From 8d6fc5250d9351523a6447117f4fee3952fdbe70 Mon Sep 17 00:00:00 2001 From: Two Seven One Three Date: Sun, 27 Sep 2026 09:14:38 +0700 Subject: [PATCH] Update README with InjectSetConsole details Added detailed description and usage instructions for InjectSetConsole. --- README.md | 36 +++++++++++++++++++++++++++++++++++- 1 file changed, 35 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 169fd15..5317d99 100644 --- a/README.md +++ b/README.md @@ -1 +1,35 @@ -# InjectSetConsole \ No newline at end of file +# InjectSetConsole + +**InjectSetConsole** performs process code injection by leveraging a **Windows named pipe**. + +Unlike traditional techniques, **it does not use the VirtualAllocEx and WriteProcessMemory APIs**. + +### Command Line Syntax + +**InjectSetConsole.exe `** + +**executable_path**: netsh.exe, nslookup.exe,... or other nteractive console program + +_Example: InjectSetConsole.exe C:\Windows\System32\netsh.exe_ + +To use different shellcode, replace the bytes starting at offset **0x19** (hexadecimal) in the **rawData** array. + +Alternatively, you can modify the search pattern to improve evasion. + +## Links + +[EDR Evasion: Process Injection Without WriteProcessMemory](https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.html) + + +## Demo Video + +Youtube EDRChoker: [https://youtu.be/hj05mT-45bo](https://youtu.be/hj05mT-45bo) + + +## 🐦 Enjoying my work? Support the journey by following me on X + +[![Twitter Follow](https://img.shields.io/twitter/follow/TwoSevenOneT?style=for-the-badge&logo=x&color=000)](https://x.com/TwoSevenOneT) + +## Author: + +[Two Seven One Three](https://x.com/TwoSevenOneT)