[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fl6ExhFVgI3lIrFdGD1YfrtW10yOrKJTNPtIQ9Bqe0d0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},464,"How does the C++ implementation of SwampThing differ and what advantage does it offer?","The C++ implementation differs by not restoring the original command line after the process resumes, and by hiding the launched process's window via `STARTUPINFO` flags (`dwFlags` and `wShowWindow`). This allows it to work with commands that exit immediately, such as `cmd.exe \u002Fc start calc.exe`, where the logged command line shows a fake parameter (e.g., `cmd.exe \u002Fc start notepad.exe`). This extends the bypass capability to one-shot executions.","\u003Cp>The C++ implementation differs by not restoring the original command line after the process resumes, and by hiding the launched process&#39;s window via `STARTUPINFO` flags (`dwFlags` and `wShowWindow`). This allows it to work with commands that exit immediately, such as `cmd.exe \u002Fc start calc.exe`, where the logged command line shows a fake parameter (e.g., `cmd.exe \u002Fc start notepad.exe`). This extends the bypass capability to one-shot executions.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-bypassing-windows-command-line-process-auditing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-c-implementation-of-swampthing-differ-and-what-advantage-does-it-of-1777483470783","C++, STARTUPINFO, ResumeThread, cmd.exe, bypass, command line auditing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},116,"Penetration Techniques - Bypassing Windows Command Line Process Auditing","penetration-techniques-bypassing-windows-command-line-process-auditing","Learn how to bypass Windows command line process auditing using SwampThing. Modify process parameters to evade Event ID 4688 logging with step-by-step implementation and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Command line process auditing is a Windows feature that, when enabled, logs command-line parameters during process creation in Event ID 4688\u003C\u002Fp>\u003Cp>This article will introduce methods to bypass logging by modifying process parameters, test the open-source tool SwampThing, share C language code for implementing SwampThing, analyze exploitation approaches, and provide defense recommendations\u003C\u002Fp>\u003Cp>SwampThing address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FSharp-Suite\u002Fblob\u002Fmaster\u002FSwampThing\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Methods to enable command line process auditing\u003C\u002Fli>\u003Cli>Testing SwampThing\u003C\u002Fli>\u003Cli>Implementing SwampThing in C++\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method is similar to creating a puppet process, with the difference being that this method only modifies the CommandLine parameter of the new process\u003C\u002Fp>\u003Cp>For technical details on puppet processes, refer to the previous article: 'Implementation and Detection of Puppet Processes'\u003C\u002Fp>\u003Ch3>Implementation Approach:\u003C\u002Fh3>\u003Col>\u003Cli>Create a process via CreateProcess, passing the lpCommandLine parameter and the CREATE_SUSPENDED flag to suspend the process\u003C\u002Fli>\u003Cli>Modify the CommandLine parameter of the new process\u003C\u002Fli>\u003Cli>Resume the process via ResumeThread to execute the new CommandLine parameter\u003C\u002Fli>\u003Cli>If the new process does not exit, restore the CommandLine parameter\u003C\u002Fli>\u003C\u002Fol>\u003Cp>In the specific implementation, the following issues also need to be considered:\u003C\u002Fp>\u003Ch4>1. Process Selection\u003C\u002Fh4>\u003Cp>The launched process must be capable of loading the CommandLine parameter, such as cmd.exe, powershell.exe, wmic.exe, etc.\u003C\u002Fp>\u003Ch4>2. Modifying the CommandLine Parameter of a Remote Process\u003C\u002Fh4>\u003Cp>Locate the base address of the remote process via NtQueryInformationProcess, calculate the offset to find the position of the CommandLine parameter, and then read and write the CommandLine parameter using ReadProcessMemory and WriteProcessMemory respectively\u003C\u002Fp>\u003Cp>Supplement:\u003C\u002Fp>\u003Cp>To modify the Commandline parameters of the current process, refer to:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x03 Enable command line process auditing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fidentity\u002Fad-ds\u002Fmanage\u002Fcomponent-updates\u002Fcommand-line-process-auditing\u003C\u002Fp>\u003Cp>This feature is disabled by default and requires manual configuration to enable\u003C\u002Fp>\u003Cp>1. Run gpedit.msc to open Group Policy\u003C\u002Fp>\u003Cp>2. Enable process auditing\u003C\u002Fp>\u003Cp>For English systems:\u003C\u002Fp>\u003Cp>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Advanced Audit Configuration &gt; Detailed Tracking &gt; Audit Process Creation\u003C\u002Fp>\u003Cp>For Chinese systems:\u003C\u002Fp>\u003Cp>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Advanced Audit Configuration &gt; Detailed Tracking &gt; Audit Process Creation\u003C\u002Fp>\u003Cp>3. Enable additional features in event logging to record command line parameters\u003C\u002Fp>\u003Cp>English System:\u003C\u002Fp>\u003Cp>Administrative Template &gt; System &gt; Audit Process Creation &gt; Include command line in process creation events\u003C\u002Fp>\u003Cp>Chinese System:\u003C\u002Fp>\u003Cp>Administrative Template &gt; System &gt; Audit Process Creation &gt; Include command line in process creation events\u003C\u002Fp>\u003Cp>After enabling command line process auditing, process creation information is recorded in Windows Security logs with Event ID 4688\u003C\u002Fp>\u003Cp>Example as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017965766_0_0302ca7894.jpeg\">\u003C\u002Fp>\u003Cp>The command to query Event ID 4688 logs via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Ff:text \u002Fq:*[System[(EventID=4688)]]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Testing SwampThing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FSharp-Suite\u002Fblob\u002Fmaster\u002FSwampThing\u003C\u002Fp>\u003Cp>Written in C#\u003C\u002Fp>\u003Cp>After successful compilation, the following three files are required:\u003C\u002Fp>\u003Cul>\u003Cli>SwampThing.exe\u003C\u002Fli>\u003Cli>CommandlLine.dll\u003C\u002Fli>\u003Cli>CommandLine.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command line parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SwampThing.exe -l C:\\Windows\\System32\\notepad.exe -f C:\\aaa.txt -r C:\\bbb.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The launched notepad.exe will load C:\\bbb.txt, but when viewing the notepad.exe process parameters via ProcessExplorer, it shows C:\\aaa.txt\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969428_1_6d14683bcf.jpeg\">\u003C\u002Fp>\u003Cp>After enabling command line process auditing, log entry ID 4688 records the notepad.exe process parameter as C:\\aaa.txt\u003C\u002Fp>\u003Cp>Successfully bypassed command line process auditing, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975953_2_8b5be6f8a7.jpeg\">\u003C\u002Fp>\u003Cp>In implementation, SwampThing only targets processes that do not automatically exit after execution (e.g., notepad.exe). That is, after resuming the process with ResumeThread, it modifies the process parameters again to restore them.\u003C\u002Fp>\u003Cp>Obviously, for processes that exit immediately after execution (e.g., cmd.exe \u002Fc), after resuming the process with ResumeThread, it cannot modify the process parameters again and will report an error, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986500_3_6843f455be.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Implementing SwampThing via C++\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I implemented functionality similar to SwampThing using C++, but with the following differences in detail:\u003C\u002Fp>\u003Col>\u003Cli>After waking the process via ResumeThread, the process parameters are no longer restored, making it applicable to cmd.exe \u002Fc\u003C\u002Fli>\u003Cli>Modified the parameters for creating the process with CreateProcess, specifying pStartupInfo-&gt;dwFlags and pStartupInfo-&gt;wShowWindow to hide the launched process's interface\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Code download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Executes the command cmd.exe \u002Fc start calc.exe\u003C\u002Fli>\u003Cli>After enabling command line process auditing, the process parameter recorded in log ID 4688 is cmd.exe \u002Fc start notepad.exe\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method can be used to hide the real parameters of a process\u003C\u002Fp>\u003Cp>For exploitation, wmic.exe can also be chosen, as mentioned by SwampThing—using wmic to load an xsl file\u003C\u002Fp>\u003Cp>For the method of loading an xsl file via wmic, refer to my two previous articles: 'Use msxsl to bypass AppLocker' and 'Analysis and Exploitation of Using wmic to Call xsl Files'\u003C\u002Fp>\u003Cp>Of course, both SwampThing's and my open-source C code require modifications to achieve loading xsl via wmic\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to creating a puppet process, this method does not require using VirtualAllocEx to allocate new memory or setting the entry point via SetThreadContext\u003C\u002Fp>\u003Cp>This method cannot be detected by comparing differences between the PE file on disk and in memory\u003C\u002Fp>\u003Cp>For detection, one can attempt to check if the parent process of a process is suspicious\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a method to bypass command line process auditing by modifying process parameters, tests the open-source tool SwampThing, shares the C language code for implementing SwampThing, analyzes the exploitation approach, and finally provides defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Command line process auditing is a Windows feature that, when enabled, logs command-line parameters during process creation in Event ID 4688\u003C\u002Fp>\u003Cp>This article will introduce methods to bypass logging by modifying process parameters, test the open-source tool SwampThing, share C language code for implementing SwampThing, analyze exploitation approaches, and provide defense recommendations\u003C\u002Fp>\u003Cp>SwampThing address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FSharp-Suite\u002Fblob\u002Fmaster\u002FSwampThing\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Methods to enable command line process auditing\u003C\u002Fli>\u003Cli>Testing SwampThing\u003C\u002Fli>\u003Cli>Implementing SwampThing in C++\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method is similar to creating a puppet process, with the difference being that this method only modifies the CommandLine parameter of the new process\u003C\u002Fp>\u003Cp>For technical details on puppet processes, refer to the previous article: 'Implementation and Detection of Puppet Processes'\u003C\u002Fp>\u003Ch3>Implementation Approach:\u003C\u002Fh3>\u003Col>\u003Cli>Create a process via CreateProcess, passing the lpCommandLine parameter and the CREATE_SUSPENDED flag to suspend the process\u003C\u002Fli>\u003Cli>Modify the CommandLine parameter of the new process\u003C\u002Fli>\u003Cli>Resume the process via ResumeThread to execute the new CommandLine parameter\u003C\u002Fli>\u003Cli>If the new process does not exit, restore the CommandLine parameter\u003C\u002Fli>\u003C\u002Fol>\u003Cp>In the specific implementation, the following issues also need to be considered:\u003C\u002Fp>\u003Ch4>1. Process Selection\u003C\u002Fh4>\u003Cp>The launched process must be capable of loading the CommandLine parameter, such as cmd.exe, powershell.exe, wmic.exe, etc.\u003C\u002Fp>\u003Ch4>2. Modifying the CommandLine Parameter of a Remote Process\u003C\u002Fh4>\u003Cp>Locate the base address of the remote process via NtQueryInformationProcess, calculate the offset to find the position of the CommandLine parameter, and then read and write the CommandLine parameter using ReadProcessMemory and WriteProcessMemory respectively\u003C\u002Fp>\u003Cp>Supplement:\u003C\u002Fp>\u003Cp>To modify the Commandline parameters of the current process, refer to:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x03 Enable command line process auditing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fidentity\u002Fad-ds\u002Fmanage\u002Fcomponent-updates\u002Fcommand-line-process-auditing\u003C\u002Fp>\u003Cp>This feature is disabled by default and requires manual configuration to enable\u003C\u002Fp>\u003Cp>1. Run gpedit.msc to open Group Policy\u003C\u002Fp>\u003Cp>2. Enable process auditing\u003C\u002Fp>\u003Cp>For English systems:\u003C\u002Fp>\u003Cp>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Advanced Audit Configuration &gt; Detailed Tracking &gt; Audit Process Creation\u003C\u002Fp>\u003Cp>For Chinese systems:\u003C\u002Fp>\u003Cp>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Advanced Audit Configuration &gt; Detailed Tracking &gt; Audit Process Creation\u003C\u002Fp>\u003Cp>3. Enable additional features in event logging to record command line parameters\u003C\u002Fp>\u003Cp>English System:\u003C\u002Fp>\u003Cp>Administrative Template &gt; System &gt; Audit Process Creation &gt; Include command line in process creation events\u003C\u002Fp>\u003Cp>Chinese System:\u003C\u002Fp>\u003Cp>Administrative Template &gt; System &gt; Audit Process Creation &gt; Include command line in process creation events\u003C\u002Fp>\u003Cp>After enabling command line process auditing, process creation information is recorded in Windows Security logs with Event ID 4688\u003C\u002Fp>\u003Cp>Example as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017965766_0_0302ca7894-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to query Event ID 4688 logs via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Ff:text \u002Fq:*[System[(EventID=4688)]]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Testing SwampThing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FSharp-Suite\u002Fblob\u002Fmaster\u002FSwampThing\u003C\u002Fp>\u003Cp>Written in C#\u003C\u002Fp>\u003Cp>After successful compilation, the following three files are required:\u003C\u002Fp>\u003Cul>\u003Cli>SwampThing.exe\u003C\u002Fli>\u003Cli>CommandlLine.dll\u003C\u002Fli>\u003Cli>CommandLine.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command line parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SwampThing.exe -l C:\\Windows\\System32\\notepad.exe -f C:\\aaa.txt -r C:\\bbb.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The launched notepad.exe will load C:\\bbb.txt, but when viewing the notepad.exe process parameters via ProcessExplorer, it shows C:\\aaa.txt\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969428_1_6d14683bcf-1.jpeg\">\u003C\u002Fp>\u003Cp>After enabling command line process auditing, log entry ID 4688 records the notepad.exe process parameter as C:\\aaa.txt\u003C\u002Fp>\u003Cp>Successfully bypassed command line process auditing, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975953_2_8b5be6f8a7-1.jpeg\">\u003C\u002Fp>\u003Cp>In implementation, SwampThing only targets processes that do not automatically exit after execution (e.g., notepad.exe). That is, after resuming the process with ResumeThread, it modifies the process parameters again to restore them.\u003C\u002Fp>\u003Cp>Obviously, for processes that exit immediately after execution (e.g., cmd.exe \u002Fc), after resuming the process with ResumeThread, it cannot modify the process parameters again and will report an error, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986500_3_6843f455be-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Implementing SwampThing via C++\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I implemented functionality similar to SwampThing using C++, but with the following differences in detail:\u003C\u002Fp>\u003Col>\u003Cli>After waking the process via ResumeThread, the process parameters are no longer restored, making it applicable to cmd.exe \u002Fc\u003C\u002Fli>\u003Cli>Modified the parameters for creating the process with CreateProcess, specifying pStartupInfo-&gt;dwFlags and pStartupInfo-&gt;wShowWindow to hide the launched process's interface\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Code download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Executes the command cmd.exe \u002Fc start calc.exe\u003C\u002Fli>\u003Cli>After enabling command line process auditing, the process parameter recorded in log ID 4688 is cmd.exe \u002Fc start notepad.exe\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method can be used to hide the real parameters of a process\u003C\u002Fp>\u003Cp>For exploitation, wmic.exe can also be chosen, as mentioned by SwampThing—using wmic to load an xsl file\u003C\u002Fp>\u003Cp>For the method of loading an xsl file via wmic, refer to my two previous articles: 'Use msxsl to bypass AppLocker' and 'Analysis and Exploitation of Using wmic to Call xsl Files'\u003C\u002Fp>\u003Cp>Of course, both SwampThing's and my open-source C code require modifications to achieve loading xsl via wmic\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to creating a puppet process, this method does not require using VirtualAllocEx to allocate new memory or setting the entry point via SetThreadContext\u003C\u002Fp>\u003Cp>This method cannot be detected by comparing differences between the PE file on disk and in memory\u003C\u002Fp>\u003Cp>For detection, one can attempt to check if the parent process of a process is suspicious\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces a method to bypass command line process auditing by modifying process parameters, tests the open-source tool SwampThing, shares the C language code for implementing SwampThing, analyzes the exploitation approach, and finally provides defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1121,"Onedaysec",4,"published","2026-02-02T07:51:00.067Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass Windows Command Line Auditing with SwampThing Techniques","Windows command line auditing bypass, SwampThing tool, process parameter modification, security evasion, Event ID 4688, penetration testing",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],465,463,462,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.173Z","2026-07-23T16:01:37.684Z","draft","2026-07-23T16:12:32.171Z"]