/Kernel-Process-Hollowing

Windows x64 kernel mode rootkit process hollowing POC.

Primary LanguageC++MIT LicenseMIT

Windows Kernel Mode Process Hollowing

This project is a proof of concept of how the Process Hollowing technique works from the kernel level.

Resources

SSDT Hook

Process Hollowing