Mud
@_mudpak
ID: 1114965788123979776
07-04-2019 18:58:53
481 Tweet
45 Followers
3 Following
Has anyone ever seen or used this evasion technique? I have been using it for many years and still find it effective (particularly with macro's), so I was surprised to see it continue to work so I decided to document it on Unprotect : unprotect.it/technique/indi⦠Feedback appreciated!
Check out this new entry in the #UnprotectProject by my friend Jean-Pierre LESUEUR! π *Indirect Memory Writing* for example an attacker calls standard Windows APIs that accept an output pointer. You can point that pointer at executable memory. The attacker can then build a payload
π€© I am honored to be nominated for the French-Australia Award in Research & Innovation (by Le Courrier Australien) after the SANS DMA Award nomination! If you found my work useful, you can vote below, it takes 10 sec and it would mean a lot! β€οΈ Vote here: lcanews.com/research-innovβ¦