19 #define PRIV_CREATE_TOKEN BIT(2) 20 #define PRIV_ASSIGN_PRIMARY_TOKEN BIT(3) 21 #define PRIV_LOCK_MEMORY BIT(4) 22 #define PRIV_INCREASE_QUOTA BIT(5) 23 #define PRIV_MACHINE_ACCOUNT BIT(6) 24 #define PRIV_TCB BIT(7) 25 #define PRIV_SECURITY BIT(8) 26 #define PRIV_TAKE_OWNERSHIP BIT(9) 27 #define PRIV_LOAD_DRIVER BIT(10) 28 #define PRIV_SYSTEM_PROFILE BIT(11) 29 #define PRIV_SYSTEM_TIME BIT(12) 30 #define PRIV_PROFILE_SINGLE_PROCESS BIT(13) 31 #define PRIV_INCREASE_BASE_PRIORITY BIT(14) 32 #define PRIV_CREATE_PAGEFILE BIT(15) 33 #define PRIV_CREATE_PERMANENT BIT(16) 34 #define PRIV_BACKUP BIT(17) 35 #define PRIV_RESTORE BIT(18) 36 #define PRIV_SHUTDOWN BIT(19) 37 #define PRIV_DEBUG BIT(20) 38 #define PRIV_AUDOT BIT(21) 39 #define PRIV_SYSTEM_ENVIRONMENT BIT(22) 40 #define PRIV_CHANGE_NOTIFY BIT(23) 41 #define PRIV_REMOTE_SHUTDOWN BIT(24) 42 #define PRIV_UNDOCK BIT(25) 43 #define PRIV_SYNC_AGENT BIT(26) 44 #define PRIV_ENABLE_DELEGATION BIT(27) 45 #define PRIV_MANAGE_VOLUME BIT(28) 46 #define PRIV_IMPERSONATE BIT(29) 47 #define PRIV_CREATE_GLOBAL BIT(30) 48 #define PRIV_TRUSTED_CRED_MAN_ACCESS BIT(31) 49 #define PRIV_RELABLE BIT(32) 50 #define PRIV_INCREASE_WORKING_SET BIT(33) 51 #define PRIV_TIMEZONE BIT(34) 52 #define PRIV_CREATE_SYMBOLIC_LINK BIT(35) 54 #define FIRST_KNOWN_PRIVILEGE 02 55 #define LAST_KNOWN_PRIVILEGE 35 97 #endif // _VISIBILITY_H_
A Windows token structure as reported by Introcore alerts.
INTSTATUS IntWinGetAccesTokenFromThread(QWORD EthreadGva, INTRO_WIN_TOKEN *Token)
Reads the contents of a _TOKEN Windows structure assigned to a thread.
INTSTATUS IntWinGetAccessTokenFromProcess(DWORD ProcessId, QWORD EprocessGva, INTRO_WIN_TOKEN *Token)
Reads the contents of a _TOKEN Windows structure assigned to a process.
int INTSTATUS
The status data type.
INTSTATUS IntWinDumpPrivileges(INTRO_TOKEN_PRIVILEGES const *Privileges)
Prints a INTRO_TOKEN_PRIVILEGES structure.
Windows process token privileges.
void IntWinDumpToken(INTRO_WIN_TOKEN const *Token)
Prints a INTRO_WIN_TOKEN structure.
INTSTATUS IntWinGetStartUpTime(QWORD *StartUpTime)
Gets the system startup time.
INTSTATUS IntWinReadSid(QWORD SidAndAttributesGva, INTRO_SID_ATTRIBUTES *Sid)
Reads the contents of a _SID_AND_ATTRIBUTES Windows structure.
INTSTATUS IntWinReadToken(QWORD TokenGva, INTRO_WIN_TOKEN *Token)
Reads the contents of a _TOKEN Windows structure.
void IntWinDumpSid(INTRO_SID_ATTRIBUTES const *Sid)
Prints a INTRO_SID_ATTRIBUTES structure.