PorLaCola25 / PPID-Spoofing

POC of PPID spoofing using NtCreateUserProcess with syscalls to create a suspended process and performing process injection by overwritting ntdll:LdrInitializeThunk with shellcode.
38Updated 3 years ago

Related projects

Alternatives and complementary repositories for PPID-Spoofing