Settings

Theme

Reflectively Loading ELFs, may we never touch Disk

github.com

2 points by wetw0rk a year ago · 1 comment

Reader

wetw0rkOP a year ago

I recently pushed an update to Sickle that generates shellcode to perform reflective ELF loading.

If you're unfamiliar with what exactly this is, to give you a quick high-level overview; an attacker uses these techniques to map an executable filetype (EXE, ELF) into memory and execute it. When done correctly this prevents the malware from ever touching disk!

If you want to see a demo run of it launching a “Hello World” application, I uploaded a video on X.

https://x.com/wetw0rk_bot/status/1867739765610811665

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection