v0.9 - Registry Callback
Fourth sensor: registry activity (create/set/delete value, key creation) is now captured via CmRegisterCallbackEx, queued, and written to disk as structured JSONL, alongside process, image load, and network events.
Added
registry_callback.c/registry_callback.h:KdaMonRegistryCallbackRegister/KdaMonRegistryCallbackUnregister, registers a single registry callback at altitude360000, dispatching onREG_NOTIFY_CLASStoRegNtPreSetValueKey,RegNtPreDeleteValueKey, andRegNtPostCreateKeyEx- Key path resolution via
CmCallbackGetKeyObjectIDEx(avoids the deadlock risk documented forObQueryNameStringin registry callbacks), process path resolution viaSeLocateProcessImageName event_types.h:KDAMON_REGISTRY_EVENT_DATA(PID, process path, action, key path, value name, value type, raw value data with size, status),KDAMON_REGISTRY_ACTIONenum (SET_VALUE/DELETE_VALUE/CREATE_KEY)log_writer.c:KdaMonLogWriterWriteRegistryEvent, dispatched via switch inKdaMonLogWriterWriteEvent, with type-awarevalue_dataformatting (string forREG_SZ/REG_EXPAND_SZ, decimal forREG_DWORD/REG_QWORD, hex forREG_BINARYand unhandled types)NTSTATUScaptured oncreate_keyoperations, surfaced as hex in logs- Registered/unregistered in
DriverEntry/DriverUnload, right after the image load callback, consistent with all event producers being torn down before the queue and log writer - Reuses
event_queue.c(v0.3) and the log writer pipeline (v0.4) unchanged
Changed
KDAMON_NETWORK_EVENT_DATA.ProcessIdandKDAMON_REGISTRY_EVENT_DATA.ProcessIdchanged fromULONGtoHANDLE, matching the process sensor and correct Windows PID typing
Notes
- Validated on Windows test VM:
reg add/reg deletecovering all three actions and all major value types (REG_SZ,REG_EXPAND_SZ,REG_DWORD,REG_QWORD,REG_BINARY); clean load/unload with no BSOD or orphaned kernel callback set_value/delete_valuehave no captured status (Pre-only notifications);REG_MULTI_SZlogged as hex rather than parsed into individual strings