InjectSetConsole performs process code injection by leveraging a Windows named pipe.

Unlike traditional techniques, it does not use the VirtualAllocEx and WriteProcessMemory APIs.

Command Line Syntax

InjectSetConsole.exe <executable_path>

executable_path: netsh.exe, nslookup.exe,... or other nteractive console program

Example: InjectSetConsole.exe C:\Windows\System32\netsh.exe

To use different shellcode, replace the bytes starting at offset 0x19 (hexadecimal) in the rawData array.

Alternatively, you can modify the search pattern to improve evasion.

EDR Evasion: Process Injection Without WriteProcessMemory

Demo Video

Youtube: https://youtu.be/DCUnbj_usPM

🐦 Enjoying my work? Support the journey by following me on X

Author:

Two Seven One Three