Skip to content

Conversation

@physics-sec
Copy link
Contributor

Hey there!
The main idea of this PR is not only to have less static-imports to make the final binary less interesting to static analysis, but to start to make DarkLoadLibrary able to be injected as shellcode directly on memory.
My final goal would be to integrate it with Cobalt Strike as a User Defined Reflective Loader, this is just one step on that direction.

Hope you find it useful!

@hypervis0r
Copy link
Contributor

makes my life easier kekw

@bats3c
Copy link
Owner

bats3c commented Aug 13, 2021

I like that idea, it would be very cool integrate it into CS as a custom loader.

@bats3c bats3c merged commit f3b7c59 into bats3c:master Aug 13, 2021
fengjixuchui added a commit to fengjixuchui/DarkLoadLibrary that referenced this pull request Aug 31, 2021
Merge pull request bats3c#10 from physics-sp/find-import-addresses
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants