The "Process Argument Spoofing" technique involves modifying or masking the arguments passed to a process running on an operating system. The aim is to trick users, system administrators or security tools into misinterpreting the process, thinking it is harmless or legitimate, while in fact it may be carrying out malicious actions.
Showing changes to arguments in Procmon and Process Hacker.
You can run with cargo run or the compiled binary directly:
cargo run
target/release/args_spoofing-rs.exe