AIbase
Product LibraryTool Navigation

ReflectiveNtdll

Public

A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by @hasherezade). Payload encryption via SystemFucntion033 NtApi and No new thread via Fiber

Creat2023-01-30T16:43:16
Update2025-03-27T00:30:16
171
Stars
0
Stars Increase