InjectSetConsole performs process code injection by leveraging a Windows named pipe.
Unlike traditional techniques, it does not use the VirtualAllocEx and WriteProcessMemory APIs.
Command Line Syntax
InjectSetConsole.exe <executable_path>
executable_path: netsh.exe, nslookup.exe,... or other nteractive console program
Example: InjectSetConsole.exe C:\Windows\System32\netsh.exe
To use different shellcode, replace the bytes starting at offset 0x19 (hexadecimal) in the rawData array.
Alternatively, you can modify the search pattern to improve evasion.
Links
EDR Evasion: Process Injection Without WriteProcessMemory
Demo Video
Youtube: https://youtu.be/DCUnbj_usPM
Comments