Search Evasion Techniques
Names, Techniques, Definitions, Keywords
1 item(s) found so far for this keyword.
When a process is running, it is possible to change the results of the call to
GetProcAddress API, for the exported functions of a module along with modifying the export's offsets and name at runtime.
For example, the offset of
VirtualAlloc can be change to the offset of another function. When
VirtualAlloc is called (after getting its address …