Bill Demirkapi's Blog · Nov 26, 2021
Abusing Windows’ Implementation of Fork() for Stealthy Memory Operations
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Note: Another researcher recently tweeted about the technique discussed in this blog post, this is addressed in the last section of the blog (warning, spoilers!). To access information about a running process, developers generally have to open a handle to the process through the OpenProcess API specifying a combination of
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.