Skip to content

v0.10 - Thread Callback

Latest

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 24 Aug 21:40

Fifth sensor: thread creation and termination events are now captured via PsSetCreateThreadNotifyRoutine, queued, and written to disk as structured JSONL, alongside process, image load, network, and registry events.

Added

  • thread_callback.c/.h: KdaMonThreadCallbackRegister/KdaMonThreadCallbackUnregister, registers a thread creation callback via PsSetCreateThreadNotifyRoutine, capturing process ID, thread ID, creation/termination state, creator process ID, and process image path
  • Process image path resolution via PsLookupProcessByProcessId and SeLocateProcessImageName
  • event_types.h: KDAMON_THREAD_EVENT_DATA (PID, process path, TID, creation flag, creator PID)
  • log_writer.c: KdaMonLogWriterWriteThreadEvent, dispatched via switch in KdaMonLogWriterWriteEvent, serializing thread events to structured JSONL
  • Registered/unregistered in DriverEntry/DriverUnload, after the registry callback, with symmetric teardown order
  • KDAMON_THREAD_PATH_MAX added to kdamon_config.h for the fixed-size process path buffer

Changed

  • event_types.h: thread process path now uses KDAMON_THREAD_PATH_MAX from kdamon_config.h instead of a hard-coded size

Notes

  • Validated on a Windows test VM with a dedicated PowerShell test script covering local thread creation/termination and remote thread injection; logs confirm correct pid/creator_pid correlation, including pid != creator_pid for injected threads, with clean driver/service teardown and no BSOD