ホーム › Security.Authentication.Identity › AuditQueryPerUserPolicy
AuditQueryPerUserPolicy
関数指定ユーザーごとの監査ポリシーを取得する。
シグネチャ
// ADVAPI32.dll
#include <windows.h>
BOOLEAN AuditQueryPerUserPolicy(
PSID pSid,
const GUID* pSubCategoryGuids,
DWORD dwPolicyCount,
AUDIT_POLICY_INFORMATION** ppAuditPolicy
);パラメーター
| 名前 | 型 | 方向 |
|---|---|---|
| pSid | PSID | in |
| pSubCategoryGuids | GUID* | in |
| dwPolicyCount | DWORD | in |
| ppAuditPolicy | AUDIT_POLICY_INFORMATION** | out |
戻り値の型: BOOLEAN
各言語での呼び出し定義
// ADVAPI32.dll
#include <windows.h>
BOOLEAN AuditQueryPerUserPolicy(
PSID pSid,
const GUID* pSubCategoryGuids,
DWORD dwPolicyCount,
AUDIT_POLICY_INFORMATION** ppAuditPolicy
);[DllImport("ADVAPI32.dll", SetLastError = true, ExactSpelling = true)]
static extern byte AuditQueryPerUserPolicy(
IntPtr pSid, // PSID
ref Guid pSubCategoryGuids, // GUID*
uint dwPolicyCount, // DWORD
IntPtr ppAuditPolicy // AUDIT_POLICY_INFORMATION** out
);<DllImport("ADVAPI32.dll", SetLastError:=True, ExactSpelling:=True)>
Public Shared Function AuditQueryPerUserPolicy(
pSid As IntPtr, ' PSID
ByRef pSubCategoryGuids As Guid, ' GUID*
dwPolicyCount As UInteger, ' DWORD
ppAuditPolicy As IntPtr ' AUDIT_POLICY_INFORMATION** out
) As Byte
End Function' pSid : PSID
' pSubCategoryGuids : GUID*
' dwPolicyCount : DWORD
' ppAuditPolicy : AUDIT_POLICY_INFORMATION** out
Declare PtrSafe Function AuditQueryPerUserPolicy Lib "advapi32" ( _
ByVal pSid As LongPtr, _
ByVal pSubCategoryGuids As LongPtr, _
ByVal dwPolicyCount As Long, _
ByVal ppAuditPolicy As LongPtr) As Byte
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。import ctypes
from ctypes import wintypes
AuditQueryPerUserPolicy = ctypes.windll.advapi32.AuditQueryPerUserPolicy
AuditQueryPerUserPolicy.restype = ctypes.c_byte
AuditQueryPerUserPolicy.argtypes = [
wintypes.HANDLE, # pSid : PSID
ctypes.c_void_p, # pSubCategoryGuids : GUID*
wintypes.DWORD, # dwPolicyCount : DWORD
ctypes.c_void_p, # ppAuditPolicy : AUDIT_POLICY_INFORMATION** out
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))require 'fiddle'
require 'fiddle/import'
lib = Fiddle.dlopen('ADVAPI32.dll')
AuditQueryPerUserPolicy = Fiddle::Function.new(
lib['AuditQueryPerUserPolicy'],
[
Fiddle::TYPE_VOIDP, # pSid : PSID
Fiddle::TYPE_VOIDP, # pSubCategoryGuids : GUID*
-Fiddle::TYPE_INT, # dwPolicyCount : DWORD
Fiddle::TYPE_VOIDP, # ppAuditPolicy : AUDIT_POLICY_INFORMATION** out
],
Fiddle::TYPE_CHAR)#[link(name = "advapi32")]
extern "system" {
fn AuditQueryPerUserPolicy(
pSid: *mut core::ffi::c_void, // PSID
pSubCategoryGuids: *const GUID, // GUID*
dwPolicyCount: u32, // DWORD
ppAuditPolicy: *mut *mut AUDIT_POLICY_INFORMATION // AUDIT_POLICY_INFORMATION** out
) -> u8;
}
// crates: windows-sys provides ready-made bindings for this API.$sig = @"
[DllImport("ADVAPI32.dll", SetLastError = true)]
public static extern byte AuditQueryPerUserPolicy(IntPtr pSid, ref Guid pSubCategoryGuids, uint dwPolicyCount, IntPtr ppAuditPolicy);
"@
$api = Add-Type -MemberDefinition $sig -Name 'ADVAPI32_AuditQueryPerUserPolicy' -Namespace Win32 -PassThru
# $api::AuditQueryPerUserPolicy(pSid, pSubCategoryGuids, dwPolicyCount, ppAuditPolicy)#uselib "ADVAPI32.dll"
#func global AuditQueryPerUserPolicy "AuditQueryPerUserPolicy" sptr, sptr, sptr, sptr
; AuditQueryPerUserPolicy pSid, varptr(pSubCategoryGuids), dwPolicyCount, varptr(ppAuditPolicy) ; 戻り値は stat
; pSid : PSID -> "sptr"
; pSubCategoryGuids : GUID* -> "sptr"
; dwPolicyCount : DWORD -> "sptr"
; ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。出力引数:
#uselib "ADVAPI32.dll" #cfunc global AuditQueryPerUserPolicy "AuditQueryPerUserPolicy" sptr, var, int, var ; res = AuditQueryPerUserPolicy(pSid, pSubCategoryGuids, dwPolicyCount, ppAuditPolicy) ; pSid : PSID -> "sptr" ; pSubCategoryGuids : GUID* -> "var" ; dwPolicyCount : DWORD -> "int" ; ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "var" ; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。#uselib "ADVAPI32.dll" #cfunc global AuditQueryPerUserPolicy "AuditQueryPerUserPolicy" sptr, sptr, int, sptr ; res = AuditQueryPerUserPolicy(pSid, varptr(pSubCategoryGuids), dwPolicyCount, varptr(ppAuditPolicy)) ; pSid : PSID -> "sptr" ; pSubCategoryGuids : GUID* -> "sptr" ; dwPolicyCount : DWORD -> "int" ; ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "sptr" ; ※出力/バッファ引数はポインタ方式(token=sptr / 呼び出しは varptr(変数))。
出力引数:
; BOOLEAN AuditQueryPerUserPolicy(PSID pSid, GUID* pSubCategoryGuids, DWORD dwPolicyCount, AUDIT_POLICY_INFORMATION** ppAuditPolicy) #uselib "ADVAPI32.dll" #cfunc global AuditQueryPerUserPolicy "AuditQueryPerUserPolicy" intptr, var, int, var ; res = AuditQueryPerUserPolicy(pSid, pSubCategoryGuids, dwPolicyCount, ppAuditPolicy) ; pSid : PSID -> "intptr" ; pSubCategoryGuids : GUID* -> "var" ; dwPolicyCount : DWORD -> "int" ; ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "var" ; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。; BOOLEAN AuditQueryPerUserPolicy(PSID pSid, GUID* pSubCategoryGuids, DWORD dwPolicyCount, AUDIT_POLICY_INFORMATION** ppAuditPolicy) #uselib "ADVAPI32.dll" #cfunc global AuditQueryPerUserPolicy "AuditQueryPerUserPolicy" intptr, intptr, int, intptr ; res = AuditQueryPerUserPolicy(pSid, varptr(pSubCategoryGuids), dwPolicyCount, varptr(ppAuditPolicy)) ; pSid : PSID -> "intptr" ; pSubCategoryGuids : GUID* -> "intptr" ; dwPolicyCount : DWORD -> "int" ; ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "intptr" ; ※出力/バッファ引数はポインタ方式(token=intptr / 呼び出しは varptr(変数))。
import (
"golang.org/x/sys/windows"
"unsafe"
)
var (
advapi32 = windows.NewLazySystemDLL("ADVAPI32.dll")
procAuditQueryPerUserPolicy = advapi32.NewProc("AuditQueryPerUserPolicy")
)
// pSid (PSID), pSubCategoryGuids (GUID*), dwPolicyCount (DWORD), ppAuditPolicy (AUDIT_POLICY_INFORMATION** out)
r1, _, err := procAuditQueryPerUserPolicy.Call(
uintptr(pSid),
uintptr(pSubCategoryGuids),
uintptr(dwPolicyCount),
uintptr(ppAuditPolicy),
)
_ = err // syscall.Errno (valid when the call sets last-error)
_ = r1 // BOOLEANfunction AuditQueryPerUserPolicy(
pSid: THandle; // PSID
pSubCategoryGuids: PGUID; // GUID*
dwPolicyCount: DWORD; // DWORD
ppAuditPolicy: Pointer // AUDIT_POLICY_INFORMATION** out
): ByteBool; stdcall;
external 'ADVAPI32.dll' name 'AuditQueryPerUserPolicy';result := DllCall("ADVAPI32\AuditQueryPerUserPolicy"
, "Ptr", pSid ; PSID
, "Ptr", pSubCategoryGuids ; GUID*
, "UInt", dwPolicyCount ; DWORD
, "Ptr", ppAuditPolicy ; AUDIT_POLICY_INFORMATION** out
, "Char") ; return: BOOLEAN●AuditQueryPerUserPolicy(pSid, pSubCategoryGuids, dwPolicyCount, ppAuditPolicy) = DLL("ADVAPI32.dll", "byte AuditQueryPerUserPolicy(void*, void*, dword, void*)")
# 呼び出し: AuditQueryPerUserPolicy(pSid, pSubCategoryGuids, dwPolicyCount, ppAuditPolicy)
# pSid : PSID -> "void*"
# pSubCategoryGuids : GUID* -> "void*"
# dwPolicyCount : DWORD -> "dword"
# ppAuditPolicy : AUDIT_POLICY_INFORMATION** out -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。