Detecting Parent Process Spoofing using KrabsETW

This blog post covers how to build a simple PoC program that will use the KrabsETW library to subscribe to an ETW provider in order to detect parent process spoofing.

Last updated