From 027ba24d4bf97a6aa866d902a3ca54c012469a33 Mon Sep 17 00:00:00 2001 From: Zero2504 <84348823+zero2504@users.noreply.github.com> Date: Sat, 5 Apr 2025 21:55:14 +0200 Subject: [PATCH] Update README.md --- README.md | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 5d6be46..eb77bfe 100644 --- a/README.md +++ b/README.md @@ -2,13 +2,15 @@ ## Table of Contents -- [Introduction](#introduction) -- [Theoretical Foundations](#theoretical-foundations) - - [Windows Job Objects](#windows-job-objects) - - [Asynchronous Procedure Calls (APC)](#asynchronous-procedure-calls-apc) -- [Early Cryo Bird Injection](#early-cryo-bird-injection) - - [DLL Injection](#early-cryo-bird-dll-injection) - - [Shellcode Injection](#early-cryo-bird-shellcode-injection) +- [Introduction](##introduction) +- [Theoretical Foundations](##theoretical-foundations) + - [Windows Job Objects](###windows-job-objects) + - [Asynchronous Procedure Calls (APC)](###asynchronous-procedure-calls-apc) + - [QueueUserAPC](###QueueUserAPC) + - [Early Bird Injection](###EarlyBirdInjection) +- [Early Cryo Bird Injection via Pre-Frozen Process in a Job Object](#EarlyCryoBirdInjectionviaPre-FrozenProcessinaJobObject) + - [DLL Injection](##early-cryo-bird-dll-injection) + - [Shellcode Injection](##early-cryo-bird-shellcode-injection) - [Detection & EDR Evaluation](#early-bird-cryo-injections-versus-edrs) - [Conclusion](#conclusion) - [References](#references)