ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
-
Updated
Mar 20, 2024 - C#
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Detecting Cobalt Strike Team Servers on targets through traffic telemetry.
Add a description, image, and links to the cobaltstrike-detection topic page so that developers can more easily learn about it.
To associate your repository with the cobaltstrike-detection topic, visit your repo's landing page and select "manage topics."