Skip to content

EspressoCake/ReadRemoteProcessCommandline_BOF

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 

Repository files navigation

Read Remote Process Commandline BOF

BOF to read the startup arguments of a remote process, when provided a process ID (PID)

Why:

A few use-cases that immediately come to mind:

  • Secondary selection for process injection
  • Inspection of remote commandline arguments to identify possible configuration paths for applications

Building

cd src
make

Usage

  • Load the remote_process_commandline.cna file from the dist folder.
  • Within a beacon: remote_process_commandline process_id_number

Images

Usage

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published