Windows Process Genealogy

Поділитися
Вставка
  • Опубліковано 26 вер 2024

КОМЕНТАРІ • 22

  • @LambdaVideos
    @LambdaVideos 6 років тому +13

    This is a genuinely fascinating video, and you've presented it perfectly.
    Cheers mate.

    • @13Cubed
      @13Cubed  6 років тому

      Lambda Videos Thanks - much appreciated!

  • @andymcstab534
    @andymcstab534 4 роки тому +1

    Great video. I am currently studying for my sans 508. Exam in two months. This explains things so clearly. Great job!!!

  • @muhammadhassoub299
    @muhammadhassoub299 3 роки тому +2

    Great content as usual. I'm really amazed by this very high quality of your videos. Keep flying to the stars ♥

  • @AshokKumar-mr4pd
    @AshokKumar-mr4pd Рік тому +1

    After searching a lot on youtube, finally found the Holy Grail.

  • @benjaminnewman3833
    @benjaminnewman3833 6 років тому +1

    These memory forensic videos are really helping, keep it up and many thanks

  • @jashandeep8192
    @jashandeep8192 3 роки тому +1

    you are the best forensics instructor i have ever seen.

  • @mduduzithanjekwayo8404
    @mduduzithanjekwayo8404 Рік тому +1

    this was very helpful, thanks

  • @umerkha
    @umerkha 6 років тому +1

    This is amazing! No idea how 23 minutes passed by. When can we expect more?

    • @13Cubed
      @13Cubed  6 років тому

      Umer Khalid Thanks! Plenty of similar videos on the channel, and I usually release at least 1 to 2 new videos each month.

    • @umerkha
      @umerkha 6 років тому +1

      Yup, exploring the channel right now :) I have to say... Great job!

  • @Pteromandias
    @Pteromandias Рік тому

    Thank you for not saying "processies."

  • @RBSRG
    @RBSRG 5 років тому +1

    So in this scenario the malicious svchost is not actually a service it’s just a malicious process pretending to be a svchost? as it was not spawned from services.exe

    • @13Cubed
      @13Cubed  5 років тому +1

      surfa exe You got it.

  • @elenastepanova6901
    @elenastepanova6901 3 роки тому +1

    great video, thanks

  • @ewinch1
    @ewinch1 6 років тому

    Question for memory forensics do you need to take a computer science operating systems course or know C programing?

  • @JeanFrancoisBOBO
    @JeanFrancoisBOBO 6 років тому

    Hello thanks for this video great job.
    It seems to me, however, that in the latest version of windows 10 taskhostw.exe has for parent svchost.exe and not services.exe

    • @13Cubed
      @13Cubed  6 років тому +1

      Jean François BOBO You are correct. In Windows 10 things have changed. See the updated description in this video as I have added a new version of the diagram. I will probably create a short update video that shows the new version of the SANS poster, new diagram, and a couple differences in Windows 10.

    • @JeanFrancoisBOBO
      @JeanFrancoisBOBO 6 років тому +1

      Yeah OK sorry i didnt show it. Good job

    • @JeanFrancoisBOBO
      @JeanFrancoisBOBO 6 років тому

      could we discuss in private way please ?

    • @13Cubed
      @13Cubed  6 років тому

      Jean François BOBO Sure - DM me on Twitter @davisrichardg