NtGetContextThread
|
thread_handle:
0x00000020
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
17600688
registers.esp:
198307352
registers.edi:
0
registers.eax:
0
registers.ebp:
2
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000020
process_identifier:
2556
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000020
suspend_count:
1
process_identifier:
2556
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000020
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000020
suspend_count:
1
process_identifier:
2556
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2712
thread_handle:
0x000001d0
process_identifier:
2708
current_directory:
filepath:
C:\Windows\System32\whoami.exe
track:
1
command_line:
whoami
filepath_r:
C:\Windows\system32\whoami.exe
stack_pivoted:
0
creation_flags:
525312
(CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x000001d4
|
1
|
1 |
0
|