Velocidex / velociraptor

Digging Deeper....
https://docs.velociraptor.app/
Other
2.98k stars 492 forks source link

native injection capability #1219

Open mgreen27 opened 3 years ago

mgreen27 commented 3 years ago

We would like an injection detection capability.

Field ideas: image

scudette commented 2 years ago

Can you please elaborate on this one? What exactly are we looking for?

If you just need page read/write/execution you can get that with the vad plugin.

mgreen27 commented 2 years ago

Yes - the idea is to remove the need to run 3rd party scripts/tools for injection detection/leads. Another capability to replicate would be hollows_hunter.