
إزالة خطافات API من عملية Beacon.
هذا ملف كائن Beacon (BOF) لتحديث DLLs وإزالة خطافاتها. الكود مأخوذ من بحث Universal Unhooking من Cylance:
https://blogs.blackberry.com/en/2017/02/universal-unhooking-blinding-security-software
للاستخدام:
حمّل unhook.cna في Cobalt Strike عبر Cobalt Strike -> Script Manager
شغّل 'unhook' من Beacon
للبناء:
x86: افتح موجه أوامر Visual Studio x86 Native Tools واكتب 'make' x64: افتح موجه أوامر Visual Studio x64 Croos Tools واكتب 'make'
هذا المشروع مشتق من:
Reflective DLL Injection BSD 3-Clause License Copyright (c) 2011, Stephen Fewer من Harmony Security (www.harmonysecurity.com) https://github.com/stephenfewer/ReflectiveDLLInjection
ReflectiveDLLRefresher BSD 3-Clause License Copyright (c) 2017, Cylance Inc. https://github.com/CylanceVulnResearch/ReflectiveDLLRefresher
Unhook Meterpreter Extension BSD-3-Clause License 2006-2018, Rapid7, Inc. https://github.com/rapid7/metasploit-payloads/commits/master/c/meterpreter/source/extensions/unhook