Skip to content

A process overwriting its own PEB to make an illusion that it has been loaded from a different path.

Notifications You must be signed in to change notification settings

hasherezade/process_chameleon

Repository files navigation

Process Chameleon

Build status

This is my "lil_calc" PoC presented on the video:
Test with ProcessExplorer vs TaskManager
It is not FUD, but it can fool some tools and it can be used as a test case.
The process overwrites its own PEB to create an illusion, that it has been loaded from a different path.

About

A process overwriting its own PEB to make an illusion that it has been loaded from a different path.

Resources

Stars

Watchers

Forks

Packages

No packages published