Pentester's Promiscuous Notebook
CtrlK
TwitterGitHubBlog
  • README
  • ⚒️Pentest
    • C2
    • Infrastructure
    • OSINT
    • Password Brute Force
    • Perimeter
    • Shells
    • Web
    • Wi-Fi
  • ⚔️Red Team
    • Basics
    • Infrastructure
    • Development
      • API Hashing
      • API Hooking
      • BOF / COFF
      • CFG
      • Code Injection
      • DLL Hijacking
      • Golang
      • Kernel Mode
      • PIC / Shellcode
      • Nim
      • Sandbox Evasion
      • Syscalls
      • Windows API
  • 🐞Exploit Dev
    • BOF
    • RE
    • WinDbg
  • ⚙️Admin
    • Git
    • Linux
    • Networking
    • Virtualization
    • Windows
Powered by GitBook
On this page
  1. ⚔️Red Team
  2. Development

API Hashing

  • https://www.ired.team/offensive-security/defense-evasion/windows-api-hashing-in-malware

  • https://www.huntress.com/blog/hackers-no-hashing-randomizing-api-hashes-to-evade-cobalt-strike-shellcode-detection

Examples

  • https://github.com/helpsystems/nanodump/blob/main/scripts/randomize_sw2_seed.py

Last updated 3 years ago