process_ghosting
process_ghosting copied to clipboard
Blocked by wdfilter?
Hi,
I think this technique is being blocked by windows defender, even when it's disabled, and I'm not sure how. CreateRemoteThreadEx fails with 0xc0000022. I've confirmed it was working on windows 10 enterprise, with no defender installed.
I believe apps like sandboxie also does something to cause that fail. mabye they hook it