Process Working Directory
ikiril01 opened this issue · comments
Ivan Kirillov commented
Proposed Change
We should add a current_working_directory field to the Process object model, which captures the absolute path to the current working directory of the process.
Field | Description | Example |
---|---|---|
current_working_directory | The current working directory string contains the absolute path to the current working directory of the process. | c:\windows\system32\ |
Justification
Current working directory is associated with UAC Bypass.
wkupersa commented
Also relevant in dll search order hijacking.
Ivan Kirillov commented
Added in b31cc5c