Skip to content

Conversation

@elad-levi-cyberark
Copy link
Contributor

@elad-levi-cyberark elad-levi-cyberark commented Mar 11, 2025

RADAR - Evidence of Execution

Description

A subkey is generated for each process that exceeds the 'HeapLeakDetection' threshold within the scan interval under 'HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications'.

Further explanations can be found in the references (it would be redundant to repeat that).

References

https://harelsegev.github.io/posts/the-mystery-of-the-heapleakdetection-registry-key/
https://github.com/MHaggis/HeapLeakDetection
https://www.youtube.com/watch?v=edJa_SLVqOo

Checklist:

  • No new new dependencies are required or l2tdevtools has been updated.
  • Test data has a Plaso compatible license. If the test data was not authored by you (the contributor), make sure to mention its orginal source in ACKNOWLEDGEMENTS.
  • Reviewer assigned.
  • Automated checks (GitHub Actions, AppVeyor) pass.

@JakePeralta7
Copy link

image
The build on MacOS is failing due to other plugins not meeting the assertion criteria

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants