Win32 API 日本語リファレンス
ホームSecurity › PrivilegedServiceAuditAlarmA

PrivilegedServiceAuditAlarmA

関数
特権サービスの使用について監査アラームを生成する(ANSI版)。
DLLADVAPI32.dll文字セットANSI (-A)呼出規約winapiSetLastErrorあり対応OSWindows XP 以降

シグネチャ

// ADVAPI32.dll  (ANSI / -A)
#include <windows.h>

BOOL PrivilegedServiceAuditAlarmA(
    LPCSTR SubsystemName,
    LPCSTR ServiceName,
    HANDLE ClientToken,
    PRIVILEGE_SET* Privileges,
    BOOL AccessGranted
);

パラメーター

名前方向
SubsystemNameLPCSTRin
ServiceNameLPCSTRin
ClientTokenHANDLEin
PrivilegesPRIVILEGE_SET*in
AccessGrantedBOOLin

戻り値の型: BOOL

各言語での呼び出し定義

// ADVAPI32.dll  (ANSI / -A)
#include <windows.h>

BOOL PrivilegedServiceAuditAlarmA(
    LPCSTR SubsystemName,
    LPCSTR ServiceName,
    HANDLE ClientToken,
    PRIVILEGE_SET* Privileges,
    BOOL AccessGranted
);
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", CharSet = CharSet.Ansi, SetLastError = true, ExactSpelling = true)]
static extern bool PrivilegedServiceAuditAlarmA(
    [MarshalAs(UnmanagedType.LPStr)] string SubsystemName,   // LPCSTR
    [MarshalAs(UnmanagedType.LPStr)] string ServiceName,   // LPCSTR
    IntPtr ClientToken,   // HANDLE
    IntPtr Privileges,   // PRIVILEGE_SET*
    bool AccessGranted   // BOOL
);
<DllImport("ADVAPI32.dll", CharSet:=CharSet.Ansi, SetLastError:=True, ExactSpelling:=True)>
Public Shared Function PrivilegedServiceAuditAlarmA(
    <MarshalAs(UnmanagedType.LPStr)> SubsystemName As String,   ' LPCSTR
    <MarshalAs(UnmanagedType.LPStr)> ServiceName As String,   ' LPCSTR
    ClientToken As IntPtr,   ' HANDLE
    Privileges As IntPtr,   ' PRIVILEGE_SET*
    AccessGranted As Boolean   ' BOOL
) As Boolean
End Function
' SubsystemName : LPCSTR
' ServiceName : LPCSTR
' ClientToken : HANDLE
' Privileges : PRIVILEGE_SET*
' AccessGranted : BOOL
Declare PtrSafe Function PrivilegedServiceAuditAlarmA Lib "advapi32" ( _
    ByVal SubsystemName As String, _
    ByVal ServiceName As String, _
    ByVal ClientToken As LongPtr, _
    ByVal Privileges As LongPtr, _
    ByVal AccessGranted As Long) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

PrivilegedServiceAuditAlarmA = ctypes.windll.advapi32.PrivilegedServiceAuditAlarmA
PrivilegedServiceAuditAlarmA.restype = wintypes.BOOL
PrivilegedServiceAuditAlarmA.argtypes = [
    wintypes.LPCSTR,  # SubsystemName : LPCSTR
    wintypes.LPCSTR,  # ServiceName : LPCSTR
    wintypes.HANDLE,  # ClientToken : HANDLE
    ctypes.c_void_p,  # Privileges : PRIVILEGE_SET*
    wintypes.BOOL,  # AccessGranted : BOOL
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('ADVAPI32.dll')
PrivilegedServiceAuditAlarmA = Fiddle::Function.new(
  lib['PrivilegedServiceAuditAlarmA'],
  [
    Fiddle::TYPE_VOIDP,  # SubsystemName : LPCSTR
    Fiddle::TYPE_VOIDP,  # ServiceName : LPCSTR
    Fiddle::TYPE_VOIDP,  # ClientToken : HANDLE
    Fiddle::TYPE_VOIDP,  # Privileges : PRIVILEGE_SET*
    Fiddle::TYPE_INT,  # AccessGranted : BOOL
  ],
  Fiddle::TYPE_INT)
#[link(name = "advapi32")]
extern "system" {
    fn PrivilegedServiceAuditAlarmA(
        SubsystemName: *const u8,  // LPCSTR
        ServiceName: *const u8,  // LPCSTR
        ClientToken: *mut core::ffi::c_void,  // HANDLE
        Privileges: *mut PRIVILEGE_SET,  // PRIVILEGE_SET*
        AccessGranted: i32  // BOOL
    ) -> i32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[return: MarshalAs(UnmanagedType.Bool)]
[DllImport("ADVAPI32.dll", CharSet = CharSet.Ansi, SetLastError = true)]
public static extern bool PrivilegedServiceAuditAlarmA([MarshalAs(UnmanagedType.LPStr)] string SubsystemName, [MarshalAs(UnmanagedType.LPStr)] string ServiceName, IntPtr ClientToken, IntPtr Privileges, bool AccessGranted);
"@
$api = Add-Type -MemberDefinition $sig -Name 'ADVAPI32_PrivilegedServiceAuditAlarmA' -Namespace Win32 -PassThru
# $api::PrivilegedServiceAuditAlarmA(SubsystemName, ServiceName, ClientToken, Privileges, AccessGranted)
#uselib "ADVAPI32.dll"
#func global PrivilegedServiceAuditAlarmA "PrivilegedServiceAuditAlarmA" sptr, sptr, sptr, sptr, sptr
; PrivilegedServiceAuditAlarmA SubsystemName, ServiceName, ClientToken, varptr(Privileges), AccessGranted   ; 戻り値は stat
; SubsystemName : LPCSTR -> "sptr"
; ServiceName : LPCSTR -> "sptr"
; ClientToken : HANDLE -> "sptr"
; Privileges : PRIVILEGE_SET* -> "sptr"
; AccessGranted : BOOL -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "ADVAPI32.dll"
#cfunc global PrivilegedServiceAuditAlarmA "PrivilegedServiceAuditAlarmA" str, str, sptr, var, int
; res = PrivilegedServiceAuditAlarmA(SubsystemName, ServiceName, ClientToken, Privileges, AccessGranted)
; SubsystemName : LPCSTR -> "str"
; ServiceName : LPCSTR -> "str"
; ClientToken : HANDLE -> "sptr"
; Privileges : PRIVILEGE_SET* -> "var"
; AccessGranted : BOOL -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; BOOL PrivilegedServiceAuditAlarmA(LPCSTR SubsystemName, LPCSTR ServiceName, HANDLE ClientToken, PRIVILEGE_SET* Privileges, BOOL AccessGranted)
#uselib "ADVAPI32.dll"
#cfunc global PrivilegedServiceAuditAlarmA "PrivilegedServiceAuditAlarmA" str, str, intptr, var, int
; res = PrivilegedServiceAuditAlarmA(SubsystemName, ServiceName, ClientToken, Privileges, AccessGranted)
; SubsystemName : LPCSTR -> "str"
; ServiceName : LPCSTR -> "str"
; ClientToken : HANDLE -> "intptr"
; Privileges : PRIVILEGE_SET* -> "var"
; AccessGranted : BOOL -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	advapi32 = windows.NewLazySystemDLL("ADVAPI32.dll")
	procPrivilegedServiceAuditAlarmA = advapi32.NewProc("PrivilegedServiceAuditAlarmA")
)

// SubsystemName (LPCSTR), ServiceName (LPCSTR), ClientToken (HANDLE), Privileges (PRIVILEGE_SET*), AccessGranted (BOOL)
r1, _, err := procPrivilegedServiceAuditAlarmA.Call(
	uintptr(unsafe.Pointer(windows.BytePtrFromString(SubsystemName))),
	uintptr(unsafe.Pointer(windows.BytePtrFromString(ServiceName))),
	uintptr(ClientToken),
	uintptr(Privileges),
	uintptr(AccessGranted),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // BOOL
function PrivilegedServiceAuditAlarmA(
  SubsystemName: PAnsiChar;   // LPCSTR
  ServiceName: PAnsiChar;   // LPCSTR
  ClientToken: THandle;   // HANDLE
  Privileges: Pointer;   // PRIVILEGE_SET*
  AccessGranted: BOOL   // BOOL
): BOOL; stdcall;
  external 'ADVAPI32.dll' name 'PrivilegedServiceAuditAlarmA';
result := DllCall("ADVAPI32\PrivilegedServiceAuditAlarmA"
    , "AStr", SubsystemName   ; LPCSTR
    , "AStr", ServiceName   ; LPCSTR
    , "Ptr", ClientToken   ; HANDLE
    , "Ptr", Privileges   ; PRIVILEGE_SET*
    , "Int", AccessGranted   ; BOOL
    , "Int")   ; return: BOOL
●PrivilegedServiceAuditAlarmA(SubsystemName, ServiceName, ClientToken, Privileges, AccessGranted) = DLL("ADVAPI32.dll", "bool PrivilegedServiceAuditAlarmA(char*, char*, void*, void*, bool)")
# 呼び出し: PrivilegedServiceAuditAlarmA(SubsystemName, ServiceName, ClientToken, Privileges, AccessGranted)
# SubsystemName : LPCSTR -> "char*"
# ServiceName : LPCSTR -> "char*"
# ClientToken : HANDLE -> "void*"
# Privileges : PRIVILEGE_SET* -> "void*"
# AccessGranted : BOOL -> "bool"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。