0xflux / Sanctum

Sanctum is a proof-of-concept EDR like tool, designed to detect modern malware techniques, above and beyond the capabilities of antivirus. Built in Rust.
https://fluxsec.red/sanctum-edr-intro
3 stars 1 forks source link

Drv - Intercept new process creation #14

Open 0xflux opened 1 week ago

0xflux commented 1 week ago

TODO: Research what indicators could be found with this one, this technique will most likely combat early bird techniques, create suspended techniques, etc. How this can detect those needs to be researched myself with a few poc's.