Driver Problems? Questions? Issues?
Put OSR's experience to work for you! Contact us for assistance with:
  • Creating the right design for your requirements
  • Reviewing your existing driver code
  • Analyzing driver reliability/performance issues
  • Custom training mixed with consulting and focused directly on your specific areas of interest/concern.
Check us out. OSR, the Windows driver experts.

OSR Seminars

Go Back   OSR Online Lists > ntfsd
Welcome, Guest
You must login to post to this list
  Message 1 of 2  
14 Jun 18 07:39
omri aviasr
Join Date: 25 May 2018
Posts To This List: 5
Getting full file path out of WRITE operation

hello, i am developing a minifilter and one of my goals is to know which file in the file system was changed and by which process and how. I am tracking only write operations and i wish to get as much knowledge as i can get about each operation, and send it to a user mode application. 1. One of my goals is finding the full path of the file which was changed and i am a little bit confused about how it could be done. I know it is possible to use FltQueryInformationFile but i couldn't understand if i can get the full path or only the file name. Then someone here in the forums told me about this version of this function in user-mode but still i can't tell if i can get the full path or only the file name. So my question is which is the easiest way of extracting the full path of target file from a WRITE operation passed to the minifilter? 2. Another problem - Can I use the pointer to an OBJECT_FILE given in the minifilter and pass it to the user application and use it there? Because it points only to someplace in the memory. 3. Another small issue if i use XXXQueryinformationFile i should pass the FILE_NAME_INFORMATION to the function but how can i know how much memory to allocate for the path
  Message 2 of 2  
14 Jun 18 08:54
Scott Noone
Join Date: 10 Jul 2002
Posts To This List: 998
List Moderator
Getting full file path out of WRITE operation

You're at the edge of a cliff and about to walk right off. You need to step back and learn more about minifilters. Have you tried playing with MiniSpy? r/minispy Using it along with FileTest can be very enlightening: I recommend adding a secondary volume to your system formatted with FAT. Then ONLY attach MiniSpy to the FAT volume, add some breakpoints, and start getting used to how things work. HTH, -scott OSR @OSRDrivers
Posting Rules  
You may not post new threads
You may not post replies
You may not post attachments
You must login to OSR Online AND be a member of the ntfsd list to be able to post.

All times are GMT -5. The time now is 23:37.

Copyright ©2015, OSR Open Systems Resources, Inc.
Based on vBulletin Copyright ©2000 - 2005, Jelsoft Enterprises Ltd.
Modified under license