mirror of
https://github.com/mandiant/capa-rules
synced 2026-06-08 15:41:20 +00:00
be2c552cff
Identify reflective dll injection using `copy PE sections` and `rebuild import table`. References: - https://0x00sec.org/t/reflective-dll-injection/3080 - https://www.ired.team/offensive-security/code-injection-process-injection/reflective-dll-injection