transacted_hollowing icon indicating copy to clipboard operation
transacted_hollowing copied to clipboard

Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging

Results 2 transacted_hollowing issues
Sort by recently updated
recently updated
newest added

Hey there, the payload or malicious PE file should be on the fileytem here. Mostly it will be already fished away by AV, especially if it is malicious or suspicious...

Appreciate your work and it was inspiring! I studyed on this kind of hollowing based on your work. Hope you find this interesting. https://github.com/Hagrid29/herpaderply_hollowing