reveng007 / DarkWidow

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing
613Updated 3 months ago

Alternatives and similar repositories for DarkWidow:

Users that are interested in DarkWidow are comparing it to the libraries listed below