Files
wavestone-cdt-edrsandblast/EDRSandblast/Includes/SyscallProcessUtils.h
T
2023-10-06 16:12:52 +02:00

13 lines
362 B
C

#pragma once
#include <Windows.h>
#include <tchar.h>
#define ProcessImageFileName 27
DWORD SandGetProcessPID(HANDLE hProcess);
PUNICODE_STRING SandGetProcessImage(HANDLE hProcess);
DWORD SandGetProcessFilename(PUNICODE_STRING ProcessImageUnicodeStr, TCHAR* ImageFileName, DWORD nSize);
DWORD SandFindProcessPidByName(TCHAR* targetProcessName, DWORD* pPid);