cuckoo-modified icon indicating copy to clipboard operation
cuckoo-modified copied to clipboard

specify thread that a NT API belongs to

Open william-vu opened this issue 7 years ago • 1 comments

Hi all, Cuckoo intercepts and logs the name and arguments of NT APIs. Is this possible to log the thread ID that calls these APIs? Thank you

william-vu avatar Aug 05 '17 06:08 william-vu

As far as I know there should be a 'TID' column in the behavioural analysis (or API) logs with the thread ID for each call.

kevoreilly avatar Apr 19 '18 08:04 kevoreilly