mirror of
https://github.com/vee1e/capa-rules.git
synced 2026-09-01 19:07:15 +00:00
Identify reflective dll injection using `copy PE sections` and `rebuild import table`. References: - https://0x00sec.org/t/reflective-dll-injection/3080 - https://www.ired.team/offensive-security/code-injection-process-injection/reflective-dll-injection |
||
|---|---|---|
| .. | ||
| pe | ||