Skip to content

v0.6 - Image Load Callback

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 02 Aug 22:11
· 18 commits to main since this release

Second sensor: every image (DLL/EXE) loaded into any process is captured, pushed into the existing queue, and written to the log through the standard pipeline.

Added

  • image_callback.c/.h: PsSetLoadImageNotifyRoutine callback, captures image base, size, properties, system/mapped/partial-map flags, signature level/type, and full image path
  • Registered/unregistered in DriverEntry/DriverUnload, after the process callback (unregistered first, symmetric teardown order)
  • event_types.h: KDAMON_IMAGE_LOAD_EVENT_DATA (PID, image base/size, properties, three BOOLEAN-as-ULONG flags, signature level/type, fixed-size image name)
  • log_writer.c: KdaMonLogWriterWriteImageEvent, dispatched via switch in KdaMonLogWriterWriteEvent