Rare find

ReflectiveNtdll. A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by @hasherezade). Payload encryption via SystemFucntion033 NtApi and No new thread via Fiber

github.com/reveng007/ReflectiveNtdll

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.