ufrisk / MemProcFS

MemProcFS
GNU Affero General Public License v3.0
2.8k stars 352 forks source link

Added findevil APC detection #293

Closed thejanit0r closed 1 month ago

thejanit0r commented 1 month ago

Added a detection to detect the usage of user-mode APCs for hiding beacons from memory scanners (sleeping beacons).

Additional information about APCs and their implementation in a sleeping beacon:

Contributed under the BSD 0-Clause License (0BSD)