This is my "lil_calc" PoC presented on the video:
Test with ProcessExplorer vs TaskManager
It is not FUD, but it can fool some tools and it can be used as a test case.
The process overwrites its own PEB to create an illusion, that it has been loaded from a different path.
forked from hasherezade/process_chameleon
-
Notifications
You must be signed in to change notification settings - Fork 0
A process overwriting its own PEB to make an illusion that it has been loaded from a different path.
ezhangle/process_chameleon
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
A process overwriting its own PEB to make an illusion that it has been loaded from a different path.
Resources
Stars
Watchers
Forks
Packages 0
No packages published
Languages
- C 92.5%
- C++ 7.2%
- CMake 0.3%