logo

Loading DLLs Reflections

ID: 14e1da55-d88a-5169-a956-d8632e6e0a8e

STIX ID: report--14e1da55-d88a-5169-a956-d8632e6e0a8e

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This technical write-up explains reflective DLL loading — a technique to load and execute a DLL directly from memory without touching disk — and provides C and C# proof-of-concept implementations, walkthroughs of PE header parsing, relocations, import resolution, and execution of DLLMain. The report discusses attacker advantages (AV evasion, anti-forensics), reversing outcomes, and basic detection suggestions such as monitoring RWX memory allocations and network captures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.