Skip to content

Releases: ignacioj/WhacAMole

File Version: 6.9.22.2531

22 Sep 18:27
09df5b4

Choose a tag to compare

Improved detection of suspicious callbacks in thread pools.

File Version: 6.9.1.2494

01 Sep 18:26
69895ae

Choose a tag to compare

Shows information and alerts for DllNotificationCallbacks. View @dec0ne_DllNotificationInjection: https://shorsec.io/blog/dll-notification-injection/.

File Version: 6.8.25.2462

25 Aug 18:55
84b9be4

Choose a tag to compare

Information about remote RDP sessions is displayed.

File version 6.8.4.2430

04 Aug 17:04
b6940d0

Choose a tag to compare

File Version: 6.5.27.2315

27 May 15:49
e2a8881

Choose a tag to compare

File Version: 6.5.21.2270

21 May 18:00
e2a8881

Choose a tag to compare

File Version: 6.5.6.2128

06 May 17:48
32e2efe

Choose a tag to compare

  • Improved search for previously executable memory that is no longer executable.
  • Added valid string check for Imports and DelayImports for Mapped modules.
  • Mark processes that are GUARD_CF in the process tree with italics.

File Version: 6.4.29.2108

29 Apr 21:11
e5da39d

Choose a tag to compare

Detect regions that were executable and now are not using the Control Flow Guard Bitmap: alert [Memory-Region previously executable].
Added displaying the text of DLLCharacteristics values. Show GUARD protection type memory with: +GUARD.

File Version: 6.4.7.2080

07 Apr 16:29
2d58c21

Choose a tag to compare

Added check to ensure that the address of the exported functions points to a code in an executable memory page.

File Version: 6.4.1.2073

01 Apr 18:06
f27a532

Choose a tag to compare

Added detection of forked processes.
Several improvements.