bird.makeup

If you are facing an EDR with PEB protection/obf which makes Ldr inaccessible & want to inject shellcode, just pass the VA of LoadLibrary (which is consistent across processes) to the shellcode via egg-hunting from your injector, enabling lib resolution without touching the PEB
See Tweet

Service load: Currently crawling 1947 users per hour
Source Code Support us on Patreon