This is my implementation of the technique presented by Gabriel Landau:
https://www.elastic.co/blog/process-ghosting-a-new-executable-image-tampering-attack
MEM_IMAGE
(unnamed: not linked to any file)RWX
)GetProcessImageFileName
returns empty string)WARNING:
The 32bit version works on 32bit system only.