Code snippets to add on top of cobalt strike sleepmask kit so that patchless hook on AMSI and ETW can be achieved.
3
3
4
4
_Only for experimental purpose._
skipped 18 lines
23
23
24
24
## Caveat
25
25
1. It cannot cater if your action will create new thread during the execution period of time, which means newly spawned threads at that specific period will not have patchless hook. Theoretically, the newly spawned thread(s) will have patchless hook after one sleep cycle.
26
-
2. If you want to address above caveat, you
26
+
2. If you want to address above caveat, you mayhookNtCreateThreadExtodoso.
27
+
3. At the moment, it only caters x64.
27
28
28
29
## Credits
29
30
All credits to [@rad9800](https://github.com/rad9800)