
PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.
Process Overwriting is a PE injection technique, closely related to Process Hollowing and Module Overloading.
With its help, you can replace the main executable (not a DLL) of the target process.
It works only for a newly created process - injection to existing processes is not supported with this technique.
WARNING: The size of the target image must be NOT SMALLER than the size of the payload image.
Steps taken:
[!IMPORTANT]
Read FAQ
The demo payload (demo.bin) injected into Windows Calc (default target):

In memory (via Process Hacker):

📹 Process Overwriting on Windows 11 24H2: https://youtu.be/sZ8tMwKfvXw
Use recursive clone to get the repo together with all the submodules:
git clone --recursive https://github.com/hasherezade/process_overwriting.git