Git Product home page Git Product logo

cmddesktopswitch's Introduction

CmdDesktopSwitch

CmdDesktopSwitch is a small utility that lists all windows desktops assigned to the window station that the default desktop is assigned to. CmdDesktopSwitch then provides the option to switch to one of the enumerated desktops.

This can be used to identify and watch malware that has created a hidden desktop in order to hide a window. More details can be found here.

##How Robust Is This Tool? This tool was mainly developed to be used in the lab not during live response. The tool operates in user land and calls the windows API so it is vulnerable to all the usual hooking techniques used to hide malware. It also only enumerates desktops on the window station that the default desktop is assigned to. The tool can certainly be used during live response but due these limitations it should only be used to prove a positive (ie. there is malware) and never relied on to prove a negative (ie. there is no malware).

##Why Use This Tool? Volatility does a much more thorough job of enumerating desktops however if a memory dump is not available and live response is required the tool could be used. Where it really excels though is during malware analysis. You can use the tool to visually watch malware operate. This is especially useful in the case of ad-fraud malware where the malware has opened a browser on a hidden desktop and is using the browser to defraud advertisers. By using this tool you can actually see what the malware is doing, what ads it is loading, etc.

cmddesktopswitch's People

Contributors

herrcore avatar

Stargazers

 avatar PragmoB avatar  avatar WebCode avatar Mariusz Banach avatar Þórhildur avatar QuickSloth avatar  avatar Andrew Williams avatar Yusuf Arslan Polat avatar Bart P avatar  avatar Radu Alexandru Popescu avatar Mishal Ali avatar  avatar Ronnie Salomonsen avatar Sandor Nemes avatar Mazen Alsenih avatar  avatar cooltree369 avatar  avatar  avatar Tennn avatar genuine_ avatar Minh-Triet Pham Tran avatar  avatar  avatar  avatar  avatar  avatar Jardel Weyrich avatar Alexandre Dulaunoy avatar

Watchers

Minh-Triet Pham Tran avatar James Cloos avatar Radu Alexandru Popescu avatar  avatar Tennn avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.