feature: process->name is now without path (its in process->image_path))

This commit is contained in:
Dobin Rutishauser
2026-06-19 09:00:22 +02:00
parent 93b63bd85f
commit 0f60bdf134
2 changed files with 17 additions and 2 deletions
+15 -1
View File
@@ -14,6 +14,19 @@ void LOG_W(int verbosity, const wchar_t* format, ...);
void LOG_A(int verbosity, const char* format, ...); void LOG_A(int verbosity, const char* format, ...);
// Helper function to extract filename from a full path
static std::string ExtractFilename(const std::string& path) {
if (path.empty()) {
return "";
}
size_t lastBackslash = path.find_last_of("\\");
if (lastBackslash != std::string::npos) {
return path.substr(lastBackslash + 1);
}
return path;
}
// Helper function to get process PEB info by PID // Helper function to get process PEB info by PID
// Falls back to process name if PEB info cannot be retrieved // Falls back to process name if PEB info cannot be retrieved
ProcessPebInfoRet GetProcessNameByPid(DWORD pid) { ProcessPebInfoRet GetProcessNameByPid(DWORD pid) {
@@ -133,7 +146,8 @@ Process* MakeProcess(DWORD pid, std::vector<std::string> targetNames) {
// Process PEB info // Process PEB info
ProcessPebInfoRet pebInfo = GetProcessNameByPid(pid); ProcessPebInfoRet pebInfo = GetProcessNameByPid(pid);
process->name = pebInfo.image_path; process->image_path = pebInfo.image_path;
process->name = ExtractFilename(pebInfo.image_path);
process->commandline = pebInfo.commandline; process->commandline = pebInfo.commandline;
// Dont observe ourselves // Dont observe ourselves
+2 -1
View File
@@ -36,7 +36,8 @@ public:
std::atomic<BOOL> augmented{FALSE}; std::atomic<BOOL> augmented{FALSE};
std::string name; std::string name; // Just the filename (e.g., "notepad.exe")
std::string image_path; // Full path (e.g., "C:\\Windows\\System32\\notepad.exe")
std::string commandline; std::string commandline;
// When augmented // When augmented