Skip to content

zimnyaa/PhaseDive

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation



PhaseDive (Ekko fork)

better explained at https://tishina.in/execution/phase-dive-sleep-obfuscation

This is a PoC for a change to Ekko to use trampoline calls to ZwContinue and a jmp rax gadget to call functions from the CONTEXT struct. The ntdll.dll gadget is static, you need to find your own call <ntdll.ZwContinue> to test this

Credit

About

Sleep Obfuscation

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C 92.1%
  • Makefile 7.9%