We previously determined how to tell if a process is packaged or unpackaged using Task Manager. Now let’s find its package and application identity in code.
Windows provides APIs to retrieve package and application identity for a process:
| Identity | Current Process | By Process HANDLE |
By Token |
|---|---|---|---|
| PACKAGE_ID | GetCurrentPackageId() | GetPackageId() | N/A |
| PackageFullName | GetCurrentPackageFullName() | GetPackageFullName() | GetPackageFullNameFromToken() |
| PackageFamilyName | GetCurrentPackageFamilyName() | GetPackageFamilyName() | GetPackageFamilyNameFromToken() |
| ApplicationUserModelId | GetCurrentApplicationUserModelId() | GetApplicationUserModelId() | GetApplicationUserModelIdFromToken() |
If you prefer WinRT:
| Class | Current Process |
|---|---|
| PackageId | Windows.ApplicationModel.Package.Current.Id |
| AppInfo | Windows.ApplicationModel.AppInfo.Current |
Kernel mode
What about kernel mode? Nearly all MSIX APIs require a user-mode caller. The Windows Driver Kit (WDK) provides RtlQueryPackageIdentity() and RtlQueryPackageIdentityEx() for querying package identity from a token.
Tools?
What about tools to do the same? Onward to Part 3…
1 RtlQueryPackageIdentity[Ex]() returns PackageFullName but provides only the Package-Relative Application ID (PRAID) portion of application identity. Additional work is required to compose an ApplicationUserModelId. This is advanced territory best left to a future blog post.🙂
0 comments
Be the first to start the discussion.