#ifndef _NTSEAPI_H
NTSYSCALLAPI
NTSTATUS
NTAPI
NtCloseObjectAuditAlarm(
_In_ PUNICODE_STRING SubsystemName,
_In_opt_ PVOID HandleId,
_In_ BOOLEAN GenerateOnClose
);
View code on GitHub
#ifndef _NTZWAPI_H
NTSYSCALLAPI
NTSTATUS
NTAPI
ZwCloseObjectAuditAlarm(
_In_ PUNICODE_STRING SubsystemName,
_In_opt_ PVOID HandleId,
_In_ BOOLEAN GenerateOnClose
);
View code on GitHub
Function NtCloseObjectAuditAlarm
sends alarm to Event Log, section Security. Alarm informs about close user's created object.
This string is sent to Event Log as the first parameter.
HANDLE
to object, or NULL
value.
If set, event is generated.
Privilege: SE_AUDIT_PRIVILEGE