/easy-hollow

Automated build for process hollowing shellcode loader. Build on top of TikiTorch and donut projects.

Primary LanguageC#GNU General Public License v3.0GPL-3.0

Very rude implemention of shellcode loader build automated by Python, for own threat emulation needs. So far bypasses 90%+ of EDR's, thanks to donut magic. Takes plain C# source code. Use for your own risk.

> python BuildAutomation\BuildAutomation.py ShowPid\Program.cs
[+] Source compiled!
[+] Shellcode encoded!
[+] Tiki code modyfied!
[+] Malware file: TikiSpawn\obj\Debug\hollow_cov.exe
[!] Cleanup.