Your browser does not seem to support JavaScript. As a result, your viewing experience will be diminished, and you have been placed in read-only mode.
Please download a browser that supports JavaScript, or enable it if it's disabled (i.e. NoScript).
how can I get the full process name in kernel, then one returned by the GetModuleFileName ? any ideas ? The EPROCESS structure has a member called ImageFileName but it is just the base name gabby