Velocidex / velociraptor

Digging Deeper....
https://docs.velociraptor.app/
Other
2.91k stars 481 forks source link

Add StackTrace to Threads plugin #3158

Open bmcder02 opened 9 months ago

bmcder02 commented 9 months ago

Received a request to add CaptureStackBackTrace to the Threads plugin. If we loop this with GetModuleFileName, it should give a stack trace similar to ProcessHacker (see ref). image

bmcder02 commented 9 months ago

Usecase reference: https://www.safebreach.com/blog/process-injection-using-windows-thread-pools