这里有些技术没听说过,记录一下: Fileless execution with remote staged encrypted binary or shellcode. Early Bird APC injection. Process masquerading. Supports Named Pipes. Strings and function calls obfuscation. Mortar covert reload subroutine. Delay execution techniques. - 暂不清楚怎么delay的