boku7 / DarkWidow
View external linksLinks

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing
16Feb 13, 2024Updated 2 years ago

Alternatives and similar repositories for DarkWidow

Users that are interested in DarkWidow are comparing it to the libraries listed below

Sorting:

Are these results useful?