Loading DLLs Reflections
ID: 14e1da55-d88a-5169-a956-d8632e6e0a8e
STIX ID: report--14e1da55-d88a-5169-a956-d8632e6e0a8e
Feed Name: TrustedSec blog
Threat Score
This technical write-up explains reflective DLL loading — a technique to load and execute a DLL directly from memory without touching disk — and provides C and C# proof-of-concept implementations, walkthroughs of PE header parsing, relocations, import resolution, and execution of DLLMain. The report discusses attacker advantages (AV evasion, anti-forensics), reversing outcomes, and basic detection suggestions such as monitoring RWX memory allocations and network captures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
