nganhkhoa
72a947ccd7
- Scan _ETHREAD with PoolTag='Thre' - Parse pid/ppid from _EPROCESS - Build process tree from output log - Static link for machine missing Windows C++ dev environment |
||
---|---|---|
.. | ||
dump_test/1 | ||
build_process_tree.py | ||
eprocess_scan_log_2.txt | ||
eprocess_scan.log | ||
file_object_scan_log_2.txt |