| 266 | // |
| 267 | // |
| 268 | bool SystemMonitorController::startInt() |
| 269 | { |
| 270 | TRACE_BEGIN; |
| 271 | LOGLVL(Detailed, "SysMon controller is being started"); |
| 272 | |
| 273 | std::scoped_lock _lock(m_mtxStartStop); |
| 274 | if (m_fInitialized) |
| 275 | { |
| 276 | LOGLVL(Detailed, "SysMon controller already started"); |
| 277 | return false; |
| 278 | } |
| 279 | |
| 280 | Size nStartMode = (m_sStartMode == "auto") ? SERVICE_SYSTEM_START : |
| 281 | ((m_sStartMode == "manual") ? SERVICE_DEMAND_START : SERVICE_DISABLED); |
| 282 | |
| 283 | Variant vResult = execCommand(Dictionary({ |
| 284 | {"processor", Dictionary({{"clsid", CLSID_WinServiceController}}) }, |
| 285 | {"command", "start"}, |
| 286 | {"params", Dictionary({ |
| 287 | {"name", c_sDrvSrvName}, |
| 288 | {"startMode", nStartMode}, |
| 289 | })}, |
| 290 | })); |
| 291 | |
| 292 | vResult = execCommand(Dictionary({ |
| 293 | {"processor", Dictionary({{"clsid", CLSID_WinServiceController}}) }, |
| 294 | {"command", "waitState"}, |
| 295 | {"params", Dictionary({ |
| 296 | {"name", c_sDrvSrvName}, |
| 297 | {"state", SERVICE_RUNNING}, |
| 298 | {"timeout", 2000}, |
| 299 | })}, |
| 300 | })); |
| 301 | |
| 302 | m_fInitialized = true; |
| 303 | m_fWasStarted = true; |
| 304 | |
| 305 | // Connect to fltport should be before update selfprotection |
| 306 | startThreads(); |
| 307 | sendConfig(m_vDefaultDriverConfig); |
| 308 | |
| 309 | // update selfprotection rules |
| 310 | if (!m_vSelfProtectConfig.isNull()) |
| 311 | { |
| 312 | TRACE_BEGIN; |
| 313 | // updateProcessRules |
| 314 | Variant vProcessRulesSets = m_vSelfProtectConfig.get("processRules", Sequence()); |
| 315 | if (vProcessRulesSets.isDictionaryLike()) |
| 316 | vProcessRulesSets = Sequence({ vProcessRulesSets }); |
| 317 | for (auto vProcessRules : vProcessRulesSets) |
| 318 | updateProcessRules(vProcessRules); |
| 319 | |
| 320 | // updateFileRules |
| 321 | Variant vFileRules = m_vSelfProtectConfig.get("fileRules", nullptr); |
| 322 | if(!vFileRules.isNull()) |
| 323 | updateFileRules(vFileRules); |
| 324 | |
| 325 | // updateRegRules |
nothing calls this directly
no test coverage detected