Skip to main content

Overview

The proc command provides comprehensive process management functionality including enumeration, creation, termination, and memory analysis of processes on the target system.

Syntax

Subcommands

list

Enumerate all running processes on the target system.
array
Array of process objects containing:
string
Process executable name
integer
Process identifier
integer
Parent process identifier
string
Process architecture (x86 or x64)
string
User context the process is running under
integer
Session ID the process belongs to

grep

Search for processes by name.
string
required
The process name to search for (case-insensitive, supports partial matches)
Returns: Process Name, Process ID, Parent PID, User, and Architecture for matching processes.

kill

Terminate a process by PID.
integer
required
The process identifier of the process to terminate

create

Start a new process in suspended or running state.
string
required
Process creation state:
  • normal - Start process in running state
  • suspended - Start process in suspended state (useful for injection)
string
required
Full path to the executable to launch
string
Command-line arguments to pass to the process

module

List loaded modules (DLLs) from a specified process.
integer
required
Process identifier to enumerate modules from
array
string
Module/DLL name
hex
Base address where the module is loaded
integer
Size of the module in bytes
string
Full path to the module file

memory

Query process memory pages with specified protection flags.
integer
required
Process identifier to query memory from
string
required
Memory protection flag to filter by:
  • PAGE_NOACCESS - No access
  • PAGE_READONLY - Read-only
  • PAGE_READWRITE - Read and write
  • PAGE_WRITECOPY - Copy-on-write
  • PAGE_EXECUTE - Execute only
  • PAGE_EXECUTE_READ - Execute and read
  • PAGE_EXECUTE_READWRITE - Execute, read, and write
  • PAGE_EXECUTE_WRITECOPY - Execute and copy-on-write
  • PAGE_GUARD - Guard page
array
hex
Starting address of the memory region
integer
Size of the memory region in bytes
string
Current protection flags
string
Memory type (Image, Mapped, Private)

Examples

List All Processes

Example Output:

Search for Specific Process

Finds all processes with “chrome” in the name.

Create Suspended Process for Injection

Creates notepad.exe in suspended state, useful for process injection:

List Modules in Process

Enumerates all loaded DLLs in process 1520.

Find Executable Memory Regions

Lists all memory regions with RWX permissions in process 1520 (useful for detecting injected code).

Kill Process

Terminates process 4521.

OPSEC Considerations

Process Enumeration

  • Process listing may trigger ETW events
  • Some EDR solutions monitor process enumeration APIs
  • Consider using proc grep for targeted searches instead of full enumeration

Process Creation

Creating processes in suspended state:
  • Advantage: Allows injection before process initialization
  • Risk: Suspended processes may appear suspicious to monitoring tools
  • Use Case: Process injection and hollowing techniques

Memory Scanning

  • Querying process memory can trigger:
    • OpenProcess monitoring
    • Memory access alerts in EDR
    • Anti-debugging protections
  • Use sparingly and only when necessary

Process Termination

  • Killing protected processes may fail or trigger alerts
  • Some processes are critical and terminating them may cause system instability
  • Consider the impact on system stability before killing processes

Use Cases

Pre-Injection Reconnaissance

Detecting Injected Code

Clean Process Creation

Advanced Usage

PPID Spoofing

Combine with proc ppidspoof command to set a specific parent process:

Notes

  • Process listing requires SeDebugPrivilege for full visibility
  • Some processes may be protected and inaccessible
  • Memory queries may fail for protected processes (PPL/PPL-Antimalware)
  • Always verify process architecture before injection to avoid crashes
  • Suspended processes must be resumed or terminated to avoid resource leaks