From aaabdfe2fa14d5ba04ece62b05501ba977600e53 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Wed, 27 Oct 2021 16:32:14 +0700 Subject: [PATCH] Add: hasherezade/process_chameleon to Defense Evasion section --- Offensive.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Offensive.md b/Offensive.md index 0a2497e..d3803bb 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1354,6 +1354,10 @@ Some tools can be categorized in more than one category. But because the current hasherezade/module_overloading A more stealthy variant of "DLL hollowing" + + hasherezade/process_chameleon + A process overwriting its own PEB to make an illusion that it has been loaded from a different path. + hasherezade/transacted_hollowing Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging