Closed albertziegenhagel closed 1 month ago
Currently we do only intercept calls to the WIN32 API function CreateProcessA and it's unicode variant CreateProcessW.
CreateProcessA
CreateProcessW
We should add support for the remaining functions (that I know of), namely:
CreateProcessAsUserA
CreateProcessAsUserW
CreateProcessWithTokenW
CreateProcessWithLogonW
Support for CreateProcessAsUserA and CreateProcessAsUserW was added in albertziegenhagel/childdebugger-concord#8.
Currently we do only intercept calls to the WIN32 API function
CreateProcessA
and it's unicode variantCreateProcessW
.We should add support for the remaining functions (that I know of), namely:
CreateProcessAsUserA
andCreateProcessAsUserW
CreateProcessWithTokenW
CreateProcessWithLogonW