

Github GitHub - hasherezade/process_ghosting: Process Ghosting - a PE injection...
source link: https://github.com/hasherezade/process_ghosting
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Process Ghosting
This is my implementation of the technique presented by Gabriel Landau:
https://www.elastic.co/blog/process-ghosting-a-new-executable-image-tampering-attack
Characteristics:
- Memory artifacts as in Process Doppelgänging
- Payload mapped as
MEM_IMAGE
(unnamed: not linked to any file) - Sections mapped with original access rights (no
RWX
) - Payload connected to PEB as the main module
- Remote injection supported (but only into a newly created process)
- Process is created from an unnamed module (
GetProcessImageFileName
returns empty string)
WARNING:
The 32bit version works on 32bit system only.
Recommend
-
70
Process Doppelgänging This is my implementation of the technique presented by enSilo: https://www.youtube.com/watch?v=Cch8dvp836w Characteristics:
-
112
README.md PE-sieve
-
66
Apple, the security guru company, is introducing a brand new feature with the release of its next software update. Currently, users are able to enable the option to be notified when someone reads their messages. Apple will now notify the recip...
-
20
README.md Module Overloading
-
16
Ghosting Ghosting occurs when an unintended signal/character is sent due to the maximum number of simultaneous key presses being reached....
-
9
"Kicking over" and "ghosting over" customer drives Once you see the same problem happen a few times, you should start thinking of things that can be done to make it disappear. If there are a lot of problems, you might have to han...
-
8
iPhone 12 Pro Is this lens flare (ghosting) effect normal? ...
-
9
Sigma Has Fixed 28-70mm Ghosting Issues, Will Replace Affected Units
-
9
Sigma has fixed ghosting issues with its 28-70mm F2.8 DG DN lens, is replacing affected lenses Back in March, Sigma iss...
-
7
CORPORATE GLOSSARYGhosting Is A Tedious Trend. The Real Demon Is More DangerousYou'll never look at your work the same way again
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK