Process Injection Techniques: Deep Dive into Process Hollowing & Shellcode

Veröffentlicht am: 01 Januar 1970
auf dem Kanal: Off By One Security
2,506
137

An advanced form of process injection used by malicious actors and red teamers to evade detection is process hollowing. This technique leverages a combination of documented and undocumented Windows APIs. Process hollowing involves starting a legitimate process in a suspended state, then replacing its original code with malicious code from the attacker. This makes the process appear legitimate to security software or anyone investigating system activity.

Shellcode is commonly used to both perform process hollowing and as the code that is executed in the hollowed process. Shellcode inherently provides a layer of obfuscation through the special techniques it has to perform in order to operate.

In this session, we'll delve into the inner workings of process hollowing, exploring how attackers leverage it to bypass detection. We'll also explore the world of shellcode and its unique characteristics.

Josh's training: https://ringzer0.training/doubledown2...


Auf dieser Seite können Sie das Online-Video Process Injection Techniques: Deep Dive into Process Hollowing & Shellcode mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Off By One Security 01 Januar 1970 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 2,506 Mal angesehen und es wurde von 137 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!