Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ImageLoad detections from hijacklibs.net #195

Open
wants to merge 6 commits into
base: master
Choose a base branch
from

Conversation

nterl0k
Copy link

@nterl0k nterl0k commented Jan 29, 2024

Data sourced from https://hijacklibs.net / https://github.com/wietze/HijackLibs/tree/main.

This include file was written mostly programmatically for each DLL in this project and it's known/expected load locations. It is rather long, so any improvement suggestions are welcome.

I included some minor noise excludes when tested in a modestly size production environment.

I'm willing to share the simple PowerShell code used to develop these files if desired.

Initial upload, pending production exclude tuning. - https://hijacklibs.net/api/hijacklibs.json
minor formatting changes
Trusted Installer noise excludes
Update known noise from production environment testing.
Update excludes after production environment testing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant