mirror of
https://github.com/dobin/RedEdr
synced 2026-08-09 12:30:51 +00:00
feature: process->name is now without path (its in process->image_path))
This commit is contained in:
@@ -14,6 +14,19 @@ void LOG_W(int verbosity, const wchar_t* format, ...);
|
|||||||
void LOG_A(int verbosity, const char* format, ...);
|
void LOG_A(int verbosity, const char* format, ...);
|
||||||
|
|
||||||
|
|
||||||
|
// Helper function to extract filename from a full path
|
||||||
|
static std::string ExtractFilename(const std::string& path) {
|
||||||
|
if (path.empty()) {
|
||||||
|
return "";
|
||||||
|
}
|
||||||
|
size_t lastBackslash = path.find_last_of("\\");
|
||||||
|
if (lastBackslash != std::string::npos) {
|
||||||
|
return path.substr(lastBackslash + 1);
|
||||||
|
}
|
||||||
|
return path;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
// Helper function to get process PEB info by PID
|
// Helper function to get process PEB info by PID
|
||||||
// Falls back to process name if PEB info cannot be retrieved
|
// Falls back to process name if PEB info cannot be retrieved
|
||||||
ProcessPebInfoRet GetProcessNameByPid(DWORD pid) {
|
ProcessPebInfoRet GetProcessNameByPid(DWORD pid) {
|
||||||
@@ -133,7 +146,8 @@ Process* MakeProcess(DWORD pid, std::vector<std::string> targetNames) {
|
|||||||
|
|
||||||
// Process PEB info
|
// Process PEB info
|
||||||
ProcessPebInfoRet pebInfo = GetProcessNameByPid(pid);
|
ProcessPebInfoRet pebInfo = GetProcessNameByPid(pid);
|
||||||
process->name = pebInfo.image_path;
|
process->image_path = pebInfo.image_path;
|
||||||
|
process->name = ExtractFilename(pebInfo.image_path);
|
||||||
process->commandline = pebInfo.commandline;
|
process->commandline = pebInfo.commandline;
|
||||||
|
|
||||||
// Dont observe ourselves
|
// Dont observe ourselves
|
||||||
|
|||||||
@@ -36,7 +36,8 @@ public:
|
|||||||
|
|
||||||
std::atomic<BOOL> augmented{FALSE};
|
std::atomic<BOOL> augmented{FALSE};
|
||||||
|
|
||||||
std::string name;
|
std::string name; // Just the filename (e.g., "notepad.exe")
|
||||||
|
std::string image_path; // Full path (e.g., "C:\\Windows\\System32\\notepad.exe")
|
||||||
std::string commandline;
|
std::string commandline;
|
||||||
|
|
||||||
// When augmented
|
// When augmented
|
||||||
|
|||||||
Reference in New Issue
Block a user