Conversation

Jarkko Sakkinen

Lessons learned from capturing Windows environment variables of launched processed with Python.

1. WMI: it's difficult path for short living processes. I could not make this work. Either I run into privilege issues or I have a racy monitoring.
2. sysmon: This is the way to go. Period ;-)

I will never try WMI again, that's for sure. And luckily Windows build issues are not every day thing...

[1] https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
[2] https://pypi.org/project/pywin32/

#windows #wmi #sysmon #win32 #cargo #rust
1
0
3
In sadomasochistic way, hacking Win32 is fun torture from time to time...
1
0
0
I've heard that eBPF is coming for Windows but given how sensitive the whole card house is I stick with this working approach at least next five years forward ;-)
0
0
1