/vx/Papers/Windows/Process Injection/

0 directories 85 files
Name Size Modified
Go up
2004-04-06 - Remote Library Injection.pdf 248 KiB
2014-02-03 - PE Injection Demonstration 1.zip 4.4 KiB
2014-04-13 - PE Injection Explained Advanced memory code injection technique.pdf 310 KiB
2016-10-27 - AtomBombing - A Brand New Code Injection Technique for Windows.pdf 214 KiB
2017-06-07 - Process Hollowing with Manalyzes PE library.pdf 386 KiB
2017-09-19 - Abusing Delay Load DLLs for Remote Code Injection.pdf 208 KiB
2018-03-26 - Ghostwrite Demonstration.c 50 KiB
2018-06-14 - PE Injection Demonstration 2.zip 3.3 KiB
2018-08-26 - Windows Process Injection - Extra Window Bytes.pdf 201 KiB
2018-08-30 - Windows Process Injection - Service Control Handler.pdf 428 KiB
2018-08-30 - Windows Process Injection Service - Service Control Handler.pdf 428 KiB
2018-09-12 - Windows Process Injection - ConsoleWindowClass.pdf 312 KiB
2018-10-16 - Injecting Code into Windows Protected Processes using COM - Part 1.pdf 1.2 MiB
2018-11-01 - Process Injection Techniques and Detection using the Volatility Framework.pdf 5.6 MiB
2018-11-30 - Injecting Code into Windows Protected Processes using COM - Part 2.pdf 690 KiB
2019-04-08 - Early Bird Injection - APC Abuse.pdf 892 KiB
2019-08-08 - Demonstating Various Process Injection Techniques - Pinjecta.zip 98 KiB
2019-08-08 - Process Injection Techniques - Gotta Catch Them All.pdf 734 KiB
2019-08-12 - Windows Process Injection via KnownDlls Cache Poisoning.pdf 355 KiB
2019-08-13 - The state of advanced code injections.pdf 462 KiB
2019-10-23 - SPReview Phantom DLLs.pdf 64 KiB
2020-01-06 - NtCreateSection and NtMapViewOfSection for Code Injection.pdf 687 KiB
2020-02-10 - From Process Injection to Function Hijacking.pdf 440 KiB
2020-03-18 - ShimBad the Sailor.pdf 95 KiB
2020-05-28 - GetEnvironmentVariable As Alternative to WriteProccessMemory in Process Injections.pdf 137 KiB
2020-06-06 - NINA - x64 Process Injection.pdf 980 KiB
2020-06-14 - Process Injection Techniques.pdf 629 KiB
2020-06-24 - Process Injection Techniques used by Malware.pdf 207 KiB
2020-07-10 - Masking Malicious Memory Artifacts Part 1 – Phantom DLL Hollowing.pdf 599 KiB
2020-07-16 - Masking Malicious Memory Artifacts Part II - Blending in with False Positives.pdf 6.6 MiB
2020-07-16 - Weaponizing Mapping Injection With instrumentation Callback.pdf 709 KiB
2020-08-04 - Masking Malicious Memory Artifacts Part III - Bypassing Defensive Scanners.pdf 3.7 MiB
2020-09-18 - More Windows 10 Phantom DLLs.pdf 65 KiB
2020-10-12 - I Like to Move It - Windows Lateral Movement Part 3 - DLL Hijacking.pdf 2.0 MiB
2020-11-29 - Weaponize GhostWriting Injection Code Injection Series Part 5.pdf 381 KiB
2021-02-28 - PE Injection_ Executing PEs inside Remote Processes.pdf 683 KiB
2021-03-28 - Executing a PE File in Memory.zip 19 MiB
2021-03-30 - KeDll Injector.rar 17 KiB
2021-04-08 - Process Code Injection Through Undocumented NTAPI.pdf 515 KiB
2021-07-26 - Shellcoding - Process Injection with Assembly.pdf 1.2 MiB
2021-11-10 - The DLL Search Order And Hijacking It.pdf 457 KiB
2022-01-15 - CreateRemoteThread Process Injection.7z 5.6 KiB
2022-01-15 - Demonstrating ATOM Bombing.7z 12 KiB
2022-01-15 - Process Doppelgänging POC.7z 129 KiB
2022-01-15 - Process HerpaDerping.7z 301 KiB
2022-01-15 - ReflectiveDLLInjection Example.7z 13 KiB
2022-01-15 - SetThreadContextInjection Example.7z 5.2 KiB
2022-01-15 - SetWindowsHookExInjection Example.7z 3.2 KiB
2022-01-15 - The ExtraWindowInject Process Injection Technique.7z 25 KiB
2022-01-15 - UserApcInject Example.7z 4.7 KiB
2022-01-18 - O365 HKCU WwlibDll Sideloading.pdf 158 KiB
2022-02-02 - Reading and writing remote process data without using ReadProcessMemory ⁄WriteProcessMemory.pdf 154 KiB
2022-02-10 - WindowsNoExec - Abusing existing instructions to executing arbitrary code without allocating executable memory.pdf 324 KiB
2022-03-17 - Process Overwriting - yet another variant.zip 73 KiB
2022-03-17 - Process-Hollowing Example.7z 229 KiB
2022-04-04 - Sharing is Caring - Abusing Shared Sections for Code Injection.pdf 231 KiB
2022-05-05 - Process Injection via Component Object Model (COM) IRundown-DoCallback().pdf 1.6 MiB
2022-05-08 - Demonstrating Process Injection in Rust - Rusty Memory LoadLibrary.zip 20 KiB
2022-05-16 - Demonstrating Reflective DLL Loading - KaynLdr.zip 114 KiB
2022-06-25 - PE Resource section for Process Injection.zip 6.2 KiB
2022-07-16 - Process Injection using QueueUserAPC Technique in Windows.pdf 638 KiB
2022-08-01 - DLL Hijacking Windows Defender NisSrv.txt 1.4 KiB
2022-08-19 - Warbird Hook - Demonstrating shellcode injection and application hijacking.7z 18 KiB
2022-08-29 - DLL Sideloading ShellChromeAPI.PNG 75 KiB
2022-09-09 - WriteProcessMemoryAPC - Write memory to a remote process using APC calls.pdf 106 KiB
2022-12-23 - Ctrl Injection Collection.7z 554 KiB
2023-01-30 - Abusing Exceptions for Code Execution Part 2.pdf 1004 KiB
2023-02-14 - Adopting Position Independent Shellcodes from Object Files in Memory for Threadless Injection.pdf 981 KiB
2023-04-18 - Process injection in 2023 evading leading EDRs.pdf 5.0 MiB
2023-06-01 - Improving the stealthiness of memory injections techniques.pdf 1.0 MiB
2023-06-09 - No Alloc, No Problem - Leveraging Program Entry Points for Process Injection.pdf 1.3 MiB
2023-06-27 - Process Mockingjay Echoing RWX In Userland To Achieve Code Execution.pdf 7.2 MiB
2023-08-15 - Dll Notification Injection.7z 1.8 MiB
2023-09-05 - Demonstrating MockingJay with a POC and BOF.7z 93 MiB
2023-10-02 - Process Injection using NtSetInformationProcess.pdf 835 KiB
2023-12-06 - Process Injection Techniques Using Windows Thread Pools.7z 4.7 MiB
2024-01-22 - Demonstrating proxy DLL loading.zip 5.8 KiB
2024-01-24 - How to perform a Complete Process Hollowing.pdf 4.0 MiB
2024-02-05 - DLL-Load Proxying.pdf 197 KiB
2024-08-10 - ShimMe - Manipulating Shim and Office for Code Injection.7z 47 KiB
2024-08-11 - DriverJack.7z 9.1 MiB
2024-08-26 - DLL Sideloading ith LicenseDiag.exe.7z 130 KiB
2024-10-15 - Introducing Early Cascade Injection from Windows process creation to stealthy injection.pdf 1.6 MiB
2024-12-19 - Process Injection Mapped Sections.pdf 534 KiB
2025-03-02 - Abusing IDispatch for Trapped COM Object Access Injecting into PPL Processes.pdf 2.1 MiB