Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.
-
Updated
May 22, 2026 - C++
Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.
Bypassing all EDR hooks while maintaining the cleanest callstack of all time with proxy calls and an exception handler.
Add a description, image, and links to the callstack-spoofing topic page so that developers can more easily learn about it.
To associate your repository with the callstack-spoofing topic, visit your repo's landing page and select "manage topics."