wietze / windows-dll-hijacking

Project for identifying executables and DLLs vulnerable to relative path DLL hijacking.
GNU General Public License v3.0
438 stars 73 forks source link

Problem with run_procmon_scan.ps1 #4

Closed josprou closed 5 months ago

josprou commented 2 years ago

The latest version of procmon does not load the generated PMC filters correctly. Go to archive.org and download an older version of procmon. I am using procmon 3.53 and it works fine. Thanks wietze

wietze commented 5 months ago

Hi @josprou , being fully aware your issue is roughly two years old, I did want to close the loop on this one. 3cdbf6e80e0203b0b5c7135306f49267fa3f2c4e has been updated to be compatible with the latest Procmon at the moment of writing, which is v3.96. For you and and anyone else encountering this issue in the future, hopefully this information helps.