Sabitlenmiş Tweet

Here is my variant of Gargoyle for x64 to evade memory scanners. Fully relies on ROP and PIC without any APC.
Huge thanks to @waldoirc for the documentation.
github.com/thefLink/DeepS…
English
thefLink
57 posts










We accidently built a Sysmon compatible tool with some neat features on top, like (in)direct syscall detection & more. Without drivers, with less resource footprint & using ETW only. Curious? My team is presenting at @x33fcon in June. Come & say hello! x33fcon.com/#!s/SebastianF…




Our powerintern @testert01 strikes again, teamed up with @thefLinkk and developed SysmonEnte: a hard to detect attack on Sysmon. Check out our new blogpost: codewhitesec.blogspot.com/2022/09/attack…









