RSSAmplifier

Bill Demirkapi's Blog · Nov 26, 2021

Abusing Windows’ Implementation of Fork() for Stealthy Memory Operations

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

Note: Another researcher recently tweeted about the technique discussed in this blog post, this is addressed in the last section of the blog (warning, spoilers!). To access information about a running process, developers generally have to open a handle to the process through the OpenProcess API specifying a combination of

Read on billdemirkapi.me

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.