Skip to content

rad9800/WTSRM

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

WTSRM - Writing Tiny Small Reliable Malware demo repository for my corresponding talk.

  • Unhooks all Windows Dlls with \KnownDlls\
  • No CRT dependencies
  • Small size
  • Low entropy
  • Random string encryption key (thus no plaintext strings)
  • API hashing
  • Hook detection
  • Walks around hooks for initial unhooking on ntdll

Diagram

Releases

No releases published

Packages

No packages published

Languages