POC for Early Cascade Injection technique to spawn a Message Box. Only NT APIs.
PS Z:\pi\new\EarlyCascade\bin\Debug\net9.0> .\EarlyCascade.exe
[^] PROCESS HANDLE: 2B0
[^] THREAD HANDLE: 2AC
[^] g_ShimsEnabled ADDRESS: 7FFF7F15D194
[^] g_pfnSE_DllLoaded ADDRESS: 7FFF7F171268
[^] STUB ADDRESS: 22EC1FB0000
[^] SHELLCODE ADDRESS: 22EC1FB0185
[^] Enjoy!
- Find
g_ShimsEnabledandg_pfnSE_DllLoadeddinamically. - Include user input for shellcode file.
