PorLaCola25 / PPID-Spoofing

POC of PPID spoofing using NtCreateUserProcess with syscalls to create a suspended process and performing process injection by overwritting ntdll:LdrInitializeThunk with shellcode.
39Updated 3 years ago

Alternatives and similar repositories for PPID-Spoofing:

Users that are interested in PPID-Spoofing are comparing it to the libraries listed below