hlldz / RefleXXion

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.
485Updated 3 years ago

Alternatives and similar repositories for RefleXXion:

Users that are interested in RefleXXion are comparing it to the libraries listed below