#process #entry-point #reverse #shell #shellcode #overwrite #hollowing

app process_hollowing

Creates a process and overwrites the entry point with shellcode (default to a reverse shell on localhost:4444)

7 stable releases

1.11.0 Nov 21, 2023
1.10.4 Mar 29, 2023
1.10.2 Jan 13, 2023
1.10.0 Nov 7, 2022
1.9.0 Sep 23, 2022

#321 in Operating systems

31 downloads per month

MIT license

43KB
563 lines

RCO: Process Hollowing

See Process Hollowing's documentation here

Dependencies

~0–43MB
~584K SLoC