Files
wavestone-cdt-edrsandblast/EDRSandblast/Includes/SyscallProcessUtils.h
T
2023-11-29 17:41:10 +01:00

14 lines
364 B
C

#pragma once
#include <Windows.h>
#include <tchar.h>
#define ProcessImageFileName 27
DWORD SandGetProcessPID(HANDLE hProcess);
PUNICODE_STRING SandGetProcessImage(HANDLE hProcess);
DWORD SandGetProcessFilename(PUNICODE_STRING ProcessImageUnicodeStr, LPWSTR ImageFileName, DWORD nSize);
DWORD SandFindProcessPidByName(LPCWSTR targetProcessName, DWORD* pPid);