Skip to content

Latest commit

 

History

History
8 lines (4 loc) · 472 Bytes

README.md

File metadata and controls

8 lines (4 loc) · 472 Bytes

FilelessNtdllReflection

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll , and trigger exported API from the export table

ntdllFromServer

ReflectiveNTDLL