Skip to content

Remove base directory from File Activity #13

@Rurik

Description

@Rurik

In many runs, especially in Win7+, there are dozens of references to:
"[CreateFolder] Explorer.exe:XXXX > PathToMalware"

The script should have an additional filter, manually implemented into logic, that takes a given malware command line:
"C:\Malware\a.exe"
"%UserProfile\Desktop\Malware\a.exe"

Get os.path.dirname() and use that as a literal (*$) filter.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions