Search Evasion Techniques
Names, Techniques, Definitions, Keywords
2 item(s) found so far for this keyword.
Dirty Vanity is a process injection technique that exploits the Windows forking (process reflection and snapshotting) feature to inject code into a new process.
It uses the
NtCreateProcess[Ex] primitives, along with the
PROCESS_DUP_HANDLE flags to reflect and execute code in a new process.
The technique also makes use of various methods, such as …
Process Ghosting is a technique used to bypass detection by manipulating the executable image when a process is loaded.
Windows attempts to prevent mapped executables from being modified. Once a file is mapped into an image section, attempts to open it with
FILE_WRITE_DATA (to modify it) will fail with
ERROR_SHARING_VIOLATION. Deletion attempts via
FILE_FLAG_DELETE_ON_CLOSE fail with