Added IAT hooking functionality to support future planned feature releases. Currently non-default Kernel32.Sleep hook poc added to sleep with ZwDelayExecution direct syscall (experimental). Fixed issues with stack frames and stack alignment that happened on some builds - Shoutout to @ilove2pwn_ @C5pider @kyleavery_
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
Added support for malleable PE "set userwx" option. When using default "sleepmask true" (without sleepmask kit), you will need to set "userwx" to "true" to avoid writing to non-writable beacon.text memory. When using sleepmask kit which supports RX beacon.text memory, set "sleepmask true" && "userwx false".
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
set entry_point supported.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
set entry_point supported.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile,VirtualAlloc(NtAlloc via direct syscall)
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile, VirtualAlloc(NtAlloc via direct syscall).
Additionally the Export Directory of the raw beacon DLL is zero'd out as there is no use for it and it contains known IOC's like "ReflectiveLoader" function name export.
All beacon memory allocators are now supported and they are pulled from the C2 malleable profile! DLL Module Stomping, HeapAlloc, MapViewOfFile,VirtualAlloc(NtAlloc via direct syscall)
boku_pe_mask($temp_dll) can cause issue if prepend transform is in C2 profile. Causes wrong bytes to be overwritten due to offset change. Disabled boku_pe_mask to honor C2 profile transformations.