Quan


WEB安全 内网安全 终端对抗 威胁情报
终端对抗
一款好像很不错的loader

这里有些技术没听说过,记录一下:
    Fileless execution with remote staged encrypted binary or shellcode.
    Early Bird APC injection.
    Process masquerading.
    Supports Named Pipes. 
    Strings and function calls obfuscation.
    Mortar covert reload subroutine.
    Delay execution techniques. - 暂不清楚怎么delay的


https://github.com/0xsp-SRD/mortar