-
-
[转帖]ExecuteAssembly - Load/Inject .NET Assemblies
-
发表于: 2021-2-7 14:25 7992
-
ExecuteAssembly - Load/Inject .NET Assemblies
ExecuteAssembly is an alternative of CS execute-assembly, built with C/C++ and it can be used to Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR Modules/AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avoiding EDR hooks via NT static syscalls (x64) and hiding imports by dynamically resolving APIs via superfasthash hashing algorithm.
350K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6%4N6%4N6Q4x3X3g2C8K9i4c8H3L8r3!0A6N6q4)9J5k6h3y4G2L8g2)9J5c8U0t1H3x3U0q4Q4x3V1j5H3x3W2)9J5c8X3g2^5k6h3y4#2N6r3g2S2M7%4y4W2L8h3u0D9P5g2)9J5k6r3I4G2j5h3c8A6L8X3A6W2j5%4c8Q4x3X3c8F1k6i4c8Q4x3X3g2Z5N6r3#2D9
赞赏
他的文章
赞赏
雪币:
留言: