From 7136dadeaca4fd8faacc6281cb803bdc7d409073 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 11:59:26 +0900 Subject: [PATCH] test: measure fixed already-enabled debug privilege adjustment --- scripts/TokenRightProbeNative.cs | 4 ++-- tests/TokenRightProbe.Feasibility.ps1 | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/scripts/TokenRightProbeNative.cs b/scripts/TokenRightProbeNative.cs index 323d69c1..3807d522 100644 --- a/scripts/TokenRightProbeNative.cs +++ b/scripts/TokenRightProbeNative.cs @@ -66,10 +66,10 @@ namespace Wela.TokenRightProbe { try { PrimaryOnly(); if(!OpenProcessToken(GetCurrentProcess(),0x28,out token))throw new Win32Exception(Marshal.GetLastWin32Error()); - if(!LookupPrivilegeValue(null,"SeChangeNotifyPrivilege",out target))throw new Win32Exception(Marshal.GetLastWin32Error()); + if(!LookupPrivilegeValue(null,"SeDebugPrivilege",out target))throw new Win32Exception(Marshal.GetLastWin32Error()); result.Luid=Hex(target);result.Before=Read(token);Privilege found=null; foreach(var item in result.Before)if(item.Luid==result.Luid)found=item; - if(found==null||(found.Attributes&2)==0||(found.Attributes&4)!=0)throw new InvalidOperationException("SeChangeNotifyPrivilege must already be present and enabled; no new privilege is granted."); + if(found==null||(found.Attributes&2)==0||(found.Attributes&4)!=0)throw new InvalidOperationException("SeDebugPrivilege must already be present and enabled; no new privilege is granted."); result.OriginalAttributes=found.Attributes; try { result.DisableStartedFileTime=Now();result.AdjustmentAttempted=true; diff --git a/tests/TokenRightProbe.Feasibility.ps1 b/tests/TokenRightProbe.Feasibility.ps1 index 0dd80e4c..4f8d56a1 100644 --- a/tests/TokenRightProbe.Feasibility.ps1 +++ b/tests/TokenRightProbe.Feasibility.ps1 @@ -43,7 +43,7 @@ try{ $events=@(Get-WinEvent -LogName Security -FilterXPath $query -MaxEvents 256 -ErrorAction SilentlyContinue) foreach($event in $events){ $raw=$event.ToXml();[xml]$xml=$raw;$data=@{};foreach($field in $xml.Event.EventData.Data){$data[[string]$field.Name]=[string]$field.'#text'} - if($data.ProcessId -and [Convert]::ToInt64($data.ProcessId,16) -eq $result.ProcessId -and ($data.EnabledPrivilegeList -match 'SeChangeNotifyPrivilege' -or $data.DisabledPrivilegeList -match 'SeChangeNotifyPrivilege')){$matches+=@([pscustomobject]@{RecordId=$event.RecordId;Xml=$raw;Data=$data})} + if($data.ProcessId -and [Convert]::ToInt64($data.ProcessId,16) -eq $result.ProcessId -and ($data.EnabledPrivilegeList -match 'SeDebugPrivilege' -or $data.DisabledPrivilegeList -match 'SeDebugPrivilege')){$matches+=@([pscustomobject]@{RecordId=$event.RecordId;Xml=$raw;Data=$data})} $event.Dispose() } $matches=@($matches|Sort-Object RecordId -Unique)