GithubHelp home page GithubHelp logo

jdu2600 / get-injectedthreadex Goto Github PK

View Code? Open in Web Editor NEW
23.0 2.0 4.0 487 KB

Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2

License: MIT License

PowerShell 64.92% C++ 35.08%

get-injectedthreadex's Introduction

screenshot

Get-InjectedThreadEx

Get-InjectedThreadEx.exe scans all running threads looking for suspicious Win32StartAddresses.

Win32Startaddress anomalies include -

  • not MEM_IMAGE
  • non-MEM_IMAGE return address within the first 5 stack frames
  • MEM_IMAGE and on a private (modified) page
  • MEM_IMAGE and x64 dll and not a valid indirect call target
  • MEM_IMAGE and unexpected Win32 dll
  • MEM_IMAGE and x64 and unexpected prolog
  • MEM_IMAGE and preceded by unexpected bytes

See my BSides Canberra 2023 talk and Elastic Security Labs blog for more details.

get-injectedthreadex's People

Contributors

jdu2600 avatar

Stargazers

 avatar Weber Tsai avatar Baier avatar  avatar S3lrius avatar David Carboveanu avatar  avatar Austin Hudson avatar Ben Cambourne avatar  avatar AVA avatar Mohamed Saher avatar  avatar Miguel Magana avatar Ozichukwu Chimezie  avatar Matthew Green avatar Charles Lester avatar Or Guetta avatar Nate Subra avatar  avatar ฯ†-Z avatar DoubtfulTurnip avatar winterknife avatar

Watchers

Matthew Green avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.