Skip to content

Real parent detection 2 #5

@lab52io

Description

@lab52io

Add real parent detection using fake ppid

an ID 10 can tell us when a process has a fake parent, using createprocess API

https://twitter.com/SBousseaden/status/1241467646526345221

This one is diferent than mine. (ID 8 Thread ID + ID 10 )

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions