-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdetector.cpp
More file actions
89 lines (67 loc) · 3.25 KB
/
Copy pathdetector.cpp
File metadata and controls
89 lines (67 loc) · 3.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
#include "detector.hpp"
PRTL_PROCESS_MODULES SystemModules = nullptr;
ULONG64 TotalGadgets = 0;
void MemoryScan() {
const PPHYSICAL_MEMORY_RANGE physicalMemoryRanges = MmGetPhysicalMemoryRanges();
if (!physicalMemoryRanges) {
LOG_INFO("Failed to get physical memory ranges!");
return;
}
LOG_INFO("Starting memory scan (this can take a while) . . .");
constexpr SIZE_T CHUNK_SIZE = PAGE_SIZE;
for (int i = 0; physicalMemoryRanges[i].BaseAddress.QuadPart || physicalMemoryRanges[i].NumberOfBytes.QuadPart; i++) {
const PHYSICAL_ADDRESS start = physicalMemoryRanges[i].BaseAddress;
const SIZE_T totalSize = static_cast<SIZE_T>(physicalMemoryRanges[i].NumberOfBytes.QuadPart);
for (SIZE_T offset = 0; offset < totalSize; offset += CHUNK_SIZE) {
PHYSICAL_ADDRESS chunkStart;
chunkStart.QuadPart = start.QuadPart + offset;
const SIZE_T chunkSize = min(CHUNK_SIZE, totalSize - offset);
MM_COPY_ADDRESS address;
address.PhysicalAddress = chunkStart;
SIZE_T bytesRead;
UCHAR CheckBuffer[CHUNK_SIZE];
NTSTATUS status = MmCopyMemory(CheckBuffer, address, chunkSize, MM_COPY_MEMORY_PHYSICAL, &bytesRead);
if (!NT_SUCCESS(status) || bytesRead != chunkSize)
continue;
// Scan for gadgets
/*
bool foundGadget = false;
for (SIZE_T j = 0; j < chunkSize - 1; j++) {
if (CheckBuffer[j] == 0xFF && CheckBuffer[j + 1] == 0x25) {
ULONG64 physicalFound = chunkStart.QuadPart + j;
ULONG64 virtualFound = Utils::PhysicalToVirtual(physicalFound);
int instructionOffset;
Utils::ReadVirtualMemory(virtualFound + 2, &instructionOffset, sizeof(instructionOffset));
ULONG64 resolved;
Utils::ReadVirtualMemory(virtualFound + instructionOffset + 6, &resolved, sizeof(resolved));
if (!resolved)
continue;
if (!Detector::IsValidKernel(resolved))
continue;
if (Detector::IsValidAny(virtualFound))
continue;
TotalGadgets++;
foundGadget = true;
LOG_INFO("Found at 0x%llx (0x%llx)", virtualFound, physicalFound);
}
}
*/
}
}
}
bool Detector::IsValidKernel(ULONG64 address) {
const PRTL_PROCESS_MODULE_INFORMATION ntoskrnl = &SystemModules->Modules[0];
const ULONG64 ntoskrnlStart = reinterpret_cast<ULONG64>(ntoskrnl->ImageBase);
const ULONG64 ntoskrnlEnd = ntoskrnlStart + ntoskrnl->ImageSize;
return address >= ntoskrnlStart && address < ntoskrnlEnd;
}
bool Detector::IsValidAny(ULONG64 address) {
for (ULONG_PTR i = 0; i < SystemModules->NumberOfModules; i++) {
const PRTL_PROCESS_MODULE_INFORMATION current = &SystemModules->Modules[i];
const ULONG64 moduleStart = reinterpret_cast<ULONG64>(current->ImageBase);
const ULONG64 moduleEnd = moduleStart + current->ImageSize;
if (address >= moduleStart && address < moduleEnd)
return true;
}
return false;
}