Documentation ¶
Overview ¶
This package executes shellcode in a child process using the following steps:
- Create a child proccess in a suspended state with CreateProcessW
- Allocate RW memory in the child process with VirtualAllocEx
- Write shellcode to the child process with WriteProcessMemory
- Change the memory permissions to RX with VirtualProtectEx
- Add a UserAPC call that executes the shellcode to the child process with QueueUserAPC
- Resume the suspended program with ResumeThread function
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.