🐙 GitHub Detail
med0x2e/ExecuteAssembly
By med0x2e
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avoiding EDR hooks via NT static syscalls (x64) and hiding imports by dynamically resolving APIs (hash).
Live Snapshot
⭐
Stars
599
🍴
Forks
113
📄
License
Unknown
🧩
Type
C++
About this open-source project
Live information fetched from GitHub.
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avoiding EDR hooks via NT static syscalls (x64) and hiding imports by dynamically resolving APIs (hash).
Default Branch
main
Open Issues
2
Watchers
599