Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-24-2019, 23:04
bolo2002 bolo2002 is offline
VIP
 
Join Date: Apr 2002
Posts: 703
Rept. Given: 112
Rept. Rcvd 14 Times in 13 Posts
Thanks Given: 281
Thanks Rcvd at 262 Times in 168 Posts
bolo2002 Reputation: 14
Quote:
Originally Posted by DavidXanatos View Post
New Release: https://github.com/DavidXanatos/TaskExplorer/releases/tag/v1.0

Finally we arrived at the build v1.0, this build features a extended xprocesshacker.sys that can unprotect (PPL) protected processes.
An other great new feature is a much better remote host name resolution for sockets, instead of just relying on reverse dns (which in the age of CDN's is not very reliable), we monitor ETW events emitted when a process issues a dns query. This way we know what domains every process requested and what IP's it got as answer, hence when observing a new socket we first check in this list for matching entries, when found it is almost certain the socket was opened with the intention to reach the captured domain.

Added

xprocesshacker.sys can now unprotect and re protect protected processes (light)
using ETW Events to monitor what domains individual processes querry
-- enabled more accurate remote hostname column display

Changed

cleaned up PH directory
improved process display for the case when multiple processes are sellected
now using https://github.com/microsoft/krabsetw to monitor ETW events
reworked socket process association
when opening finder the search term ist selected such it can be replaced quickly

Fixed

no longer trying to do reverse dns on adresses that returned no results
Like said Fyyre on (https://forum.exetools.com/showthread.php?t=19038)

excellent work!
your task explorer could even be source closed,i hope your work will not be stolen,it's more than a simple github project.
__________________
I like this forum!
Reply With Quote
  #2  
Old 10-28-2019, 19:44
DavidXanatos DavidXanatos is offline
Family
 
Join Date: Jun 2018
Posts: 183
Rept. Given: 3
Rept. Rcvd 47 Times in 33 Posts
Thanks Given: 59
Thanks Rcvd at 363 Times in 120 Posts
DavidXanatos Reputation: 47
Quote:
Originally Posted by bolo2002 View Post
your task explorer could even be source closed,i hope your work will not be stolen,it's more than a simple github project.
Making a closed source task explorer would be quite paradoxic as the reason I had to code it in the first place was that the Task Manager I was using since almost two decades was itself closed source and stopped being maintained 7 years ago...
So I really wouldn't want to risk putting others in the same kind of pickle I found my self in.
Reply With Quote
  #3  
Old 10-29-2019, 00:01
bolo2002 bolo2002 is offline
VIP
 
Join Date: Apr 2002
Posts: 703
Rept. Given: 112
Rept. Rcvd 14 Times in 13 Posts
Thanks Given: 281
Thanks Rcvd at 262 Times in 168 Posts
bolo2002 Reputation: 14
Quote:
Originally Posted by DavidXanatos View Post
Making a closed source task explorer would be quite paradoxic as the reason I had to code it in the first place was that the Task Manager I was using since almost two decades was itself closed source and stopped being maintained 7 years ago...
So I really wouldn't want to risk putting others in the same kind of pickle I found my self in.
I understand,it were just to say it,frankly for an open source it's a very well done work.
__________________
I like this forum!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Simple Task [make loader for UPX target]... diablo2oo2 General Discussion 1 12-30-2004 07:03
Hackers View Hiew.exe Help ME PiG_DoG General Discussion 5 07-04-2003 04:36


All times are GMT +8. The time now is 17:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )