filerenameop
#
$ target-query <path/to/target> -f filerenameop
Module |
|
Output |
|
Module documentation
Generic Windows plugin.
Provides some plugins that don’t fit in a separate plugin.
Function documentation
Return all pending file rename operations.
The PendingFileRenameOperations registry key value contains information about files that will be renamed on reboot. Can be used to hunt for malicious binaries.
- References: