65 WARNING(
"[WARNING] Failed to find MmHighestUserAddress: %08x\n", status);
72 WARNING(
"[WARNING] Failed to read MmHighestUserAddress value!\n");
76 LOG(
"[INTRO-INIT] Found MmHighestUserAddress at GVA 0x%08llx with value 0x%08x\n", expGva, value);
INTSTATUS IntWinGuestIsSupported(void)
Load os information from cami.
INTSTATUS IntPeFindKernelExport(const char *Name, QWORD *ExportGva)
Find an export inside the NT kernel image.
#define INT_STATUS_SUCCESS
#define INT_SUCCESS(Status)
BOOLEAN SafeToApplyOptions
True if the current options can be changed dynamically.
int INTSTATUS
The status data type.
DWORD OSVersion
Os version.
Section will contain information about a supported OS.
INTSTATUS IntKernVirtMemFetchDword(QWORD GuestVirtualAddress, DWORD *Data)
Reads 4 bytes from the guest kernel memory.
BOOLEAN Guest64
True if this is a 64-bit guest, False if it is a 32-bit guest.
Exposes the definitions used by the CAMI parser and the functions used to load guest support informat...
BOOLEAN IntWinGuestIsIncreasedUserVa(void)
Check if the guest has an increased user address space.
GUEST_STATE gGuest
The current guest state.
Section will contain windows related information.
BOOLEAN KptiInstalled
True if KPTI was detected as installed (not necessarily active).
INTSTATUS IntCamiLoadSection(DWORD CamiSectionHint)
Load CAMI objects from section with given hint.