Classic RunPE (CreateProcess, NtGetContextThread, NtUnmapViewOfSection, NtWriteVirtualMemory, NtSetContextThread, NtResumeThread) using the Hell's Gate technique to evade usermode API monitoring by dynamically executing syscalls.
-
Notifications
You must be signed in to change notification settings - Fork 8
RunPE using Hell's Gate technique.
License
TheKevinWang/HellsRunPE
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
RunPE using Hell's Gate technique.
Topics
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published