cyberstars
cyberstars / tools / clr-stomp

CLR-Stomp

BOF that hides .NET execution via CLR module stomping

Beacon Object File that loads a .NET assembly into a running beacon by stomping the CLR module — overwriting the mapped image of a legitimately loaded assembly with the payload before metadata parsing occurs. Execution appears to originate from a genuine Global Assembly Cache path, so ETW and image-load telemetry report the real on-disk module rather than the in-memory payload.