diff --git a/Offensive.md b/Offensive.md index 0a2497e..d3803bb 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1354,6 +1354,10 @@ Some tools can be categorized in more than one category. But because the current hasherezade/module_overloading A more stealthy variant of "DLL hollowing" + + hasherezade/process_chameleon + A process overwriting its own PEB to make an illusion that it has been loaded from a different path. + hasherezade/transacted_hollowing Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging