Alaris icon indicating copy to clipboard operation
Alaris copied to clipboard

Hollowing detected by Crowdstrike

Open kosztyua opened this issue 4 years ago • 0 comments

Heads up here, Crowdstrike gave a medium risk flag with "Defense Evasion via Process Hollowing". However, it seems simply by using different hollow_bin it still can be bypassed. Did they really set the detection rule against mobsync.exe :D By the way, amazing tool, almost nothing worked out-of-the-box with defender bypass using meterpreter payload, Alaris did.

kosztyua avatar Nov 23 '21 00:11 kosztyua