12.07.2013 Views

Anti Incident Response - SANS Computer Forensics

Anti Incident Response - SANS Computer Forensics

Anti Incident Response - SANS Computer Forensics

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8<br />

Windows Process Injection Mechanisms<br />

• VirtualAllocEx()<br />

• VirtualProtect()<br />

• WriteProcessMemory()<br />

• CreateRemoteThread()<br />

• SetWindowsHookEx()<br />

• QueueUserAPC()<br />

© 2012 CrowdStrike, Inc. All rights reserved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!