Skip to content

Direct Syscalls and Sleep Obfuscate #1171

Answered by moloch--
hipstertrojan asked this question in Q&A
Discussion options

You must be logged in to vote

We already implement some direct syscalls, we may add more in the future --though typically these will be most effective to implement in your loader. Obfuscated sleep is complicated because of the go runtime, but we're open to ideas on how to implement it.

Replies: 4 comments 7 replies

Comment options

You must be logged in to vote
4 replies
@hipstertrojan
Comment options

@moloch--
Comment options

@moloch--
Comment options

@hipstertrojan
Comment options

Answer selected by hipstertrojan
Comment options

You must be logged in to vote
3 replies
@moloch--
Comment options

@scriptchildie
Comment options

@moloch--
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants