漏洞利用 ======================================== 利用工具 ---------------------------------------- - `pwntools `_ - `ROPgadget `_ Anti-AV ---------------------------------------- - `GhostShell `_ - `DefenderCheck `_ Identifies the bytes that Microsoft Defender flags on ShellCode ---------------------------------------- - `GhostShell `_ Malware indetectable, with AV bypass techniques, anti-disassembly, etc - `donut `_ Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters