __inline
+ #else
+ // In user mode, save code size by inlining templates as appropriate.
+ #define ETW_INLINE __inline
+ #endif
+#endif // ETW_INLINE
+
+#if defined(__cplusplus)
+extern "C" {
+#endif
+
+//
+// MCGEN_DISABLE_PROVIDER_CODE_GENERATION macro:
+// Define this macro to have the compiler skip the generated functions in this
+// header.
+//
+#ifndef MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+//
+// MCGEN_USE_KERNEL_MODE_APIS macro:
+// Controls whether the generated code uses kernel-mode or user-mode APIs.
+// - Set to 0 to use Windows user-mode APIs such as EventRegister.
+// - Set to 1 to use Windows kernel-mode APIs such as EtwRegister.
+// Default is based on whether the _ETW_KM_ macro is defined (i.e. by wdm.h).
+// Note that the APIs can also be overridden directly, e.g. by setting the
+// MCGEN_EVENTWRITETRANSFER or MCGEN_EVENTREGISTER macros.
+//
+#ifndef MCGEN_USE_KERNEL_MODE_APIS
+ #ifdef _ETW_KM_
+ #define MCGEN_USE_KERNEL_MODE_APIS 1
+ #else
+ #define MCGEN_USE_KERNEL_MODE_APIS 0
+ #endif
+#endif // MCGEN_USE_KERNEL_MODE_APIS
+
+//
+// MCGEN_HAVE_EVENTSETINFORMATION macro:
+// Controls how McGenEventSetInformation uses the EventSetInformation API.
+// - Set to 0 to disable the use of EventSetInformation
+// (McGenEventSetInformation will always return an error).
+// - Set to 1 to directly invoke MCGEN_EVENTSETINFORMATION.
+// - Set to 2 to to locate EventSetInformation at runtime via GetProcAddress
+// (user-mode) or MmGetSystemRoutineAddress (kernel-mode).
+// Default is determined as follows:
+// - If MCGEN_EVENTSETINFORMATION has been customized, set to 1
+// (i.e. use MCGEN_EVENTSETINFORMATION).
+// - Else if the target OS version has EventSetInformation, set to 1
+// (i.e. use MCGEN_EVENTSETINFORMATION).
+// - Else set to 2 (i.e. try to dynamically locate EventSetInformation).
+// Note that an McGenEventSetInformation function will only be generated if one
+// or more provider in a manifest has provider traits.
+//
+#ifndef MCGEN_HAVE_EVENTSETINFORMATION
+ #ifdef MCGEN_EVENTSETINFORMATION // if MCGEN_EVENTSETINFORMATION has been customized,
+ #define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
+ #elif MCGEN_USE_KERNEL_MODE_APIS // else if using kernel-mode APIs,
+ #if NTDDI_VERSION >= 0x06040000 // if target OS is Windows 10 or later,
+ #define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
+ #else // else
+ #define MCGEN_HAVE_EVENTSETINFORMATION 2 // find "EtwSetInformation" via MmGetSystemRoutineAddress.
+ #endif // else (using user-mode APIs)
+ #else // if target OS and SDK is Windows 8 or later,
+ #if WINVER >= 0x0602 && defined(EVENT_FILTER_TYPE_SCHEMATIZED)
+ #define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
+ #else // else
+ #define MCGEN_HAVE_EVENTSETINFORMATION 2 // find "EventSetInformation" via GetModuleHandleExW/GetProcAddress.
+ #endif
+ #endif
+#endif // MCGEN_HAVE_EVENTSETINFORMATION
+
+//
+// MCGEN Override Macros
+//
+// The following override macros may be defined before including this header
+// to control the APIs used by this header:
+//
+// - MCGEN_EVENTREGISTER
+// - MCGEN_EVENTUNREGISTER
+// - MCGEN_EVENTSETINFORMATION
+// - MCGEN_EVENTWRITETRANSFER
+//
+// If the the macro is undefined, the MC implementation will default to the
+// corresponding ETW APIs. For example, if the MCGEN_EVENTREGISTER macro is
+// undefined, the EventRegister[MyProviderName] macro will use EventRegister
+// in user mode and will use EtwRegister in kernel mode.
+//
+// To prevent issues from conflicting definitions of these macros, the value
+// of the override macro will be used as a suffix in certain internal function
+// names. Because of this, the override macros must follow certain rules:
+//
+// - The macro must be defined before any MC-generated header is included and
+// must not be undefined or redefined after any MC-generated header is
+// included. Different translation units (i.e. different .c or .cpp files)
+// may set the macros to different values, but within a translation unit
+// (within a single .c or .cpp file), the macro must be set once and not
+// changed.
+// - The override must be an object-like macro, not a function-like macro
+// (i.e. the override macro must not have a parameter list).
+// - The override macro's value must be a simple identifier, i.e. must be
+// something that starts with a letter or '_' and contains only letters,
+// numbers, and '_' characters.
+// - If the override macro's value is the name of a second object-like macro,
+// the second object-like macro must follow the same rules. (The override
+// macro's value can also be the name of a function-like macro, in which
+// case the function-like macro does not need to follow the same rules.)
+//
+// For example, the following will cause compile errors:
+//
+// #define MCGEN_EVENTWRITETRANSFER MyNamespace::MyClass::MyFunction // Value has non-identifier characters (colon).
+// #define MCGEN_EVENTWRITETRANSFER GetEventWriteFunctionPointer(7) // Value has non-identifier characters (parentheses).
+// #define MCGEN_EVENTWRITETRANSFER(h,e,a,r,c,d) EventWrite(h,e,c,d) // Override is defined as a function-like macro.
+// #define MY_OBJECT_LIKE_MACRO MyNamespace::MyClass::MyEventWriteFunction
+// #define MCGEN_EVENTWRITETRANSFER MY_OBJECT_LIKE_MACRO // Evaluates to something with non-identifier characters (colon).
+//
+// The following would be ok:
+//
+// #define MCGEN_EVENTWRITETRANSFER MyEventWriteFunction1 // OK, suffix will be "MyEventWriteFunction1".
+// #define MY_OBJECT_LIKE_MACRO MyEventWriteFunction2
+// #define MCGEN_EVENTWRITETRANSFER MY_OBJECT_LIKE_MACRO // OK, suffix will be "MyEventWriteFunction2".
+// #define MY_FUNCTION_LIKE_MACRO(h,e,a,r,c,d) MyNamespace::MyClass::MyEventWriteFunction3(h,e,c,d)
+// #define MCGEN_EVENTWRITETRANSFER MY_FUNCTION_LIKE_MACRO // OK, suffix will be "MY_FUNCTION_LIKE_MACRO".
+//
+#ifndef MCGEN_EVENTREGISTER
+ #if MCGEN_USE_KERNEL_MODE_APIS
+ #define MCGEN_EVENTREGISTER EtwRegister
+ #else
+ #define MCGEN_EVENTREGISTER EventRegister
+ #endif
+#endif // MCGEN_EVENTREGISTER
+#ifndef MCGEN_EVENTUNREGISTER
+ #if MCGEN_USE_KERNEL_MODE_APIS
+ #define MCGEN_EVENTUNREGISTER EtwUnregister
+ #else
+ #define MCGEN_EVENTUNREGISTER EventUnregister
+ #endif
+#endif // MCGEN_EVENTUNREGISTER
+#ifndef MCGEN_EVENTSETINFORMATION
+ #if MCGEN_USE_KERNEL_MODE_APIS
+ #define MCGEN_EVENTSETINFORMATION EtwSetInformation
+ #else
+ #define MCGEN_EVENTSETINFORMATION EventSetInformation
+ #endif
+#endif // MCGEN_EVENTSETINFORMATION
+#ifndef MCGEN_EVENTWRITETRANSFER
+ #if MCGEN_USE_KERNEL_MODE_APIS
+ #define MCGEN_EVENTWRITETRANSFER EtwWriteTransfer
+ #else
+ #define MCGEN_EVENTWRITETRANSFER EventWriteTransfer
+ #endif
+#endif // MCGEN_EVENTWRITETRANSFER
+
+//
+// MCGEN_EVENT_ENABLED macro:
+// Override to control how the EventWrite[EventName] macros determine whether
+// an event is enabled. The default behavior is for EventWrite[EventName] to
+// use the EventEnabled[EventName] macros.
+//
+#ifndef MCGEN_EVENT_ENABLED
+#define MCGEN_EVENT_ENABLED(EventName) EventEnabled##EventName()
+#endif
+
+//
+// MCGEN_EVENT_ENABLED_FORCONTEXT macro:
+// Override to control how the EventWrite[EventName]_ForContext macros
+// determine whether an event is enabled. The default behavior is for
+// EventWrite[EventName]_ForContext to use the
+// EventEnabled[EventName]_ForContext macros.
+//
+#ifndef MCGEN_EVENT_ENABLED_FORCONTEXT
+#define MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, EventName) EventEnabled##EventName##_ForContext(pContext)
+#endif
+
+//
+// MCGEN_ENABLE_CHECK macro:
+// Determines whether the specified event would be considered as enabled
+// based on the state of the specified context. Slightly faster than calling
+// McGenEventEnabled directly.
+//
+#ifndef MCGEN_ENABLE_CHECK
+#define MCGEN_ENABLE_CHECK(Context, Descriptor) (Context.IsEnabled && McGenEventEnabled(&Context, &Descriptor))
+#endif
+
+#if !defined(MCGEN_TRACE_CONTEXT_DEF)
+#define MCGEN_TRACE_CONTEXT_DEF
+// This structure is for use by MC-generated code and should not be used directly.
+typedef struct _MCGEN_TRACE_CONTEXT
+{
+ TRACEHANDLE RegistrationHandle;
+ TRACEHANDLE Logger; // Used as pointer to provider traits.
+ ULONGLONG MatchAnyKeyword;
+ ULONGLONG MatchAllKeyword;
+ ULONG Flags;
+ ULONG IsEnabled;
+ UCHAR Level;
+ UCHAR Reserve;
+ USHORT EnableBitsCount;
+ PULONG EnableBitMask;
+ const ULONGLONG* EnableKeyWords;
+ const UCHAR* EnableLevel;
+} MCGEN_TRACE_CONTEXT, *PMCGEN_TRACE_CONTEXT;
+#endif // MCGEN_TRACE_CONTEXT_DEF
+
+#if !defined(MCGEN_LEVEL_KEYWORD_ENABLED_DEF)
+#define MCGEN_LEVEL_KEYWORD_ENABLED_DEF
+//
+// Determines whether an event with a given Level and Keyword would be
+// considered as enabled based on the state of the specified context.
+// Note that you may want to use MCGEN_ENABLE_CHECK instead of calling this
+// function directly.
+//
+FORCEINLINE
+BOOLEAN
+McGenLevelKeywordEnabled(
+ _In_ PMCGEN_TRACE_CONTEXT EnableInfo,
+ _In_ UCHAR Level,
+ _In_ ULONGLONG Keyword
+ )
+{
+ //
+ // Check if the event Level is lower than the level at which
+ // the channel is enabled.
+ // If the event Level is 0 or the channel is enabled at level 0,
+ // all levels are enabled.
+ //
+
+ if ((Level <= EnableInfo->Level) || // This also covers the case of Level == 0.
+ (EnableInfo->Level == 0)) {
+
+ //
+ // Check if Keyword is enabled
+ //
+
+ if ((Keyword == (ULONGLONG)0) ||
+ ((Keyword & EnableInfo->MatchAnyKeyword) &&
+ ((Keyword & EnableInfo->MatchAllKeyword) == EnableInfo->MatchAllKeyword))) {
+ return TRUE;
+ }
+ }
+
+ return FALSE;
+}
+#endif // MCGEN_LEVEL_KEYWORD_ENABLED_DEF
+
+#if !defined(MCGEN_EVENT_ENABLED_DEF)
+#define MCGEN_EVENT_ENABLED_DEF
+//
+// Determines whether the specified event would be considered as enabled based
+// on the state of the specified context. Note that you may want to use
+// MCGEN_ENABLE_CHECK instead of calling this function directly.
+//
+FORCEINLINE
+BOOLEAN
+McGenEventEnabled(
+ _In_ PMCGEN_TRACE_CONTEXT EnableInfo,
+ _In_ PCEVENT_DESCRIPTOR EventDescriptor
+ )
+{
+ return McGenLevelKeywordEnabled(EnableInfo, EventDescriptor->Level, EventDescriptor->Keyword);
+}
+#endif // MCGEN_EVENT_ENABLED_DEF
+
+#if !defined(MCGEN_CONTROL_CALLBACK)
+#define MCGEN_CONTROL_CALLBACK
+
+// This function is for use by MC-generated code and should not be used directly.
+DECLSPEC_NOINLINE __inline
+VOID
+__stdcall
+McGenControlCallbackV2(
+ _In_ LPCGUID SourceId,
+ _In_ ULONG ControlCode,
+ _In_ UCHAR Level,
+ _In_ ULONGLONG MatchAnyKeyword,
+ _In_ ULONGLONG MatchAllKeyword,
+ _In_opt_ PEVENT_FILTER_DESCRIPTOR FilterData,
+ _Inout_opt_ PVOID CallbackContext
+ )
+/*++
+
+Routine Description:
+
+ This is the notification callback for Windows Vista and later.
+
+Arguments:
+
+ SourceId - The GUID that identifies the session that enabled the provider.
+
+ ControlCode - The parameter indicates whether the provider
+ is being enabled or disabled.
+
+ Level - The level at which the event is enabled.
+
+ MatchAnyKeyword - The bitmask of keywords that the provider uses to
+ determine the category of events that it writes.
+
+ MatchAllKeyword - This bitmask additionally restricts the category
+ of events that the provider writes.
+
+ FilterData - The provider-defined data.
+
+ CallbackContext - The context of the callback that is defined when the provider
+ called EtwRegister to register itself.
+
+Remarks:
+
+ ETW calls this function to notify provider of enable/disable
+
+--*/
+{
+ PMCGEN_TRACE_CONTEXT Ctx = (PMCGEN_TRACE_CONTEXT)CallbackContext;
+ ULONG Ix;
+#ifndef MCGEN_PRIVATE_ENABLE_CALLBACK_V2
+ UNREFERENCED_PARAMETER(SourceId);
+ UNREFERENCED_PARAMETER(FilterData);
+#endif
+
+ if (Ctx == NULL) {
+ return;
+ }
+
+ switch (ControlCode) {
+
+ case EVENT_CONTROL_CODE_ENABLE_PROVIDER:
+ Ctx->Level = Level;
+ Ctx->MatchAnyKeyword = MatchAnyKeyword;
+ Ctx->MatchAllKeyword = MatchAllKeyword;
+ Ctx->IsEnabled = EVENT_CONTROL_CODE_ENABLE_PROVIDER;
+
+ for (Ix = 0; Ix < Ctx->EnableBitsCount; Ix += 1) {
+ if (McGenLevelKeywordEnabled(Ctx, Ctx->EnableLevel[Ix], Ctx->EnableKeyWords[Ix]) != FALSE) {
+ Ctx->EnableBitMask[Ix >> 5] |= (1 << (Ix % 32));
+ } else {
+ Ctx->EnableBitMask[Ix >> 5] &= ~(1 << (Ix % 32));
+ }
+ }
+ break;
+
+ case EVENT_CONTROL_CODE_DISABLE_PROVIDER:
+ Ctx->IsEnabled = EVENT_CONTROL_CODE_DISABLE_PROVIDER;
+ Ctx->Level = 0;
+ Ctx->MatchAnyKeyword = 0;
+ Ctx->MatchAllKeyword = 0;
+ if (Ctx->EnableBitsCount > 0) {
+#pragma warning(suppress: 26451) // Arithmetic overflow cannot occur, no matter the value of EnableBitCount
+ RtlZeroMemory(Ctx->EnableBitMask, (((Ctx->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
+ }
+ break;
+
+ default:
+ break;
+ }
+
+#ifdef MCGEN_PRIVATE_ENABLE_CALLBACK_V2
+ //
+ // Call user defined callback
+ //
+ MCGEN_PRIVATE_ENABLE_CALLBACK_V2(
+ SourceId,
+ ControlCode,
+ Level,
+ MatchAnyKeyword,
+ MatchAllKeyword,
+ FilterData,
+ CallbackContext
+ );
+#endif // MCGEN_PRIVATE_ENABLE_CALLBACK_V2
+
+ return;
+}
+
+#endif // MCGEN_CONTROL_CALLBACK
+
+#ifndef _mcgen_PENABLECALLBACK
+ #if MCGEN_USE_KERNEL_MODE_APIS
+ #define _mcgen_PENABLECALLBACK PETWENABLECALLBACK
+ #else
+ #define _mcgen_PENABLECALLBACK PENABLECALLBACK
+ #endif
+#endif // _mcgen_PENABLECALLBACK
+
+#if !defined(_mcgen_PASTE2)
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_PASTE2(a, b) _mcgen_PASTE2_imp(a, b)
+#define _mcgen_PASTE2_imp(a, b) a##b
+#endif // _mcgen_PASTE2
+
+#if !defined(_mcgen_PASTE3)
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_PASTE3(a, b, c) _mcgen_PASTE3_imp(a, b, c)
+#define _mcgen_PASTE3_imp(a, b, c) a##b##_##c
+#endif // _mcgen_PASTE3
+
+//
+// Macro validation
+//
+
+// Validate MCGEN_EVENTREGISTER:
+
+// Trigger an error if MCGEN_EVENTREGISTER is not an unqualified (simple) identifier:
+struct _mcgen_PASTE2(MCGEN_EVENTREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTREGISTER);
+
+// Trigger an error if MCGEN_EVENTREGISTER is redefined:
+typedef struct _mcgen_PASTE2(MCGEN_EVENTREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTREGISTER)
+ MCGEN_EVENTREGISTER_must_not_be_redefined_between_headers;
+
+// Trigger an error if MCGEN_EVENTREGISTER is defined as a function-like macro:
+typedef void MCGEN_EVENTREGISTER_must_not_be_a_functionLike_macro_MCGEN_EVENTREGISTER;
+typedef int _mcgen_PASTE2(MCGEN_EVENTREGISTER_must_not_be_a_functionLike_macro_, MCGEN_EVENTREGISTER);
+
+// Validate MCGEN_EVENTUNREGISTER:
+
+// Trigger an error if MCGEN_EVENTUNREGISTER is not an unqualified (simple) identifier:
+struct _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTUNREGISTER);
+
+// Trigger an error if MCGEN_EVENTUNREGISTER is redefined:
+typedef struct _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTUNREGISTER)
+ MCGEN_EVENTUNREGISTER_must_not_be_redefined_between_headers;
+
+// Trigger an error if MCGEN_EVENTUNREGISTER is defined as a function-like macro:
+typedef void MCGEN_EVENTUNREGISTER_must_not_be_a_functionLike_macro_MCGEN_EVENTUNREGISTER;
+typedef int _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_must_not_be_a_functionLike_macro_, MCGEN_EVENTUNREGISTER);
+
+// Validate MCGEN_EVENTSETINFORMATION:
+
+// Trigger an error if MCGEN_EVENTSETINFORMATION is not an unqualified (simple) identifier:
+struct _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTSETINFORMATION);
+
+// Trigger an error if MCGEN_EVENTSETINFORMATION is redefined:
+typedef struct _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTSETINFORMATION)
+ MCGEN_EVENTSETINFORMATION_must_not_be_redefined_between_headers;
+
+// Trigger an error if MCGEN_EVENTSETINFORMATION is defined as a function-like macro:
+typedef void MCGEN_EVENTSETINFORMATION_must_not_be_a_functionLike_macro_MCGEN_EVENTSETINFORMATION;
+typedef int _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_must_not_be_a_functionLike_macro_, MCGEN_EVENTSETINFORMATION);
+
+// Validate MCGEN_EVENTWRITETRANSFER:
+
+// Trigger an error if MCGEN_EVENTWRITETRANSFER is not an unqualified (simple) identifier:
+struct _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTWRITETRANSFER);
+
+// Trigger an error if MCGEN_EVENTWRITETRANSFER is redefined:
+typedef struct _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTWRITETRANSFER)
+ MCGEN_EVENTWRITETRANSFER_must_not_be_redefined_between_headers;;
+
+// Trigger an error if MCGEN_EVENTWRITETRANSFER is defined as a function-like macro:
+typedef void MCGEN_EVENTWRITETRANSFER_must_not_be_a_functionLike_macro_MCGEN_EVENTWRITETRANSFER;
+typedef int _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_must_not_be_a_functionLike_macro_, MCGEN_EVENTWRITETRANSFER);
+
+#ifndef McGenEventWrite_def
+#define McGenEventWrite_def
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define McGenEventWrite _mcgen_PASTE2(McGenEventWrite_, MCGEN_EVENTWRITETRANSFER)
+
+// This function is for use by MC-generated code and should not be used directly.
+DECLSPEC_NOINLINE __inline
+ULONG __stdcall
+McGenEventWrite(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_opt_ LPCGUID ActivityId,
+ _In_range_(1, 128) ULONG EventDataCount,
+ _Pre_cap_(EventDataCount) EVENT_DATA_DESCRIPTOR* EventData
+ )
+{
+ const USHORT UNALIGNED* Traits;
+
+ // Some customized MCGEN_EVENTWRITETRANSFER macros might ignore ActivityId.
+ UNREFERENCED_PARAMETER(ActivityId);
+
+ Traits = (const USHORT UNALIGNED*)(UINT_PTR)Context->Logger;
+
+ if (Traits == NULL) {
+ EventData[0].Ptr = 0;
+ EventData[0].Size = 0;
+ EventData[0].Reserved = 0;
+ } else {
+ EventData[0].Ptr = (ULONG_PTR)Traits;
+ EventData[0].Size = *Traits;
+ EventData[0].Reserved = 2; // EVENT_DATA_DESCRIPTOR_TYPE_PROVIDER_METADATA
+ }
+
+ return MCGEN_EVENTWRITETRANSFER(
+ Context->RegistrationHandle,
+ Descriptor,
+ ActivityId,
+ NULL,
+ EventDataCount,
+ EventData);
+}
+#endif // McGenEventWrite_def
+
+#if !defined(McGenEventRegisterUnregister)
+#define McGenEventRegisterUnregister
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define McGenEventRegister _mcgen_PASTE2(McGenEventRegister_, MCGEN_EVENTREGISTER)
+
+#pragma warning(push)
+#pragma warning(disable:6103)
+// This function is for use by MC-generated code and should not be used directly.
+DECLSPEC_NOINLINE __inline
+ULONG __stdcall
+McGenEventRegister(
+ _In_ LPCGUID ProviderId,
+ _In_opt_ _mcgen_PENABLECALLBACK EnableCallback,
+ _In_opt_ PVOID CallbackContext,
+ _Inout_ PREGHANDLE RegHandle
+ )
+/*++
+
+Routine Description:
+
+ This function registers the provider with ETW.
+
+Arguments:
+
+ ProviderId - Provider ID to register with ETW.
+
+ EnableCallback - Callback to be used.
+
+ CallbackContext - Context for the callback.
+
+ RegHandle - Pointer to registration handle.
+
+Remarks:
+
+ Should not be called if the provider is already registered (i.e. should not
+ be called if *RegHandle != 0). Repeatedly registering a provider is a bug
+ and may indicate a race condition. However, for compatibility with previous
+ behavior, this function will return SUCCESS in this case.
+
+--*/
+{
+ ULONG Error;
+
+ if (*RegHandle != 0)
+ {
+ Error = 0; // ERROR_SUCCESS
+ }
+ else
+ {
+ Error = MCGEN_EVENTREGISTER(ProviderId, EnableCallback, CallbackContext, RegHandle);
+ }
+
+ return Error;
+}
+#pragma warning(pop)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define McGenEventUnregister _mcgen_PASTE2(McGenEventUnregister_, MCGEN_EVENTUNREGISTER)
+
+// This function is for use by MC-generated code and should not be used directly.
+DECLSPEC_NOINLINE __inline
+ULONG __stdcall
+McGenEventUnregister(_Inout_ PREGHANDLE RegHandle)
+/*++
+
+Routine Description:
+
+ Unregister from ETW and set *RegHandle = 0.
+
+Arguments:
+
+ RegHandle - the pointer to the provider registration handle
+
+Remarks:
+
+ If provider has not been registered (i.e. if *RegHandle == 0),
+ return SUCCESS. It is safe to call McGenEventUnregister even if the
+ call to McGenEventRegister returned an error.
+
+--*/
+{
+ ULONG Error;
+
+ if(*RegHandle == 0)
+ {
+ Error = 0; // ERROR_SUCCESS
+ }
+ else
+ {
+ Error = MCGEN_EVENTUNREGISTER(*RegHandle);
+ *RegHandle = (REGHANDLE)0;
+ }
+
+ return Error;
+}
+
+#endif // McGenEventRegisterUnregister
+
+#ifndef _mcgen_EVENT_BIT_SET
+ #if defined(_M_IX86) || defined(_M_X64)
+ // This macro is for use by MC-generated code and should not be used directly.
+ #define _mcgen_EVENT_BIT_SET(EnableBits, BitPosition) ((((const unsigned char*)EnableBits)[BitPosition >> 3] & (1u << (BitPosition & 7))) != 0)
+ #else // CPU type
+ // This macro is for use by MC-generated code and should not be used directly.
+ #define _mcgen_EVENT_BIT_SET(EnableBits, BitPosition) ((EnableBits[BitPosition >> 5] & (1u << (BitPosition & 31))) != 0)
+ #endif // CPU type
+#endif // _mcgen_EVENT_BIT_SET
+
+#endif // MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+//+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+// Provider "JonMon-Lite" event count 11
+//+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+
+// Provider GUID = d8909c24-5be9-4502-98ca-ab7bdc24899d
+EXTERN_C __declspec(selectany) const GUID JonMonLiteProvider = {0xd8909c24, 0x5be9, 0x4502, {0x98, 0xca, 0xab, 0x7b, 0xdc, 0x24, 0x89, 0x9d}};
+
+#ifndef JonMonLiteProvider_Traits
+#define JonMonLiteProvider_Traits NULL
+#endif // JonMonLiteProvider_Traits
+
+//
+// Channel
+//
+#define JonMonLiteProvider_CHANNEL_JonMon_Lite 0x10
+#define JonMonLiteProvider_CHANNEL_JonMon_Lite_KEYWORD 0x8000000000000000
+
+//
+// Event Descriptors
+//
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR ProcessCreation = {0x1, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define ProcessCreation_value 0x1
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR RegistryCreateKey = {0x2, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define RegistryCreateKey_value 0x2
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR ServiceCreation = {0x3, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define ServiceCreation_value 0x3
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR FileCreation = {0x4, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define FileCreation_value 0x4
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR DotNetLoad = {0x5, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define DotNetLoad_value 0x5
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR WMIEventFilter = {0x6, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define WMIEventFilter_value 0x6
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR RPCClient = {0x7, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define RPCClient_value 0x7
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR RPCServer = {0x8, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define RPCServer_value 0x8
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR DPAPIUnprotect = {0x9, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define DPAPIUnprotect_value 0x9
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR NetworkConnection = {0xa, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define NetworkConnection_value 0xa
+EXTERN_C __declspec(selectany) const EVENT_DESCRIPTOR AMSI = {0xb, 0x0, 0x10, 0x4, 0x0, 0x0, 0x8000000000000000};
+#define AMSI_value 0xb
+
+//
+// MCGEN_DISABLE_PROVIDER_CODE_GENERATION macro:
+// Define this macro to have the compiler skip the generated functions in this
+// header.
+//
+#ifndef MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+//
+// Event Enablement Bits
+// These variables are for use by MC-generated code and should not be used directly.
+//
+EXTERN_C __declspec(selectany) DECLSPEC_CACHEALIGN ULONG JonMon_LiteEnableBits[1];
+EXTERN_C __declspec(selectany) const ULONGLONG JonMon_LiteKeywords[1] = {0x8000000000000000};
+EXTERN_C __declspec(selectany) const unsigned char JonMon_LiteLevels[1] = {4};
+
+//
+// Provider context
+//
+EXTERN_C __declspec(selectany) MCGEN_TRACE_CONTEXT JonMonLiteProvider_Context = {0, (ULONG_PTR)JonMonLiteProvider_Traits, 0, 0, 0, 0, 0, 0, 1, JonMon_LiteEnableBits, JonMon_LiteKeywords, JonMon_LiteLevels};
+
+//
+// Provider REGHANDLE
+//
+#define JonMon_LiteHandle (JonMonLiteProvider_Context.RegistrationHandle)
+
+//
+// This macro is set to 0, indicating that the EventWrite[Name] macros do not
+// have an Activity parameter. This is controlled by the -km and -um options.
+//
+#define JonMonLiteProvider_EventWriteActivity 0
+
+//
+// Register with ETW using the control GUID specified in the manifest.
+// Invoke this macro during module initialization (i.e. program startup,
+// DLL process attach, or driver load) to initialize the provider.
+// Note that if this function returns an error, the error means that
+// will not work, but no action needs to be taken -- even if EventRegister
+// returns an error, it is generally safe to use EventWrite and
+// EventUnregister macros (they will be no-ops if EventRegister failed).
+//
+#ifndef EventRegisterJonMon_Lite
+#define EventRegisterJonMon_Lite() McGenEventRegister(&JonMonLiteProvider, McGenControlCallbackV2, &JonMonLiteProvider_Context, &JonMon_LiteHandle)
+#endif
+
+//
+// Register with ETW using a specific control GUID (i.e. a GUID other than what
+// is specified in the manifest). Advanced scenarios only.
+//
+#ifndef EventRegisterByGuidJonMon_Lite
+#define EventRegisterByGuidJonMon_Lite(Guid) McGenEventRegister(&(Guid), McGenControlCallbackV2, &JonMonLiteProvider_Context, &JonMon_LiteHandle)
+#endif
+
+//
+// Unregister with ETW and close the provider.
+// Invoke this macro during module shutdown (i.e. program exit, DLL process
+// detach, or driver unload) to unregister the provider.
+// Note that you MUST call EventUnregister before DLL or driver unload
+// (not optional): failure to unregister a provider before DLL or driver unload
+// will result in crashes.
+//
+#ifndef EventUnregisterJonMon_Lite
+#define EventUnregisterJonMon_Lite() McGenEventUnregister(&JonMon_LiteHandle)
+#endif
+
+//
+// MCGEN_ENABLE_FORCONTEXT_CODE_GENERATION macro:
+// Define this macro to enable support for caller-allocated provider context.
+//
+#ifdef MCGEN_ENABLE_FORCONTEXT_CODE_GENERATION
+
+//
+// Advanced scenarios: Caller-allocated provider context.
+// Use when multiple differently-configured provider handles are needed,
+// e.g. for container-aware drivers, one context per container.
+//
+// Usage:
+//
+// - Caller enables the feature before including this header, e.g.
+// #define MCGEN_ENABLE_FORCONTEXT_CODE_GENERATION 1
+// - Caller allocates memory, e.g. pContext = malloc(sizeof(McGenContext_JonMon_Lite));
+// - Caller registers the provider, e.g. EventRegisterJonMon_Lite_ForContext(pContext);
+// - Caller writes events, e.g. EventWriteMyEvent_ForContext(pContext, ...);
+// - Caller unregisters, e.g. EventUnregisterJonMon_Lite_ForContext(pContext);
+// - Caller frees memory, e.g. free(pContext);
+//
+
+typedef struct tagMcGenContext_JonMon_Lite {
+ // The fields of this structure are subject to change and should
+ // not be accessed directly. To access the provider's REGHANDLE,
+ // use JonMon_LiteHandle_ForContext(pContext).
+ MCGEN_TRACE_CONTEXT Context;
+ ULONG EnableBits[1];
+} McGenContext_JonMon_Lite;
+
+#define EventRegisterJonMon_Lite_ForContext(pContext) _mcgen_PASTE2(_mcgen_RegisterForContext_JonMon_Lite_, MCGEN_EVENTREGISTER)(&JonMonLiteProvider, pContext)
+#define EventRegisterByGuidJonMon_Lite_ForContext(Guid, pContext) _mcgen_PASTE2(_mcgen_RegisterForContext_JonMon_Lite_, MCGEN_EVENTREGISTER)(&(Guid), pContext)
+#define EventUnregisterJonMon_Lite_ForContext(pContext) McGenEventUnregister(&(pContext)->Context.RegistrationHandle)
+
+//
+// Provider REGHANDLE for caller-allocated context.
+//
+#define JonMon_LiteHandle_ForContext(pContext) ((pContext)->Context.RegistrationHandle)
+
+// This function is for use by MC-generated code and should not be used directly.
+// Initialize and register the caller-allocated context.
+__inline
+ULONG __stdcall
+_mcgen_PASTE2(_mcgen_RegisterForContext_JonMon_Lite_, MCGEN_EVENTREGISTER)(
+ _In_ LPCGUID pProviderId,
+ _Out_ McGenContext_JonMon_Lite* pContext)
+{
+ RtlZeroMemory(pContext, sizeof(*pContext));
+ pContext->Context.Logger = (ULONG_PTR)JonMonLiteProvider_Traits;
+ pContext->Context.EnableBitsCount = 1;
+ pContext->Context.EnableBitMask = pContext->EnableBits;
+ pContext->Context.EnableKeyWords = JonMon_LiteKeywords;
+ pContext->Context.EnableLevel = JonMon_LiteLevels;
+ return McGenEventRegister(
+ pProviderId,
+ McGenControlCallbackV2,
+ &pContext->Context,
+ &pContext->Context.RegistrationHandle);
+}
+
+// This function is for use by MC-generated code and should not be used directly.
+// Trigger a compile error if called with the wrong parameter type.
+FORCEINLINE
+_Ret_ McGenContext_JonMon_Lite*
+_mcgen_CheckContextType_JonMon_Lite(_In_ McGenContext_JonMon_Lite* pContext)
+{
+ return pContext;
+}
+
+#endif // MCGEN_ENABLE_FORCONTEXT_CODE_GENERATION
+
+//
+// Enablement check macro for event "ProcessCreation"
+//
+#define EventEnabledProcessCreation() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledProcessCreation_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "ProcessCreation"
+//
+#define EventWriteProcessCreation(EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) \
+ MCGEN_EVENT_ENABLED(ProcessCreation) \
+ ? _mcgen_TEMPLATE_FOR_ProcessCreation(&JonMonLiteProvider_Context, &ProcessCreation, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) : 0
+#define EventWriteProcessCreation_AssumeEnabled(EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) \
+ _mcgen_TEMPLATE_FOR_ProcessCreation(&JonMonLiteProvider_Context, &ProcessCreation, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations)
+#define EventWriteProcessCreation_ForContext(pContext, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, ProcessCreation) \
+ ? _mcgen_TEMPLATE_FOR_ProcessCreation(&(pContext)->Context, &ProcessCreation, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) : 0
+#define EventWriteProcessCreation_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations) \
+ _mcgen_TEMPLATE_FOR_ProcessCreation(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &ProcessCreation, EventTime, WorkstationName, NewProcessId, ParentProcessId, SessionId, Flags, IsElevated, MandatoryLabel, ImageName, PackageFullName, SecurityMitigations)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_ProcessCreation _mcgen_PASTE2(McTemplateU0yzqqqqqkzzq_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "RegistryCreateKey"
+//
+#define EventEnabledRegistryCreateKey() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledRegistryCreateKey_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "RegistryCreateKey"
+//
+#define EventWriteRegistryCreateKey(EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) \
+ MCGEN_EVENT_ENABLED(RegistryCreateKey) \
+ ? _mcgen_TEMPLATE_FOR_RegistryCreateKey(&JonMonLiteProvider_Context, &RegistryCreateKey, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) : 0
+#define EventWriteRegistryCreateKey_AssumeEnabled(EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) \
+ _mcgen_TEMPLATE_FOR_RegistryCreateKey(&JonMonLiteProvider_Context, &RegistryCreateKey, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status)
+#define EventWriteRegistryCreateKey_ForContext(pContext, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, RegistryCreateKey) \
+ ? _mcgen_TEMPLATE_FOR_RegistryCreateKey(&(pContext)->Context, &RegistryCreateKey, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) : 0
+#define EventWriteRegistryCreateKey_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status) \
+ _mcgen_TEMPLATE_FOR_RegistryCreateKey(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &RegistryCreateKey, EventTime, WorkstationName, BaseName, RelativeName, Disposition, Status)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_RegistryCreateKey _mcgen_PASTE2(McTemplateU0yzzzqq_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "ServiceCreation"
+//
+#define EventEnabledServiceCreation() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledServiceCreation_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "ServiceCreation"
+//
+#define EventWriteServiceCreation(EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) \
+ MCGEN_EVENT_ENABLED(ServiceCreation) \
+ ? _mcgen_TEMPLATE_FOR_ServiceCreation(&JonMonLiteProvider_Context, &ServiceCreation, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) : 0
+#define EventWriteServiceCreation_AssumeEnabled(EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) \
+ _mcgen_TEMPLATE_FOR_ServiceCreation(&JonMonLiteProvider_Context, &ServiceCreation, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName)
+#define EventWriteServiceCreation_ForContext(pContext, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, ServiceCreation) \
+ ? _mcgen_TEMPLATE_FOR_ServiceCreation(&(pContext)->Context, &ServiceCreation, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) : 0
+#define EventWriteServiceCreation_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName) \
+ _mcgen_TEMPLATE_FOR_ServiceCreation(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &ServiceCreation, EventTime, WorkstationName, ServiceName, ImagePath, ServiceType, StartType, AccountName)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_ServiceCreation _mcgen_PASTE2(McTemplateU0yzzzzzz_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "FileCreation"
+//
+#define EventEnabledFileCreation() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledFileCreation_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "FileCreation"
+//
+#define EventWriteFileCreation(EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) \
+ MCGEN_EVENT_ENABLED(FileCreation) \
+ ? _mcgen_TEMPLATE_FOR_FileCreation(&JonMonLiteProvider_Context, &FileCreation, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) : 0
+#define EventWriteFileCreation_AssumeEnabled(EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) \
+ _mcgen_TEMPLATE_FOR_FileCreation(&JonMonLiteProvider_Context, &FileCreation, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions)
+#define EventWriteFileCreation_ForContext(pContext, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, FileCreation) \
+ ? _mcgen_TEMPLATE_FOR_FileCreation(&(pContext)->Context, &FileCreation, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) : 0
+#define EventWriteFileCreation_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions) \
+ _mcgen_TEMPLATE_FOR_FileCreation(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &FileCreation, EventTime, WorkstationName, FileName, IssuingThreadId, ShareAccess, CreateOptions)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_FileCreation _mcgen_PASTE2(McTemplateU0yzzqqq_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "DotNetLoad"
+//
+#define EventEnabledDotNetLoad() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledDotNetLoad_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "DotNetLoad"
+//
+#define EventWriteDotNetLoad(EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) \
+ MCGEN_EVENT_ENABLED(DotNetLoad) \
+ ? _mcgen_TEMPLATE_FOR_DotNetLoad(&JonMonLiteProvider_Context, &DotNetLoad, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) : 0
+#define EventWriteDotNetLoad_AssumeEnabled(EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) \
+ _mcgen_TEMPLATE_FOR_DotNetLoad(&JonMonLiteProvider_Context, &DotNetLoad, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID)
+#define EventWriteDotNetLoad_ForContext(pContext, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, DotNetLoad) \
+ ? _mcgen_TEMPLATE_FOR_DotNetLoad(&(pContext)->Context, &DotNetLoad, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) : 0
+#define EventWriteDotNetLoad_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID) \
+ _mcgen_TEMPLATE_FOR_DotNetLoad(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &DotNetLoad, EventTime, WorkstationName, ProcessId, AssemblyID, AppDomainID, AssemblyName, ClrInstanceID)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_DotNetLoad _mcgen_PASTE2(McTemplateU0yzxxxzh_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "WMIEventFilter"
+//
+#define EventEnabledWMIEventFilter() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledWMIEventFilter_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "WMIEventFilter"
+//
+#define EventWriteWMIEventFilter(EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) \
+ MCGEN_EVENT_ENABLED(WMIEventFilter) \
+ ? _mcgen_TEMPLATE_FOR_WMIEventFilter(&JonMonLiteProvider_Context, &WMIEventFilter, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) : 0
+#define EventWriteWMIEventFilter_AssumeEnabled(EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) \
+ _mcgen_TEMPLATE_FOR_WMIEventFilter(&JonMonLiteProvider_Context, &WMIEventFilter, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause)
+#define EventWriteWMIEventFilter_ForContext(pContext, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, WMIEventFilter) \
+ ? _mcgen_TEMPLATE_FOR_WMIEventFilter(&(pContext)->Context, &WMIEventFilter, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) : 0
+#define EventWriteWMIEventFilter_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause) \
+ _mcgen_TEMPLATE_FOR_WMIEventFilter(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &WMIEventFilter, EventTime, WorkstationName, ProcessId, Namespace, ESS, Consumer, PossibleCause)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_WMIEventFilter _mcgen_PASTE2(McTemplateU0yzxzzzz_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "RPCClient"
+//
+#define EventEnabledRPCClient() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledRPCClient_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "RPCClient"
+//
+#define EventWriteRPCClient(EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ MCGEN_EVENT_ENABLED(RPCClient) \
+ ? _mcgen_TEMPLATE_FOR_RPCClient(&JonMonLiteProvider_Context, &RPCClient, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) : 0
+#define EventWriteRPCClient_AssumeEnabled(EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ _mcgen_TEMPLATE_FOR_RPCClient(&JonMonLiteProvider_Context, &RPCClient, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString)
+#define EventWriteRPCClient_ForContext(pContext, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, RPCClient) \
+ ? _mcgen_TEMPLATE_FOR_RPCClient(&(pContext)->Context, &RPCClient, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) : 0
+#define EventWriteRPCClient_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ _mcgen_TEMPLATE_FOR_RPCClient(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &RPCClient, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_RPCClient _mcgen_PASTE2(McTemplateU0yzxzqqzzzz_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "RPCServer"
+//
+#define EventEnabledRPCServer() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledRPCServer_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "RPCServer"
+//
+#define EventWriteRPCServer(EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ MCGEN_EVENT_ENABLED(RPCServer) \
+ ? _mcgen_TEMPLATE_FOR_RPCServer(&JonMonLiteProvider_Context, &RPCServer, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) : 0
+#define EventWriteRPCServer_AssumeEnabled(EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ _mcgen_TEMPLATE_FOR_RPCServer(&JonMonLiteProvider_Context, &RPCServer, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString)
+#define EventWriteRPCServer_ForContext(pContext, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, RPCServer) \
+ ? _mcgen_TEMPLATE_FOR_RPCServer(&(pContext)->Context, &RPCServer, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) : 0
+#define EventWriteRPCServer_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString) \
+ _mcgen_TEMPLATE_FOR_RPCServer(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &RPCServer, EventTime, WorkstationName, ProcessId, InterfaceUUID, ProcNum, Protocol, NetworkAddress, Endpoint, InterfaceString, MethodString)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_RPCServer _mcgen_PASTE2(McTemplateU0yzxzqqzzzz_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "DPAPIUnprotect"
+//
+#define EventEnabledDPAPIUnprotect() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledDPAPIUnprotect_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "DPAPIUnprotect"
+//
+#define EventWriteDPAPIUnprotect(EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) \
+ MCGEN_EVENT_ENABLED(DPAPIUnprotect) \
+ ? _mcgen_TEMPLATE_FOR_DPAPIUnprotect(&JonMonLiteProvider_Context, &DPAPIUnprotect, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) : 0
+#define EventWriteDPAPIUnprotect_AssumeEnabled(EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) \
+ _mcgen_TEMPLATE_FOR_DPAPIUnprotect(&JonMonLiteProvider_Context, &DPAPIUnprotect, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags)
+#define EventWriteDPAPIUnprotect_ForContext(pContext, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, DPAPIUnprotect) \
+ ? _mcgen_TEMPLATE_FOR_DPAPIUnprotect(&(pContext)->Context, &DPAPIUnprotect, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) : 0
+#define EventWriteDPAPIUnprotect_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags) \
+ _mcgen_TEMPLATE_FOR_DPAPIUnprotect(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &DPAPIUnprotect, EventTime, WorkstationName, ProcessId, OperationType, DataDescription, Flags, ProtectionFlags)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_DPAPIUnprotect _mcgen_PASTE2(McTemplateU0yzxzzqq_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "NetworkConnection"
+//
+#define EventEnabledNetworkConnection() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledNetworkConnection_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "NetworkConnection"
+//
+#define EventWriteNetworkConnection(EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) \
+ MCGEN_EVENT_ENABLED(NetworkConnection) \
+ ? _mcgen_TEMPLATE_FOR_NetworkConnection(&JonMonLiteProvider_Context, &NetworkConnection, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) : 0
+#define EventWriteNetworkConnection_AssumeEnabled(EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) \
+ _mcgen_TEMPLATE_FOR_NetworkConnection(&JonMonLiteProvider_Context, &NetworkConnection, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated)
+#define EventWriteNetworkConnection_ForContext(pContext, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, NetworkConnection) \
+ ? _mcgen_TEMPLATE_FOR_NetworkConnection(&(pContext)->Context, &NetworkConnection, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) : 0
+#define EventWriteNetworkConnection_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated) \
+ _mcgen_TEMPLATE_FOR_NetworkConnection(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &NetworkConnection, EventTime, WorkstationName, ProcessId, SrcIpAddressIpv4, DestIpAddressIpv4, SrcPort, DestPort, Initiated)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_NetworkConnection _mcgen_PASTE2(McTemplateU0yzqzzhht_, MCGEN_EVENTWRITETRANSFER)
+
+//
+// Enablement check macro for event "AMSI"
+//
+#define EventEnabledAMSI() _mcgen_EVENT_BIT_SET(JonMon_LiteEnableBits, 0)
+#define EventEnabledAMSI_ForContext(pContext) _mcgen_EVENT_BIT_SET(_mcgen_CheckContextType_JonMon_Lite(pContext)->EnableBits, 0)
+
+//
+// Event write macros for event "AMSI"
+//
+#define EventWriteAMSI(EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) \
+ MCGEN_EVENT_ENABLED(AMSI) \
+ ? _mcgen_TEMPLATE_FOR_AMSI(&JonMonLiteProvider_Context, &AMSI, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) : 0
+#define EventWriteAMSI_AssumeEnabled(EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) \
+ _mcgen_TEMPLATE_FOR_AMSI(&JonMonLiteProvider_Context, &AMSI, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent)
+#define EventWriteAMSI_ForContext(pContext, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) \
+ MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, AMSI) \
+ ? _mcgen_TEMPLATE_FOR_AMSI(&(pContext)->Context, &AMSI, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) : 0
+#define EventWriteAMSI_ForContextAssumeEnabled(pContext, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent) \
+ _mcgen_TEMPLATE_FOR_AMSI(&_mcgen_CheckContextType_JonMon_Lite(pContext)->Context, &AMSI, EventTime, WorkstationName, ProcessId, AppName, ContentName, ScanStatus, ScanResult, ContentSize, Content, DecodedContent)
+
+// This macro is for use by MC-generated code and should not be used directly.
+#define _mcgen_TEMPLATE_FOR_AMSI _mcgen_PASTE2(McTemplateU0yzxzzuqqbr7z_, MCGEN_EVENTWRITETRANSFER)
+
+#endif // MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+//
+// MCGEN_DISABLE_PROVIDER_CODE_GENERATION macro:
+// Define this macro to have the compiler skip the generated functions in this
+// header.
+//
+#ifndef MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+//
+// Template Functions
+//
+
+//
+// Function for template "EID1" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzqqqqqkzzq_def
+#define McTemplateU0yzqqqqqkzzq_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzqqqqqkzzq_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned int _Arg2,
+ _In_ const unsigned int _Arg3,
+ _In_ const unsigned int _Arg4,
+ _In_ const unsigned int _Arg5,
+ _In_ const unsigned int _Arg6,
+ _In_ const SID* _Arg7,
+ _In_opt_ PCWSTR _Arg8,
+ _In_opt_ PCWSTR _Arg9,
+ _In_ const unsigned int _Arg10
+ )
+{
+#define McTemplateU0yzqqqqqkzzq_ARGCOUNT 11
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzqqqqqkzzq_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[4],&_Arg3, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[5],&_Arg4, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[7],&_Arg6, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[8],(_Arg7 != NULL) ? _Arg7 : (const void*)"\0\0\0\0\0\0\0", (_Arg7 != NULL) ? (8u + _Arg7->SubAuthorityCount * 4u) : 8);
+
+ EventDataDescCreate(&EventData[9],
+ (_Arg8 != NULL) ? _Arg8 : L"NULL",
+ (_Arg8 != NULL) ? (ULONG)((wcslen(_Arg8) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[10],
+ (_Arg9 != NULL) ? _Arg9 : L"NULL",
+ (_Arg9 != NULL) ? (ULONG)((wcslen(_Arg9) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[11],&_Arg10, sizeof(const unsigned int) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzqqqqqkzzq_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzqqqqqkzzq_def
+
+//
+// Function for template "EID10" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzqzzhht_def
+#define McTemplateU0yzqzzhht_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzqzzhht_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned int _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_opt_ PCWSTR _Arg4,
+ _In_ const unsigned short _Arg5,
+ _In_ const unsigned short _Arg6,
+ _In_ const signed int _Arg7
+ )
+{
+#define McTemplateU0yzqzzhht_ARGCOUNT 8
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzqzzhht_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],
+ (_Arg4 != NULL) ? _Arg4 : L"NULL",
+ (_Arg4 != NULL) ? (ULONG)((wcslen(_Arg4) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned short) );
+
+ EventDataDescCreate(&EventData[7],&_Arg6, sizeof(const unsigned short) );
+
+ EventDataDescCreate(&EventData[8],&_Arg7, sizeof(const signed int) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzqzzhht_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzqzzhht_def
+
+//
+// Function for template "EID5" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzxxxzh_def
+#define McTemplateU0yzxxxzh_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzxxxzh_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned __int64 _Arg2,
+ _In_ const unsigned __int64 _Arg3,
+ _In_ const unsigned __int64 _Arg4,
+ _In_opt_ PCWSTR _Arg5,
+ _In_ const unsigned short _Arg6
+ )
+{
+#define McTemplateU0yzxxxzh_ARGCOUNT 7
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzxxxzh_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[4],&_Arg3, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[5],&_Arg4, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[6],
+ (_Arg5 != NULL) ? _Arg5 : L"NULL",
+ (_Arg5 != NULL) ? (ULONG)((wcslen(_Arg5) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[7],&_Arg6, sizeof(const unsigned short) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzxxxzh_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzxxxzh_def
+
+//
+// Function for template "EID7" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzxzqqzzzz_def
+#define McTemplateU0yzxzqqzzzz_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzxzqqzzzz_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned __int64 _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_ const unsigned int _Arg4,
+ _In_ const unsigned int _Arg5,
+ _In_opt_ PCWSTR _Arg6,
+ _In_opt_ PCWSTR _Arg7,
+ _In_opt_ PCWSTR _Arg8,
+ _In_opt_ PCWSTR _Arg9
+ )
+{
+#define McTemplateU0yzxzqqzzzz_ARGCOUNT 10
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzxzqqzzzz_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],&_Arg4, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[7],
+ (_Arg6 != NULL) ? _Arg6 : L"NULL",
+ (_Arg6 != NULL) ? (ULONG)((wcslen(_Arg6) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[8],
+ (_Arg7 != NULL) ? _Arg7 : L"NULL",
+ (_Arg7 != NULL) ? (ULONG)((wcslen(_Arg7) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[9],
+ (_Arg8 != NULL) ? _Arg8 : L"NULL",
+ (_Arg8 != NULL) ? (ULONG)((wcslen(_Arg8) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[10],
+ (_Arg9 != NULL) ? _Arg9 : L"NULL",
+ (_Arg9 != NULL) ? (ULONG)((wcslen(_Arg9) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzxzqqzzzz_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzxzqqzzzz_def
+
+//
+// Function for template "EID9" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzxzzqq_def
+#define McTemplateU0yzxzzqq_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzxzzqq_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned __int64 _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_opt_ PCWSTR _Arg4,
+ _In_ const unsigned int _Arg5,
+ _In_ const unsigned int _Arg6
+ )
+{
+#define McTemplateU0yzxzzqq_ARGCOUNT 7
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzxzzqq_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],
+ (_Arg4 != NULL) ? _Arg4 : L"NULL",
+ (_Arg4 != NULL) ? (ULONG)((wcslen(_Arg4) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[7],&_Arg6, sizeof(const unsigned int) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzxzzqq_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzxzzqq_def
+
+//
+// Function for template "EID11" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzxzzuqqbr7z_def
+#define McTemplateU0yzxzzuqqbr7z_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzxzzuqqbr7z_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned __int64 _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_opt_ PCWSTR _Arg4,
+ _In_ const unsigned char _Arg5,
+ _In_ const unsigned int _Arg6,
+ _In_ const unsigned int _Arg7,
+ _In_reads_(_Arg7) const unsigned char* _Arg8,
+ _In_opt_ PCWSTR _Arg9
+ )
+{
+#define McTemplateU0yzxzzuqqbr7z_ARGCOUNT 10
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzxzzuqqbr7z_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],
+ (_Arg4 != NULL) ? _Arg4 : L"NULL",
+ (_Arg4 != NULL) ? (ULONG)((wcslen(_Arg4) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned char) );
+
+ EventDataDescCreate(&EventData[7],&_Arg6, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[8],&_Arg7, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[9],_Arg8, (ULONG)sizeof(char)*_Arg7);
+
+ EventDataDescCreate(&EventData[10],
+ (_Arg9 != NULL) ? _Arg9 : L"NULL",
+ (_Arg9 != NULL) ? (ULONG)((wcslen(_Arg9) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzxzzuqqbr7z_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzxzzuqqbr7z_def
+
+//
+// Function for template "EID6" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzxzzzz_def
+#define McTemplateU0yzxzzzz_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzxzzzz_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_ const unsigned __int64 _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_opt_ PCWSTR _Arg4,
+ _In_opt_ PCWSTR _Arg5,
+ _In_opt_ PCWSTR _Arg6
+ )
+{
+#define McTemplateU0yzxzzzz_ARGCOUNT 7
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzxzzzz_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],&_Arg2, sizeof(const unsigned __int64) );
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],
+ (_Arg4 != NULL) ? _Arg4 : L"NULL",
+ (_Arg4 != NULL) ? (ULONG)((wcslen(_Arg4) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[6],
+ (_Arg5 != NULL) ? _Arg5 : L"NULL",
+ (_Arg5 != NULL) ? (ULONG)((wcslen(_Arg5) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[7],
+ (_Arg6 != NULL) ? _Arg6 : L"NULL",
+ (_Arg6 != NULL) ? (ULONG)((wcslen(_Arg6) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzxzzzz_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzxzzzz_def
+
+//
+// Function for template "EID4" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzzqqq_def
+#define McTemplateU0yzzqqq_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzzqqq_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_opt_ PCWSTR _Arg2,
+ _In_ const unsigned int _Arg3,
+ _In_ const unsigned int _Arg4,
+ _In_ const unsigned int _Arg5
+ )
+{
+#define McTemplateU0yzzqqq_ARGCOUNT 6
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzzqqq_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],
+ (_Arg2 != NULL) ? _Arg2 : L"NULL",
+ (_Arg2 != NULL) ? (ULONG)((wcslen(_Arg2) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[4],&_Arg3, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[5],&_Arg4, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned int) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzzqqq_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzzqqq_def
+
+//
+// Function for template "EID2" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzzzqq_def
+#define McTemplateU0yzzzqq_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzzzqq_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_opt_ PCWSTR _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_ const unsigned int _Arg4,
+ _In_ const unsigned int _Arg5
+ )
+{
+#define McTemplateU0yzzzqq_ARGCOUNT 6
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzzzqq_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],
+ (_Arg2 != NULL) ? _Arg2 : L"NULL",
+ (_Arg2 != NULL) ? (ULONG)((wcslen(_Arg2) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],&_Arg4, sizeof(const unsigned int) );
+
+ EventDataDescCreate(&EventData[6],&_Arg5, sizeof(const unsigned int) );
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzzzqq_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzzzqq_def
+
+//
+// Function for template "EID3" (and possibly others).
+// This function is for use by MC-generated code and should not be used directly.
+//
+#ifndef McTemplateU0yzzzzzz_def
+#define McTemplateU0yzzzzzz_def
+ETW_INLINE
+ULONG
+_mcgen_PASTE2(McTemplateU0yzzzzzz_, MCGEN_EVENTWRITETRANSFER)(
+ _In_ PMCGEN_TRACE_CONTEXT Context,
+ _In_ PCEVENT_DESCRIPTOR Descriptor,
+ _In_ const SYSTEMTIME* _Arg0,
+ _In_opt_ PCWSTR _Arg1,
+ _In_opt_ PCWSTR _Arg2,
+ _In_opt_ PCWSTR _Arg3,
+ _In_opt_ PCWSTR _Arg4,
+ _In_opt_ PCWSTR _Arg5,
+ _In_opt_ PCWSTR _Arg6
+ )
+{
+#define McTemplateU0yzzzzzz_ARGCOUNT 7
+
+ EVENT_DATA_DESCRIPTOR EventData[McTemplateU0yzzzzzz_ARGCOUNT + 1];
+
+ EventDataDescCreate(&EventData[1],_Arg0, sizeof(SYSTEMTIME) );
+
+ EventDataDescCreate(&EventData[2],
+ (_Arg1 != NULL) ? _Arg1 : L"NULL",
+ (_Arg1 != NULL) ? (ULONG)((wcslen(_Arg1) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[3],
+ (_Arg2 != NULL) ? _Arg2 : L"NULL",
+ (_Arg2 != NULL) ? (ULONG)((wcslen(_Arg2) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[4],
+ (_Arg3 != NULL) ? _Arg3 : L"NULL",
+ (_Arg3 != NULL) ? (ULONG)((wcslen(_Arg3) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[5],
+ (_Arg4 != NULL) ? _Arg4 : L"NULL",
+ (_Arg4 != NULL) ? (ULONG)((wcslen(_Arg4) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[6],
+ (_Arg5 != NULL) ? _Arg5 : L"NULL",
+ (_Arg5 != NULL) ? (ULONG)((wcslen(_Arg5) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ EventDataDescCreate(&EventData[7],
+ (_Arg6 != NULL) ? _Arg6 : L"NULL",
+ (_Arg6 != NULL) ? (ULONG)((wcslen(_Arg6) + 1) * sizeof(WCHAR)) : (ULONG)sizeof(L"NULL"));
+
+ return McGenEventWrite(Context, Descriptor, NULL, McTemplateU0yzzzzzz_ARGCOUNT + 1, EventData);
+}
+#endif // McTemplateU0yzzzzzz_def
+
+#endif // MCGEN_DISABLE_PROVIDER_CODE_GENERATION
+
+#if defined(__cplusplus)
+}
+#endif
+
+#define MSG_ProcessCreation_EventMessage 0xB0000001L
+#define MSG_RegistryCreateKey_EventMessage 0xB0000002L
+#define MSG_ServiceCreation_EventMessage 0xB0000003L
+#define MSG_FileCreation_EventMessage 0xB0000004L
+#define MSG_DotNetLoad_EventMessage 0xB0000005L
+#define MSG_WMIEventFilter_EventMessage 0xB0000006L
+#define MSG_RPCClient_EventMessage 0xB0000007L
+#define MSG_RPCServer_EventMessage 0xB0000008L
+#define MSG_DPAPIUnprotect_EventMessage 0xB0000009L
+#define MSG_NetworkConnection_EventMessage 0xB000000AL
+#define MSG_AMSI_EventMessage 0xB000000BL
diff --git a/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.man b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.man
new file mode 100644
index 0000000..d953964
--- /dev/null
+++ b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.man
@@ -0,0 +1,601 @@
+
+
+
+
+
+
+
+
+ 67112660
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.rc b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.rc
new file mode 100644
index 0000000..88eeff4
--- /dev/null
+++ b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.rc
@@ -0,0 +1,3 @@
+LANGUAGE 0x9,0x1
+1 11 "MSG00001.bin"
+1 WEVT_TEMPLATE "JonMon-Lite-ProviderTEMP.BIN"
diff --git a/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.res b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.res
new file mode 100644
index 0000000..1959ed4
Binary files /dev/null and b/JonMon-Lite/ETWProvider/JonMon-Lite-Provider.res differ
diff --git a/JonMon-Lite/ETWProvider/JonMon-Lite-ProviderTEMP.BIN b/JonMon-Lite/ETWProvider/JonMon-Lite-ProviderTEMP.BIN
new file mode 100644
index 0000000..8171e13
Binary files /dev/null and b/JonMon-Lite/ETWProvider/JonMon-Lite-ProviderTEMP.BIN differ
diff --git a/JonMon-Lite/ETWProvider/JonMon-LiteTEMP.BIN b/JonMon-Lite/ETWProvider/JonMon-LiteTEMP.BIN
new file mode 100644
index 0000000..e25ad77
Binary files /dev/null and b/JonMon-Lite/ETWProvider/JonMon-LiteTEMP.BIN differ
diff --git a/JonMon-Lite/ETWProvider/MSG00001.bin b/JonMon-Lite/ETWProvider/MSG00001.bin
new file mode 100644
index 0000000..8a9dbd2
Binary files /dev/null and b/JonMon-Lite/ETWProvider/MSG00001.bin differ
diff --git a/JonMon-Lite/JonMon-Lite-Collector.cpp b/JonMon-Lite/JonMon-Lite-Collector.cpp
new file mode 100644
index 0000000..87ea4a9
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite-Collector.cpp
@@ -0,0 +1,1824 @@
+#include
+#include "JonMon-Lite-Global.h"
+#include "JonMon-Lite.h"
+#include "JonMon-Lite-Collector.h"
+#include
+#include
+#include
+#include
+#include
+#include
+#include
+
+#pragma comment(lib, "Ws2_32.lib")
+
+//
+// Using thread_local so that each thread gets its own instance of the global variable
+//
+thread_local std::deque g_EventOrder;
+thread_local std::unordered_set g_EventHashes;
+
+const size_t MAX_CONTAINER_SIZE = 2000000;
+
+//
+// Main Processing Functions
+//
+VOID StartCollector(
+ _In_ Etw_Processing* processingInfo
+)
+{
+ DWORD waitResult;
+ TRACEHANDLE hTrace = NULL;
+ printf("Processing events...\n");
+
+
+ ULONG status;
+ EVENT_TRACE_LOGFILEW logfile = { 0 };
+ DWORD fileAttrib;
+
+ fileAttrib = GetFileAttributesW(processingInfo->ETLFilePath.c_str());
+ if (fileAttrib == INVALID_FILE_ATTRIBUTES) {
+ wprintf(L"ETL file not found: %ls, waiting 4 seconds...\n", processingInfo->ETLFilePath.c_str());
+
+ waitResult = WaitForSingleObject(finishJobs, 4000);
+ if (waitResult == WAIT_OBJECT_0) {
+ wprintf(L"Shutdown signaled while waiting for file: %ls\n", processingInfo->ETLFilePath.c_str());
+ goto Exit;
+ }
+ }
+ while (g_Process) {
+ logfile.LogFileName = (LPWSTR)processingInfo->ETLFilePath.c_str();
+ logfile.ProcessTraceMode = PROCESS_TRACE_MODE_EVENT_RECORD | EVENT_TRACE_FILE_MODE_CIRCULAR;
+ logfile.EventRecordCallback = ProcessEvents;
+ logfile.Context = processingInfo;
+
+ hTrace = OpenTraceW(&logfile);
+ if (hTrace == INVALID_PROCESSTRACE_HANDLE) {
+ printf("Failed to open trace file. Error: %lu\n", GetLastError());
+ goto Exit;
+ }
+
+ status = ProcessTrace(&hTrace, 1, NULL, NULL);
+ if (status != ERROR_SUCCESS && status != ERROR_CANCELLED) {
+ printf("Failed to process trace. Error: %lu\n", status);
+ goto Exit;
+ }
+
+ CloseTrace(hTrace);
+ hTrace = NULL;
+
+ waitResult = WaitForSingleObject(finishJobs, 1000);
+ if (waitResult == WAIT_TIMEOUT) {
+
+ }
+ else if (waitResult == WAIT_OBJECT_0) {
+ printf("Shutdown signaled, exiting wait...\n");
+ goto Exit;
+ }
+ }
+
+Exit:
+ if (hTrace != NULL && hTrace != INVALID_PROCESSTRACE_HANDLE) {
+ CloseTrace(hTrace);
+ }
+ return;
+}
+
+
+//
+// Processes events in ETL
+//
+VOID WINAPI ProcessEvents(
+ _In_ PEVENT_RECORD pEvent
+) {
+ PEVENT_HEADER eventHeader = &pEvent->EventHeader;
+ PEVENT_DESCRIPTOR eventDescriptor = &eventHeader->EventDescriptor;
+ DWORD status = ERROR_SUCCESS;
+ PTRACE_EVENT_INFO pInfo = NULL;
+ DWORD bufferSize = 0;
+
+ //
+ // Creating unique event hash for tracking
+ //
+ ULONGLONG hash = CreateEventHash(pEvent);
+
+ //
+ // If hash has been seen - return
+ //
+ if (g_EventHashes.count(hash) > 0) {
+ return;
+ }
+
+ //
+ // Add to unordered set and double-ended queue
+ //
+ g_EventOrder.push_back(hash);
+ g_EventHashes.insert(hash);
+
+ //
+ // Adjusting so that size doesn't exceed max
+ //
+ TrimToMaxSize();
+
+ Etw_Processing* processingInfo = (Etw_Processing*)pEvent->UserContext;
+ if (!processingInfo)
+ {
+ wprintf(L"Error getting UserContext\n");
+ return;
+ }
+
+ if (eventHeader->ProviderId == DotNet_Provider) {
+ switch (eventDescriptor->Id) {
+ case 154: {
+ status = WriteDotNetEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing DotNet Events\n");
+ }
+ break;
+ }
+ default: {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == Network_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 10:
+ case 11:
+ {
+ status = WriteNetworkEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing Network Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == Registry_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 1:
+ {
+ // removing due to noise
+ status = WriteRegistryEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing Service Control Manager Provider Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == Service_Control_Manager_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 7045:
+ {
+ status = WriteServiceEvent(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing Service Control Manager Provider Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == File_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 30:
+ {
+ status = WriteFileEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing File Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == Process_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 1:
+ {
+ status = WriteProcessCreationEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing Process Creation Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == DPAPI_Provider)
+ {
+ switch (eventDescriptor->Id) {
+ case 16385: {
+ status = WriteDpapiEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing DPAPI Events\n");
+ }
+ break;
+ }
+ default: {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == WMIActivty_Provider) {
+ switch (eventDescriptor->Id) {
+ case 5861:
+ {
+ status = WriteWMIEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing WMI Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+ }
+ }
+ if (eventHeader->ProviderId == RPC_Provider) {
+ switch (eventDescriptor->Id) {
+ case 5:
+ {
+ status = WriteRpcEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str(), 0); // 0 == CLIENT
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing RPC Events\n");
+ }
+
+ break;
+ }
+ case 6:
+ {
+ status = WriteRpcEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str(), 1); // 1 == SERVER
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing RPC Events\n");
+ }
+ break;
+ }
+ default: {
+ break;
+ }
+
+ }
+ }
+ if (eventHeader->ProviderId == AMSI_Provider) {
+ switch (eventDescriptor->Id) {
+ case 1101:
+ {
+ status = WriteAMSIEvents(pEvent, eventHeader, (LPWSTR)processingInfo->WorkstationName.c_str());
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error writing AMSI Events\n");
+ }
+ break;
+ }
+ default:
+ {
+ break;
+ }
+
+
+ }
+ }
+}
+
+//
+// Helper Functions
+//
+
+//
+// Creating unique event hash using Provider GUID, ThreadId, ProcessId, and Timestamp
+//
+ULONGLONG CreateEventHash(
+ _In_ PEVENT_RECORD pEvent
+) {
+ ULONGLONG hash = pEvent->EventHeader.TimeStamp.QuadPart;
+ hash ^= ((ULONGLONG)pEvent->EventHeader.EventDescriptor.Id << 32);
+ hash ^= ((ULONGLONG)pEvent->EventHeader.ThreadId << 16);
+ hash ^= pEvent->EventHeader.ProcessId;
+
+ ULONGLONG* guid = (ULONGLONG*)&pEvent->EventHeader.ProviderId;
+ hash ^= guid[0] ^ guid[1];
+
+ return hash;
+}
+
+//
+// Triming container to proper size
+//
+VOID TrimToMaxSize() {
+ while (g_EventOrder.size() > MAX_CONTAINER_SIZE) {
+ ULONGLONG oldestHash = g_EventOrder.front();
+ g_EventOrder.pop_front();
+ g_EventHashes.erase(oldestHash);
+ }
+}
+
+//
+// ETW Event Processing Helper Functions
+//
+NTSTATUS EtwEventProcessing(
+ _In_ PEVENT_RECORD EventRecord,
+ _Out_ PTRACE_EVENT_INFO* ppInfo,
+ _Out_ BYTE*** ppPropertyDataVector
+) {
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ //
+ // Get event information
+ //
+ status = TdhGetEventInformation(EventRecord, 0, nullptr, nullptr, &bufferSize);
+ if (status == ERROR_INSUFFICIENT_BUFFER) {
+ pInfo = (PTRACE_EVENT_INFO)malloc(bufferSize);
+ if (!pInfo) {
+ OutputDebugString(L"Error allocating memory for event info\n");
+ return ERROR_NOT_ENOUGH_MEMORY;
+ }
+ status = TdhGetEventInformation(EventRecord, 0, nullptr, pInfo, &bufferSize);
+ }
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error fetching event info\n");
+ if (pInfo) free(pInfo);
+ return status;
+ }
+
+ //
+ // Allocate property data vector
+ //
+ propertyDataVector = (BYTE**)malloc(sizeof(BYTE*) * pInfo->TopLevelPropertyCount);
+ if (!propertyDataVector) {
+ OutputDebugString(L"Error allocating memory for propertyDataVector\n");
+ free(pInfo);
+ return ERROR_NOT_ENOUGH_MEMORY;
+ }
+
+ //
+ // Process the event
+ //
+ status = ProcessEtwProperties(EventRecord, pInfo, propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error processing ETW event\n");
+ free(pInfo);
+ free(propertyDataVector);
+ return status;
+ }
+
+ *ppInfo = pInfo;
+ *ppPropertyDataVector = propertyDataVector;
+ return ERROR_SUCCESS;
+}
+
+NTSTATUS ProcessEtwProperties(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PTRACE_EVENT_INFO PropertyInfo,
+ _In_ BYTE** EventData
+) {
+ NTSTATUS status = ERROR_SUCCESS;
+ int vectorSize = 0;
+
+ //
+ // Process each property in the event
+ //
+ for (ULONG i = 0; i < PropertyInfo->TopLevelPropertyCount; i++) {
+ PROPERTY_DATA_DESCRIPTOR dataDescriptor;
+ DWORD propertySize = 0;
+ WCHAR* propertyName = (WCHAR*)((BYTE*)PropertyInfo + PropertyInfo->EventPropertyInfoArray[i].NameOffset);
+ dataDescriptor.PropertyName = (ULONGLONG)propertyName;
+ dataDescriptor.ArrayIndex = ULONG_MAX;
+
+ //
+ // Determine the size of the property
+ //
+ status = TdhGetPropertySize(EventRecord, 0, NULL, 1, &dataDescriptor, &propertySize);
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error getting size for property\n");
+ goto Exit;
+ }
+
+ BYTE* propertyData = (BYTE*)malloc(propertySize);
+ if (!propertyData) {
+ OutputDebugString(L" Error allocating memory for propertyData\n");
+ goto Exit;
+ }
+
+ //
+ // Get the actual property data
+ //
+ status = TdhGetProperty(EventRecord, 0, NULL, 1, &dataDescriptor, propertySize, propertyData);
+ if (status != ERROR_SUCCESS) {
+ OutputDebugString(L"Error getting data for property\n");
+ goto Exit;
+ }
+
+ //
+ // Add the data to the vector
+ //
+ EventData[vectorSize++] = propertyData;
+
+ if (vectorSize > PropertyInfo->TopLevelPropertyCount) {
+ OutputDebugString(L"Error: vectorSize exceeded allocated EventData size\n");
+ status = ERROR_BUFFER_OVERFLOW;
+ goto Exit;
+ }
+ }
+
+Exit:
+ if (status != ERROR_SUCCESS) {
+ for (int i = 0; i < vectorSize; i++) {
+ if (EventData[i] != nullptr) {
+ free(EventData[i]);
+ }
+ }
+ }
+ return status;
+
+}
+
+//
+// Specific Event Processing Function
+//
+BOOL WriteAMSIEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+
+ UINT_PTR Session;
+ UINT8 ScanStatus;
+ UINT32 ScanResult, ContentSize, OriginalSize;
+ std::wstring AppName, ContentName, decodedString;
+ BYTE* Content;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ SYSTEMTIME systemTime;
+ BYTE** propertyDataVector = nullptr;
+ FILETIME fileTime;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ Session = *(ULONG64*)propertyDataVector[0];
+ ScanStatus = *(UINT8*)propertyDataVector[1];
+ ScanResult = *(UINT32*)propertyDataVector[2];
+ AppName = (WCHAR*)propertyDataVector[3];
+
+ if (AppName != L"VBScript" && AppName != L"JScript" && AppName != L"OFFICE_VBA" && AppName != L"Excel" && AppName != L"Excel.exe")
+ {
+ goto Exit;
+ }
+
+ ContentName = (WCHAR*)propertyDataVector[4];
+ ContentSize = *(UINT32*)propertyDataVector[5];
+ OriginalSize = *(UINT32*)propertyDataVector[6];
+ Content = (BYTE*)propertyDataVector[7];
+
+ if (ScanResult != (UINT32)1 && ScanResult != (UINT32)32768) {
+ goto Exit;
+ }
+
+ decodedString = std::wstring(reinterpret_cast(Content), ContentSize / sizeof(wchar_t));
+
+ EventWriteAMSI(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ AppName.c_str(),
+ ContentName.c_str(),
+ ScanStatus,
+ ScanResult,
+ ContentSize,
+ Content,
+ decodedString.c_str()
+ );
+
+Exit:
+ // Free each element in propertyDataVector and the vector itself
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+ return TRUE;
+}
+
+NTSTATUS WriteRpcEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName,
+ _In_ INT32 EventType
+) {
+ PEVENT_HEADER_EXTENDED_DATA_ITEM extendedData = EventRecord->ExtendedData;
+ wchar_t szInterfaceUUID[64] = { 0 };
+ GUID interfaceUUID;
+ UINT32 procNum, protocol, authenticationLevel, authenticationService, impersonationLevel;
+ std::wstring networkAddress, endpoint, options, methodString, interfaceString;
+ int result;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ SYSTEMTIME systemTime;
+ FILETIME fileTime;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ interfaceUUID = *(GUID*)propertyDataVector[0];
+ procNum = *(UINT32*)propertyDataVector[1];
+ protocol = *(UINT32*)propertyDataVector[2];
+ networkAddress = (WCHAR*)propertyDataVector[3];
+ endpoint = (WCHAR*)propertyDataVector[4];
+ options = (WCHAR*)propertyDataVector[5];
+ authenticationLevel = *(UINT32*)propertyDataVector[6];
+ authenticationService = *(UINT32*)propertyDataVector[7];
+ impersonationLevel = *(UINT32*)propertyDataVector[8];
+
+ //
+ // convert GUID to string
+ //
+ result = StringFromGUID2(interfaceUUID, szInterfaceUUID, 64);
+ if (result == 0) {
+ OutputDebugString(L"Error converting GUID to string\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //MS-SCMR {367ABB81-9844-35F1-AD32-98F038001003}
+ if (wcscmp(szInterfaceUUID, L"{367ABB81-9844-35F1-AD32-98F038001003}") == 0) {
+ interfaceString = L"MS-SCMR";
+ switch (procNum)
+ {
+ case 12:
+ {
+ methodString = L"RCreateServiceW";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ //MS-DRSR {E3514235-4B06-11D1-AB04-00C04FC2DCD2}
+ if (wcscmp(szInterfaceUUID, L"{E3514235-4B06-11D1-AB04-00C04FC2DCD2}") == 0) {
+ interfaceString = L"MS-DRSR";
+ switch (procNum) {
+ case 3:
+ {
+ methodString = L"GetNCChanges";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default: {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ //MS-RRP {338CD001-2244-31F1-AAAA-900038001003}
+ if (wcscmp(szInterfaceUUID, L"{338CD001-2244-31F1-AAAA-900038001003}") == 0) {
+ interfaceString = L"MS-RRP";
+ switch (procNum) {
+ case 6:
+ {
+ methodString = L"BaseRegCreateKey";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ case 22:
+ {
+ methodString = L"BaseRegSetValue";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ //MS-SRVS {4B324FC8-1670-01D3-1278-5A47BF6EE188}
+ if (wcscmp(szInterfaceUUID, L"{4B324FC8-1670-01D3-1278-5A47BF6EE188}") == 0) {
+ interfaceString = L"MS-SRVS";
+ switch (procNum) {
+ case 12:
+ {
+ methodString = L"NetrSessionEnum";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ //MS-RPRN {12345678-1234-ABCD-EF00-0123456789AB}
+ if (wcscmp(szInterfaceUUID, L"{12345678-1234-ABCD-EF00-0123456789AB}") == 0) {
+ interfaceString = L"MS-RPRN";
+ switch (procNum) {
+ case 89:
+ {
+ methodString = L"RpcAddPrinterDriverEx";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ break;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ //MS-PAR 76F03F96-CDFD-44FC-A22C-64950A001209
+ if (wcscmp(szInterfaceUUID, L"{76F03F96-CDFD-44FC-A22C-64950A001209}") == 0) {
+ interfaceString = L"MS-PAR";
+ switch (procNum) {
+ case 39:
+ {
+ methodString = L"RpcAsyncAddPrinterDriver";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+ // MS-EFSR {D9A0A0C0-150F-11D1-8C7A-00C04FC297EB} || {C681D488-D850-11D0-8C52-00C04FD90F7E}"
+ if ((wcscmp(szInterfaceUUID, L"{C681D488-D850-11D0-8C52-00C04FD90F7E}") == 0) ||
+ (wcscmp(szInterfaceUUID, L"{DF1941C5-FE89-4E79-BF10-463657ACF44D}") == 0)) {
+ interfaceString = L"MS-EFSR";
+ switch (procNum) {
+ case 0:
+ {
+ methodString = L"EfsRpcOpenFileRaw";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ case 4:
+ {
+ methodString = L"EfsRpcEncryptFileSrv";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ wprintf(L"RPC Server Event\n");
+ wprintf(L"SystemTime: %02d:%02d\n", systemTime.wHour, systemTime.wMinute);
+ wprintf(L"InterfaceUUID: %s\n", szInterfaceUUID);
+ wprintf(L"Interface String: %s\n", interfaceString.c_str());
+ wprintf(L"Method String: %s\n", methodString.c_str());
+ wprintf(L"procNum: %lu\n", procNum);
+ wprintf(L"protocol: %lu\n", protocol);
+ wprintf(L"networkAddress: %s\n", networkAddress.c_str());
+ wprintf(L"endpoint: %s\n", endpoint.c_str());
+ wprintf(L"options: %s\n", options.c_str());
+ wprintf(L"authenticationLevel: %lu\n", authenticationLevel);
+ wprintf(L"authenticationService: %lu\n", authenticationService);
+ wprintf(L"impersonationLevel: %lu\n", impersonationLevel);
+
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ case 5:
+ {
+ methodString = L"EfsRpcDecryptFileSrv";
+ switch (EventType)
+ {
+ case 0:
+ {
+ EventWriteRPCClient(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ case 1:
+ {
+ EventWriteRPCServer(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ szInterfaceUUID,
+ procNum,
+ protocol,
+ networkAddress.c_str(),
+ endpoint.c_str(),
+ interfaceString.c_str(),
+ methodString.c_str()
+ );
+ break;
+ }
+ }
+ goto Exit;
+ }
+ default:
+ {
+ goto Exit;
+ }
+ }
+ goto Exit;
+ }
+
+Exit:
+ // Free each element in propertyDataVector and the vector itself
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteNetworkEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+ SYSTEMTIME systemTime;
+ UINT32 processId, size, sourceAddress, destinationAddress;
+ UINT16 sourcePort, destinationPort;
+ WCHAR wide_deststring_ip[INET_ADDRSTRLEN];
+ WCHAR wide_sourcestring_ip[INET_ADDRSTRLEN];
+ struct in_addr srceaddr = {};
+ struct in_addr destaddr = {};
+ BOOL isInitiated = false;
+ FILETIME fileTime;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ processId = *(UINT32*)propertyDataVector[0];
+
+ if (processId == 4)
+ {
+ goto Exit;
+ }
+
+ size = *(UINT32*)propertyDataVector[1];
+ destinationAddress = *(UINT32*)propertyDataVector[2];
+ sourceAddress = *(UINT32*)propertyDataVector[3];
+ sourcePort = *(UINT16*)propertyDataVector[4];
+ destinationPort = *(UINT16*)propertyDataVector[5];
+
+
+ if (EventHeader->EventDescriptor.Id == 10)
+ {
+ isInitiated = true;
+ destaddr.s_addr = destinationAddress;
+ srceaddr.s_addr = sourceAddress;
+ }
+ else if (EventHeader->EventDescriptor.Id == 11)
+ {
+ isInitiated = false;
+ destaddr.s_addr = sourceAddress;
+ srceaddr.s_addr = destinationAddress;
+
+ }
+
+ if (InetNtop(AF_INET, &srceaddr, wide_sourcestring_ip, INET_ADDRSTRLEN) == nullptr) {
+ OutputDebugString(L"Error converting source IP address\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ if (InetNtop(AF_INET, &destaddr, wide_deststring_ip, INET_ADDRSTRLEN) == nullptr) {
+ OutputDebugString(L"Error converting destination IP address\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ EventWriteNetworkConnection(
+ &systemTime,
+ WorkstationName,
+ processId,
+ wide_sourcestring_ip,
+ wide_deststring_ip,
+ sourcePort,
+ destinationPort,
+ isInitiated
+ );
+
+
+Exit:
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteProcessCreationEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ UINT64 ProcessSequenceNumber, ParentProcessSequenceNumber;
+ UINT32 ProcessId, ParentProcessID, SessionID, Flags, ProcessTokenElevationType, ProcessTokenIsElevated, ImageCheckSum, TimeDataStamp, SecurityMitigations;
+ UINT16 ClrInstanceID;
+ std::wstring ImageName, PackageFullName, PackageRelativeAppId;
+ SID MandatoryLabel;
+ FILETIME CreateTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ ProcessId = *(UINT32*)propertyDataVector[0];
+ ProcessSequenceNumber = *(UINT64*)propertyDataVector[1];
+ CreateTime = *(FILETIME*)propertyDataVector[2];
+ ParentProcessID = *(UINT32*)propertyDataVector[3];
+ ParentProcessSequenceNumber = *(UINT64*)propertyDataVector[4];
+ SessionID = *(UINT32*)propertyDataVector[5];
+ Flags = *(UINT32*)propertyDataVector[6];
+ ProcessTokenElevationType = *(UINT32*)propertyDataVector[7];
+ ProcessTokenIsElevated = *(UINT32*)propertyDataVector[8];
+ MandatoryLabel = *(SID*)propertyDataVector[9];
+ ImageName = (WCHAR*)propertyDataVector[10];
+ ImageCheckSum = *(UINT32*)propertyDataVector[11];
+ TimeDataStamp = *(UINT32*)propertyDataVector[12];
+ PackageFullName = (WCHAR*)propertyDataVector[13];
+ PackageRelativeAppId = (WCHAR*)propertyDataVector[14];
+
+ if (pInfo->TopLevelPropertyCount >= 16)
+ {
+ SecurityMitigations = *(UINT32*)propertyDataVector[15];
+ }
+ else
+ {
+ SecurityMitigations = 0;
+ }
+
+ if (!FileTimeToSystemTime(&CreateTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+
+ EventWriteProcessCreation(
+ &systemTime,
+ WorkstationName,
+ ProcessId,
+ ParentProcessID,
+ SessionID,
+ Flags,
+ ProcessTokenIsElevated,
+ &MandatoryLabel,
+ ImageName.c_str(),
+ PackageFullName.c_str(),
+ SecurityMitigations
+ );
+
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteDotNetEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ UINT64 AssemblyID, AppDomainID, BindingID;
+ UINT32 AssemblyFlags;
+ UINT16 ClrInstanceID;
+ std::wstring FQAN;
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ AssemblyID = *(UINT64*)propertyDataVector[0];
+ AppDomainID = *(UINT64*)propertyDataVector[1];
+ BindingID = *(UINT64*)propertyDataVector[2];
+ AssemblyFlags = *(UINT32*)propertyDataVector[3];
+ FQAN = (WCHAR*)propertyDataVector[4];
+ ClrInstanceID = *(UINT16*)propertyDataVector[5];
+
+
+ EventWriteDotNetLoad(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ AssemblyID,
+ AppDomainID,
+ FQAN.c_str(),
+ ClrInstanceID
+ );
+
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteRegistryEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ switch (EventHeader->EventDescriptor.Id) {
+ // Registry Key Creation
+ case 1:
+ {
+ UINT_PTR BaseObject, KeyObject;
+ UINT32 Status, Disposition;
+ std::wstring BaseName, RelativeName;
+
+ BaseObject = *(UINT_PTR*)propertyDataVector[0];
+ KeyObject = *(UINT_PTR*)propertyDataVector[1];
+ Status = *(UINT32*)propertyDataVector[2];
+ Disposition = *(UINT32*)propertyDataVector[3];
+ BaseName = (WCHAR*)propertyDataVector[4];
+ RelativeName = (WCHAR*)propertyDataVector[5];
+
+ EventWriteRegistryCreateKey(
+ &systemTime,
+ WorkstationName,
+ BaseName.c_str(),
+ RelativeName.c_str(),
+ Disposition,
+ Status
+ );
+
+ break;
+ }
+ // Registry Set Value
+ case 5:
+ {
+ UINT_PTR KeyObject;
+ UINT32 Status, Type, DataSize, PreviousDataType, PreviousDataSize;
+ UINT16 CapturedDataSize, PreviousDataCapturedSize;
+ std::wstring KeyName, ValueName, capturedDataString;
+ BYTE* CapturedData;
+ BYTE* PreviousData;
+
+ KeyObject = *(UINT_PTR*)propertyDataVector[0];
+ Status = *(UINT32*)propertyDataVector[1];
+ Type = *(UINT32*)propertyDataVector[2];
+ DataSize = *(UINT32*)propertyDataVector[3];
+ KeyName = (WCHAR*)propertyDataVector[4];
+ ValueName = (WCHAR*)propertyDataVector[5];
+ CapturedDataSize = *(UINT16*)propertyDataVector[6];
+ CapturedData = (BYTE*)propertyDataVector[7];
+ PreviousDataType = *(UINT32*)propertyDataVector[8];
+ PreviousDataSize = *(UINT32*)propertyDataVector[9];
+ PreviousDataCapturedSize = *(UINT16*)propertyDataVector[10];
+ PreviousData = (BYTE*)propertyDataVector[11];
+
+ capturedDataString = std::wstring(reinterpret_cast(CapturedData), CapturedDataSize / sizeof(wchar_t));
+
+ //EventWriteRegistrySetValueKey(
+ // &systemTime,
+ // WorkstationName,
+ // KeyName.c_str(),
+ // ValueName.c_str(),
+ // capturedDataString.c_str(),
+ // Type
+ //);
+
+ break;
+ }
+
+ default:
+ {
+ break;
+ }
+ }
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteFileEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ UINT_PTR Irp, FileObject;
+ UINT32 IssuingThreadId, CreateOptions, CreateAttributes, ShareAccess;
+ std::wstring FileName;
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+ bool hasValidExtension;
+ static const std::wregex validExtensions(LR"((\.exe|\.sys|\.dll|\.js|\.vbs|\.ps1|\.bat|\.cmd|\.hta|\.msi)$)", std::regex_constants::icase);
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ Irp = *(UINT_PTR*)propertyDataVector[0];
+ FileObject = *(UINT_PTR*)propertyDataVector[1];
+ IssuingThreadId = *(UINT32*)propertyDataVector[2];
+ CreateOptions = *(UINT32*)propertyDataVector[3];
+ CreateAttributes = *(UINT32*)propertyDataVector[4];
+ ShareAccess = *(UINT32*)propertyDataVector[5];
+ FileName = (WCHAR*)propertyDataVector[6];
+
+ //
+ // Reducing noise by looking for certian extensions
+ //
+ hasValidExtension = std::regex_search(FileName, validExtensions);
+
+ if (!hasValidExtension)
+ {
+ goto Exit;
+ }
+
+ EventWriteFileCreation(
+ &systemTime,
+ WorkstationName,
+ FileName.c_str(),
+ IssuingThreadId,
+ ShareAccess,
+ CreateOptions
+ );
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteServiceEvent(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+ std::wstring ServiceName, ImagePath, ServiceType, StartType, AccountName;
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ ServiceName = (WCHAR*)propertyDataVector[0];
+ ImagePath = (WCHAR*)propertyDataVector[1];
+ ServiceType = (WCHAR*)propertyDataVector[2];
+ StartType = (WCHAR*)propertyDataVector[3];
+ AccountName = (WCHAR*)propertyDataVector[4];
+
+ EventWriteServiceCreation(
+ &systemTime,
+ WorkstationName,
+ ServiceName.c_str(),
+ ImagePath.c_str(),
+ ServiceType.c_str(),
+ StartType.c_str(),
+ AccountName.c_str()
+ );
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteDpapiEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+
+ UINT32 Flags, ProtectionFlags, ReturnValue, CallerProcessID, PlainTextDataSize;
+ std::wstring OperationType, DataDescription;
+ GUID MasterKeyGUID;
+ UINT64 CallerProcessStartKey, CallerProcessCreationTime;
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ OperationType = (WCHAR*)propertyDataVector[0];
+ DataDescription = (WCHAR*)propertyDataVector[1];
+ MasterKeyGUID = *(GUID*)propertyDataVector[2];
+ Flags = *(UINT32*)propertyDataVector[3];
+ ProtectionFlags = *(UINT32*)propertyDataVector[4];
+ ReturnValue = *(UINT32*)propertyDataVector[5];
+ CallerProcessStartKey = *(UINT64*)propertyDataVector[6];
+ CallerProcessID = *(UINT32*)propertyDataVector[7];
+ CallerProcessCreationTime = *(UINT64*)propertyDataVector[8];
+ PlainTextDataSize = *(UINT32*)propertyDataVector[9];
+
+ if (OperationType == L"SPCryptUnprotect")
+ {
+ EventWriteDPAPIUnprotect(
+ &systemTime,
+ WorkstationName,
+ CallerProcessID,
+ OperationType.c_str(),
+ DataDescription.c_str(),
+ Flags,
+ ProtectionFlags
+ );
+
+ }
+
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
+
+NTSTATUS WriteWMIEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+) {
+
+ std::wstring Namespace, ESS, Consumer, PossibleCause;
+ FILETIME fileTime;
+ SYSTEMTIME systemTime;
+ NTSTATUS status = ERROR_SUCCESS;
+ DWORD bufferSize = 0;
+ PTRACE_EVENT_INFO pInfo = nullptr;
+ BYTE** propertyDataVector = nullptr;
+
+ fileTime.dwLowDateTime = EventHeader->TimeStamp.LowPart;
+ fileTime.dwHighDateTime = EventHeader->TimeStamp.HighPart;
+
+ if (!FileTimeToSystemTime(&fileTime, &systemTime)) {
+ OutputDebugString(L"Error converting timestamp\n");
+ status = ERROR_INVALID_DATA;
+ goto Exit;
+ }
+
+ //
+ // Processing ETW
+ //
+ status = EtwEventProcessing(EventRecord, &pInfo, &propertyDataVector);
+ if (status != ERROR_SUCCESS) {
+ goto Exit;
+ }
+
+ Namespace = (WCHAR*)propertyDataVector[0];
+ ESS = (WCHAR*)propertyDataVector[1];
+ Consumer = (WCHAR*)propertyDataVector[2];
+ PossibleCause = (WCHAR*)propertyDataVector[3];
+
+ EventWriteWMIEventFilter(
+ &systemTime,
+ WorkstationName,
+ EventHeader->ProcessId,
+ Namespace.c_str(),
+ ESS.c_str(),
+ Consumer.c_str(),
+ PossibleCause.c_str()
+ );
+
+
+
+Exit:
+ //
+ // Free each element in propertyDataVector and the vector itself
+ //
+ if (propertyDataVector != nullptr) {
+ if (pInfo != nullptr) {
+ for (int i = 0; i < pInfo->TopLevelPropertyCount; i++) {
+ if (propertyDataVector[i] != nullptr) {
+ free(propertyDataVector[i]);
+ }
+ }
+ }
+ free(propertyDataVector);
+ }
+
+ if (pInfo != nullptr) {
+ free(pInfo);
+ }
+
+ return status;
+}
diff --git a/JonMon-Lite/JonMon-Lite-Collector.h b/JonMon-Lite/JonMon-Lite-Collector.h
new file mode 100644
index 0000000..af5420a
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite-Collector.h
@@ -0,0 +1,104 @@
+#pragma once
+#include "JonMon-Lite-Global.h"
+#include
+#pragma comment(lib, "tdh.lib")
+
+
+
+static GUID RPC_Provider = { 0x6ad52b32, 0xd609, 0x4be9, { 0xae, 0x07, 0xce, 0x8d, 0xae, 0x93, 0x7e, 0x39 } };
+static GUID Network_Provider = { 0x7DD42A49,0x5329,0x4832,{0x8D, 0xFD, 0x43, 0xD9, 0x79, 0x15, 0x3A, 0x88} };
+static GUID DotNet_Provider = { 0xe13c0d23, 0xccbc, 0x4e12, { 0x93, 0x1b, 0xd9, 0xcc, 0x2e, 0xee, 0x27, 0xe4 } };
+static GUID AMSI_Provider = { 0x2a576b87, 0x09a7, 0x520e, { 0xc2, 0x1a, 0x49, 0x42, 0xf0, 0x27, 0x1d, 0x67 } };
+static GUID WMIActivty_Provider = { 0x1418ef04, 0xb0b4, 0x4623, { 0xbf, 0x7e, 0xd7, 0x4a, 0xb4, 0x7b, 0xbd, 0xaa } };
+static GUID DPAPI_Provider = { 0x89fe8f40, 0xcdce, 0x464e, { 0x82, 0x17, 0x15, 0xef, 0x97, 0xd4, 0xc7, 0xc3 } };
+static GUID Registry_Provider = { 0x70eb4f03, 0xc1de, 0x4f73, { 0xa0, 0x51, 0x33, 0xd1, 0x3d, 0x54, 0x13, 0xbd } };
+static GUID Process_Provider = { 0x22fb2cd6, 0x0e7b, 0x422b, { 0xa0, 0xc7, 0x2f, 0xad, 0x1f, 0xd0, 0xe7, 0x16 } };
+static GUID File_Provider = { 0xedd08927, 0x9cc4, 0x4e65, { 0xb9, 0x70, 0xc2, 0x56, 0x0f, 0xb5, 0xc2, 0x89 } };
+static GUID Service_Control_Manager_Provider = { 0x555908d1, 0xa6d7, 0x4695, { 0x8e, 0x1e, 0x26, 0x93, 0x1d, 0x20, 0x12, 0xf4 } };
+
+VOID StartCollector(
+ _In_ Etw_Processing* processingInfo
+);
+
+VOID TrimToMaxSize();
+
+ULONGLONG CreateEventHash(
+ _In_ PEVENT_RECORD pEvent
+);
+
+VOID WINAPI ProcessEvents(
+ _In_ PEVENT_RECORD pEvent
+);
+
+NTSTATUS EtwEventProcessing(
+ _In_ PEVENT_RECORD EventRecord,
+ _Out_ PTRACE_EVENT_INFO* ppInfo,
+ _Out_ BYTE*** ppPropertyDataVector
+);
+
+NTSTATUS ProcessEtwProperties(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PTRACE_EVENT_INFO PropertyInfo,
+ _In_ BYTE** EventData
+);
+
+NTSTATUS WriteDotNetEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+BOOL WriteAMSIEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteWMIEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteNetworkEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteRpcEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName,
+ _In_ INT32 EventType
+);
+
+NTSTATUS WriteDpapiEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteFileEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteRegistryEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteProcessCreationEvents(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
+
+NTSTATUS WriteServiceEvent(
+ _In_ PEVENT_RECORD EventRecord,
+ _In_ PEVENT_HEADER EventHeader,
+ _In_ LPWSTR WorkstationName
+);
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite-Creation.cpp b/JonMon-Lite/JonMon-Lite-Creation.cpp
new file mode 100644
index 0000000..86aa675
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite-Creation.cpp
@@ -0,0 +1,275 @@
+#include "JonMon-Lite-Creation.h"
+
+
+VOID CreateCollectorSet(
+ _In_ LPCWSTR workstationName,
+ _In_ LPCWSTR collectorSetName,
+ _In_ LPCWSTR xmlFilePath,
+ _In_ LPCWSTR rootPath,
+ _In_ LPCWSTR userName,
+ _In_ LPCWSTR userPassword
+)
+{
+ HRESULT hr;
+ IDataCollectorSet* pDataCollectorSet = NULL;
+ BSTR bstrWorkstationName = NULL;
+ BSTR bstrXml = NULL;
+ BSTR bstrUserName = NULL;
+ BSTR bstrPassword = NULL;
+ BSTR bstrCollectorSetName = NULL;
+ BSTR bstrRootPath = NULL;
+ IValueMap* pCommitValidation = NULL;
+ DWORD waitResult;
+
+
+ wprintf(L"Creating JonMon-Lite Trace...\n");
+
+ if (wcscmp(workstationName, L"Local") == 0)
+ {
+ bstrWorkstationName = NULL;
+ }
+ else
+ {
+ bstrWorkstationName = SysAllocString(workstationName);
+ }
+
+
+
+ std::wstring xmlContent = ReadXmlFile(xmlFilePath);
+ if (xmlContent.empty()) {
+ wprintf(L"Failed to read XML file or file is empty.\n");
+ goto Exit;
+ }
+
+ //
+ // Convert XML to BSTR
+ //
+ bstrXml = SysAllocString(xmlContent.c_str());
+
+ //
+ // Initializing COM
+ //
+ hr = CoInitializeEx(NULL, COINIT_MULTITHREADED);
+ if (FAILED(hr))
+ {
+ wprintf(L"Failed to initialize COM library. Error: %x\n", hr);
+ goto Exit;
+ }
+
+ //
+ // Create the DataCollectorSet Instance
+ //
+ hr = CoCreateInstance(__uuidof(DataCollectorSet),
+ NULL,
+ CLSCTX_SERVER,
+ __uuidof(IDataCollectorSet),
+ (void**)&pDataCollectorSet);
+
+ if (FAILED(hr)) {
+ wprintf(L"CoCreateInstance(__uuidof(DataCollectorSet) failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ //
+ // Setting CollectorSetDisplayName
+ //
+ bstrCollectorSetName = SysAllocString(collectorSetName);
+
+ hr = pDataCollectorSet->put_DisplayName(
+ bstrCollectorSetName
+ );
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->put_DisplayName failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ //
+ // Setting user that the trace will run under
+ //
+ if (userName != L"")
+ {
+ bstrUserName = SysAllocString(userName);
+ bstrPassword = SysAllocString(userPassword);
+
+ hr = pDataCollectorSet->SetCredentials(
+ bstrUserName,
+ bstrPassword
+ );
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->SetCredentials failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+ else {
+ wprintf(L"Credentials set successfully.\n");
+ }
+ }
+
+ //
+ // Applying RootPath
+ //
+ bstrRootPath = SysAllocString(rootPath);
+
+ hr = pDataCollectorSet->put_RootPath(bstrRootPath);
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->put_RootPath failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+ else {
+ wprintf(L"pDataCollectorSet->put_RootPath was set successfully\n");
+ }
+
+ //
+ // Apply the XML file to the collector set
+ //
+ hr = pDataCollectorSet->SetXml(
+ bstrXml,
+ &pCommitValidation
+ );
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->SetXml failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+ else {
+ wprintf(L"pDataCollectorSet->SetXml was set successfully\n");
+ }
+
+ //
+ // Setting the CollectorSet
+ //
+ hr = pDataCollectorSet->Commit(
+ bstrCollectorSetName,
+ bstrWorkstationName,
+ plaCreateNew,
+ &pCommitValidation
+ );
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->Commit failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ wprintf(L"Collector set '%s' has been created/updated successfully.\n", collectorSetName);
+
+ hr = pDataCollectorSet->Start(VARIANT_TRUE);
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->Start failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ wprintf(L"Collector set '%s' started successfully.\n", collectorSetName);
+
+ waitResult = WaitForSingleObject(finishJobs, INFINITE);
+ if (waitResult == WAIT_OBJECT_0) {
+ hr = pDataCollectorSet->Stop(VARIANT_TRUE);
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->Stop failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ hr = pDataCollectorSet->Delete();
+ if (FAILED(hr)) {
+ wprintf(L"pDataCollectorSet->Delete failed with 0x%x.\n", hr);
+ goto Exit;
+ }
+
+ goto Exit;
+ }
+ else {
+ wprintf(L"WaitForSingleObject failed %d\n", GetLastError());
+ goto Exit;
+ }
+
+Exit:
+ if (bstrCollectorSetName)
+ {
+ SysFreeString(bstrCollectorSetName);
+ }
+ if (bstrUserName)
+ {
+ SysFreeString(bstrUserName);
+ }
+ if (bstrPassword)
+ {
+ SysFreeString(bstrPassword);
+ }
+ if (bstrXml)
+ {
+ SysFreeString(bstrXml);
+ }
+ if (bstrWorkstationName)
+ {
+ SysFreeString(bstrWorkstationName);
+ }
+ if (pDataCollectorSet)
+ {
+ pDataCollectorSet->Release();
+ }
+ CoUninitialize();
+
+ return;
+
+}
+
+
+std::wstring ReadXmlFile(
+ const wchar_t* filePath
+) {
+ FILE* file = nullptr;
+ char* buffer = nullptr;
+ errno_t err;
+ long fileSize;
+ std::wstring result;
+ size_t bytesRead;
+ const unsigned char* pBuffer;
+ int wideLength;
+ wchar_t* wideBuffer = nullptr;
+
+ err = _wfopen_s(&file, filePath, L"rb");
+ if (err != 0 || !file) {
+ wprintf(L"Failed to open file: %s (Error: %d)\n", filePath, err);
+ result = L"";
+ goto Exit;
+ }
+
+ // Get file size
+ fseek(file, 0, SEEK_END);
+ fileSize = ftell(file);
+ fseek(file, 0, SEEK_SET);
+
+ if (fileSize <= 0) {
+ fclose(file);
+ result = L"";
+ goto Exit;
+ }
+
+ // Allocate buffer for file content
+ buffer = new char[fileSize + 2];
+ bytesRead = fread(buffer, 1, fileSize, file);
+ fclose(file);
+
+ buffer[bytesRead] = '\0';
+ buffer[bytesRead + 1] = '\0';
+
+ pBuffer = (unsigned char*)buffer;
+ if (bytesRead >= 3 && pBuffer[0] == 0xEF && pBuffer[1] == 0xBB && pBuffer[2] == 0xBF) {
+ pBuffer += 3;
+ }
+
+ wideLength = MultiByteToWideChar(CP_UTF8, 0, (char*)pBuffer, -1, NULL, 0);
+ wideBuffer = new wchar_t[wideLength];
+ MultiByteToWideChar(CP_UTF8, 0, (char*)pBuffer, -1, wideBuffer, wideLength);
+
+ result = wideBuffer;
+
+
+Exit:
+ if (buffer)
+ {
+ delete[] buffer;
+ }
+ if (wideBuffer)
+ {
+ delete[] wideBuffer;
+ }
+
+ return result;
+}
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite-Creation.h b/JonMon-Lite/JonMon-Lite-Creation.h
new file mode 100644
index 0000000..fce6d0a
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite-Creation.h
@@ -0,0 +1,16 @@
+#pragma once
+#include "JonMon-Lite-Global.h"
+
+VOID CreateCollectorSet(
+ _In_ LPCWSTR workstationName,
+ _In_ LPCWSTR collectorSetName,
+ _In_ LPCWSTR xmlFilePath,
+ _In_ LPCWSTR rootPath,
+ _In_ LPCWSTR userName,
+ _In_ LPCWSTR userPassword
+);
+
+
+std::wstring ReadXmlFile(
+ const wchar_t* filePath
+);
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite-Global.h b/JonMon-Lite/JonMon-Lite-Global.h
new file mode 100644
index 0000000..d63f709
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite-Global.h
@@ -0,0 +1,19 @@
+#pragma once
+#include
+#include
+#include
+#include
+#include
+#include ".\ETWProvider\JonMon-Lite-Provider.h"
+
+struct Etw_Processing
+{
+ std::wstring ETLFilePath;
+ std::wstring WorkstationName;
+};
+
+extern BOOL g_Process;
+
+extern HANDLE programExit;
+
+extern HANDLE finishJobs;
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite.cpp b/JonMon-Lite/JonMon-Lite.cpp
new file mode 100644
index 0000000..bb19b93
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.cpp
@@ -0,0 +1,377 @@
+#include "JonMon-Lite-Global.h"
+#include "JonMon-Lite-Creation.h"
+#include "JonMon-Lite-Collector.h"
+#include "JonMon-Lite.h"
+#include "nlohmann/json.hpp"
+#include
+#include
+
+using json = nlohmann::json;
+
+BOOL g_Process = TRUE;
+
+HANDLE programExit = NULL;
+HANDLE finishJobs = NULL;
+
+VOID ParseConfig(
+ _In_ std::wstring ConfigFile,
+ _Out_ JonMon_Lite_Config* Config
+)
+{
+ std::ifstream jsonFile(ConfigFile.c_str());
+ if (!jsonFile.is_open()) {
+ wprintf(L"Failed to open file: %s\n", ConfigFile.c_str());
+ return;
+ }
+
+ json jsonData;
+ jsonFile >> jsonData;
+
+ std::string tempXMLFilePath = jsonData["XMLFilePath"].get();
+ Config->XMLFilePath = std::wstring(tempXMLFilePath.begin(), tempXMLFilePath.end());
+
+ std::string tempRootFilePath = jsonData["RootPath"].get();
+ Config->RootFilePath = std::wstring(tempRootFilePath.begin(), tempRootFilePath.end());
+
+ std::string tempTraceName = jsonData["TraceName"].get();
+ Config->TraceName = std::wstring(tempTraceName.begin(), tempTraceName.end());
+
+ std::vector tempWorkstationNames = jsonData["WorkstationName"].get>();
+ for (const auto& name : tempWorkstationNames) {
+ Config->WorkstationName.push_back(std::wstring(name.begin(), name.end()));
+ }
+
+ std::string tempUser = jsonData["User"].get();
+ Config->User = std::wstring(tempUser.begin(), tempUser.end());
+
+ std::string tempPassword = jsonData["Password"].get();
+ Config->Password = std::wstring(tempPassword.begin(), tempPassword.end());
+
+ std::string tempETLFilePath = jsonData["ETLFilePath"].get();
+ Config->ETLFilePath = std::wstring(tempETLFilePath.begin(), tempETLFilePath.end());
+
+ return;
+}
+
+VOID CALLBACK ProcessingThreadCallback
+(
+ _In_ PTP_CALLBACK_INSTANCE Instance,
+ _In_ PVOID Context,
+ _In_ PTP_WORK Work
+)
+{
+ Etw_Processing* config = static_cast(Context);
+
+ StartCollector(config);
+
+Exit:
+
+ wprintf(L"Cleaning up ProcessingThreadCallback\n");
+ delete config;
+ return;
+}
+
+DWORD UninstallManifest() {
+ STARTUPINFOW si;
+ PROCESS_INFORMATION pi;
+ DWORD result = 0;
+ wchar_t cmdLine[] = L"C:\\Windows\\System32\\wevtutil.exe um JonMon-Lite-Provider.man";
+
+ EventUnregisterJonMon_Lite();
+
+ printf("Uninstalling ETW Manifest\n");
+
+ ZeroMemory(&si, sizeof(si));
+ si.cb = sizeof(si);
+ ZeroMemory(&pi, sizeof(pi));
+
+ if (!CreateProcessW(NULL, cmdLine, NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi)) {
+ result = GetLastError();
+ }
+
+ WaitForSingleObject(pi.hProcess, INFINITE);
+
+ DeleteFileW(L"C:\\Windows\\JonMon-Lite-Provider.dll");
+
+Exit:
+ if (pi.hProcess)
+ {
+ CloseHandle(pi.hProcess);
+ }
+ if (pi.hThread)
+ {
+ CloseHandle(pi.hThread);
+ }
+ return result;
+}
+
+DWORD InstallManifest() {
+ STARTUPINFOW si{};
+ PROCESS_INFORMATION pi{};
+ BOOL FileCopy = FALSE;
+ DWORD result = UninstallManifest();
+ wchar_t cmdLine[] = L"C:\\Windows\\System32\\wevtutil.exe im JonMon-Lite-Provider.man";
+
+
+ printf("Installing ETW Manifest\n");
+ FileCopy = CopyFileW(L"JonMon-Lite-Provider.dll", L"C:\\Windows\\JonMon-Lite-Provider.dll", FALSE);
+ if (FileCopy == FALSE) {
+ printf("[-] JonMon-Lite-Provider.dll did not copy to C:\\Windows\\JonMon-Lite-Provider.dll\n");
+ printf("error: %d", GetLastError());
+ result = 1;
+ goto Exit;
+ }
+
+ ZeroMemory(&si, sizeof(si));
+ si.cb = sizeof(si);
+ ZeroMemory(&pi, sizeof(pi));
+
+ if (!CreateProcessW(NULL, cmdLine, NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi)) {
+ result = GetLastError();
+ }
+ result = 0;
+ WaitForSingleObject(pi.hProcess, INFINITE);
+
+ EventRegisterJonMon_Lite();
+
+Exit:
+ if (pi.hProcess)
+ {
+ CloseHandle(pi.hProcess);
+ }
+ if (pi.hThread)
+ {
+ CloseHandle(pi.hThread);
+ }
+ return result;
+}
+
+VOID CALLBACK CollectionCreationCallback
+(
+ _In_ PTP_CALLBACK_INSTANCE Instance,
+ _In_ PVOID Context,
+ _In_ PTP_WORK Work
+)
+{
+ Create_Collector_Set* config = static_cast(Context);
+
+ CreateCollectorSet(
+ config->WorkstationName.c_str(),
+ config->TraceName.c_str(),
+ config->XMLFilePath.c_str(),
+ config->RootFilePath.c_str(),
+ config->User.c_str(),
+ config->Password.c_str()
+ );
+
+Exit:
+ wprintf(L"Cleaning up CollectionCreationCallback\n");
+ delete config;
+ return;
+}
+
+int wmain(int argc, wchar_t* argv[])
+{
+ std::wstring ConfigFilePath = L"JonMon-Lite.json";
+ NTSTATUS status = ERROR_SUCCESS;
+ PTP_POOL processesingPool = NULL;
+ TP_CALLBACK_ENVIRON processesingPoolEnv;
+ PTP_WORK processessingWork, collectionWork;
+ PTP_CLEANUP_GROUP cleanupGroup = NULL;
+ DWORD waitResult, manifestResult;
+ std::wstring uncPath;
+
+
+ programExit = CreateEvent(NULL, TRUE, FALSE, NULL);
+ if (programExit == NULL)
+ {
+ wprintf(L"Error creating synchronization object: %d\n", GetLastError());
+ return GetLastError();
+ }
+
+ finishJobs = CreateEvent(NULL, TRUE, FALSE, NULL);
+ if (programExit == NULL)
+ {
+ wprintf(L"Error creating synchronization object: %d\n", GetLastError());
+ return GetLastError();
+ }
+
+ if (argc == 2)
+ {
+ ConfigFilePath = argv[1];
+ }
+
+ JonMon_Lite_Config* config = new JonMon_Lite_Config();
+
+
+ wprintf(L"Reading JonMon-Lite Config File...\n\n");
+
+ ParseConfig(ConfigFilePath, config);
+
+ manifestResult = InstallManifest();
+ if (manifestResult != 0)
+ {
+ wprintf(L"Manifest installation failed...exiting\n");
+ goto Exit;
+ }
+
+ //
+ // Creating thread pool to handle processing
+ //
+ processesingPool = CreateThreadpool(NULL);
+
+ InitializeThreadpoolEnvironment(&processesingPoolEnv);
+
+ SetThreadpoolThreadMaximum(processesingPool, 5);
+ if (!SetThreadpoolThreadMinimum(processesingPool, 3))
+ {
+ wprintf(L"Error with SetThreadpoolThreadMinimum %d\n", GetLastError());
+ goto Exit;
+ }
+
+ SetThreadpoolCallbackPool(&processesingPoolEnv, processesingPool);
+
+ cleanupGroup = CreateThreadpoolCleanupGroup();
+ if (cleanupGroup == NULL)
+ {
+ wprintf(L"Error setting up cleanupGroup: %d\n", GetLastError());
+ goto Exit;
+ }
+
+ SetThreadpoolCallbackCleanupGroup(&processesingPoolEnv, cleanupGroup, NULL);
+
+ for (const auto& workstationName : config->WorkstationName)
+ {
+ std::wstring* etlFilePath = new std::wstring(config->ETLFilePath + workstationName + L"_\\JonMon-Lite.etl");
+
+ wprintf(L"XMLFilePath: %s\n", config->XMLFilePath.c_str());
+ wprintf(L"TraceName: %s\n", config->TraceName.c_str());
+ wprintf(L"ETLFilePath %s\n", config->ETLFilePath.c_str());
+ wprintf(L"RootPath: %s\n", config->RootFilePath.c_str());
+ wprintf(L"WorkstationName: %s\n", workstationName.c_str());
+ wprintf(L"User: %s\n", config->User.c_str());
+ wprintf(L"Password: %s\n\n", config->Password.c_str());
+
+
+ Create_Collector_Set* tempConfig = new Create_Collector_Set
+ {
+ config->TraceName,
+ config->XMLFilePath,
+ config->RootFilePath,
+ workstationName,
+ config->User,
+ config->Password
+ };
+
+
+ collectionWork = CreateThreadpoolWork(CollectionCreationCallback, (PVOID)tempConfig, &processesingPoolEnv);
+ if (collectionWork == NULL) {
+ wprintf(L"CreateThreadpoolWork failed %d\n", GetLastError());
+ delete tempConfig;
+ delete etlFilePath;
+ goto Exit;
+ }
+
+ SubmitThreadpoolWork(collectionWork);
+
+ Etw_Processing* tempProcessing = new Etw_Processing
+ {
+ etlFilePath->c_str(),
+ workstationName,
+ };
+
+ processessingWork = CreateThreadpoolWork(ProcessingThreadCallback, (PVOID)tempProcessing, &processesingPoolEnv);
+ if (processessingWork == NULL) {
+ wprintf(L"CreateThreadpoolWork failed %d\n", GetLastError());
+ delete etlFilePath;
+ delete tempProcessing;
+ goto Exit;
+ }
+
+ SubmitThreadpoolWork(processessingWork);
+ }
+
+ processessingWork = CreateThreadpoolWork(InputConoleCallback, NULL, &processesingPoolEnv);
+ if (processessingWork == NULL) {
+ wprintf(L"CreateThreadpoolWork failed %d\n", GetLastError());
+ goto Exit;
+ }
+
+ SubmitThreadpoolWork(processessingWork);
+
+ waitResult = WaitForSingleObject(programExit, INFINITE);
+ if (waitResult == WAIT_OBJECT_0) {
+ goto Exit;
+ }
+ else {
+ wprintf(L"WaitForSingleObject failed %d\n", GetLastError());
+ goto Exit;
+ }
+
+Exit:
+ SetEvent(finishJobs);
+
+
+ //
+ // create secondary wait
+ //
+ wprintf(L"Moving to cleanup...\n");
+
+ g_Process = FALSE;
+
+ if (cleanupGroup)
+ {
+ CloseThreadpoolCleanupGroupMembers(cleanupGroup, TRUE, NULL);
+ CloseThreadpoolCleanupGroup(cleanupGroup);
+ }
+
+ if (&processesingPoolEnv) {
+ DestroyThreadpoolEnvironment(&processesingPoolEnv);
+ }
+
+ if (processesingPool)
+ {
+ CloseThreadpool(processesingPool);
+ }
+ if (config)
+ {
+ delete config;
+ }
+ if (finishJobs != NULL) {
+ CloseHandle(finishJobs);
+ }
+
+ if (programExit != NULL) {
+ CloseHandle(programExit);
+ }
+
+ manifestResult = UninstallManifest();
+ if (manifestResult != 0)
+ {
+ wprintf(L"Manifest did not uninstall\n");
+ }
+
+ wprintf(L"Cleanup complete\n");
+
+ return 0;
+}
+
+VOID CALLBACK InputConoleCallback
+(
+ _In_ PTP_CALLBACK_INSTANCE Instance,
+ _In_ PVOID Callback,
+ _In_ PTP_WORK Work
+) {
+ BOOL exit_program = FALSE;
+ while (!exit_program) {
+ std::wstring input;
+ std::wcin >> input;
+ if (input == L"exit" || input == L"stop")
+ {
+ exit_program = TRUE;
+ SetEvent(programExit);
+ return;
+ }
+ }
+ return;
+}
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite.h b/JonMon-Lite/JonMon-Lite.h
new file mode 100644
index 0000000..a621c8e
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.h
@@ -0,0 +1,47 @@
+#pragma once
+#include "JonMon-Lite-Global.h"
+
+
+struct JonMon_Lite_Config
+{
+ std::wstring TraceName;
+ std::wstring XMLFilePath;
+ std::wstring ETLFilePath;
+ std::wstring RootFilePath;
+ std::vector WorkstationName;
+ std::wstring User;
+ std::wstring Password;
+};
+
+struct Create_Collector_Set
+{
+ std::wstring TraceName;
+ std::wstring XMLFilePath;
+ std::wstring RootFilePath;
+ std::wstring WorkstationName;
+ std::wstring User;
+ std::wstring Password;
+};
+
+
+
+
+VOID CALLBACK InputConoleCallback
+(
+ _In_ PTP_CALLBACK_INSTANCE Instance,
+ _In_ PVOID Callback,
+ _In_ PTP_WORK Work
+);
+
+
+VOID CALLBACK ProcessingThreadCallback
+(
+ _In_ PTP_CALLBACK_INSTANCE Instance,
+ _In_ PVOID Context,
+ _In_ PTP_WORK Work
+);
+
+VOID ParseConfig(
+ _In_ std::wstring ConfigFile,
+ _Out_ JonMon_Lite_Config* Config
+);
diff --git a/JonMon-Lite/JonMon-Lite.json b/JonMon-Lite/JonMon-Lite.json
new file mode 100644
index 0000000..7dc572f
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.json
@@ -0,0 +1,10 @@
+{
+ "XMLFilePath": "C:\\Users\\johns\\OneDrive\\Desktop\\JonMon-Lite.xml",
+ "ETLFilePath": "C:\\PerfLogs\\Admin\\JonMon-Lite\\",
+ "TraceName": "JonMon-Lite",
+ "Namespace": "Service",
+ "WorkstationName": ["Local", "Remote"],
+ "User": "TestUser",
+ "Password": "Changeme1!"
+
+}
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite.sln b/JonMon-Lite/JonMon-Lite.sln
new file mode 100644
index 0000000..d64e1a4
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.sln
@@ -0,0 +1,31 @@
+
+Microsoft Visual Studio Solution File, Format Version 12.00
+# Visual Studio Version 17
+VisualStudioVersion = 17.13.35931.197 d17.13
+MinimumVisualStudioVersion = 10.0.40219.1
+Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "JonMon-Lite", "JonMon-Lite.vcxproj", "{322285C1-3F4A-4599-8EB5-76F99E184E11}"
+EndProject
+Global
+ GlobalSection(SolutionConfigurationPlatforms) = preSolution
+ Debug|x64 = Debug|x64
+ Debug|x86 = Debug|x86
+ Release|x64 = Release|x64
+ Release|x86 = Release|x86
+ EndGlobalSection
+ GlobalSection(ProjectConfigurationPlatforms) = postSolution
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Debug|x64.ActiveCfg = Debug|x64
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Debug|x64.Build.0 = Debug|x64
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Debug|x86.ActiveCfg = Debug|Win32
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Debug|x86.Build.0 = Debug|Win32
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Release|x64.ActiveCfg = Release|x64
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Release|x64.Build.0 = Release|x64
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Release|x86.ActiveCfg = Release|Win32
+ {322285C1-3F4A-4599-8EB5-76F99E184E11}.Release|x86.Build.0 = Release|Win32
+ EndGlobalSection
+ GlobalSection(SolutionProperties) = preSolution
+ HideSolutionNode = FALSE
+ EndGlobalSection
+ GlobalSection(ExtensibilityGlobals) = postSolution
+ SolutionGuid = {EC80EFEA-7962-42DD-8D8C-3ADD9337C7F7}
+ EndGlobalSection
+EndGlobal
diff --git a/JonMon-Lite/JonMon-Lite.vcxproj b/JonMon-Lite/JonMon-Lite.vcxproj
new file mode 100644
index 0000000..8589459
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.vcxproj
@@ -0,0 +1,146 @@
+
+
+
+
+ Debug
+ Win32
+
+
+ Release
+ Win32
+
+
+ Debug
+ x64
+
+
+ Release
+ x64
+
+
+
+ 17.0
+ Win32Proj
+ {322285c1-3f4a-4599-8eb5-76f99e184e11}
+ JonMonLite
+ 10.0
+
+
+
+ Application
+ true
+ v143
+ Unicode
+
+
+ Application
+ false
+ v143
+ true
+ Unicode
+
+
+ Application
+ true
+ v143
+ Unicode
+
+
+ Application
+ false
+ v143
+ true
+ Unicode
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Level3
+ true
+ WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+
+
+
+
+ Level3
+ true
+ true
+ true
+ WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+ true
+ true
+
+
+
+
+ Level3
+ true
+ _DEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+
+
+
+
+ Level3
+ true
+ true
+ true
+ NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+ .\Lib;%(AdditionalIncludeDirectories)
+
+
+ Console
+ true
+ true
+ true
+
+
+
+
+
+
+ .\Lib;%(AdditionalIncludeDirectories)
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite.vcxproj.filters b/JonMon-Lite/JonMon-Lite.vcxproj.filters
new file mode 100644
index 0000000..e0c3d19
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.vcxproj.filters
@@ -0,0 +1,42 @@
+
+
+
+
+ {4FC737F1-C7A5-4376-A066-2A32D752A2FF}
+ cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx
+
+
+ {93995380-89BD-4b04-88EB-625FBE52EBFB}
+ h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd
+
+
+ {67DA6AB6-F800-4c08-8B7A-83BB121AAD01}
+ rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms
+
+
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+
+
+ Header Files
+
+
+ Header Files
+
+
+ Header Files
+
+
+ Header Files
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/JonMon-Lite.vcxproj.user b/JonMon-Lite/JonMon-Lite.vcxproj.user
new file mode 100644
index 0000000..a6dc6d6
--- /dev/null
+++ b/JonMon-Lite/JonMon-Lite.vcxproj.user
@@ -0,0 +1,10 @@
+
+
+
+
+
+ WindowsLocalDebugger
+
+
+
+
\ No newline at end of file
diff --git a/JonMon-Lite/Lib/nlohmann/adl_serializer.hpp b/JonMon-Lite/Lib/nlohmann/adl_serializer.hpp
new file mode 100644
index 0000000..56a606c
--- /dev/null
+++ b/JonMon-Lite/Lib/nlohmann/adl_serializer.hpp
@@ -0,0 +1,55 @@
+// __ _____ _____ _____
+// __| | __| | | | JSON for Modern C++
+// | | |__ | | | | | | version 3.11.3
+// |_____|_____|_____|_|___| https://github.com/nlohmann/json
+//
+// SPDX-FileCopyrightText: 2013-2023 Niels Lohmann
+// SPDX-License-Identifier: MIT
+
+#pragma once
+
+#include
+
+#include
+#include
+#include
+#include
+
+NLOHMANN_JSON_NAMESPACE_BEGIN
+
+/// @sa https://json.nlohmann.me/api/adl_serializer/
+template
+struct adl_serializer
+{
+ /// @brief convert a JSON value to any value type
+ /// @sa https://json.nlohmann.me/api/adl_serializer/from_json/
+ template
+ static auto from_json(BasicJsonType && j, TargetType& val) noexcept(
+ noexcept(::nlohmann::from_json(std::forward(j), val)))
+ -> decltype(::nlohmann::from_json(std::forward(j), val), void())
+ {
+ ::nlohmann::from_json(std::forward(j), val);
+ }
+
+ /// @brief convert a JSON value to any value type
+ /// @sa https://json.nlohmann.me/api/adl_serializer/from_json/
+ template
+ static auto from_json(BasicJsonType && j) noexcept(
+ noexcept(::nlohmann::from_json(std::forward(j), detail::identity_tag {})))
+ -> decltype(::nlohmann::from_json(std::forward(j), detail::identity_tag {}))
+ {
+ return ::nlohmann::from_json(std::forward(j), detail::identity_tag {});
+ }
+
+ /// @brief convert any value type to a JSON value
+ /// @sa https://json.nlohmann.me/api/adl_serializer/to_json/
+ template
+ static auto to_json(BasicJsonType& j, TargetType && val) noexcept(
+ noexcept(::nlohmann::to_json(j, std::forward(val))))
+ -> decltype(::nlohmann::to_json(j, std::forward(val)), void())
+ {
+ ::nlohmann::to_json(j, std::forward(val));
+ }
+};
+
+NLOHMANN_JSON_NAMESPACE_END
diff --git a/JonMon-Lite/Lib/nlohmann/byte_container_with_subtype.hpp b/JonMon-Lite/Lib/nlohmann/byte_container_with_subtype.hpp
new file mode 100644
index 0000000..91382cd
--- /dev/null
+++ b/JonMon-Lite/Lib/nlohmann/byte_container_with_subtype.hpp
@@ -0,0 +1,103 @@
+// __ _____ _____ _____
+// __| | __| | | | JSON for Modern C++
+// | | |__ | | | | | | version 3.11.3
+// |_____|_____|_____|_|___| https://github.com/nlohmann/json
+//
+// SPDX-FileCopyrightText: 2013-2023 Niels Lohmann
+// SPDX-License-Identifier: MIT
+
+#pragma once
+
+#include // uint8_t, uint64_t
+#include // tie
+#include // move
+
+#include
+
+NLOHMANN_JSON_NAMESPACE_BEGIN
+
+/// @brief an internal type for a backed binary type
+/// @sa https://json.nlohmann.me/api/byte_container_with_subtype/
+template
+class byte_container_with_subtype : public BinaryType
+{
+ public:
+ using container_type = BinaryType;
+ using subtype_type = std::uint64_t;
+
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/byte_container_with_subtype/
+ byte_container_with_subtype() noexcept(noexcept(container_type()))
+ : container_type()
+ {}
+
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/byte_container_with_subtype/
+ byte_container_with_subtype(const container_type& b) noexcept(noexcept(container_type(b)))
+ : container_type(b)
+ {}
+
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/byte_container_with_subtype/
+ byte_container_with_subtype(container_type&& b) noexcept(noexcept(container_type(std::move(b))))
+ : container_type(std::move(b))
+ {}
+
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/byte_container_with_subtype/
+ byte_container_with_subtype(const container_type& b, subtype_type subtype_) noexcept(noexcept(container_type(b)))
+ : container_type(b)
+ , m_subtype(subtype_)
+ , m_has_subtype(true)
+ {}
+
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/byte_container_with_subtype/
+ byte_container_with_subtype(container_type&& b, subtype_type subtype_) noexcept(noexcept(container_type(std::move(b))))
+ : container_type(std::move(b))
+ , m_subtype(subtype_)
+ , m_has_subtype(true)
+ {}
+
+ bool operator==(const byte_container_with_subtype& rhs) const
+ {
+ return std::tie(static_cast(*this), m_subtype, m_has_subtype) ==
+ std::tie(static_cast(rhs), rhs.m_subtype, rhs.m_has_subtype);
+ }
+
+ bool operator!=(const byte_container_with_subtype& rhs) const
+ {
+ return !(rhs == *this);
+ }
+
+ /// @brief sets the binary subtype
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/set_subtype/
+ void set_subtype(subtype_type subtype_) noexcept
+ {
+ m_subtype = subtype_;
+ m_has_subtype = true;
+ }
+
+ /// @brief return the binary subtype
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/subtype/
+ constexpr subtype_type subtype() const noexcept
+ {
+ return m_has_subtype ? m_subtype : static_cast(-1);
+ }
+
+ /// @brief return whether the value has a subtype
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/has_subtype/
+ constexpr bool has_subtype() const noexcept
+ {
+ return m_has_subtype;
+ }
+
+ /// @brief clears the binary subtype
+ /// @sa https://json.nlohmann.me/api/byte_container_with_subtype/clear_subtype/
+ void clear_subtype() noexcept
+ {
+ m_subtype = 0;
+ m_has_subtype = false;
+ }
+
+ private:
+ subtype_type m_subtype = 0;
+ bool m_has_subtype = false;
+};
+
+NLOHMANN_JSON_NAMESPACE_END
diff --git a/JonMon-Lite/Lib/nlohmann/detail/abi_macros.hpp b/JonMon-Lite/Lib/nlohmann/detail/abi_macros.hpp
new file mode 100644
index 0000000..f48b9eb
--- /dev/null
+++ b/JonMon-Lite/Lib/nlohmann/detail/abi_macros.hpp
@@ -0,0 +1,100 @@
+// __ _____ _____ _____
+// __| | __| | | | JSON for Modern C++
+// | | |__ | | | | | | version 3.11.3
+// |_____|_____|_____|_|___| https://github.com/nlohmann/json
+//
+// SPDX-FileCopyrightText: 2013-2023 Niels Lohmann
+// SPDX-License-Identifier: MIT
+
+#pragma once
+
+// This file contains all macro definitions affecting or depending on the ABI
+
+#ifndef JSON_SKIP_LIBRARY_VERSION_CHECK
+ #if defined(NLOHMANN_JSON_VERSION_MAJOR) && defined(NLOHMANN_JSON_VERSION_MINOR) && defined(NLOHMANN_JSON_VERSION_PATCH)
+ #if NLOHMANN_JSON_VERSION_MAJOR != 3 || NLOHMANN_JSON_VERSION_MINOR != 11 || NLOHMANN_JSON_VERSION_PATCH != 3
+ #warning "Already included a different version of the library!"
+ #endif
+ #endif
+#endif
+
+#define NLOHMANN_JSON_VERSION_MAJOR 3 // NOLINT(modernize-macro-to-enum)
+#define NLOHMANN_JSON_VERSION_MINOR 11 // NOLINT(modernize-macro-to-enum)
+#define NLOHMANN_JSON_VERSION_PATCH 3 // NOLINT(modernize-macro-to-enum)
+
+#ifndef JSON_DIAGNOSTICS
+ #define JSON_DIAGNOSTICS 0
+#endif
+
+#ifndef JSON_USE_LEGACY_DISCARDED_VALUE_COMPARISON
+ #define JSON_USE_LEGACY_DISCARDED_VALUE_COMPARISON 0
+#endif
+
+#if JSON_DIAGNOSTICS
+ #define NLOHMANN_JSON_ABI_TAG_DIAGNOSTICS _diag
+#else
+ #define NLOHMANN_JSON_ABI_TAG_DIAGNOSTICS
+#endif
+
+#if JSON_USE_LEGACY_DISCARDED_VALUE_COMPARISON
+ #define NLOHMANN_JSON_ABI_TAG_LEGACY_DISCARDED_VALUE_COMPARISON _ldvcmp
+#else
+ #define NLOHMANN_JSON_ABI_TAG_LEGACY_DISCARDED_VALUE_COMPARISON
+#endif
+
+#ifndef NLOHMANN_JSON_NAMESPACE_NO_VERSION
+ #define NLOHMANN_JSON_NAMESPACE_NO_VERSION 0
+#endif
+
+// Construct the namespace ABI tags component
+#define NLOHMANN_JSON_ABI_TAGS_CONCAT_EX(a, b) json_abi ## a ## b
+#define NLOHMANN_JSON_ABI_TAGS_CONCAT(a, b) \
+ NLOHMANN_JSON_ABI_TAGS_CONCAT_EX(a, b)
+
+#define NLOHMANN_JSON_ABI_TAGS \
+ NLOHMANN_JSON_ABI_TAGS_CONCAT( \
+ NLOHMANN_JSON_ABI_TAG_DIAGNOSTICS, \
+ NLOHMANN_JSON_ABI_TAG_LEGACY_DISCARDED_VALUE_COMPARISON)
+
+// Construct the namespace version component
+#define NLOHMANN_JSON_NAMESPACE_VERSION_CONCAT_EX(major, minor, patch) \
+ _v ## major ## _ ## minor ## _ ## patch
+#define NLOHMANN_JSON_NAMESPACE_VERSION_CONCAT(major, minor, patch) \
+ NLOHMANN_JSON_NAMESPACE_VERSION_CONCAT_EX(major, minor, patch)
+
+#if NLOHMANN_JSON_NAMESPACE_NO_VERSION
+#define NLOHMANN_JSON_NAMESPACE_VERSION
+#else
+#define NLOHMANN_JSON_NAMESPACE_VERSION \
+ NLOHMANN_JSON_NAMESPACE_VERSION_CONCAT(NLOHMANN_JSON_VERSION_MAJOR, \
+ NLOHMANN_JSON_VERSION_MINOR, \
+ NLOHMANN_JSON_VERSION_PATCH)
+#endif
+
+// Combine namespace components
+#define NLOHMANN_JSON_NAMESPACE_CONCAT_EX(a, b) a ## b
+#define NLOHMANN_JSON_NAMESPACE_CONCAT(a, b) \
+ NLOHMANN_JSON_NAMESPACE_CONCAT_EX(a, b)
+
+#ifndef NLOHMANN_JSON_NAMESPACE
+#define NLOHMANN_JSON_NAMESPACE \
+ nlohmann::NLOHMANN_JSON_NAMESPACE_CONCAT( \
+ NLOHMANN_JSON_ABI_TAGS, \
+ NLOHMANN_JSON_NAMESPACE_VERSION)
+#endif
+
+#ifndef NLOHMANN_JSON_NAMESPACE_BEGIN
+#define NLOHMANN_JSON_NAMESPACE_BEGIN \
+ namespace nlohmann \
+ { \
+ inline namespace NLOHMANN_JSON_NAMESPACE_CONCAT( \
+ NLOHMANN_JSON_ABI_TAGS, \
+ NLOHMANN_JSON_NAMESPACE_VERSION) \
+ {
+#endif
+
+#ifndef NLOHMANN_JSON_NAMESPACE_END
+#define NLOHMANN_JSON_NAMESPACE_END \
+ } /* namespace (inline namespace) NOLINT(readability/namespace) */ \
+ } // namespace nlohmann
+#endif
diff --git a/JonMon-Lite/Lib/nlohmann/detail/conversions/from_json.hpp b/JonMon-Lite/Lib/nlohmann/detail/conversions/from_json.hpp
new file mode 100644
index 0000000..aa2f0cb
--- /dev/null
+++ b/JonMon-Lite/Lib/nlohmann/detail/conversions/from_json.hpp
@@ -0,0 +1,497 @@
+// __ _____ _____ _____
+// __| | __| | | | JSON for Modern C++
+// | | |__ | | | | | | version 3.11.3
+// |_____|_____|_____|_|___| https://github.com/nlohmann/json
+//
+// SPDX-FileCopyrightText: 2013-2023 Niels Lohmann
+// SPDX-License-Identifier: MIT
+
+#pragma once
+
+#include // transform
+#include // array
+#include // forward_list
+#include // inserter, front_inserter, end
+#include