PID | Process name | VAD start | VAD tag |
---|---|---|---|
{{mal.process_id}} | {{mal.process_name}} | {{mal.vad_start}} | {{mal.vad_tag}} |
PID | Process name | Victim module | Victim function | Hook address | Hooking module | Hook mode | Hook type |
---|---|---|---|---|---|---|---|
{{ah.process_id}} | {{ah.process_name}} | {{ah.victim_module}} | {{ah.victim_function}} | {{ah.hook_address}} | {{ah.hooking_module}} | {{ah.hook_mode}} | {{ah.hook_type}} |
PID | Process name | Parent PID | Session ID | Number of threads | Number of handles | Create time | Exit time |
---|---|---|---|---|---|---|---|
{{p.pid}} | {{p.process_name}} | {{p.ppid}} | {{p.session_id}} | {{p.num_threads}} | {{p.num_handles}} | {{p.create_time}} | {{p.exit_time}} |
PID | Process name | In pslist | In psscan | In thrdproc | In pspcid | In csrss | In session | In deskthrd |
---|---|---|---|---|---|---|---|---|
{{p.process_id}} | {{p.process_name}} | {{p.pslist}} | {{p.psscan}} | {{p.thrdproc}} | {{p.pspcid}} | {{p.csrss}} | {{p.session}} | {{p.deskthrd}} |
PID | Process name | Commandline | Dll full name | Dll base | Dll size | Load count |
---|---|---|---|---|---|---|
{{d.process_id}} | {{d.process_name}} | {{d.commandline}} | {{m.dll_full_name}} | {{m.dll_base}} | {{m.dll_size}} | {{m.dll_load_count}} |
PID | Handle name | Handle type | Handle value | Handle granted access | |
---|---|---|---|---|---|
{{h.process_id}} | {{h.handle_name}} | {{h.handle_type}} | {{h.handle_value}} | {{h.handle_granted_access}} | {{h.dll_size}} |
Type | Callback | Module | Detail |
---|---|---|---|
{{h.type}} | {{h.callback}} | {{h.module}} | {{h.details}} |
Offset | Session | Desktop | Thread | Filter | Flags | Function | Module |
---|---|---|---|---|---|---|---|
{{h.offset}} | {{h.session}} | {{h.desktop}} | {{h.thread}} | {{h.filter}} | {{h.flags}} | {{h.function}} | {{h.module}} |
Process Id | Name | SID String | SID Name |
---|---|---|---|
{{h.process_id}} | {{h.filename}} | {{h.sid_string}} | {{h.sid_name}} |
Process Id | Name | Value | Privilege | Attributes | Description |
---|---|---|---|---|---|
{{h.process_id}} | {{h.filename}} | {{h.value}} | {{h.privilege}} | {{h.attributes}} | {{h.description}} |
PID | Process name | Dll mapped path | Dll base | In load | In init | In mem | Load full dll name | Init full dll name | Mem full dll name |
---|---|---|---|---|---|---|---|---|---|
{{l.process_id}} | {{l.process_name}} | {{l.dll_mapped_path}} | {{l.dll_base}} | {{l.dll_in_load}} | {{l.dll_in_init}} | {{l.dll_in_mem}} | {{l.load_full_dll_name}} | {{l.init_full_dll_name}} | {{l.mem_full_dll_name}} |
Driver offset | Driver name | Device offset | Device name | Device type | Attached Device offset | Attached Device name | Attached device type | Attached device level |
---|---|---|---|---|---|---|---|---|
{{dr.driver_offset}} | {{dr.driver_name}} | |||||||
{{de.device_offset}} | {{de.device_name}} | {{de.device_type}} | ||||||
{{at.attached_device_offset}} | {{at.attached_device_name}} | {{at.attached_device_type}} | {{at.level}} |
PID | Service name | Display name | Binary path | Type | State | Service offset | Service order |
---|---|---|---|---|---|---|---|
{{s.process_id}} | {{s.service_name}} | {{s.service_display_name}} | {{s.service_binary_path}} | {{s.service_type}} | {{s.service_state}} | {{s.service_offset}} | {{s.service_order}} |
Module name | Module file name | Module offset | Module base | Module size |
---|---|---|---|---|
{{m.kernel_module_name}} | {{m.kernel_module_file}} | {{m.kernel_module_offset}} | {{m.kernel_module_base}} | {{m.kernel_module_size}} |
CPU | Index | Selector | Address | Module | Section |
---|---|---|---|---|---|
{{h.cpu_number}} | {{h.index}} | {{h.selector}} | {{h.address}} | {{h.module}} | {{h.section}} |
Offset | Due time | Period (ms) | Signaled | Routine | Module |
---|---|---|---|---|---|
{{h.offset}} | {{h.due_time}} | {{h.period}} | {{h.signaled}} | {{h.routine}} | {{h.module}} |