![]() |
Panoptes 1.0.0
Endpoint Detection and Response
|
#include "trace.h"Go to the source code of this file.
Functions | |
| TRACELOGGING_DEFINE_PROVIDER (g_hPanoProvider, "Panoptes",(0x7036af95, 0x9daf, 0x4486, 0x8d, 0x93, 0x70, 0x5, 0xd4, 0x5a, 0x6a, 0x6)) | |
| void | TraceInit () |
| void | TraceUninit () |
| void | Log_DriverEntry (PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath) |
| void | Log_DriverExit (PDRIVER_OBJECT DriverObject) |
| void | Log_MailSlotOpen (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
| void | Log_MailSlotCreate (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
| void | Log_NamedPipeCreate (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
| void | Log_NamedPipeOpen (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
| void | Log_FileCreated (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName, BOOLEAN Oplocked) |
| void | Log_FileOpen (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName, BOOLEAN Oplocked) |
| void | Log_FileOverwritten (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
| void | Log_FileRead (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName, LARGE_INTEGER FileOffset, ULONG ReadLength, BOOLEAN Compressed) |
| void | Log_FileWrite (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName, LARGE_INTEGER FileOffset, ULONG ReadLength, BOOLEAN Compressed) |
| void | Log_FileSuperseded (HANDLE ProcessId, HANDLE ThreadId, PWCH FileName) |
Variables | |
| PDRIVER_OBJECT | g_DriverObject |
| void Log_DriverEntry | ( | PDRIVER_OBJECT | DriverObject, |
| PUNICODE_STRING | RegistryPath | ||
| ) |
Definition at line 22 of file trace.cpp.
References g_DriverObject.
Referenced by DriverEntry().
| void Log_DriverExit | ( | PDRIVER_OBJECT | DriverObject | ) |
Definition at line 34 of file trace.cpp.
Referenced by UnloadPanoptes().
| void Log_FileCreated | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName, | ||
| BOOLEAN | Oplocked | ||
| ) |
Definition at line 97 of file trace.cpp.
| void Log_FileOpen | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName, | ||
| BOOLEAN | Oplocked | ||
| ) |
Definition at line 111 of file trace.cpp.
| void Log_FileOverwritten | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void Log_FileRead | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName, | ||
| LARGE_INTEGER | FileOffset, | ||
| ULONG | ReadLength, | ||
| BOOLEAN | Compressed | ||
| ) |
Definition at line 137 of file trace.cpp.
| void Log_FileSuperseded | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void Log_FileWrite | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName, | ||
| LARGE_INTEGER | FileOffset, | ||
| ULONG | ReadLength, | ||
| BOOLEAN | Compressed | ||
| ) |
Definition at line 155 of file trace.cpp.
| void Log_MailSlotCreate | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void Log_MailSlotOpen | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void Log_NamedPipeCreate | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void Log_NamedPipeOpen | ( | HANDLE | ProcessId, |
| HANDLE | ThreadId, | ||
| PWCH | FileName | ||
| ) |
| void TraceInit | ( | ) |
| TRACELOGGING_DEFINE_PROVIDER | ( | g_hPanoProvider | , |
| "Panoptes" | , | ||
| (0x7036af95, 0x9daf, 0x4486, 0x8d, 0x93, 0x70, 0x5, 0xd4, 0x5a, 0x6a, 0x6) | |||
| ) |
| void TraceUninit | ( | ) |
| PDRIVER_OBJECT g_DriverObject |
Definition at line 3 of file trace.cpp.
Referenced by Log_DriverEntry().