From the course: Windows Performance Toolkit: Spyware Detection
Unlock the full course today
Join today to access over 22,400 courses taught by industry experts or purchase this course individually.
Finding the keylogger hooks, part 1 - Windows Tutorial
From the course: Windows Performance Toolkit: Spyware Detection
Finding the keylogger hooks, part 1
- [Instructor] On the left-hand side, let's click on the drop down arrow for Computation. Let's then click on the drop down arrow for CPU Usage (Precise) to reveal more charts. The chart we want to look at first is Timeline By Process Thread. Let's select it and drag and drop it over to the right-hand side. This chart shows the thread activity for all the processes that were running during our key presses in Notepad. We use Notepad so we can find out what other processes are active, or coming in at the same time Notepad activity is occurring. By activity, I mean, our key presses. I will take a moment to make the graph more visible. To do this, let select the Maximize button in the top right. Then select the edge right above the data table and drag it down. Now let's locate the Notepad thread activity. We can see the activity increases while we are pressing and holding down our keyboard buttons. This is indicated by the solid bars, rather than little lines that we see occur in between.…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
Looking at a keylogger4m 6s
-
Looking at the keylogger source code, part 14m 45s
-
Looking at the keylogger source code, part 24m 44s
-
Looking at the keylogger source code, part 34m 57s
-
Gathering keylogger evidence setup1m 55s
-
Gathering keylogger evidence4m 23s
-
WPA and symbol loading1m 49s
-
Finding the keylogger hooks, part 13m 12s
-
Finding the keylogger hooks, part 23m 13s
-
Finding the keylogger hooks, part 33m 27s
-
Finding the keylogger hooks, part 44m 41s
-
Finding the keylogger hooks, part 51m 51s
-
Keylogger deletion2m 36s
-
-