Skip to content

Instantly share code, notes, and snippets.

@kernullist
Created November 19, 2019 00:15
Show Gist options
  • Save kernullist/0ad638d43cc26fbf436a49988c40dc5d to your computer and use it in GitHub Desktop.
Save kernullist/0ad638d43cc26fbf436a49988c40dc5d to your computer and use it in GitHub Desktop.
createprocess with a suspended thread
$path = "\??\C:\Users\$env:USERNAME\Desktop\bin\evil.exe"
$sect = New-NtSectionImage -Path $path
$p = [NtApiDotNet.NtProcess]::CreateProcessEx($sect)
Get-NtStatus $p.ExitStatus
[NtApiDotNet.NtThread]::Create($p, 0, 0, "Suspended", 4096)
Get-NtStatus $p.ExitStatus
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment