Nothing groundbreaking, but ported the ETW patch from @_xpn_ (mdsec.co.uk/2020/03/hiding-y…) to a beacon object file github.com/ajpc500/BOFs/tree…

1:43 PM · Dec 19, 2020

6
36
94
Added a more general purpose BOF to the repo for reading loaded module functions, and comparing and patching them from on-disk DLLs. github.com/ajpc500/BOFs/tree…
1
5
9
Replying to @ajpc500 @_xpn_
Congrats 👍
0
0
1
Replying to @ajpc500 @_xpn_
Nice work wreck it Alf 💪
1
0
0
Replying to @ajpc500
Awesome stuff mate 🤘
1
0
1
Cheers buddy - you did the important bit! 🙇🏼‍♂️😅
0
0
1
Replying to @ajpc500 @_xpn_
Thank for sharing and nice code!
0
0
1