BOF
to read the startup arguments of a remote process, when provided a process ID (PID)
A few use-cases that immediately come to mind:
- Secondary selection for process injection
- Inspection of remote commandline arguments to identify possible configuration paths for applications
cd src
make
- Load the
remote_process_commandline.cna
file from thedist
folder. - Within a
beacon
:remote_process_commandline process_id_number