This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
@BPry https://blogs.msdn.microsoft.com/wsl/2016/05/23/pico-process-overview/ This is what I'm referring to. It's the "minimal process that is associated with a pico profider kernel-mode driver." I'm curious if Traps can see these processes in Windows 10 when using Windows Subsystem for Linux (WSL). Bashware can leverage these processes to avoid detection from antivirus software installed on windows by utilizing these processes and I'm looking for clarification on how Traps does or does not protect against this.
... View more
Wanted to know if Traps was capable of stoping a bashware attack in Windows 10 by being able to analyze a pico process as part of the Windows Subsystem for Linux. If not by default, how would you enable Traps to see the pico processes?
... View more