Neo23x0 / Raccine

A Simple Ransomware Vaccine

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Consider Parent PID spoofing

JohnLaTwC opened this issue · comments

pid = getppid(pid);

You may want to check out this article on parent pid spoofing.
https://pentestlab.blog/2020/02/24/parent-pid-spoofing/

commented

is there any reasonable user land way to detect @JohnLaTwC ?

commented

the only the way I can see to detect PPID spoofing is via ETW..

Afaik, UAC will also spoof your parent process by using svchost service name.

Tüm işlemleri iptal etmek istiyorum