WCU / Cybersecurity
Home
CSC 471
CSC 472
Search
/
~
/
CSC 471
/
Class 06
CSC 471 · Class 06
DLL Injection
21 knowledge points. Work through them in order, or jump to any topic.
//
Knowledge Points
01
What Is DLL Injection?
→
02
Why Attackers (and Defenders) Use It
→
03
Process Address Space and Modules
→
04
The Two Functions at the Heart of It
→
05
The Classic Technique: Overview
→
06
Sequence Diagram
→
07
Condensed C Sketch
→
08
What DllMain Sees
→
09
SetWindowsHookEx
→
10
AppInit_DLLs (Legacy)
→
11
Reflective DLL Injection
→
12
APC Injection (QueueUserAPC)
→
13
Process Hollowing (RunPE)
→
14
Thread Execution Hijacking
→
15
Modern Twists: Early Bird and Module Stomping
→
16
Technique Cheat Sheet
→
17
Detecting Injection: The API Trail
→
18
Detecting Injection: Modules, Hooks, ETW
→
19
Lab 3: Inject Into Notepad
→
20
Lab 3: Deliverables and Tips
→
21
Summary
→