0xyg3n / mem64

Run Any Native PE file as a memory ONLY Payload , most likely as a shellcode using hta attack vector which interacts with Powershell.
27Updated 7 years ago

Related projects

Alternatives and complementary repositories for mem64