![]() |
|
#3
|
||||
|
||||
|
Actually if I remember correctly, a few years back some guys found bug in windows driver, and managed to store whole exploit/shellcode in wrongly parsed registry key (which driver parsed during boot). This could count as fileless persistent code
![]() I don't remember who did it, or how article or poc was named. Was long time ago, if somebody remembers would be awesome to post link
__________________
http://accessroot.com |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware Analysis | ldmd | General Discussion | 7 | 03-09-2025 18:42 |
| ahk malware analysis | dion | General Discussion | 0 | 12-20-2021 08:50 |
| Malware Sample analysis | Aesculapius | Source Code | 2 | 02-13-2018 19:35 |