Process Injection - Avoiding Kernel Triggered Memory Scans.
r-tec.net/r-tec-blog-process…
#windows , #process_injection , #memory_scan
r-tec.net/r-tec-blog-process…
#windows , #process_injection , #memory_scan
Source Byte
https://www.safebreach.com/blog/process-injection-using-windows-thread-pools/
A set of fully-undetectable process injection techniques abusing Windows Thread Pools
https://github.com/SafeBreach-Labs/PoolParty
#process_injection , #tools
https://github.com/SafeBreach-Labs/PoolParty
#process_injection , #tools
❤🔥2🎃1
Novel Detection of Process Injection Using Network Anomalies
https://akamai.com/blog/security-research/novel-detection-methodology-process-injection-using-network-anomalies
#process_injection , #detection
https://akamai.com/blog/security-research/novel-detection-methodology-process-injection-using-network-anomalies
#process_injection , #detection
👍5
New PoolParty Process Injection Techniques Outsmart Top EDR Solutions
thehackernews.com/2023/12/ne…
#EDR , #process_injection
thehackernews.com/2023/12/ne…
#EDR , #process_injection
Northsec:
Advanced process injection
https://www.youtube.com/live/pgaGpH2dYFc?si=AO8C8i-Xm9DDSF7F
#malware_dev , #process_injection
Advanced process injection
https://www.youtube.com/live/pgaGpH2dYFc?si=AO8C8i-Xm9DDSF7F
#malware_dev , #process_injection
YouTube
Advanced Process Injection Techniques
"Advanced Process Injection Techniques" is a hands-on workshop focused on providing candidates insights about the APT tactics & techniques on the privilege escalation & persistence phase. This workshop is a quick deep-dive into the Microsoft windows world…
Black hat: process injection techniques - Gotta catch them all
https://youtu.be/xewv122qxnk?si=MvVaE9RLQCPQ67wn
#malware_analysis , #malware_dev , #process_injection
https://youtu.be/xewv122qxnk?si=MvVaE9RLQCPQ67wn
#malware_analysis , #malware_dev , #process_injection
YouTube
Process Injection Techniques - Gotta Catch Them All
In this presentation, we provide the most comprehensive to-date "Windows process injection" collection of techniques - the first time such resource is available, that really covers all (or almost all) true injection techniques. We focus on Windows 10 x64…
👍1
Needles Without The Thread: Threadless Process Injection
https://m.youtube.com/watch?si=UlFxll8AwTtMM0Cz&v=z8GIjk0rfbI&feature=youtu.be
Credit : @_EthicalChaos_
#thread , #process_injection
https://m.youtube.com/watch?si=UlFxll8AwTtMM0Cz&v=z8GIjk0rfbI&feature=youtu.be
Credit : @_EthicalChaos_
#thread , #process_injection
Linux process injection: sshd injection for credential harvesting
credits : @_xpn_ , @jm33_m0
blog.xpnsec.com/linux-proces…
jm33.me/sshd-injection-and-p…
#process_injection ,
———
@islemolecule_source
credits : @_xpn_ , @jm33_m0
blog.xpnsec.com/linux-proces…
jm33.me/sshd-injection-and-p…
#process_injection ,
———
@islemolecule_source
Process injection techniques $
(꩜)ListPlanting ->( Mitre )
(꩜)Process Doppelganging ->( Mitre)
(꩜)Process Hollowing ->( GitHub)
(꩜)Extra Window Memory Injection -> ( Mitre )
(꩜)TLS callback ->( GitHub)
(꩜)APC injection -> ( earlybird )
(꩜) Thread Hijacking ->( GitHub )
(꩜) Transacted Hollowing (hasherezade)
(꩜) Process Ghosting (hasherezade)
(꩜) DLL hollowing (hasherezade)
(꩜) ChimeraPE (hasherezade)
(꩜) Process Overwriting (hasherezade)
(꩜) Process Chameleon (YouTube)
+Demo by hasherezade
------------------_---------------
Others:
Mockingjay
+ thread namecalling:
https://github.com/hasherezade/thread_namecalling.git
https://t.iss.one/Source_byte
#malware_dev #process_injection
(꩜)ListPlanting ->( Mitre )
(꩜)Process Doppelganging ->( Mitre)
(꩜)Process Hollowing ->( GitHub)
(꩜)Extra Window Memory Injection -> ( Mitre )
(꩜)TLS callback ->( GitHub)
(꩜)APC injection -> ( earlybird )
(꩜) Thread Hijacking ->( GitHub )
(꩜) Transacted Hollowing (hasherezade)
(꩜) Process Ghosting (hasherezade)
(꩜) DLL hollowing (hasherezade)
(꩜) ChimeraPE (hasherezade)
(꩜) Process Overwriting (hasherezade)
(꩜) Process Chameleon (YouTube)
+Demo by hasherezade
------------------_---------------
Others:
Mockingjay
+ thread namecalling:
https://github.com/hasherezade/thread_namecalling.git
https://t.iss.one/Source_byte
#malware_dev #process_injection