|
| virtual uint64_t | ProcessHandle () const =0 |
| | Getter for ProcessHandle.
|
| |
| virtual guest_ptr< void > | BaseAddressPtr () const =0 |
| | Getter for BaseAddressPtr.
|
| |
| virtual guest_ptr< void > | BufferPtr () const =0 |
| | Getter for BufferPtr.
|
| |
| virtual uint32_t | BufferSize () const =0 |
| | Getter for BufferSize.
|
| |
| virtual guest_ptr< void > | ResultLengthPtr () const =0 |
| | Getter for ResultLengthPtr.
|
| |
| virtual void | ProcessHandle (uint64_t ProcessHandle)=0 |
| | Setter for ProcessHandle.
|
| |
| virtual void | BaseAddressPtr (const guest_ptr< void > &pBaseAddress)=0 |
| | Setter for BaseAddressPtr.
|
| |
| virtual void | BufferPtr (const guest_ptr< void > &pBuffer)=0 |
| | Setter for BufferPtr.
|
| |
| virtual void | BufferSize (uint32_t BufferSize)=0 |
| | Setter for BufferSize.
|
| |
| virtual void | ResultLengthPtr (const guest_ptr< void > &pResultLength)=0 |
| | Setter for ResultLengthPtr.
|
| |
| virtual uint32_t | ResultLength () const =0 |
| |
| virtual void | ResultLength (uint32_t ResultLength)=0 |
| |
| virtual NTSTATUS | result () const =0 |
| | Get the result code.
|
| |
| virtual void | result (NTSTATUS_CODE code)=0 |
| | Set the result code.
|
| |
| virtual SystemCallIndex | index () const =0 |
| | Get the system call number.
|
| |
| virtual const std::string & | name () const =0 |
| | Get the name of the system call.
|
| |
| virtual void | write (std::ostream &os=std::cout) const =0 |
| | Write a human-readable description of this system call.
|
| |
| virtual Json::Value | json () const =0 |
| |
| virtual bool | will_return () const =0 |
| |
| virtual void | data (const std::string &key, const std::shared_ptr< void > &value)=0 |
| | Store arbitrary data with the SystemCall.
|
| |
| virtual void | data (const std::string &key, std::shared_ptr< void > &&value)=0 |
| | Store arbitrary data with the SystemCall.
|
| |
| virtual std::shared_ptr< void > | data (const std::string &key)=0 |
| | Retrieve arbitrary data stored with the SystemCall.
|
| |
| virtual std::shared_ptr< const void > | data (const std::string &key) const =0 |
| | Retrieve arbitrary data stored with the SystemCall.
|
| |
| virtual bool | supported () const =0 |
| | Check if this system call is supported by a more specific handler.
|
| |
| virtual void | handle_return_event (Event &event)=0 |
| | Handle a system call return event.
|
| |
| virtual | ~SystemCall ()=default |
| | Destroy the instance.
|
| |
Handler class for the NtWriteVirtualMemory system call.