From 76424950e373d3b04ac3dd13019151bfba3e8423 Mon Sep 17 00:00:00 2001 From: sumuel Date: Mon, 17 Aug 2026 20:44:55 +0000 Subject: Add the files --- src/detection/uptime/uptime_windows.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 src/detection/uptime/uptime_windows.c (limited to 'src/detection/uptime/uptime_windows.c') diff --git a/src/detection/uptime/uptime_windows.c b/src/detection/uptime/uptime_windows.c new file mode 100644 index 0000000..695edad --- /dev/null +++ b/src/detection/uptime/uptime_windows.c @@ -0,0 +1,17 @@ +#include "uptime.h" +#include "common/time.h" +#include "common/windows/nt.h" + +const char* ffDetectUptime(FFUptimeResult* result) { + // QueryInterruptTime with Win7 support + uint64_t interruptTime = ffKSystemTimeToUInt64(&SharedUserData->InterruptTime); + + result->uptime = interruptTime / 10000; // Convert from 100-nanosecond intervals to milliseconds + result->bootTime = ffTimeGetNow() - result->uptime; + + // Alternatively, `NtQuerySystemInformation(SystemTimeOfDayInformation)` reports the boot time directly, + // whose result exactly equals what WMI `Win32_OperatingSystem` reports + // with much lower accuracy (0.5 seconds) + + return NULL; +} -- cgit v1.2.3