如何检测Windows新启动进程的权限提升需求?
进程监控程序权限提升识别问题
当前实现方案
- GUI线程:负责处理用户界面交互
- 监控线程:利用Event Tracing for Windows(ETW)监听进程创建事件,将新进程的ID和路径封装为
Process类实例后传递给GUI线程 - 权限提升检查逻辑:
Process类构造时立即读取目标程序的清单文件,通过查找<requestedExecutionLevel level="requireAdministrator" />标记判断该进程是否需要权限提升
遇到的问题
当前方案对大部分.exe进程有效,但无法识别无清单声明却需要权限提升的可执行文件(例如.msi安装包)。我尝试过监控consent.exe和svchost.exe的调用行为,但遇到多进程嵌套启动的场景时,无法准确溯源到触发权限提升的原始进程。我考虑采用类似Process Explorer的进程树映射方案,但顾虑该方案的复杂度和性能开销。
疑问
请问采用进程树映射的方向是否合理?有没有更简单高效的方法来识别需要权限提升的进程?
已实现的核心代码
// Process Listener Thread: void ProcessListener::onRecord(EVENT_RECORD *record) { if ( record->EventHeader.EventDescriptor.Id == EVENT_TRACE_TYPE_START ) { EventParser parser( record ); auto &p_info = parser.getTraceEventInfo(); for ( auto i = 0u; i < p_info->TopLevelPropertyCount; i++ ) { const auto current = p_info->EventPropertyInfoArray[ i ]; const auto property = std::wstring( reinterpret_cast< LPWSTR >( p_info.data() + current.NameOffset ) ); if ( current.nonStructType.InType == TDH_INTYPE_UNICODESTRING ) { if ( property == L"ImageName" ) { auto data = parser.getPropertyData( property ); auto path = std::wstring( reinterpret_cast< const wchar_t * >( data.data() ), data.size() / sizeof( wchar_t ) - 1 ); try { Process process( record->EventHeader.ProcessId, path ); if ( filter_func != nullptr ) { if ( filter_func( process ) ) { queue.push( std::make_unique< Process >( std::move( process ) ) ); } } else { queue.push( std::make_unique< Process >( std::move( process ) ) ); } } catch ( const std::exception &e ) { spdlog::info(e.what()); } } } } } } // GUI Thread: psm.setFilter( [] (const ProcessBase &process)-> bool { return process.getPath().extension() == ".exe" && process.needsElevation() && // Checks the manifest file. process.getPath().wstring().find( L"\\Windows\\System32" ) == std::wstring::npos; } ); psm.run();
内容的提问来源于stack exchange,提问作者Eviatar
相关产品推荐
相关产品推荐

