Process Ghosting Tool - 64 bits Only!

Based in the excellent article published by Gabriel Landau (Process Ghosting a New Executable Image Tampering Attack, I have developed a tool for Process Ghosting, this should be of help for the detection of such behavior by malware or other threats.

Article (Spanish):

Code & Tool:

4 Likes

This is awesome @Iker! :slightly_smiling_face:

I've shared it with the team and got great feedback. Thanks for taking the time to contribute and share your work -- love being a part of the security community! :heart:

Cheers!
Garrett

2 Likes

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.