#shellcode #point #entry-point

app process_hollowing

Creates a process and overwrites the entry point with shellcode (default to a reverse shell on localhost:4444)

8 stable releases

1.12.0 Jul 21, 2024
1.11.0 Nov 21, 2023
1.10.4 Mar 29, 2023
1.10.2 Jan 13, 2023
1.9.0 Sep 23, 2022

#3 in #point

MIT license

43KB
563 lines

RCO: Process Hollowing

See Process Hollowing's documentation here

Dependencies

~0–35MB
~534K SLoC