Fifth sensor: thread creation and termination events are now captured via PsSetCreateThreadNotifyRoutine, queued, and written to disk as structured JSONL, alongside process, image load, network, and registry events.
Added
thread_callback.c/.h:KdaMonThreadCallbackRegister/KdaMonThreadCallbackUnregister, registers a thread creation callback viaPsSetCreateThreadNotifyRoutine, capturing process ID, thread ID, creation/termination state, creator process ID, and process image path- Process image path resolution via
PsLookupProcessByProcessIdandSeLocateProcessImageName event_types.h:KDAMON_THREAD_EVENT_DATA(PID, process path, TID, creation flag, creator PID)log_writer.c:KdaMonLogWriterWriteThreadEvent, dispatched via switch inKdaMonLogWriterWriteEvent, serializing thread events to structured JSONL- Registered/unregistered in
DriverEntry/DriverUnload, after the registry callback, with symmetric teardown order KDAMON_THREAD_PATH_MAXadded tokdamon_config.hfor the fixed-size process path buffer
Changed
event_types.h: thread process path now usesKDAMON_THREAD_PATH_MAXfromkdamon_config.hinstead of a hard-coded size
Notes
- Validated on a Windows test VM with a dedicated PowerShell test script covering local thread creation/termination and remote thread injection; logs confirm correct
pid/creator_pidcorrelation, includingpid != creator_pidfor injected threads, with clean driver/service teardown and no BSOD