v0.5 - Process Callback
The first sensor is live: process create/exit events are now captured, queued, and written to disk as structured JSONL.
Added
process_callback.c/process_callback.h:PsSetCreateProcessNotifyRoutineExcallback, logs process create/exit- Registered/unregistered in
DriverEntry/DriverUnload event_types.h:KDAMON_PROCESS_EVENT_DATA(PID, PPID, create/exit flag, fixed-size image name)log_writer.c:KdaMonLogWriterWriteProcessEvent, dispatched via switch inKdaMonLogWriterWriteEventlog_writer.c:KdaMonJsonEscapeWhelper for safe JSON string escaping of NT-style paths- Reuses
event_queue.c(v0.3) and the log writer pipeline (v0.4) unchanged
Fixed
EventBufferinlog_writer.cundersized for worst-case process event payload (256 → 1000 bytes), causing silent event drops on long pathsppidnow serialized as JSONnullinstead of0for exit events, where no parent PID is provided by the kernel
Notes
- Validated on Windows test VM: process create/exit lifecycle confirmed via DbgView and resulting
.jsonl