Skip to content

Significantly reworked Windows architecture handling in Process module#1434

Open
s-m-martin wants to merge 1 commit into
shirou:masterfrom
huntresslabs:chore/sc-81826-research-and-fix-issue-with-arm64-kill-process
Open

Significantly reworked Windows architecture handling in Process module#1434
s-m-martin wants to merge 1 commit into
shirou:masterfrom
huntresslabs:chore/sc-81826-research-and-fix-issue-with-arm64-kill-process

Conversation

@s-m-martin
Copy link
Copy Markdown

@s-m-martin s-m-martin commented Mar 21, 2023

While testing out killing processes on Windows ARM64 hosts, ran into an issue where it just didn't work. After digging into it, turned out to be the wrong memory address for the process itself.

Full disclosure, I'm not a Golang rockstar here - there's probably a smarter way to do this. But, this was functional on ARM64, as well as AMD64 (killing both X86 and AMD64 processes) as well as X86. Let me know what I can do / change to get this up to spec and worthy of merge :)

  - Fixed several issues around struct and pointer sizing for 64-bit queries
  - Process handling now functions as expected on ARM64 Windows hosts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants