Skip to content

Direct Syscalls and Sleep Obfuscate #1171

Answered by moloch--
hipstertrojan asked this question in Q&A

You must be logged in to vote

We already implement some direct syscalls, we may add more in the future --though typically these will be most effective to implement in your loader. Obfuscated sleep is complicated because of the go runtime, but we're open to ideas on how to implement it.

Replies: 6 comments 8 replies

You must be logged in to vote
4 replies
@hipstertrojan

@moloch--

@moloch--

@hipstertrojan

Answer selected by hipstertrojan

You must be logged in to vote
3 replies
@moloch--

@scriptchildie

@moloch--

You must be logged in to vote
0 replies

You must be logged in to vote
0 replies

You must be logged in to vote
0 replies

You must be logged in to vote
1 reply
@wheeeyeyeye

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
7 participants