Skip to content

ezhangle/process_chameleon

 
 

Repository files navigation

Process Chameleon

Build status

This is my "lil_calc" PoC presented on the video:
Test with ProcessExplorer vs TaskManager
It is not FUD, but it can fool some tools and it can be used as a test case.
The process overwrites its own PEB to create an illusion, that it has been loaded from a different path.

About

A process overwriting its own PEB to make an illusion that it has been loaded from a different path.

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages

  • C 92.5%
  • C++ 7.2%
  • CMake 0.3%