Skip to content

v0.2: retAddr=0

Latest
Compare
Choose a tag to compare
@mgeeky mgeeky released this 01 Oct 17:15
· 11 commits to master since this release

Now the Thread Stack Spoofer simply overwrites MySleep's return address with 0 making the call stack cut in half. This should be enough to fend off AVs and EDRs while not being that anomalous at the same time.