hasherezade / process_ghosting

Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Change Process

Frocz opened this issue · comments

commented

Hi, Is there any chance so that i can change the svchost.exe process creation so i can decide what name to use.
And if you can tell me on what command line is the process created and change temp creation, for random file creation...