Creative Process Enumeration
ID: 2e67ce98-2cfc-5bfd-929c-e2a4671a0195
STIX ID: report--2e67ce98-2cfc-5bfd-929c-e2a4671a0195
Feed Name: TrustedSec blog
This write-up demonstrates a practical technique to infer process architecture (32-bit vs 64-bit) on Windows by examining the Win32_Process VirtualSize value via WMI/VBScript, provides sample scripts and outputs, compares results with Process Explorer and Task Manager, and discusses edge cases and limitations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
