03-01-2018 12:27 PM - edited 03-01-2018 12:30 PM
Does anybody know if Traps has protections against process doppelganging? There is a detailed write up at the link below explaining what this is.
https://hshrzd.wordpress.com/2017/12/18/process-doppelganging-a-new-way-to-impersonate-a-process/
It comes from a Blackhat EU presentation last year: