mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-04 21:44:43 +02:00
test: measure fixed already-enabled debug privilege adjustment
This commit is contained in:
1 parent
cd65133fc4
commit
7136dadeac
2 files changed
+3
-3
No files matched your search
@@ -66,10 +66,10 @@ namespace Wela.TokenRightProbe {
|
||||
try {
|
||||
PrimaryOnly();
|
||||
if(!OpenProcessToken(GetCurrentProcess(),0x28,out token))throw new Win32Exception(Marshal.GetLastWin32Error());
|
||||
if(!LookupPrivilegeValue(null,"SeChangeNotifyPrivilege",out target))throw new Win32Exception(Marshal.GetLastWin32Error());
|
||||
if(!LookupPrivilegeValue(null,"SeDebugPrivilege",out target))throw new Win32Exception(Marshal.GetLastWin32Error());
|
||||
result.Luid=Hex(target);result.Before=Read(token);Privilege found=null;
|
||||
foreach(var item in result.Before)if(item.Luid==result.Luid)found=item;
|
||||
if(found==null||(found.Attributes&2)==0||(found.Attributes&4)!=0)throw new InvalidOperationException("SeChangeNotifyPrivilege must already be present and enabled; no new privilege is granted.");
|
||||
if(found==null||(found.Attributes&2)==0||(found.Attributes&4)!=0)throw new InvalidOperationException("SeDebugPrivilege must already be present and enabled; no new privilege is granted.");
|
||||
result.OriginalAttributes=found.Attributes;
|
||||
try {
|
||||
result.DisableStartedFileTime=Now();result.AdjustmentAttempted=true;
|
||||
|
||||
@@ -43,7 +43,7 @@ try{
|
||||
$events=@(Get-WinEvent -LogName Security -FilterXPath $query -MaxEvents 256 -ErrorAction SilentlyContinue)
|
||||
foreach($event in $events){
|
||||
$raw=$event.ToXml();[xml]$xml=$raw;$data=@{};foreach($field in $xml.Event.EventData.Data){$data[[string]$field.Name]=[string]$field.'#text'}
|
||||
if($data.ProcessId -and [Convert]::ToInt64($data.ProcessId,16) -eq $result.ProcessId -and ($data.EnabledPrivilegeList -match 'SeChangeNotifyPrivilege' -or $data.DisabledPrivilegeList -match 'SeChangeNotifyPrivilege')){$matches+=@([pscustomobject]@{RecordId=$event.RecordId;Xml=$raw;Data=$data})}
|
||||
if($data.ProcessId -and [Convert]::ToInt64($data.ProcessId,16) -eq $result.ProcessId -and ($data.EnabledPrivilegeList -match 'SeDebugPrivilege' -or $data.DisabledPrivilegeList -match 'SeDebugPrivilege')){$matches+=@([pscustomobject]@{RecordId=$event.RecordId;Xml=$raw;Data=$data})}
|
||||
$event.Dispose()
|
||||
}
|
||||
$matches=@($matches|Sort-Object RecordId -Unique)
|
||||
|
||||
Reference in new issue
Block a user