From ec0237c5f8b1acd052d57562a43f40a20752b5ca Mon Sep 17 00:00:00 2001 From: "Mariusz B. / mgeeky" Date: Thu, 30 Sep 2021 15:15:40 +0200 Subject: [PATCH] readme --- README.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/README.md b/README.md index dca9353..06e3239 100644 --- a/README.md +++ b/README.md @@ -195,6 +195,20 @@ Unhook is done. --- +## Final remark + +This PoC was designed to work with Cobalt Strike's Beacon shellcodes. The Beacon is known to call out to `kernel32!Sleep` to await further instructions from its C2. +This loader leverages that fact by hooking `Sleep` in order to perform its housekeeping. + +This implementation might not work with other shellcodes in the market (such as _Meterpreter_) if they don't use `Sleep` to cool down. +Since this is merely a _Proof of Concept_ showing the technique, I don't intend on adding support for any other C2 framework. + +When you understand the concept, surely you'll be able to translate it into your shellcode requirements and adapt the solution for your advantage. + +Please do not open Github issues related to "this code doesn't work with XYZ shellcode", they'll be closed immediately. + +--- + ### ☕ Show Support ☕ This and other projects are outcome of sleepless nights and **plenty of hard work**. If you like what I do and appreciate that I always give back to the community,