{"id":20563721,"url":"https://github.com/trustedsec/inproc_evade_get-injectedthread","last_synced_at":"2025-04-14T14:43:26.953Z","repository":{"id":115337041,"uuid":"246048561","full_name":"trustedsec/inProc_Evade_Get-InjectedThread","owner":"trustedsec","description":"PoC code from blog","archived":false,"fork":false,"pushed_at":"2020-03-10T16:10:41.000Z","size":24,"stargazers_count":16,"open_issues_count":0,"forks_count":4,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-03-28T03:41:23.607Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://www.trustedsec.com/blog/avoiding-get-injectedthread-for-internal-thread-creation/","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/trustedsec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-03-09T13:51:23.000Z","updated_at":"2024-08-21T05:29:08.000Z","dependencies_parsed_at":"2023-05-09T10:46:23.328Z","dependency_job_id":null,"html_url":"https://github.com/trustedsec/inProc_Evade_Get-InjectedThread","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trustedsec%2FinProc_Evade_Get-InjectedThread","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trustedsec%2FinProc_Evade_Get-InjectedThread/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trustedsec%2FinProc_Evade_Get-InjectedThread/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trustedsec%2FinProc_Evade_Get-InjectedThread/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/trustedsec","download_url":"https://codeload.github.com/trustedsec/inProc_Evade_Get-InjectedThread/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248898729,"owners_count":21179830,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-16T04:20:27.896Z","updated_at":"2025-04-14T14:43:26.942Z","avatar_url":"https://github.com/trustedsec.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# inProc_Evade_Get-InjectedThread\n\nThis PoC was built using visual studio 2019.  \nIt gives a demo of internal thread creation of memory injected code that will not trigger a detection using Get-InjectedThread.\n\n## Build instructions\ngit clone -r https://github.com/trustedsec/inProc_Evade_Get-InjectedThread.git   \nopen .sln file using visual studio 2019  \nbuild the solution\n\n## Running\nAquire a copy of Get-InjectedThread (https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2)  \nStart powershell and import Get-InjectedThread.ps1  \nrun the built solution exe with either the argument \"caught\" or \"evade\"  \nrun Get-InjectedThread in powershell and observe the result  \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrustedsec%2Finproc_evade_get-injectedthread","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftrustedsec%2Finproc_evade_get-injectedthread","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrustedsec%2Finproc_evade_get-injectedthread/lists"}