Process-Dump icon indicating copy to clipboard operation
Process-Dump copied to clipboard

Close monitor mode dumps codechunks from ProcessDump injections

Open glmcdona opened this issue 9 years ago • 0 comments

Process Dump hooks NtTerminateProcess and injects a executable region used to handle the hook. When Process Dump then dumps this process on terminate, it will find it's own executable region added for the hook and dump it as a codechunk. Ideally, we wan't to ignore Process Dump's own injections.

glmcdona avatar Sep 19 '16 15:09 glmcdona