Yarden Shafir@yarden_shafir·Oct 4, 2022Fun fact: this process creation was not actually done by explorer.exe (no, this is not a bug)9867
namazso@namazsoI assume this was done with the thing where you can pass the parent process in process creation parameters?2:57 PM · Oct 4, 20226 Likes
namazso@namazso·Oct 4, 2022*PsAttributeParentProcessgithub.comphnt/ntpsapi.h at 0f32b6e51337b0527344e9c280a6bc6e2b333db0 · winsiderss/phntNative API header files for the System Informer project. - phnt/ntpsapi.h at 0f32b6e51337b0527344e9c280a6bc6e2b333db0 · winsiderss/phnt4
Hypercall@Hypercall3·Oct 5, 2022I guess the same approach like HLeaker (https://github.com/Schnocker/HLeaker/blob/master/HLeaker%20-%20c%2B%2B/HLeaker/Service.cpp#L14…) has been used to accomplish this.github.comHLeaker/HLeaker - c++/HLeaker/Service.cpp at master · Schnocker/HLeakerAn usermode alternative for DuplicateHandle. Contribute to Schnocker/HLeaker development by creating an account on GitHub.