aboutsummaryrefslogtreecommitdiff
path: root/Exfiltration/mimikatz-1.0/driver/processes.h
diff options
context:
space:
mode:
authorclymb3r <bialek.joseph@gmail.com>2014-04-16 21:02:50 -0700
committerclymb3r <bialek.joseph@gmail.com>2014-04-16 21:02:50 -0700
commitb783b459c12112509a733253df9f5935e104200c (patch)
treee58bce1f7d2f2584d1426262cc609f153d774e51 /Exfiltration/mimikatz-1.0/driver/processes.h
parent47b90647c11cb4956c735cfa47628dc7dcb03bb6 (diff)
parent946328cf9e6d6c60eca2bb9d71a38e210c1c3b6c (diff)
downloadPowerSploit-b783b459c12112509a733253df9f5935e104200c.tar.gz
PowerSploit-b783b459c12112509a733253df9f5935e104200c.zip
Merge branch 'master' of https://github.com/mattifestation/PowerSploit
Conflicts: Recon/Get-ComputerDetails.ps1 Recon/Recon.psd1
Diffstat (limited to 'Exfiltration/mimikatz-1.0/driver/processes.h')
-rw-r--r--Exfiltration/mimikatz-1.0/driver/processes.h33
1 files changed, 0 insertions, 33 deletions
diff --git a/Exfiltration/mimikatz-1.0/driver/processes.h b/Exfiltration/mimikatz-1.0/driver/processes.h
deleted file mode 100644
index ae99825..0000000
--- a/Exfiltration/mimikatz-1.0/driver/processes.h
+++ /dev/null
@@ -1,33 +0,0 @@
-#pragma once
-#include <ntifs.h>
-#include "k_types.h"
-
-#define INDEX_EPROCESS_NEXT 0
-#define INDEX_EPROCESS_FLAGS2 1
-#define INDEX_TOKEN_PRIVS 2
-#define MAX_EPROCESS_LEN 3
-
-#define TOKEN_FROZEN_MASK 0x00008000
-
-typedef struct _KIWI_NT6_PRIVILEGES
-{
- UCHAR Present[8];
- UCHAR Enabled[8];
- UCHAR EnabledByDefault[8];
-} KIWI_NT6_PRIVILEGES, *PKIWI_NT6_PRIVILEGES;
-
-typedef enum _KIWI_EPROCESS_ACTION
-{
- ListProcesses,
- ExchangeToken,
- FullPrivilegeNT6
-} KIWI_EPROCESS_ACTION;
-
-extern char* PsGetProcessImageFileName(PEPROCESS monProcess);
-extern NTSYSAPI NTSTATUS NTAPI ZwSetInformationProcess (__in HANDLE ProcessHandle, __in PROCESSINFOCLASS ProcessInformationClass, __in_bcount(ProcessInformationLength) PVOID ProcessInformation, __in ULONG ProcessInformationLength);
-
-NTSTATUS listProcesses(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
-NTSTATUS sysToken(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
-NTSTATUS privProcesses(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
-
-NTSTATUS listProcessesOrSysToken(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining, KIWI_EPROCESS_ACTION action); \ No newline at end of file