Skip to content

v0.9 - Registry Callback

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 17 Aug 19:54
· 4 commits to main since this release

Fourth sensor: registry activity (create/set/delete value, key creation) is now captured via CmRegisterCallbackEx, queued, and written to disk as structured JSONL, alongside process, image load, and network events.

Added

  • registry_callback.c/registry_callback.h: KdaMonRegistryCallbackRegister/KdaMonRegistryCallbackUnregister, registers a single registry callback at altitude 360000, dispatching on REG_NOTIFY_CLASS to RegNtPreSetValueKey, RegNtPreDeleteValueKey, and RegNtPostCreateKeyEx
  • Key path resolution via CmCallbackGetKeyObjectIDEx (avoids the deadlock risk documented for ObQueryNameString in registry callbacks), process path resolution via SeLocateProcessImageName
  • event_types.h: KDAMON_REGISTRY_EVENT_DATA (PID, process path, action, key path, value name, value type, raw value data with size, status), KDAMON_REGISTRY_ACTION enum (SET_VALUE/DELETE_VALUE/CREATE_KEY)
  • log_writer.c: KdaMonLogWriterWriteRegistryEvent, dispatched via switch in KdaMonLogWriterWriteEvent, with type-aware value_data formatting (string for REG_SZ/REG_EXPAND_SZ, decimal for REG_DWORD/REG_QWORD, hex for REG_BINARY and unhandled types)
  • NTSTATUS captured on create_key operations, surfaced as hex in logs
  • Registered/unregistered in DriverEntry/DriverUnload, right after the image load callback, consistent with all event producers being torn down before the queue and log writer
  • Reuses event_queue.c (v0.3) and the log writer pipeline (v0.4) unchanged

Changed

  • KDAMON_NETWORK_EVENT_DATA.ProcessId and KDAMON_REGISTRY_EVENT_DATA.ProcessId changed from ULONG to HANDLE, matching the process sensor and correct Windows PID typing

Notes

  • Validated on Windows test VM: reg add/reg delete covering all three actions and all major value types (REG_SZ, REG_EXPAND_SZ, REG_DWORD, REG_QWORD, REG_BINARY); clean load/unload with no BSOD or orphaned kernel callback
  • set_value/delete_value have no captured status (Pre-only notifications); REG_MULTI_SZ logged as hex rather than parsed into individual strings