Skip to content

0lddriv3r/loadEXE

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

傀儡进程注入

技术原理

启动Windows傀儡进程挂起,修改内存印象为注入进程,之后再引导傀儡进程执行,即可执行注入代码。 参考:

  1. ProcessHollow
  2. loadEXE

使用方法

命令行执行:loadEXE.exe process1.exe process2.exe,其中参数1为傀儡进程名,参数2为注入进程名。 示例:

  1. HelloWorld.exe注入calc.exeloadEXE.exe calc.exe HelloWorld.exe
  2. HelloTest.exe注入notepad.exeloadEXE.exe notepad.exe HelloTest.exe

About

Windows process injection.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published