daem0nc0re / TangledWinExec

PoCs and tools for investigation of Windows process execution techniques
BSD 3-Clause "New" or "Revised" License
881 stars 139 forks source link
red-team reverse-engineering windbg-extension windows windows-internals

Tangled WinExec

This repository is for investigation of Windows process execution techniques. Most of PoCs are given a name corresponding to the technique.

Projects

NOTE : Currently ProcessHollowing code does not works for Debug build. To test it, use Release build. See this issue.

Reference

Blocking DLL

Command Line Spoofing

Dark Load Library

Phantom DLL Hollowing

PPID Spoofing

Process Doppelgänging

Process Ghosting

Process Herpaderping

Process Hollowing

Ghostly Hollowing and Transacted Hollowing

Protected Process

Reflective DLL Injection

sRDI

Acknowledgments

Thanks for your research: