Log in
Sign up
See new Tweets

Conversation

Yarden Shafir
@yarden_shafir
·
Oct 4, 2022
Fun fact: this process creation was not actually done by explorer.exe (no, this is not a bug)
Image
9
8
67
namazso
@namazso
I assume this was done with the thing where you can pass the parent process in process creation parameters?
2:57 PM · Oct 4, 2022
6
Likes
namazso
@namazso
·
Oct 4, 2022
*PsAttributeParentProcess
github.com
phnt/ntpsapi.h at 0f32b6e51337b0527344e9c280a6bc6e2b333db0 · winsiderss/phnt
Native API header files for the System Informer project. - phnt/ntpsapi.h at 0f32b6e51337b0527344e9c280a6bc6e2b333db0 · winsiderss/phnt
4
Yarden Shafir
@yarden_shafir
·
Oct 4, 2022
Exactly :)
1
Hypercall
@Hypercall3
·
Oct 5, 2022
I guess the same approach like HLeaker (https://github.com/Schnocker/HLeaker/blob/master/HLeaker%20-%20c%2B%2B/HLeaker/Service.cpp#L14…) has been used to accomplish this.
github.com
HLeaker/HLeaker - c++/HLeaker/Service.cpp at master · Schnocker/HLeaker
An usermode alternative for DuplicateHandle. Contribute to Schnocker/HLeaker development by creating an account on GitHub.