0xrawsec / whids

Open Source EDR for Windows
https://rawsec.lu
GNU Affero General Public License v3.0
1.14k stars 138 forks source link

Consider adding TargetImageProtected flag to ProcessAccess events #114

Closed qjerome closed 2 years ago

qjerome commented 2 years ago

https://blog.menasec.net/2022/04/auditing-protected-lsass-runasppl.html

RunAsPPL seems to apply only to LSASS, a more reliable approach would be to use Windows API -> try to use: https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-getprocessinformation