Kansa
Kansa copied to clipboard
Kansa Module & Analysis: DLL Search Order Hijacking
Create an module and/or analysis script that can generate leads for DLL Search Order hijacking.
The Get-ProcsNModules.ps1 doesn't include the actual process name in the output. I don't know if that is by design. Should I open a separate issue?
Relatively easy fix, there's a line commented out in the code that will restore the name of the process.
I saw that. It spits out the full path, so a couple lines to parse that and grab just the process name. I'll work on that tomorrow.