Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / MALWARE REVERSE / ANALYSIS / STATIC / DANGEROUS FUNCS / WIN32

Discovery

System Info

  • GetSystemInfo

  • GetNativeSystemInfo

  • GetComputerName

  • GetUserName

  • NetUserEnum

  • NetLocalGroupEnum


Process Enumeration

  • CreateToolhelp32Snapshot

  • Process32First

  • Process32Next

  • EnumProcesses