TGViewer
网络安全笔记 网络安全笔记 @tsecrecord · 7.95K subscribers
Post #1493 2.39K
【📰 文章类型】:开源安全工具/反检测技术
【⚙️ 技术摘要】:通过Native API绕过hook,精准修复ntdll.dll的.text节,避免加载第二个ntdll,使用NtOpenFile、NtCreateSection、NtMapViewOfSection等原生调用实现无痕内存替换,并通过NtUnmapViewOfSection彻底释放映射,防止EDR检测。

查看原文
GitHub GitHub - hwbp/NTDLL-Unhook: proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls… proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported. - hwbp/NTDLL-Unhook
More from @tsecrecord
  1. Sep 27, 2026一款本地数字取证/事件响应辅助工具。该浏览器扩展程序会捕获您调查过程中的屏幕截图(例如 Velociraptor、EDR/SIEM 控制面板、Security Onion、Splu…
  2. Sep 20, 2026https://opsectechniques.com/
  3. Aug 27, 2026https://github.com/hypnguyen1209/log4j2-rce
  4. Aug 15, 2026https://telegra.ph/weekly-408-08-14
  5. Jul 6, 2026The Long Watch — Scenario Select https://mr-r3b00t.github.io/org_cyber_attack_sim/
  6. Jun 24, 2026https://techblog.zozo.com/entry/soc-claude-agent#SOC-Agent%E3%81%AE%E8%A8%AD%E8%A8%88
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →