SkillAgentSearch skills...

WowInjector

PoC: Exploit 32-bit Thread Snapshot of WOW64 to Take Over $RIP & Inject & Bypass Antivirus HIPS (HITB 2021)

Install / Use

/learn @aaaddress1/WowInjector
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

wowInjector

Inject payload to WOW64(Windows 32 on Windows 64) process via exploit 32-bit thread snapshot. This trick makes us possible to do malicious attacks and bypass Antivirus agents at the same time, e.g. Injection, Hollowing, Dropper, etc.

It's a proof-of-concept of the talk of HITB 2021. There are more details about reversing the whole WOW64 layer by Microsoft and abuse, see Rebuild The Heaven's Gate: from 32 bit Hell back to Heaven Wonderland.

Demo

Related Skills

View on GitHub
GitHub Stars167
CategoryDevelopment
Updated2mo ago
Forks37

Languages

C

Security Score

100/100

Audited on Jan 7, 2026

No findings