From a0d5a6dc3492d5c58653bf73167662a486780b58 Mon Sep 17 00:00:00 2001 From: grisuno security-export bot Date: Fri, 18 Sep 2026 03:53:41 -0300 Subject: [PATCH] chore(security): export issues + knowledge base + agent docs + network links --- KNOWLEDGE_BASE.md | 2401 +++++++++++++++++ README.md | 32 + issues/README.md | 22 + issues/codescan/alert_0.md | 10 + issues/dependabot/alert_0.md | 13 + readmenator-agent/API.md | 1431 ++++++++++ readmenator-agent/ARCHITECTURE.md | 114 + readmenator-agent/GOTCHAS.md | 42 + readmenator-agent/INDEX.md | 45 + readmenator-agent/KB_calc.md | 23 + readmenator-agent/KB_etw.md | 22 + readmenator-agent/KB_root.md | 767 ++++++ readmenator-agent/KB_test.md | 283 ++ readmenator-agent/KB_whoami.md | 22 + readmenator-agent/MANIFEST.json | 25 + readmenator-agent/SECURITY.md | 3 + readmenator-agent/SYMBOLS.md | 872 ++++++ readmenator-agent/recipes/add-function.md | 8 + readmenator-agent/recipes/fix-cycle.md | 6 + readmenator-agent/recipes/fix-security.md | 6 + .../recipes/reduce-complexity.md | 9 + readmenator-rules/readmenator_all.yml | 21 + readmenator-rules/readmenator_multi.yml | 13 + readmenator-rules/readmenator_python.yml | 10 + 24 files changed, 6200 insertions(+) create mode 100644 KNOWLEDGE_BASE.md create mode 100644 issues/README.md create mode 100644 issues/codescan/alert_0.md create mode 100644 issues/dependabot/alert_0.md create mode 100644 readmenator-agent/API.md create mode 100644 readmenator-agent/ARCHITECTURE.md create mode 100644 readmenator-agent/GOTCHAS.md create mode 100644 readmenator-agent/INDEX.md create mode 100644 readmenator-agent/KB_calc.md create mode 100644 readmenator-agent/KB_etw.md create mode 100644 readmenator-agent/KB_root.md create mode 100644 readmenator-agent/KB_test.md create mode 100644 readmenator-agent/KB_whoami.md create mode 100644 readmenator-agent/MANIFEST.json create mode 100644 readmenator-agent/SECURITY.md create mode 100644 readmenator-agent/SYMBOLS.md create mode 100644 readmenator-agent/recipes/add-function.md create mode 100644 readmenator-agent/recipes/fix-cycle.md create mode 100644 readmenator-agent/recipes/fix-security.md create mode 100644 readmenator-agent/recipes/reduce-complexity.md create mode 100644 readmenator-rules/readmenator_all.yml create mode 100644 readmenator-rules/readmenator_multi.yml create mode 100644 readmenator-rules/readmenator_python.yml diff --git a/KNOWLEDGE_BASE.md b/KNOWLEDGE_BASE.md new file mode 100644 index 0000000..9f291de --- /dev/null +++ b/KNOWLEDGE_BASE.md @@ -0,0 +1,2401 @@ +# Polyglot Codebase Knowledge Graph + +> Generated offline by **readmenator**. 41 files, 856 symbols, 107 imports. Supports C, C++, Python, Go, Rust, JS/TS, Java, C#, Shell, PHP, Dart, GDScript, Nim, ASM, Ruby, Swift, Kotlin, Scala, Lua, Elixir. +> No LLMs. No tokens. Pure static analysis. See more [here](https://github.com/grisuno/ReadMenator) + +**Start here:** Statistics Dashboard for scope, God Nodes for blast radius, Architecture Reference for per-file API. Agents: prefer `readmenator-agent/INDEX.md` + `SYMBOLS.md`. + +**Wiki:** prefer `readmenator-wiki/index.md` for progressive disclosure: one synthesis page per community, `connections.json` with EXTRACTED vs INFERRED confidence, `queries.md` log, `REPORT.md` audit. + +**Confidence:** EXTRACTED = parsed from source, INFERRED = heuristic bridge, AMBIGUOUS = reported, never hidden. See `readmenator-wiki/REPORT.md`. + +**Total Files Parsed:** 41 | **Total Symbols Extracted:** 856 | **Total Imports:** 107 + | **Resolved Imports:** 25 + + + + +## Table of Contents + +1. [Statistics Dashboard](#statistics-dashboard) +2. [Architectural Layers](#architectural-layers) +3. [Ranked Context](#ranked-context) +4. [God Nodes](#god-nodes) +5. [Community Analysis](#community-analysis) +6. [Surprising Connections](#surprising-connections) +7. [Suggested Questions](#suggested-questions) +8. [Taint Propagation Map](#taint-propagation-map) +9. [Hotspot Analysis](#hotspot-analysis) +10. [Change Impact Analysis](#change-impact-analysis) +11. [Suggested Linting Rules](#suggested-linting-rules) +12. [Dataflow Analysis](#dataflow-analysis) +13. [Orphans](#orphans) +14. [Query Recipes](#query-recipes) +15. [Structural Knowledge Map](#structural-knowledge-map) +16. [UML Class Diagram](#uml-class-diagram) +17. [Code Property Graph](#code-property-graph) +18. [Architecture Reference](#architecture-reference) + - [C (23 files)](#c-23-files) + - [H (8 files)](#h-8-files) + - [PY (3 files)](#py-3-files) + - [SH (7 files)](#sh-7-files) + +--- + +## Statistics Dashboard + +| Metric | Value | +|--------|-------| +| Total Files | 41 | +| Total Symbols | 856 | +| Total Imports | 107 | +| Call Edges | 96 | +| Inheritance Edges | 0 | +| Languages | 4 | +| Avg Symbols/File | 20.9 | +| Avg Imports/File | 2.6 | +| Resolved Imports | 25 | + +### Top Files by Import Count (Fan-Out) + +| File | Imports | Symbols | Language | +|------|---------|---------|----------| +| `beacon.c` | 26 | 160 | c | +| `cJSON.c` | 9 | 125 | c | +| `COFFLoader3.c` | 6 | 258 | c | +| `tel.py` | 6 | 6 | py | +| `generate_hashs.py` | 6 | 4 | py | +| `disablelog.c` | 5 | 9 | c | +| `scan_shellcode.c` | 3 | 9 | c | +| `vncrelay.c` | 3 | 8 | c | +| `aes.c` | 2 | 43 | c | +| `aes.h` | 2 | 21 | h | + +### Top Files by Imported-By Count (Fan-In) + +| File | Imported By | Symbols | Language | +|------|-------------|---------|----------| +| `beacon.h` | 20 | 4 | h | +| `aes.h` | 2 | 21 | h | +| `cJSON.h` | 2 | 37 | h | +| `COFFLoader.h` | 1 | 1 | h | + +--- + +## Architectural Layers + +Auto-detected from path patterns, naming conventions, and imported frameworks. + +| Layer | Files | +|-------|-------| +| utility | 23 | +| testing | 16 | +| infrastructure | 2 | + +### utility + +- `COFFLoader.h` (h, 1 symbols) +- `COFFLoader3.c` (c, 258 symbols) +- `aes.c` (c, 43 symbols) +- `aes.h` (h, 21 symbols) +- `app.py` (py, 0 symbols) +- `beacon.c` (c, 160 symbols) +- `beacon.h` (h, 4 symbols) +- `beacon.h` (h, 4 symbols) +- `calc.c` (c, 6 symbols) +- `beacon.h` (h, 4 symbols) +- `etw.c` (c, 5 symbols) +- `beacon.h` (h, 4 symbols) +- `whoami.c` (c, 5 symbols) +- `cJSON.c` (c, 125 symbols) +- `cJSON.h` (h, 37 symbols) +- *... and 8 more* + +### testing + +- `Test.c` (c, 1 symbols) +- `amsibypass.c` (c, 5 symbols) +- `beacon.h` (h, 4 symbols) +- `cmdwhoami.c` (c, 4 symbols) +- `loadvnc.c` (c, 8 symbols) +- `make_table.c` (c, 2 symbols) +- `persist.c` (c, 4 symbols) +- `persistsvc.c` (c, 13 symbols) +- `scan_shellcode.c` (c, 9 symbols) +- `shellcode.c` (c, 3 symbols) +- `sock5.c` (c, 41 symbols) +- `tel.py` (py, 6 symbols) +- `uacbypass.c` (c, 5 symbols) +- `upload.c` (c, 41 symbols) +- `vncrelay.c` (c, 8 symbols) +- *... and 1 more* + +### infrastructure + +- `disablelog.c` (c, 9 symbols) +- `getenv.c` (c, 2 symbols) + +--- + +## Ranked Context + +Files ranked by composite score for the current query context. The ranking combines Personalized PageRank (query relevance), global authority, test coverage, documentation coverage, and code freshness. Model: v1.0. + +| Rank | File | Composite | PPR | Authority | Test | Doc | +|------|------|-----------|-----|-----------|------|-----| +| 1 | `gen_dll_rev.sh` | 0.2000 | 0.0000 | 0.0000 | 0.00 | 2.00 | +| 2 | `gen_dll_ss.sh` | 0.2000 | 0.0000 | 0.0000 | 0.00 | 2.00 | +| 3 | `gen_key.sh` | 0.2000 | 0.0000 | 0.0000 | 0.00 | 2.00 | +| 4 | `gen_module.sh` | 0.1500 | 0.0000 | 0.0000 | 0.00 | 1.50 | +| 5 | `beacon.h` | 0.1296 | 0.1994 | 0.1994 | 0.00 | 0.00 | +| 6 | `app.py` | 0.1000 | 0.0000 | 0.0000 | 0.00 | 1.00 | +| 7 | `gen_beacon.sh` | 0.1000 | 0.0000 | 0.0000 | 0.00 | 1.00 | +| 8 | `gen_dll.sh` | 0.1000 | 0.0000 | 0.0000 | 0.00 | 1.00 | +| 9 | `beacon.h` | 0.0984 | 0.1514 | 0.1514 | 0.00 | 0.00 | +| 10 | `uacbypass.c` | 0.0733 | 0.0205 | 0.0205 | 0.00 | 0.60 | + +--- + +## God Nodes + +Most architecturally central files ranked by combined import/export degree and symbol richness. + +| File | Score | Connections | PageRank | +|------|-------|-------------|----------| +| `beacon.h` | 40.4 | | 0.1994 | +| `beacon.h` | 30.4 | | 0.1514 | +| `COFFLoader3.c` | 27.8 | | 0.0000 | +| `beacon.c` | 24.0 | | 0.0000 | +| `cJSON.c` | 14.5 | | 0.0000 | +| `sock5.c` | 8.1 | | 0.0000 | +| `upload.c` | 8.1 | | 0.0000 | +| `cJSON.h` | 7.7 | | 0.0000 | +| `aes.c` | 6.3 | | 0.0000 | +| `aes.h` | 6.1 | | 0.0000 | + +--- + +## Community Analysis + +Files grouped by import-based community detection. Cohesion measures how tightly connected each community is internally. + +### root (Cohesion: 0.83) + +**6 files** in this community: + +- `COFFLoader.h` (h, 1 symbols) +- `aes.c` (c, 43 symbols) +- `aes.h` (h, 21 symbols) +- `beacon.c` (c, 160 symbols) +- `cJSON.c` (c, 125 symbols) +- `cJSON.h` (h, 37 symbols) + +### bof/test (Cohesion: 0.97) + +**24 files** in this community: + +- `COFFLoader3.c` (c, 258 symbols) +- `beacon.h` (h, 4 symbols) +- `beacon.h` (h, 4 symbols) +- `calc.c` (c, 6 symbols) +- `beacon.h` (h, 4 symbols) +- `etw.c` (c, 5 symbols) +- `Test.c` (c, 1 symbols) +- `amsibypass.c` (c, 5 symbols) +- `beacon.h` (h, 4 symbols) +- `cmdwhoami.c` (c, 4 symbols) +- `disablelog.c` (c, 9 symbols) +- `getenv.c` (c, 2 symbols) +- `loadvnc.c` (c, 8 symbols) +- `persist.c` (c, 4 symbols) +- `persistsvc.c` (c, 13 symbols) +- `scan_shellcode.c` (c, 9 symbols) +- `shellcode.c` (c, 3 symbols) +- `sock5.c` (c, 41 symbols) +- `uacbypass.c` (c, 5 symbols) +- `upload.c` (c, 41 symbols) +- ... and 4 more files + +--- + +## Surprising Connections + +Files in different communities connected through 3+ indirect hops. + +- `aes.c` <-> `beacon.h` (5 hops, across 2 communities) +- `aes.c` <-> `beacon.h` (5 hops, across 2 communities) +- `aes.c` <-> `beacon.h` (5 hops, across 2 communities) +- `aes.c` <-> `beacon.h` (5 hops, across 2 communities) +- `beacon.h` <-> `cJSON.c` (5 hops, across 2 communities) + +--- + +## Suggested Questions + +Auto-generated exploration prompts based on graph structure: + +- What does beacon.h depend on, and what depends on it? (20 connections) +- What does beacon.h depend on, and what depends on it? (15 connections) +- What does COFFLoader3.c depend on, and what depends on it? (1 connections) +- How are the 6 files in 'root' related to each other? +- Why are aes.c and beacon.h connected through 5 hops across 2 communities? + +--- + +## Taint Propagation Map + +Taint analysis traces how dangerous imports propagate through the codebase via transitive dependencies. Source files import dangerous modules directly; sink files receive the danger indirectly. + +**Taint Sources:** 1 | **Taint Sinks:** 1 | **Propagation Paths:** 1 + +- `tel.py` imports `requests` (0 hop to `tel.py`) [medium] + Path: tel.py + +--- + +## Hotspot Analysis + +Files ranked by combined complexity (symbol count) and centrality (connection count). High-scoring files are architecturally critical and may need refactoring attention. + +| File | Complexity | Centrality | Combined | Symbols | Connections | +|------|-----------|------------|----------|---------|-------------| +| `gen_dll_rev.sh` | 0.004 | 0.000 | 0.002 | 1 | 0 | +| `gen_dll_ss.sh` | 0.004 | 0.000 | 0.002 | 1 | 0 | +| `gen_key.sh` | 0.004 | 0.000 | 0.002 | 1 | 0 | +| `gen_module.sh` | 0.008 | 0.000 | 0.003 | 2 | 0 | +| `beacon.h` | 0.015 | 0.767 | 0.466 | 4 | 23 | +| `app.py` | 0.000 | 0.033 | 0.020 | 0 | 1 | +| `gen_beacon.sh` | 0.012 | 0.000 | 0.005 | 3 | 0 | +| `gen_dll.sh` | 0.000 | 0.000 | 0.000 | 0 | 0 | +| `beacon.h` | 0.015 | 0.533 | 0.326 | 4 | 16 | +| `uacbypass.c` | 0.019 | 0.100 | 0.068 | 5 | 3 | +| `beacon.c` | 0.620 | 1.000 | 0.848 | 160 | 30 | +| `COFFLoader3.c` | 1.000 | 0.233 | 0.540 | 258 | 7 | +| `cJSON.c` | 0.484 | 0.333 | 0.394 | 125 | 10 | +| `cJSON.h` | 0.143 | 0.167 | 0.157 | 37 | 5 | +| `aes.h` | 0.081 | 0.200 | 0.153 | 21 | 6 | + +--- + +## Dataflow Analysis + +Procedural intra-function dataflow findings (zero tokens, regex-based heuristics, all INFERRED). Each lead is grounded at file:line for manual review. + +**15 findings** (DEAD_STORE: 4, UNCHECKED_ALLOC: 11). + +| File | Function | Line | Kind | Variable | Description | +|------|----------|------|------|----------|-------------| +| `beacon.c` | `extract_shellcode` | 1305 | `UNCHECKED_ALLOC` | `sc` | Result of allocator stored in `sc` is never checked against NULL. | +| `beacon.c` | `ReverseShell` | 1429 | `UNCHECKED_ALLOC` | `s` | Result of allocator stored in `s` is never checked against NULL. | +| `beacon.c` | `discoverLocalHosts` | 1730 | `UNCHECKED_ALLOC` | `reply` | Result of allocator stored in `reply` is never checked against NULL. | +| `beacon.c` | `proxy_thread` | 1788 | `UNCHECKED_ALLOC` | `server` | Result of allocator stored in `server` is never checked against NULL. | +| `beacon.c` | `startProxy` | 1968 | `UNCHECKED_ALLOC` | `listenSock` | Result of allocator stored in `listenSock` is never checked against NULL. | +| `beacon.c` | `executeUACBypass` | 3570 | `DEAD_STORE` | `maliciousCmd` | `maliciousCmd` assigned at line 3570 but never read afterwards. | +| `beacon.c` | `scanPort` | 3621 | `UNCHECKED_ALLOC` | `s` | Result of allocator stored in `s` is never checked against NULL. | +| `cJSON.c` | `print_array` | 1654 | `DEAD_STORE` | `output_pointer` | `output_pointer` assigned at line 1654 but never read afterwards. | +| `cJSON.c` | `print_object` | 1887 | `DEAD_STORE` | `output_pointer` | `output_pointer` assigned at line 1887 but never read afterwards. | +| `gen_beacon.sh` | `xor_string` | 4053 | `DEAD_STORE` | `maliciousCmd` | `maliciousCmd` assigned at line 4053 but never read afterwards. | +| `gen_beacon.sh` | `xor_string` | 1796 | `UNCHECKED_ALLOC` | `sc` | Result of allocator stored in `sc` is never checked against NULL. | +| `gen_beacon.sh` | `xor_string` | 4104 | `UNCHECKED_ALLOC` | `s` | Result of allocator stored in `s` is never checked against NULL. | +| `gen_beacon.sh` | `xor_string` | 2221 | `UNCHECKED_ALLOC` | `reply` | Result of allocator stored in `reply` is never checked against NULL. | +| `gen_beacon.sh` | `xor_string` | 2279 | `UNCHECKED_ALLOC` | `server` | Result of allocator stored in `server` is never checked against NULL. | +| `gen_beacon.sh` | `xor_string` | 2459 | `UNCHECKED_ALLOC` | `listenSock` | Result of allocator stored in `listenSock` is never checked against NULL. | + +--- + +## Change Impact Analysis + +Files sorted by how many other files would be affected if they changed. High-impact files should be changed with caution. + +| File | Direct Dependents | Transitive Dependents | Total Impact | +|------|------------------|----------------------|--------------| +| `beacon.h` | 15 | 0 | 15 | +| `aes.h` | 2 | 0 | 2 | +| `beacon.h` | 2 | 0 | 2 | +| `cJSON.h` | 2 | 0 | 2 | +| `COFFLoader.h` | 1 | 0 | 1 | +| `beacon.h` | 1 | 0 | 1 | +| `beacon.h` | 1 | 0 | 1 | +| `beacon.h` | 1 | 0 | 1 | +| `COFFLoader3.c` | 0 | 0 | 0 | +| `aes.c` | 0 | 0 | 0 | +| `app.py` | 0 | 0 | 0 | +| `beacon.c` | 0 | 0 | 0 | +| `calc.c` | 0 | 0 | 0 | +| `etw.c` | 0 | 0 | 0 | +| `Test.c` | 0 | 0 | 0 | + +--- + +## Suggested Linting Rules + +Automatically suggested linting and security rules based on patterns detected in the codebase. These can be exported as Semgrep rules using the `--export-rules` flag. + +| Rule ID | Severity | Description | Language | Matches | +|---------|----------|-------------|----------|---------| +| `RM006` | error | Hardcoded credential detected | multi | 4 | +| `RM001` | info | Large number of functions in h: 9 total | h | 9 | +| `RM002` | info | Large number of functions in c: 288 total | c | 288 | +| `RM003` | info | Large number of functions in py: 10 total | py | 10 | +| `RM004` | info | Large number of functions in sh: 8 total | sh | 8 | +| `RM005` | info | Print statement found (consider logging instead) | python | 17 | + +--- + +## Orphans + +Files with no documentation or low connectivity. These are candidates for documentation investment or cleanup. + +- `beacon.h` (4 symbols, no doc) +- `beacon.h` (4 symbols, no doc) +- `COFFLoader.h` (1 symbols, no doc) +- `beacon.h` (4 symbols, no doc) +- `beacon.h` (4 symbols, no doc) +- `Test.c` (1 symbols, no doc) +- `cmdwhoami.c` (4 symbols, no doc) +- `disablelog.c` (9 symbols, no doc) +- `getenv.c` (2 symbols, no doc) +- `make_table.c` (2 symbols, no doc) +- `persist.c` (4 symbols, no doc) +- `shellcode.c` (3 symbols, no doc) +- `winver.c` (2 symbols, no doc) +- `beacon.h` (4 symbols, no doc) +- `install.sh` (0 symbols, no doc) + +--- + +## Query Recipes + +Example queries you can run against this knowledge base using the ranking engine: + +``` +# Find files most relevant to a concept +readmenator query "Where is the import resolver implemented?" + +# Rank files by relevance to a topic +readmenator query "How does documentation generation work?" + +# Explain why a file ranks highly +readmenator query "explain readmenator/_documentation.py" + +# Trace dependency paths with ranked context +readmenator query "path from CLI to exporter" +``` + +The ranking model uses the following signals: + +- **Personalized PageRank** (45% weight): query-specific relevance via seed propagation +- **Global Authority** (20% weight): structural importance via standard PageRank +- **Test Coverage** (15% weight): fraction of symbols referenced in test files +- **Doc Coverage** (10% weight): presence of docstrings and file-level docs +- **Freshness** (10% weight): recent modification activity + +Results include score decomposition and justification paths for each ranked item. + +--- + +## Structural Knowledge Map + +```mermaid +graph TD + classDef mod fill:#1e1e1e,stroke:#ff6666,stroke-width:2px,color:#fff; + classDef cls fill:#2d2d2d,stroke:#4ec9b0,stroke-width:2px,color:#fff; + classDef fn fill:#333,stroke:#dcdcaa,stroke-width:1px,color:#dcdcaa; + classDef ext fill:#111,stroke:#666,stroke-dasharray:5 5,color:#aaa; + subgraph community_0 ["root"] + beacon_c["beacon.c (c)"] + class beacon_c mod; + beacon_c__PROCESS_BASIC_INFORMATION["_PROCESS_BASIC_INFORMATION"] + class beacon_c__PROCESS_BASIC_INFORMATION cls; + beacon_c --> beacon_c__PROCESS_BASIC_INFORMATION + beacon_c__UNICODE_STRING["_UNICODE_STRING"] + class beacon_c__UNICODE_STRING cls; + beacon_c --> beacon_c__UNICODE_STRING + beacon_c__LDR_DATA_TABLE_ENTRY["_LDR_DATA_TABLE_ENTRY"] + class beacon_c__LDR_DATA_TABLE_ENTRY cls; + beacon_c --> beacon_c__LDR_DATA_TABLE_ENTRY + beacon_c__PEB_LDR_DATA["_PEB_LDR_DATA"] + class beacon_c__PEB_LDR_DATA cls; + beacon_c --> beacon_c__PEB_LDR_DATA + beacon_c__PEB["_PEB"] + class beacon_c__PEB cls; + beacon_c --> beacon_c__PEB + cJSON_c["cJSON.c (c)"] + class cJSON_c mod; + end + subgraph community_1 ["bof/test"] + COFFLoader3_c["COFFLoader3.c (c)"] + class COFFLoader3_c mod; + bof_test_disablelog_c["disablelog.c (c)"] + class bof_test_disablelog_c mod; + bof_test_tel_py["tel.py (py)"] + class bof_test_tel_py mod; + generate_hashs_py["generate_hashs.py (py)"] + class generate_hashs_py mod; + bof_test_scan_shellcode_c["scan_shellcode.c (c)"] + class bof_test_scan_shellcode_c mod; + bof_test_vncrelay_c["vncrelay.c (c)"] + class bof_test_vncrelay_c mod; + aes_c["aes.c (c)"] + class aes_c mod; + bof_test_sock5_c["sock5.c (c)"] + class bof_test_sock5_c mod; + bof_test_upload_c["upload.c (c)"] + class bof_test_upload_c mod; + bof_test_persistsvc_c["persistsvc.c (c)"] + class bof_test_persistsvc_c mod; + bof_test_loadvnc_c["loadvnc.c (c)"] + class bof_test_loadvnc_c mod; + bof_calc_calc_c["calc.c (c)"] + class bof_calc_calc_c mod; + bof_etw_etw_c["etw.c (c)"] + class bof_etw_etw_c mod; + bof_test_amsibypass_c["amsibypass.c (c)"] + class bof_test_amsibypass_c mod; + bof_test_uacbypass_c["uacbypass.c (c)"] + class bof_test_uacbypass_c mod; + bof_whoami_whoami_c["whoami.c (c)"] + class bof_whoami_whoami_c mod; + bof_test_cmdwhoami_c["cmdwhoami.c (c)"] + class bof_test_cmdwhoami_c mod; + bof_test_persist_c["persist.c (c)"] + class bof_test_persist_c mod; + bof_test_shellcode_c["shellcode.c (c)"] + class bof_test_shellcode_c mod; + bof_test_getenv_c["getenv.c (c)"] + class bof_test_getenv_c mod; + bof_test_winver_c["winver.c (c)"] + class bof_test_winver_c mod; + aes_h["aes.h (h)"] + class aes_h mod; + bof_test_make_table_c["make_table.c (c)"] + class bof_test_make_table_c mod; + bof_test_Test_c["Test.c (c)"] + class bof_test_Test_c mod; + cJSON_h["cJSON.h (h)"] + class cJSON_h mod; + beacon_h["beacon.h (h)"] + class beacon_h mod; + bof_calc_beacon_h["beacon.h (h)"] + class bof_calc_beacon_h mod; + bof_etw_beacon_h["beacon.h (h)"] + class bof_etw_beacon_h mod; + bof_test_beacon_h["beacon.h (h)"] + class bof_test_beacon_h mod; + bof_whoami_beacon_h["beacon.h (h)"] + class bof_whoami_beacon_h mod; + COFFLoader_h["COFFLoader.h (h)"] + class COFFLoader_h mod; + app_py["app.py (py)"] + class app_py mod; + gen_beacon_sh["gen_beacon.sh (sh)"] + class gen_beacon_sh mod; + gen_module_sh["gen_module.sh (sh)"] + class gen_module_sh mod; + gen_dll_rev_sh["gen_dll_rev.sh (sh)"] + class gen_dll_rev_sh mod; + gen_dll_ss_sh["gen_dll_ss.sh (sh)"] + class gen_dll_ss_sh mod; + gen_key_sh["gen_key.sh (sh)"] + class gen_key_sh mod; + gen_dll_sh["gen_dll.sh (sh)"] + class gen_dll_sh mod; + install_sh["install.sh (sh)"] + class install_sh mod; + end + COFFLoader3_c -- resolved_imports --> beacon_h + aes_c -- resolved_imports --> aes_h + beacon_c -- resolved_imports --> aes_h + beacon_c -- resolved_imports --> cJSON_h + beacon_c -- resolved_imports --> beacon_h + beacon_c -- resolved_imports --> COFFLoader_h + bof_calc_calc_c -- resolved_imports --> bof_calc_beacon_h + bof_etw_etw_c -- resolved_imports --> bof_etw_beacon_h + bof_test_Test_c -- resolved_imports --> bof_test_beacon_h + bof_test_amsibypass_c -- resolved_imports --> bof_test_beacon_h + bof_test_cmdwhoami_c -- resolved_imports --> bof_test_beacon_h + bof_test_disablelog_c -- resolved_imports --> bof_test_beacon_h + bof_test_getenv_c -- resolved_imports --> bof_test_beacon_h + bof_test_loadvnc_c -- resolved_imports --> bof_test_beacon_h + bof_test_persist_c -- resolved_imports --> bof_test_beacon_h + bof_test_persistsvc_c -- resolved_imports --> bof_test_beacon_h + bof_test_scan_shellcode_c -- resolved_imports --> bof_test_beacon_h + bof_test_shellcode_c -- resolved_imports --> bof_test_beacon_h + bof_test_sock5_c -- resolved_imports --> bof_test_beacon_h + bof_test_uacbypass_c -- resolved_imports --> bof_test_beacon_h + bof_test_upload_c -- resolved_imports --> bof_test_beacon_h + bof_test_vncrelay_c -- resolved_imports --> bof_test_beacon_h + bof_test_winver_c -- resolved_imports --> bof_test_beacon_h + bof_whoami_whoami_c -- resolved_imports --> bof_whoami_beacon_h + cJSON_c -- resolved_imports --> cJSON_h + ext_windows_h["windows.h"] + class ext_windows_h ext; + COFFLoader_h -.->|imports| ext_windows_h + COFFLoader3_c -.->|imports| ext_windows_h + ext_stdio_h["stdio.h"] + class ext_stdio_h ext; + COFFLoader3_c -.->|imports| ext_stdio_h + ext_stdlib_h["stdlib.h"] + class ext_stdlib_h ext; + COFFLoader3_c -.->|imports| ext_stdlib_h + ext_string_h["string.h"] + class ext_string_h ext; + COFFLoader3_c -.->|imports| ext_string_h + ext_stdint_h["stdint.h"] + class ext_stdint_h ext; + COFFLoader3_c -.->|imports| ext_stdint_h + ext_beacon_h["beacon.h"] + class ext_beacon_h ext; + COFFLoader3_c -.->|imports| ext_beacon_h + ext_aes_h["aes.h"] + class ext_aes_h ext; + aes_c -.->|imports| ext_aes_h + aes_c -.->|imports| ext_string_h + aes_h -.->|imports| ext_stdint_h + ext_stddef_h["stddef.h"] + class ext_stddef_h ext; + aes_h -.->|imports| ext_stddef_h + ext_os["os"] + class ext_os ext; + app_py -.->|imports| ext_os + ext_winsock2_h["winsock2.h"] + class ext_winsock2_h ext; + beacon_c -.->|imports| ext_winsock2_h + ext_ws2tcpip_h["ws2tcpip.h"] + class ext_ws2tcpip_h ext; + beacon_c -.->|imports| ext_ws2tcpip_h + beacon_c -.->|imports| ext_windows_h + ext_winnt_h["winnt.h"] + class ext_winnt_h ext; + beacon_c -.->|imports| ext_winnt_h + ext_winhttp_h["winhttp.h"] + class ext_winhttp_h ext; + beacon_c -.->|imports| ext_winhttp_h + ext_wincrypt_h["wincrypt.h"] + class ext_wincrypt_h ext; + beacon_c -.->|imports| ext_wincrypt_h + ext_ntstatus_h["ntstatus.h"] + class ext_ntstatus_h ext; + beacon_c -.->|imports| ext_ntstatus_h + ext_tlhelp32_h["tlhelp32.h"] + class ext_tlhelp32_h ext; + beacon_c -.->|imports| ext_tlhelp32_h + beacon_c -.->|imports| ext_stdio_h + beacon_c -.->|imports| ext_stdlib_h + beacon_c -.->|imports| ext_string_h + ext_io_h["io.h"] + class ext_io_h ext; + beacon_c -.->|imports| ext_io_h + ext_process_h["process.h"] + class ext_process_h ext; + beacon_c -.->|imports| ext_process_h + ext_time_h["time.h"] + class ext_time_h ext; + beacon_c -.->|imports| ext_time_h + ext_iphlpapi_h["iphlpapi.h"] + class ext_iphlpapi_h ext; + beacon_c -.->|imports| ext_iphlpapi_h + ext_icmpapi_h["icmpapi.h"] + class ext_icmpapi_h ext; + beacon_c -.->|imports| ext_icmpapi_h + ext_bcrypt_h["bcrypt.h"] + class ext_bcrypt_h ext; + beacon_c -.->|imports| ext_bcrypt_h + ext_shlobj_h["shlobj.h"] + class ext_shlobj_h ext; + beacon_c -.->|imports| ext_shlobj_h + ext_objbase_h["objbase.h"] + class ext_objbase_h ext; + beacon_c -.->|imports| ext_objbase_h + ext_shellapi_h["shellapi.h"] + class ext_shellapi_h ext; + beacon_c -.->|imports| ext_shellapi_h + ext_winioctl_h["winioctl.h"] + class ext_winioctl_h ext; + beacon_c -.->|imports| ext_winioctl_h + ext_setjmp_h["setjmp.h"] + class ext_setjmp_h ext; + beacon_c -.->|imports| ext_setjmp_h + beacon_c -.->|imports| ext_aes_h + ext_cJSON_h["cJSON.h"] + class ext_cJSON_h ext; + beacon_c -.->|imports| ext_cJSON_h + beacon_c -.->|imports| ext_beacon_h + ext_COFFLoader_h["COFFLoader.h"] + class ext_COFFLoader_h ext; + beacon_c -.->|imports| ext_COFFLoader_h + beacon_h -.->|imports| ext_windows_h + bof_calc_beacon_h -.->|imports| ext_windows_h + bof_calc_calc_c -.->|imports| ext_windows_h + bof_calc_calc_c -.->|imports| ext_beacon_h + bof_etw_beacon_h -.->|imports| ext_windows_h + bof_etw_etw_c -.->|imports| ext_windows_h + bof_etw_etw_c -.->|imports| ext_beacon_h + bof_test_Test_c -.->|imports| ext_beacon_h + bof_test_amsibypass_c -.->|imports| ext_windows_h + bof_test_amsibypass_c -.->|imports| ext_beacon_h + bof_test_beacon_h -.->|imports| ext_windows_h + bof_test_cmdwhoami_c -.->|imports| ext_windows_h + bof_test_cmdwhoami_c -.->|imports| ext_beacon_h + bof_test_disablelog_c -.->|imports| ext_windows_h + bof_test_disablelog_c -.->|imports| ext_tlhelp32_h + ext_psapi_h["psapi.h"] + class ext_psapi_h ext; + bof_test_disablelog_c -.->|imports| ext_psapi_h + ext_winternl_h["winternl.h"] + class ext_winternl_h ext; + bof_test_disablelog_c -.->|imports| ext_winternl_h + bof_test_disablelog_c -.->|imports| ext_beacon_h + bof_test_getenv_c -.->|imports| ext_windows_h + bof_test_getenv_c -.->|imports| ext_beacon_h + bof_test_loadvnc_c -.->|imports| ext_windows_h + bof_test_loadvnc_c -.->|imports| ext_beacon_h + bof_test_make_table_c -.->|imports| ext_stdint_h + bof_test_make_table_c -.->|imports| ext_stdio_h + bof_test_persist_c -.->|imports| ext_windows_h + bof_test_persist_c -.->|imports| ext_beacon_h + bof_test_persistsvc_c -.->|imports| ext_windows_h + bof_test_persistsvc_c -.->|imports| ext_beacon_h + bof_test_scan_shellcode_c -.->|imports| ext_windows_h + bof_test_scan_shellcode_c -.->|imports| ext_tlhelp32_h + bof_test_scan_shellcode_c -.->|imports| ext_beacon_h + bof_test_shellcode_c -.->|imports| ext_windows_h + bof_test_shellcode_c -.->|imports| ext_beacon_h + bof_test_sock5_c -.->|imports| ext_windows_h + bof_test_sock5_c -.->|imports| ext_beacon_h + ext_requests["requests"] + class ext_requests ext; + bof_test_tel_py -.->|imports| ext_requests + ext_re["re"] + class ext_re ext; + bof_test_tel_py -.->|imports| ext_re + ext_uuid["uuid"] + class ext_uuid ext; + bof_test_tel_py -.->|imports| ext_uuid + ext_json["json"] + class ext_json ext; + bof_test_tel_py -.->|imports| ext_json + ext_Crypto_Cipher["Crypto.Cipher"] + class ext_Crypto_Cipher ext; + bof_test_tel_py -.->|imports| ext_Crypto_Cipher + ext_datetime["datetime"] + class ext_datetime ext; + bof_test_tel_py -.->|imports| ext_datetime + bof_test_uacbypass_c -.->|imports| ext_windows_h + bof_test_uacbypass_c -.->|imports| ext_beacon_h + bof_test_upload_c -.->|imports| ext_windows_h + bof_test_upload_c -.->|imports| ext_beacon_h + bof_test_vncrelay_c -.->|imports| ext_winsock2_h + bof_test_vncrelay_c -.->|imports| ext_windows_h + bof_test_vncrelay_c -.->|imports| ext_beacon_h + bof_test_winver_c -.->|imports| ext_windows_h + bof_test_winver_c -.->|imports| ext_beacon_h + bof_whoami_beacon_h -.->|imports| ext_windows_h + bof_whoami_whoami_c -.->|imports| ext_windows_h + bof_whoami_whoami_c -.->|imports| ext_beacon_h + cJSON_c -.->|imports| ext_string_h + cJSON_c -.->|imports| ext_stdio_h + ext_math_h["math.h"] + class ext_math_h ext; + cJSON_c -.->|imports| ext_math_h + cJSON_c -.->|imports| ext_stdlib_h + ext_limits_h["limits.h"] + class ext_limits_h ext; + cJSON_c -.->|imports| ext_limits_h + ext_ctype_h["ctype.h"] + class ext_ctype_h ext; + cJSON_c -.->|imports| ext_ctype_h + ext_float_h["float.h"] + class ext_float_h ext; + cJSON_c -.->|imports| ext_float_h + ext_locale_h["locale.h"] + class ext_locale_h ext; + cJSON_c -.->|imports| ext_locale_h + cJSON_c -.->|imports| ext_cJSON_h + cJSON_h -.->|imports| ext_stddef_h + ext_argparse["argparse"] + class ext_argparse ext; + generate_hashs_py -.->|imports| ext_argparse + ext_sys["sys"] + class ext_sys ext; + generate_hashs_py -.->|imports| ext_sys + generate_hashs_py -.->|imports| ext_re + ext_pygments["pygments"] + class ext_pygments ext; + generate_hashs_py -.->|imports| ext_pygments + ext_pygments_lexers["pygments.lexers"] + class ext_pygments_lexers ext; + generate_hashs_py -.->|imports| ext_pygments_lexers + ext_pygments_formatters["pygments.formatters"] + class ext_pygments_formatters ext; + generate_hashs_py -.->|imports| ext_pygments_formatters +``` + +--- + +## UML Class Diagram + +Auto-generated Mermaid class diagram from parsed class-level symbols. Shows classes, structs, interfaces, traits, and their methods with inheritance and dependency relationships. + +```mermaid +classDiagram + class COFFLoader3_c_COFFSection { + <> + +djb2_hash(const char* str) + +create_trampoline(void* target) + +handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ... + +get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size) + +__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2) + +RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*... + } + class COFFLoader3_c_COFFRelocation { + <> + +djb2_hash(const char* str) + +create_trampoline(void* target) + +handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ... + +get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size) + +__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2) + +RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*... + } + class COFFLoader3_c_COFFHeader { + <> + +djb2_hash(const char* str) + +create_trampoline(void* target) + +handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ... + +get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size) + +__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2) + +RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*... + } + class COFFLoader3_c_SymbolHash { + <> + +djb2_hash(const char* str) + +create_trampoline(void* target) + +handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ... + +get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size) + +__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2) + +RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*... + } + class aes_h_AES_ctx { + <> + +AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key); + +AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv); + +AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv); + +AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf); + +AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf); + +AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length); + +AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length); + +AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length); + } + class beacon_c__PROCESS_BASIC_INFORMATION { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c__UNICODE_STRING { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c__LDR_DATA_TABLE_ENTRY { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c__PEB_LDR_DATA { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c__PEB { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_ProxySession { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_ProxyThreadData { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_ReverseArgs { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_PortScannerArgs { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_LazyDataType { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_ProxyListener { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_PacketEncryptionContext { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_c_PortResult { + <> + +ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo) + +get_shell_cmd() + +__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size) + +__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size) + +__declspec(dllexport) int BeaconDataInt(datap * parser) + +__declspec(dllexport) short BeaconDataShort(datap * parser) + +__declspec(dllexport) int BeaconDataLength(datap * parser) + +__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size) + +__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...) + +__declspec(dllexport) void BeaconOutput(int type, const char * data, int len) + } + class beacon_h_datap { + <> + } + class beacon_h_datap { + <> + } + class beacon_h_datap { + <> + } + class beacon_h_datap { + <> + } + class loadvnc_c__PROCESSENTRY32 { + <> + +execute_cmd_hidden(char* cmd) + +go(char *args, int alen) + } + class sock5_c_WSAData { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_fd_set { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_timeval { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_in_addr { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_sockaddr_in { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_sockaddr { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class sock5_c_hostent { + <> + +my_FD_ISSET(SOCKET s, fd_set *set) + +HandleSocks5Connection(SOCKET client_sock, + CONNECT pConnect, RECV pRecv, SEND pSe... + +ProxyThread(LPVOID _) + +go(char *args, int alen) + } + class upload_c_AES_ctx { + <> + +my_strlen(const char *s) + +my_memcpy(void* dst, const void* src, size_t len) + +my_memset(void* dst, int val, size_t len) + +my_contains_dotdot(const char* path) + +my_strchr(const char *s, int c) + +xtime(uint8_t x) + +AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey) + +SubBytes(state_t* state, const uint8_t* sbox) + +ShiftRows(state_t* state) + +MixColumns(state_t* state) + } + class beacon_h_datap { + <> + } + class cJSON_c_internal_hooks { + <> + +CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void) + +CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item) + +CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item) + +CJSON_PUBLIC(const char*) cJSON_Version(void) + +case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2) + +internal_malloc(size_t size) + +internal_free(void *pointer) + +internal_realloc(void *pointer, size_t size) + +cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks) + +CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks) + } + class cJSON_c_error { + <> + +CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void) + +CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item) + +CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item) + +CJSON_PUBLIC(const char*) cJSON_Version(void) + +case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2) + +internal_malloc(size_t size) + +internal_free(void *pointer) + +internal_realloc(void *pointer, size_t size) + +cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks) + +CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks) + } + class cJSON_c_parse_buffer { + <> + +CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void) + +CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item) + +CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item) + +CJSON_PUBLIC(const char*) cJSON_Version(void) + +case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2) + +internal_malloc(size_t size) + +internal_free(void *pointer) + +internal_realloc(void *pointer, size_t size) + +cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks) + +CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks) + } + class cJSON_c_printbuffer { + <> + +CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void) + +CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item) + +CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item) + +CJSON_PUBLIC(const char*) cJSON_Version(void) + +case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2) + +internal_malloc(size_t size) + +internal_free(void *pointer) + +internal_realloc(void *pointer, size_t size) + +cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks) + +CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks) + } + class cJSON_h_cJSON { + <> + +sensitive(1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo + } + class cJSON_h_cJSON_Hooks { + <> + +sensitive(1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo + } + COFFLoader3_c_COFFHeader --> beacon_h_datap : uses + COFFLoader3_c_COFFRelocation --> beacon_h_datap : uses + COFFLoader3_c_COFFSection --> beacon_h_datap : uses + COFFLoader3_c_SymbolHash --> beacon_h_datap : uses + beacon_c_LazyDataType --> aes_h_AES_ctx : uses + beacon_c_LazyDataType --> beacon_h_datap : uses + beacon_c_LazyDataType --> cJSON_h_cJSON : uses + beacon_c_LazyDataType --> cJSON_h_cJSON_Hooks : uses + beacon_c_PacketEncryptionContext --> aes_h_AES_ctx : uses + beacon_c_PacketEncryptionContext --> beacon_h_datap : uses + beacon_c_PacketEncryptionContext --> cJSON_h_cJSON : uses + beacon_c_PacketEncryptionContext --> cJSON_h_cJSON_Hooks : uses + beacon_c_PortResult --> aes_h_AES_ctx : uses + beacon_c_PortResult --> beacon_h_datap : uses + beacon_c_PortResult --> cJSON_h_cJSON : uses + beacon_c_PortResult --> cJSON_h_cJSON_Hooks : uses + beacon_c_PortScannerArgs --> aes_h_AES_ctx : uses + beacon_c_PortScannerArgs --> beacon_h_datap : uses + beacon_c_PortScannerArgs --> cJSON_h_cJSON : uses + beacon_c_PortScannerArgs --> cJSON_h_cJSON_Hooks : uses + beacon_c_ProxyListener --> aes_h_AES_ctx : uses + beacon_c_ProxyListener --> beacon_h_datap : uses + beacon_c_ProxyListener --> cJSON_h_cJSON : uses + beacon_c_ProxyListener --> cJSON_h_cJSON_Hooks : uses + beacon_c_ProxySession --> aes_h_AES_ctx : uses + beacon_c_ProxySession --> beacon_h_datap : uses + beacon_c_ProxySession --> cJSON_h_cJSON : uses + beacon_c_ProxySession --> cJSON_h_cJSON_Hooks : uses + beacon_c_ProxyThreadData --> aes_h_AES_ctx : uses + beacon_c_ProxyThreadData --> beacon_h_datap : uses + beacon_c_ProxyThreadData --> cJSON_h_cJSON : uses + beacon_c_ProxyThreadData --> cJSON_h_cJSON_Hooks : uses + beacon_c_ReverseArgs --> aes_h_AES_ctx : uses + beacon_c_ReverseArgs --> beacon_h_datap : uses + beacon_c_ReverseArgs --> cJSON_h_cJSON : uses + beacon_c_ReverseArgs --> cJSON_h_cJSON_Hooks : uses + beacon_c__LDR_DATA_TABLE_ENTRY --> aes_h_AES_ctx : uses + beacon_c__LDR_DATA_TABLE_ENTRY --> beacon_h_datap : uses + beacon_c__LDR_DATA_TABLE_ENTRY --> cJSON_h_cJSON : uses + beacon_c__LDR_DATA_TABLE_ENTRY --> cJSON_h_cJSON_Hooks : uses + beacon_c__PEB --> aes_h_AES_ctx : uses + beacon_c__PEB --> beacon_h_datap : uses + beacon_c__PEB --> cJSON_h_cJSON : uses + beacon_c__PEB --> cJSON_h_cJSON_Hooks : uses + beacon_c__PEB_LDR_DATA --> aes_h_AES_ctx : uses + beacon_c__PEB_LDR_DATA --> beacon_h_datap : uses + beacon_c__PEB_LDR_DATA --> cJSON_h_cJSON : uses + beacon_c__PEB_LDR_DATA --> cJSON_h_cJSON_Hooks : uses + beacon_c__PROCESS_BASIC_INFORMATION --> aes_h_AES_ctx : uses + beacon_c__PROCESS_BASIC_INFORMATION --> beacon_h_datap : uses + beacon_c__PROCESS_BASIC_INFORMATION --> cJSON_h_cJSON : uses + beacon_c__PROCESS_BASIC_INFORMATION --> cJSON_h_cJSON_Hooks : uses + beacon_c__UNICODE_STRING --> aes_h_AES_ctx : uses + beacon_c__UNICODE_STRING --> beacon_h_datap : uses + beacon_c__UNICODE_STRING --> cJSON_h_cJSON : uses + beacon_c__UNICODE_STRING --> cJSON_h_cJSON_Hooks : uses + cJSON_c_error --> cJSON_h_cJSON : uses + cJSON_c_error --> cJSON_h_cJSON_Hooks : uses + cJSON_c_internal_hooks --> cJSON_h_cJSON : uses + cJSON_c_internal_hooks --> cJSON_h_cJSON_Hooks : uses + cJSON_c_parse_buffer --> cJSON_h_cJSON : uses + cJSON_c_parse_buffer --> cJSON_h_cJSON_Hooks : uses + cJSON_c_printbuffer --> cJSON_h_cJSON : uses + cJSON_c_printbuffer --> cJSON_h_cJSON_Hooks : uses + loadvnc_c__PROCESSENTRY32 --> beacon_h_datap : uses + sock5_c_WSAData --> beacon_h_datap : uses + sock5_c_fd_set --> beacon_h_datap : uses + sock5_c_hostent --> beacon_h_datap : uses + sock5_c_in_addr --> beacon_h_datap : uses + sock5_c_sockaddr --> beacon_h_datap : uses + sock5_c_sockaddr_in --> beacon_h_datap : uses + sock5_c_timeval --> beacon_h_datap : uses + upload_c_AES_ctx --> beacon_h_datap : uses +``` + +--- + +## Code Property Graph + +Machine-readable Code Property Graph (CPG) in JSON-LD format. This block allows AI agents to parse the full structural graph without additional file reads. Compatible with GraphRAG pipelines. + +```json +{"@context": "https://schema.org", "analysis": {"communities": [{"cohesion": 0.833, "id": 0, "label": "root", "size": 6}, {"cohesion": 0.974, "id": 1, "label": "bof/test", "size": 24}], "god_nodes": [{"node_id": "beacon.h", "score": 40.4}, {"node_id": "bof/test/beacon.h", "score": 30.4}, {"node_id": "COFFLoader3.c", "score": 27.8}, {"node_id": "beacon.c", "score": 24.0}, {"node_id": "cJSON.c", "score": 14.5}, {"node_id": "bof/test/sock5.c", "score": 8.1}, {"node_id": "bof/test/upload.c", "score": 8.1}, {"node_id": "cJSON.h", "score": 7.7}, {"node_id": "aes.c", "score": 6.3}, {"node_id": "aes.h", "score": 6.1}], "surprising_connections": [{"hops": 5, "source": "aes.c", "target": "bof/calc/beacon.h"}, {"hops": 5, "source": "aes.c", "target": "bof/etw/beacon.h"}, {"hops": 5, "source": "aes.c", "target": "bof/test/beacon.h"}, {"hops": 5, "source": "aes.c", "target": "bof/whoami/beacon.h"}, {"hops": 5, "source": "bof/calc/beacon.h", "target": "cJSON.c"}]}, "edges": [{"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "stdio.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "stdlib.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "string.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "stdint.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "COFFLoader3.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "aes.c", "target": "aes.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "aes.c", "target": "string.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "aes.h", "target": "stdint.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "aes.h", "target": "stddef.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "app.py", "target": "os"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "winsock2.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "ws2tcpip.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "winnt.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "winhttp.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "wincrypt.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "ntstatus.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "tlhelp32.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "stdio.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "stdlib.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "string.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "io.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "process.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "time.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "iphlpapi.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "icmpapi.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "bcrypt.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "shlobj.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "objbase.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "shellapi.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "winioctl.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "setjmp.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "aes.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "cJSON.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.c", "target": "COFFLoader.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "beacon.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/calc/beacon.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/calc/calc.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/calc/calc.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/etw/beacon.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/etw/etw.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/etw/etw.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/Test.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/amsibypass.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/amsibypass.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/beacon.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/cmdwhoami.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/cmdwhoami.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/disablelog.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/disablelog.c", "target": "tlhelp32.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/disablelog.c", "target": "psapi.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/disablelog.c", "target": "winternl.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/disablelog.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/getenv.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/getenv.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/loadvnc.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/loadvnc.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/make_table.c", "target": "stdint.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/make_table.c", "target": "stdio.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/persist.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/persist.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/persistsvc.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/persistsvc.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/scan_shellcode.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/scan_shellcode.c", "target": "tlhelp32.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/scan_shellcode.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/shellcode.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/shellcode.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/sock5.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/sock5.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "requests"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "re"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "uuid"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "json"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "Crypto.Cipher"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/tel.py", "target": "datetime"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/uacbypass.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/uacbypass.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/upload.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/upload.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/vncrelay.c", "target": "winsock2.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/vncrelay.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/vncrelay.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/winver.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/test/winver.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/whoami/beacon.h", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/whoami/whoami.c", "target": "windows.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "bof/whoami/whoami.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "string.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "stdio.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "math.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "stdlib.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "limits.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "ctype.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "float.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "locale.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.c", "target": "cJSON.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "cJSON.h", "target": "stddef.h"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "argparse"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "sys"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "re"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "pygments"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "pygments.lexers"}, {"confidence": "EXTRACTED", "relation": "imports", "source": "generate_hashs.py", "target": "pygments.formatters"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "COFFLoader3.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "aes.c", "target": "aes.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "beacon.c", "target": "aes.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "beacon.c", "target": "cJSON.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "beacon.c", "target": "beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "beacon.c", "target": "COFFLoader.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/calc/calc.c", "target": "bof/calc/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/etw/etw.c", "target": "bof/etw/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/Test.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/amsibypass.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/cmdwhoami.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/disablelog.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/getenv.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/loadvnc.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/persist.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/persistsvc.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/scan_shellcode.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/shellcode.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/sock5.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/uacbypass.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/upload.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/vncrelay.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/test/winver.c", "target": "bof/test/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "bof/whoami/whoami.c", "target": "bof/whoami/beacon.h"}, {"confidence": "EXTRACTED", "relation": "resolved_imports", "source": "cJSON.c", "target": "cJSON.h"}], "generator": "readmenator", "metadata": {"edge_count": 228, "file_count": 41, "language_count": 4, "symbol_count": 856}, "nodes": [{"id": "COFFLoader.h", "kind": "module", "label": "COFFLoader.h", "language": "h", "sha256": "fb8f42ff4d8704ce", "symbol_count": 1, "symbols": [{"kind": "macro", "line": 21, "name": "COFFLOADER_H", "signature": "#define COFFLOADER_H"}]}, {"id": "COFFLoader3.c", "kind": "module", "label": "COFFLoader3.c", "language": "c", "sha256": "340e4ba48f54dca7", "symbol_count": 258, "symbols": [{"kind": "struct", "line": 586, "name": "COFFSection"}, {"kind": "struct", "line": 599, "name": "COFFRelocation"}, {"kind": "struct", "line": 620, "name": "COFFHeader"}, {"doc": "=== Tabla de símbolos por hash ===", "kind": "struct", "line": 642, "name": "SymbolHash"}, {"doc": "=== Función hash DJB2 ===", "kind": "function", "line": 632, "name": "djb2_hash", "signature": "static uint32_t djb2_hash(const char* str)"}, {"kind": "function", "line": 913, "name": "create_trampoline", "signature": "static void* create_trampoline(void* target)"}, {"kind": "function", "line": 940, "name": "handle_relocation", "signature": "BOOL handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, \n ..."}, {"kind": "function", "line": 1080, "name": "get_symbol_name", "signature": "static char* get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size)"}, {"kind": "function", "line": 1103, "name": "__attribute__", "signature": "__attribute__((noinline))\nstatic void call_go_aligned(void* func, char* arg1, int arg2)"}, {"doc": "=== Cargador COFF ===", "kind": "function", "line": 1112, "name": "RunCOFF", "signature": "int RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*..."}, {"kind": "variable", "line": 332, "name": "__imp_BeaconPrintf", "signature": "extern PVOID __imp_BeaconPrintf;"}, {"kind": "variable", "line": 333, "name": "__imp_BeaconOutput", "signature": "extern PVOID __imp_BeaconOutput;"}, {"kind": "variable", "line": 334, "name": "__imp_BeaconDataParse", "signature": "extern PVOID __imp_BeaconDataParse;"}, {"kind": "variable", "line": 335, "name": "__imp_BeaconDataInt", "signature": "extern PVOID __imp_BeaconDataInt;"}, {"kind": "variable", "line": 336, "name": "__imp_BeaconDataShort", "signature": "extern PVOID __imp_BeaconDataShort;"}, {"kind": "variable", "line": 337, "name": "__imp_BeaconDataExtract", "signature": "extern PVOID __imp_BeaconDataExtract;"}, {"kind": "variable", "line": 338, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 339, "name": "__imp_LoadLibraryW", "signature": "extern PVOID __imp_LoadLibraryW;"}, {"kind": "variable", "line": 340, "name": "__imp_GetModuleHandleA", "signature": "extern PVOID __imp_GetModuleHandleA;"}, {"kind": "variable", "line": 341, "name": "__imp_GetModuleHandleW", "signature": "extern PVOID __imp_GetModuleHandleW;"}, {"kind": "variable", "line": 342, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 343, "name": "__imp_GetLastError", "signature": "extern PVOID __imp_GetLastError;"}, {"kind": "variable", "line": 344, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}, {"kind": "variable", "line": 345, "name": "__imp_ExitProcess", "signature": "extern PVOID __imp_ExitProcess;"}, {"kind": "variable", "line": 346, "name": "__imp_ExitThread", "signature": "extern PVOID __imp_ExitThread;"}, {"kind": "variable", "line": 347, "name": "__imp_Sleep", "signature": "extern PVOID __imp_Sleep;"}, {"kind": "variable", "line": 348, "name": "__imp_CreateThread", "signature": "extern PVOID __imp_CreateThread;"}, {"kind": "variable", "line": 349, "name": "__imp_GetCurrentProcess", "signature": "extern PVOID __imp_GetCurrentProcess;"}, {"kind": "variable", "line": 350, "name": "__imp_GetCurrentProcessId", "signature": "extern PVOID __imp_GetCurrentProcessId;"}, {"kind": "variable", "line": 351, "name": "__imp_GetCurrentThreadId", "signature": "extern PVOID __imp_GetCurrentThreadId;"}, {"kind": "variable", "line": 352, "name": "__imp_GetTickCount", "signature": "extern PVOID __imp_GetTickCount;"}, {"kind": "variable", "line": 353, "name": "__imp_GetTickCount64", "signature": "extern PVOID __imp_GetTickCount64;"}, {"kind": "variable", "line": 354, "name": "__imp_CreateFileA", "signature": "extern PVOID __imp_CreateFileA;"}, {"kind": "variable", "line": 355, "name": "__imp_CreateFileW", "signature": "extern PVOID __imp_CreateFileW;"}, {"kind": "variable", "line": 356, "name": "__imp_ReadFile", "signature": "extern PVOID __imp_ReadFile;"}, {"kind": "variable", "line": 357, "name": "__imp_WriteFile", "signature": "extern PVOID __imp_WriteFile;"}, {"kind": "variable", "line": 358, "name": "__imp_SetFilePointer", "signature": "extern PVOID __imp_SetFilePointer;"}, {"kind": "variable", "line": 359, "name": "__imp_SetEndOfFile", "signature": "extern PVOID __imp_SetEndOfFile;"}, {"kind": "variable", "line": 360, "name": "__imp_DeleteFileA", "signature": "extern PVOID __imp_DeleteFileA;"}, {"kind": "variable", "line": 361, "name": "__imp_DeleteFileW", "signature": "extern PVOID __imp_DeleteFileW;"}, {"kind": "variable", "line": 362, "name": "__imp_MoveFileA", "signature": "extern PVOID __imp_MoveFileA;"}, {"kind": "variable", "line": 363, "name": "__imp_MoveFileW", "signature": "extern PVOID __imp_MoveFileW;"}, {"kind": "variable", "line": 364, "name": "__imp_CopyFileA", "signature": "extern PVOID __imp_CopyFileA;"}, {"kind": "variable", "line": 365, "name": "__imp_CopyFileW", "signature": "extern PVOID __imp_CopyFileW;"}, {"kind": "variable", "line": 366, "name": "__imp_GetFileSize", "signature": "extern PVOID __imp_GetFileSize;"}, {"kind": "variable", "line": 367, "name": "__imp_GetFileSizeEx", "signature": "extern PVOID __imp_GetFileSizeEx;"}, {"kind": "variable", "line": 368, "name": "__imp_CreateDirectoryA", "signature": "extern PVOID __imp_CreateDirectoryA;"}, {"kind": "variable", "line": 369, "name": "__imp_CreateDirectoryW", "signature": "extern PVOID __imp_CreateDirectoryW;"}, {"kind": "variable", "line": 370, "name": "__imp_RemoveDirectoryA", "signature": "extern PVOID __imp_RemoveDirectoryA;"}, {"kind": "variable", "line": 371, "name": "__imp_RemoveDirectoryW", "signature": "extern PVOID __imp_RemoveDirectoryW;"}, {"kind": "variable", "line": 372, "name": "__imp_FindFirstFileA", "signature": "extern PVOID __imp_FindFirstFileA;"}, {"kind": "variable", "line": 373, "name": "__imp_FindFirstFileW", "signature": "extern PVOID __imp_FindFirstFileW;"}, {"kind": "variable", "line": 374, "name": "__imp_FindNextFileA", "signature": "extern PVOID __imp_FindNextFileA;"}, {"kind": "variable", "line": 375, "name": "__imp_FindNextFileW", "signature": "extern PVOID __imp_FindNextFileW;"}, {"kind": "variable", "line": 376, "name": "__imp_FindClose", "signature": "extern PVOID __imp_FindClose;"}, {"kind": "variable", "line": 377, "name": "__imp_GetFileAttributesA", "signature": "extern PVOID __imp_GetFileAttributesA;"}, {"kind": "variable", "line": 378, "name": "__imp_GetFileAttributesW", "signature": "extern PVOID __imp_GetFileAttributesW;"}, {"kind": "variable", "line": 379, "name": "__imp_SetFileAttributesA", "signature": "extern PVOID __imp_SetFileAttributesA;"}, {"kind": "variable", "line": 380, "name": "__imp_SetFileAttributesW", "signature": "extern PVOID __imp_SetFileAttributesW;"}, {"kind": "variable", "line": 381, "name": "__imp_GetSystemDirectoryA", "signature": "extern PVOID __imp_GetSystemDirectoryA;"}, {"kind": "variable", "line": 382, "name": "__imp_GetSystemDirectoryW", "signature": "extern PVOID __imp_GetSystemDirectoryW;"}, {"kind": "variable", "line": 383, "name": "__imp_GetWindowsDirectoryA", "signature": "extern PVOID __imp_GetWindowsDirectoryA;"}, {"kind": "variable", "line": 384, "name": "__imp_GetWindowsDirectoryW", "signature": "extern PVOID __imp_GetWindowsDirectoryW;"}, {"kind": "variable", "line": 385, "name": "__imp_GetTempPathA", "signature": "extern PVOID __imp_GetTempPathA;"}, {"kind": "variable", "line": 386, "name": "__imp_GetTempPathW", "signature": "extern PVOID __imp_GetTempPathW;"}, {"kind": "variable", "line": 387, "name": "__imp_GetComputerNameA", "signature": "extern PVOID __imp_GetComputerNameA;"}, {"kind": "variable", "line": 388, "name": "__imp_GetComputerNameW", "signature": "extern PVOID __imp_GetComputerNameW;"}, {"kind": "variable", "line": 389, "name": "__imp_GetUserNameA", "signature": "extern PVOID __imp_GetUserNameA;"}, {"kind": "variable", "line": 390, "name": "__imp_GetUserNameW", "signature": "extern PVOID __imp_GetUserNameW;"}, {"kind": "variable", "line": 391, "name": "__imp_GetVersionExA", "signature": "extern PVOID __imp_GetVersionExA;"}, {"kind": "variable", "line": 392, "name": "__imp_GetVersionExW", "signature": "extern PVOID __imp_GetVersionExW;"}, {"kind": "variable", "line": 393, "name": "__imp_GetNativeSystemInfo", "signature": "extern PVOID __imp_GetNativeSystemInfo;"}, {"kind": "variable", "line": 394, "name": "__imp_VirtualAlloc", "signature": "extern PVOID __imp_VirtualAlloc;"}, {"kind": "variable", "line": 395, "name": "__imp_VirtualFree", "signature": "extern PVOID __imp_VirtualFree;"}, {"kind": "variable", "line": 396, "name": "__imp_VirtualProtect", "signature": "extern PVOID __imp_VirtualProtect;"}, {"kind": "variable", "line": 397, "name": "__imp_VirtualQuery", "signature": "extern PVOID __imp_VirtualQuery;"}, {"kind": "variable", "line": 398, "name": "__imp_HeapAlloc", "signature": "extern PVOID __imp_HeapAlloc;"}, {"kind": "variable", "line": 399, "name": "__imp_HeapFree", "signature": "extern PVOID __imp_HeapFree;"}, {"kind": "variable", "line": 400, "name": "__imp_LocalAlloc", "signature": "extern PVOID __imp_LocalAlloc;"}, {"kind": "variable", "line": 401, "name": "__imp_LocalFree", "signature": "extern PVOID __imp_LocalFree;"}, {"kind": "variable", "line": 402, "name": "__imp_GlobalAlloc", "signature": "extern PVOID __imp_GlobalAlloc;"}, {"kind": "variable", "line": 403, "name": "__imp_GlobalFree", "signature": "extern PVOID __imp_GlobalFree;"}, {"kind": "variable", "line": 404, "name": "__imp_RtlMoveMemory", "signature": "extern PVOID __imp_RtlMoveMemory;"}, {"kind": "variable", "line": 405, "name": "__imp_RtlCopyMemory", "signature": "extern PVOID __imp_RtlCopyMemory;"}, {"kind": "variable", "line": 406, "name": "__imp_RtlFillMemory", "signature": "extern PVOID __imp_RtlFillMemory;"}, {"kind": "variable", "line": 407, "name": "__imp_RtlZeroMemory", "signature": "extern PVOID __imp_RtlZeroMemory;"}, {"kind": "variable", "line": 408, "name": "__imp_lstrlenA", "signature": "extern PVOID __imp_lstrlenA;"}, {"kind": "variable", "line": 409, "name": "__imp_lstrlenW", "signature": "extern PVOID __imp_lstrlenW;"}, {"kind": "variable", "line": 410, "name": "__imp_lstrcpyA", "signature": "extern PVOID __imp_lstrcpyA;"}, {"kind": "variable", "line": 411, "name": "__imp_lstrcpyW", "signature": "extern PVOID __imp_lstrcpyW;"}, {"kind": "variable", "line": 412, "name": "__imp_lstrcatA", "signature": "extern PVOID __imp_lstrcatA;"}, {"kind": "variable", "line": 413, "name": "__imp_lstrcatW", "signature": "extern PVOID __imp_lstrcatW;"}, {"kind": "variable", "line": 414, "name": "__imp_lstrcmpA", "signature": "extern PVOID __imp_lstrcmpA;"}, {"kind": "variable", "line": 415, "name": "__imp_lstrcmpW", "signature": "extern PVOID __imp_lstrcmpW;"}, {"kind": "variable", "line": 416, "name": "__imp_lstrcmpiA", "signature": "extern PVOID __imp_lstrcmpiA;"}, {"kind": "variable", "line": 417, "name": "__imp_lstrcmpiW", "signature": "extern PVOID __imp_lstrcmpiW;"}, {"kind": "variable", "line": 418, "name": "__imp_MultiByteToWideChar", "signature": "extern PVOID __imp_MultiByteToWideChar;"}, {"kind": "variable", "line": 419, "name": "__imp_WideCharToMultiByte", "signature": "extern PVOID __imp_WideCharToMultiByte;"}, {"kind": "variable", "line": 420, "name": "__imp_FormatMessageA", "signature": "extern PVOID __imp_FormatMessageA;"}, {"kind": "variable", "line": 421, "name": "__imp_FormatMessageW", "signature": "extern PVOID __imp_FormatMessageW;"}, {"kind": "variable", "line": 422, "name": "__imp_GetEnvironmentVariableA", "signature": "extern PVOID __imp_GetEnvironmentVariableA;"}, {"kind": "variable", "line": 423, "name": "__imp_GetEnvironmentVariableW", "signature": "extern PVOID __imp_GetEnvironmentVariableW;"}, {"kind": "variable", "line": 424, "name": "__imp_SetEnvironmentVariableA", "signature": "extern PVOID __imp_SetEnvironmentVariableA;"}, {"kind": "variable", "line": 425, "name": "__imp_SetEnvironmentVariableW", "signature": "extern PVOID __imp_SetEnvironmentVariableW;"}, {"kind": "variable", "line": 426, "name": "__imp_ExpandEnvironmentStringsA", "signature": "extern PVOID __imp_ExpandEnvironmentStringsA;"}, {"kind": "variable", "line": 427, "name": "__imp_ExpandEnvironmentStringsW", "signature": "extern PVOID __imp_ExpandEnvironmentStringsW;"}, {"kind": "variable", "line": 428, "name": "__imp_GetCommandLineA", "signature": "extern PVOID __imp_GetCommandLineA;"}, {"kind": "variable", "line": 429, "name": "__imp_GetCommandLineW", "signature": "extern PVOID __imp_GetCommandLineW;"}, {"kind": "variable", "line": 430, "name": "__imp_GetModuleFileNameA", "signature": "extern PVOID __imp_GetModuleFileNameA;"}, {"kind": "variable", "line": 431, "name": "__imp_GetModuleFileNameW", "signature": "extern PVOID __imp_GetModuleFileNameW;"}, {"kind": "variable", "line": 432, "name": "__imp_GetStartupInfoA", "signature": "extern PVOID __imp_GetStartupInfoA;"}, {"kind": "variable", "line": 433, "name": "__imp_GetStartupInfoW", "signature": "extern PVOID __imp_GetStartupInfoW;"}, {"kind": "variable", "line": 434, "name": "__imp_FreeLibrary", "signature": "extern PVOID __imp_FreeLibrary;"}, {"kind": "variable", "line": 435, "name": "__imp_GetConsoleWindow", "signature": "extern PVOID __imp_GetConsoleWindow;"}, {"kind": "variable", "line": 436, "name": "__imp_AllocConsole", "signature": "extern PVOID __imp_AllocConsole;"}, {"kind": "variable", "line": 437, "name": "__imp_FreeConsole", "signature": "extern PVOID __imp_FreeConsole;"}, {"kind": "variable", "line": 438, "name": "__imp_AttachConsole", "signature": "extern PVOID __imp_AttachConsole;"}, {"kind": "variable", "line": 439, "name": "__imp_IsDebuggerPresent", "signature": "extern PVOID __imp_IsDebuggerPresent;"}, {"kind": "variable", "line": 440, "name": "__imp_CheckRemoteDebuggerPresent", "signature": "extern PVOID __imp_CheckRemoteDebuggerPresent;"}, {"kind": "variable", "line": 441, "name": "__imp_OutputDebugStringA", "signature": "extern PVOID __imp_OutputDebugStringA;"}, {"kind": "variable", "line": 442, "name": "__imp_OutputDebugStringW", "signature": "extern PVOID __imp_OutputDebugStringW;"}, {"kind": "variable", "line": 443, "name": "__imp_OpenProcess", "signature": "extern PVOID __imp_OpenProcess;"}, {"kind": "variable", "line": 444, "name": "__imp_OpenProcessToken", "signature": "extern PVOID __imp_OpenProcessToken;"}, {"kind": "variable", "line": 445, "name": "__imp_DuplicateTokenEx", "signature": "extern PVOID __imp_DuplicateTokenEx;"}, {"kind": "variable", "line": 446, "name": "__imp_ImpersonateLoggedOnUser", "signature": "extern PVOID __imp_ImpersonateLoggedOnUser;"}, {"kind": "variable", "line": 447, "name": "__imp_RevertToSelf", "signature": "extern PVOID __imp_RevertToSelf;"}, {"kind": "variable", "line": 448, "name": "__imp_LookupPrivilegeValueA", "signature": "extern PVOID __imp_LookupPrivilegeValueA;"}, {"kind": "variable", "line": 449, "name": "__imp_LookupPrivilegeValueW", "signature": "extern PVOID __imp_LookupPrivilegeValueW;"}, {"kind": "variable", "line": 450, "name": "__imp_AdjustTokenPrivileges", "signature": "extern PVOID __imp_AdjustTokenPrivileges;"}, {"kind": "variable", "line": 451, "name": "__imp_CreateProcessAsUserA", "signature": "extern PVOID __imp_CreateProcessAsUserA;"}, {"kind": "variable", "line": 452, "name": "__imp_CreateProcessAsUserW", "signature": "extern PVOID __imp_CreateProcessAsUserW;"}, {"kind": "variable", "line": 453, "name": "__imp_RegOpenKeyExA", "signature": "extern PVOID __imp_RegOpenKeyExA;"}, {"kind": "variable", "line": 454, "name": "__imp_RegOpenKeyExW", "signature": "extern PVOID __imp_RegOpenKeyExW;"}, {"kind": "variable", "line": 455, "name": "__imp_RegCreateKeyExA", "signature": "extern PVOID __imp_RegCreateKeyExA;"}, {"kind": "variable", "line": 456, "name": "__imp_RegCreateKeyExW", "signature": "extern PVOID __imp_RegCreateKeyExW;"}, {"kind": "variable", "line": 457, "name": "__imp_RegSetValueExA", "signature": "extern PVOID __imp_RegSetValueExA;"}, {"kind": "variable", "line": 458, "name": "__imp_RegSetValueExW", "signature": "extern PVOID __imp_RegSetValueExW;"}, {"kind": "variable", "line": 459, "name": "__imp_RegQueryValueExA", "signature": "extern PVOID __imp_RegQueryValueExA;"}, {"kind": "variable", "line": 460, "name": "__imp_RegQueryValueExW", "signature": "extern PVOID __imp_RegQueryValueExW;"}, {"kind": "variable", "line": 461, "name": "__imp_RegDeleteValueA", "signature": "extern PVOID __imp_RegDeleteValueA;"}, {"kind": "variable", "line": 462, "name": "__imp_RegDeleteValueW", "signature": "extern PVOID __imp_RegDeleteValueW;"}, {"kind": "variable", "line": 463, "name": "__imp_RegCloseKey", "signature": "extern PVOID __imp_RegCloseKey;"}, {"kind": "variable", "line": 464, "name": "__imp_RegEnumKeyExA", "signature": "extern PVOID __imp_RegEnumKeyExA;"}, {"kind": "variable", "line": 465, "name": "__imp_RegEnumKeyExW", "signature": "extern PVOID __imp_RegEnumKeyExW;"}, {"kind": "variable", "line": 466, "name": "__imp_RegEnumValueA", "signature": "extern PVOID __imp_RegEnumValueA;"}, {"kind": "variable", "line": 467, "name": "__imp_RegEnumValueW", "signature": "extern PVOID __imp_RegEnumValueW;"}, {"kind": "variable", "line": 468, "name": "__imp_CryptAcquireContextA", "signature": "extern PVOID __imp_CryptAcquireContextA;"}, {"kind": "variable", "line": 469, "name": "__imp_CryptAcquireContextW", "signature": "extern PVOID __imp_CryptAcquireContextW;"}, {"kind": "variable", "line": 470, "name": "__imp_CryptCreateHash", "signature": "extern PVOID __imp_CryptCreateHash;"}, {"kind": "variable", "line": 471, "name": "__imp_CryptHashData", "signature": "extern PVOID __imp_CryptHashData;"}, {"kind": "variable", "line": 472, "name": "__imp_CryptDeriveKey", "signature": "extern PVOID __imp_CryptDeriveKey;"}, {"kind": "variable", "line": 473, "name": "__imp_CryptEncrypt", "signature": "extern PVOID __imp_CryptEncrypt;"}, {"kind": "variable", "line": 474, "name": "__imp_CryptDecrypt", "signature": "extern PVOID __imp_CryptDecrypt;"}, {"kind": "variable", "line": 475, "name": "__imp_CryptReleaseContext", "signature": "extern PVOID __imp_CryptReleaseContext;"}, {"kind": "variable", "line": 476, "name": "__imp_CryptDestroyHash", "signature": "extern PVOID __imp_CryptDestroyHash;"}, {"kind": "variable", "line": 477, "name": "__imp_CryptDestroyKey", "signature": "extern PVOID __imp_CryptDestroyKey;"}, {"kind": "variable", "line": 478, "name": "__imp_CryptGenRandom", "signature": "extern PVOID __imp_CryptGenRandom;"}, {"kind": "variable", "line": 479, "name": "__imp_CoInitializeEx", "signature": "extern PVOID __imp_CoInitializeEx;"}, {"kind": "variable", "line": 480, "name": "__imp_CoUninitialize", "signature": "extern PVOID __imp_CoUninitialize;"}, {"kind": "variable", "line": 481, "name": "__imp_CoCreateInstance", "signature": "extern PVOID __imp_CoCreateInstance;"}, {"kind": "variable", "line": 482, "name": "__imp_CoTaskMemFree", "signature": "extern PVOID __imp_CoTaskMemFree;"}, {"kind": "variable", "line": 483, "name": "__imp_IIDFromString", "signature": "extern PVOID __imp_IIDFromString;"}, {"kind": "variable", "line": 484, "name": "__imp_StringFromGUID2", "signature": "extern PVOID __imp_StringFromGUID2;"}, {"kind": "variable", "line": 485, "name": "__imp_VariantInit", "signature": "extern PVOID __imp_VariantInit;"}, {"kind": "variable", "line": 486, "name": "__imp_VariantClear", "signature": "extern PVOID __imp_VariantClear;"}, {"kind": "variable", "line": 487, "name": "__imp_VariantChangeType", "signature": "extern PVOID __imp_VariantChangeType;"}, {"kind": "variable", "line": 488, "name": "__imp_SysAllocString", "signature": "extern PVOID __imp_SysAllocString;"}, {"kind": "variable", "line": 489, "name": "__imp_SysFreeString", "signature": "extern PVOID __imp_SysFreeString;"}, {"kind": "variable", "line": 490, "name": "__imp_SysStringLen", "signature": "extern PVOID __imp_SysStringLen;"}, {"kind": "variable", "line": 491, "name": "__imp_SHGetFolderPathA", "signature": "extern PVOID __imp_SHGetFolderPathA;"}, {"kind": "variable", "line": 492, "name": "__imp_SHGetFolderPathW", "signature": "extern PVOID __imp_SHGetFolderPathW;"}, {"kind": "variable", "line": 493, "name": "__imp_SHGetKnownFolderPath", "signature": "extern PVOID __imp_SHGetKnownFolderPath;"}, {"kind": "variable", "line": 494, "name": "__imp_PathFileExistsA", "signature": "extern PVOID __imp_PathFileExistsA;"}, {"kind": "variable", "line": 495, "name": "__imp_PathFileExistsW", "signature": "extern PVOID __imp_PathFileExistsW;"}, {"kind": "variable", "line": 496, "name": "__imp_PathCombineA", "signature": "extern PVOID __imp_PathCombineA;"}, {"kind": "variable", "line": 497, "name": "__imp_PathCombineW", "signature": "extern PVOID __imp_PathCombineW;"}, {"kind": "variable", "line": 498, "name": "__imp_GetDesktopWindow", "signature": "extern PVOID __imp_GetDesktopWindow;"}, {"kind": "variable", "line": 499, "name": "__imp_GetShellWindow", "signature": "extern PVOID __imp_GetShellWindow;"}, {"kind": "variable", "line": 500, "name": "__imp_FindWindowA", "signature": "extern PVOID __imp_FindWindowA;"}, {"kind": "variable", "line": 501, "name": "__imp_FindWindowW", "signature": "extern PVOID __imp_FindWindowW;"}, {"kind": "variable", "line": 502, "name": "__imp_EnumWindows", "signature": "extern PVOID __imp_EnumWindows;"}, {"kind": "variable", "line": 503, "name": "__imp_GetWindowTextA", "signature": "extern PVOID __imp_GetWindowTextA;"}, {"kind": "variable", "line": 504, "name": "__imp_GetWindowTextW", "signature": "extern PVOID __imp_GetWindowTextW;"}, {"kind": "variable", "line": 505, "name": "__imp_GetClassNameA", "signature": "extern PVOID __imp_GetClassNameA;"}, {"kind": "variable", "line": 506, "name": "__imp_GetClassNameW", "signature": "extern PVOID __imp_GetClassNameW;"}, {"kind": "variable", "line": 507, "name": "__imp_SendMessageA", "signature": "extern PVOID __imp_SendMessageA;"}, {"kind": "variable", "line": 508, "name": "__imp_SendMessageW", "signature": "extern PVOID __imp_SendMessageW;"}, {"kind": "variable", "line": 509, "name": "__imp_EnumProcesses", "signature": "extern PVOID __imp_EnumProcesses;"}, {"kind": "variable", "line": 510, "name": "__imp_EnumProcessModules", "signature": "extern PVOID __imp_EnumProcessModules;"}, {"kind": "variable", "line": 511, "name": "__imp_GetModuleBaseNameA", "signature": "extern PVOID __imp_GetModuleBaseNameA;"}, {"kind": "variable", "line": 512, "name": "__imp_GetModuleBaseNameW", "signature": "extern PVOID __imp_GetModuleBaseNameW;"}, {"kind": "variable", "line": 513, "name": "__imp_GetModuleInformation", "signature": "extern PVOID __imp_GetModuleInformation;"}, {"kind": "variable", "line": 514, "name": "__imp_WSASocketA", "signature": "extern PVOID __imp_WSASocketA;"}, {"kind": "variable", "line": 515, "name": "__imp_WSASocketW", "signature": "extern PVOID __imp_WSASocketW;"}, {"kind": "variable", "line": 516, "name": "__imp_WSAStartup", "signature": "extern PVOID __imp_WSAStartup;"}, {"kind": "variable", "line": 517, "name": "__imp_WSACleanup", "signature": "extern PVOID __imp_WSACleanup;"}, {"kind": "variable", "line": 518, "name": "__imp_bind", "signature": "extern PVOID __imp_bind;"}, {"kind": "variable", "line": 519, "name": "__imp_listen", "signature": "extern PVOID __imp_listen;"}, {"kind": "variable", "line": 520, "name": "__imp_accept", "signature": "extern PVOID __imp_accept;"}, {"kind": "variable", "line": 521, "name": "__imp_connect", "signature": "extern PVOID __imp_connect;"}, {"kind": "variable", "line": 522, "name": "__imp_send", "signature": "extern PVOID __imp_send;"}, {"kind": "variable", "line": 523, "name": "__imp_recv", "signature": "extern PVOID __imp_recv;"}, {"kind": "variable", "line": 524, "name": "__imp_closesocket", "signature": "extern PVOID __imp_closesocket;"}, {"kind": "variable", "line": 525, "name": "__imp_ioctlsocket", "signature": "extern PVOID __imp_ioctlsocket;"}, {"kind": "variable", "line": 526, "name": "__imp_gethostname", "signature": "extern PVOID __imp_gethostname;"}, {"kind": "variable", "line": 527, "name": "__imp_gethostbyname", "signature": "extern PVOID __imp_gethostbyname;"}, {"kind": "variable", "line": 528, "name": "__imp_getaddrinfo", "signature": "extern PVOID __imp_getaddrinfo;"}, {"kind": "variable", "line": 529, "name": "__imp_freeaddrinfo", "signature": "extern PVOID __imp_freeaddrinfo;"}, {"kind": "variable", "line": 530, "name": "__imp_htons", "signature": "extern PVOID __imp_htons;"}, {"kind": "variable", "line": 531, "name": "__imp_ntohs", "signature": "extern PVOID __imp_ntohs;"}, {"kind": "variable", "line": 532, "name": "__imp_htonl", "signature": "extern PVOID __imp_htonl;"}, {"kind": "variable", "line": 533, "name": "__imp_ntohl", "signature": "extern PVOID __imp_ntohl;"}, {"kind": "variable", "line": 534, "name": "__imp_NetUserEnum", "signature": "extern PVOID __imp_NetUserEnum;"}, {"kind": "variable", "line": 535, "name": "__imp_NetLocalGroupEnum", "signature": "extern PVOID __imp_NetLocalGroupEnum;"}, {"kind": "variable", "line": 536, "name": "__imp_NetShareEnum", "signature": "extern PVOID __imp_NetShareEnum;"}, {"kind": "variable", "line": 537, "name": "__imp_NetWkstaUserEnum", "signature": "extern PVOID __imp_NetWkstaUserEnum;"}, {"kind": "variable", "line": 538, "name": "__imp_NetSessionEnum", "signature": "extern PVOID __imp_NetSessionEnum;"}, {"kind": "variable", "line": 539, "name": "__imp_NetApiBufferFree", "signature": "extern PVOID __imp_NetApiBufferFree;"}, {"kind": "variable", "line": 540, "name": "__imp_WNetOpenEnumA", "signature": "extern PVOID __imp_WNetOpenEnumA;"}, {"kind": "variable", "line": 541, "name": "__imp_WNetOpenEnumW", "signature": "extern PVOID __imp_WNetOpenEnumW;"}, {"kind": "variable", "line": 542, "name": "__imp_WNetEnumResourceA", "signature": "extern PVOID __imp_WNetEnumResourceA;"}, {"kind": "variable", "line": 543, "name": "__imp_WNetEnumResourceW", "signature": "extern PVOID __imp_WNetEnumResourceW;"}, {"kind": "variable", "line": 544, "name": "__imp_WNetCloseEnum", "signature": "extern PVOID __imp_WNetCloseEnum;"}, {"kind": "variable", "line": 545, "name": "__imp__stricmp", "signature": "extern PVOID __imp__stricmp;"}, {"kind": "variable", "line": 546, "name": "__imp_Process32Next", "signature": "extern PVOID __imp_Process32Next;"}, {"kind": "variable", "line": 547, "name": "__imp_IsWow64Process", "signature": "extern PVOID __imp_IsWow64Process;"}, {"kind": "variable", "line": 548, "name": "__imp_Process32First", "signature": "extern PVOID __imp_Process32First;"}, {"kind": "variable", "line": 549, "name": "__imp_CreateToolhelp32Snapshot", "signature": "extern PVOID __imp_CreateToolhelp32Snapshot;"}, {"kind": "variable", "line": 550, "name": "__imp_select", "signature": "extern PVOID __imp_select;"}, {"kind": "variable", "line": 551, "name": "__imp_CreateProcessA", "signature": "extern PVOID __imp_CreateProcessA;"}, {"kind": "variable", "line": 552, "name": "__imp_CreateProcessW", "signature": "extern PVOID __imp_CreateProcessW;"}, {"kind": "variable", "line": 553, "name": "__imp_SuspendThread", "signature": "extern PVOID __imp_SuspendThread;"}, {"kind": "variable", "line": 554, "name": "__imp_OpenThread", "signature": "extern PVOID __imp_OpenThread;"}, {"kind": "variable", "line": 555, "name": "__imp_Thread32First", "signature": "extern PVOID __imp_Thread32First;"}, {"kind": "variable", "line": 556, "name": "__imp_Thread32Next", "signature": "extern PVOID __imp_Thread32Next;"}, {"kind": "variable", "line": 557, "name": "__imp_NtQueryInformationThread", "signature": "extern PVOID __imp_NtQueryInformationThread;"}, {"kind": "variable", "line": 561, "name": "g_pNtCreateFileUnhooked", "signature": "extern PVOID g_pNtCreateFileUnhooked;"}, {"kind": "variable", "line": 562, "name": "g_pNtWriteVirtualMemoryUnhooked", "signature": "extern PVOID g_pNtWriteVirtualMemoryUnhooked;"}, {"kind": "variable", "line": 563, "name": "g_pNtProtectVirtualMemoryUnhooked", "signature": "extern PVOID g_pNtProtectVirtualMemoryUnhooked;"}, {"kind": "variable", "line": 564, "name": "g_pNtResumeThreadUnhooked", "signature": "extern PVOID g_pNtResumeThreadUnhooked;"}, {"kind": "variable", "line": 565, "name": "g_pNtCreateThreadExUnhooked", "signature": "extern PVOID g_pNtCreateThreadExUnhooked;"}, {"kind": "macro", "line": 568, "name": "IMAGE_REL_AMD64_ABSOLUTE", "signature": "#define IMAGE_REL_AMD64_ABSOLUTE"}, {"kind": "macro", "line": 569, "name": "IMAGE_REL_AMD64_ADDR64", "signature": "#define IMAGE_REL_AMD64_ADDR64"}, {"kind": "macro", "line": 570, "name": "IMAGE_REL_AMD64_ADDR32", "signature": "#define IMAGE_REL_AMD64_ADDR32"}, {"kind": "macro", "line": 571, "name": "IMAGE_REL_AMD64_ADDR32NB", "signature": "#define IMAGE_REL_AMD64_ADDR32NB"}, {"kind": "macro", "line": 572, "name": "IMAGE_REL_AMD64_REL32", "signature": "#define IMAGE_REL_AMD64_REL32"}, {"kind": "macro", "line": 573, "name": "IMAGE_REL_AMD64_REL32_1", "signature": "#define IMAGE_REL_AMD64_REL32_1"}, {"kind": "macro", "line": 574, "name": "IMAGE_REL_AMD64_REL32_2", "signature": "#define IMAGE_REL_AMD64_REL32_2"}, {"kind": "macro", "line": 575, "name": "IMAGE_REL_AMD64_REL32_3", "signature": "#define IMAGE_REL_AMD64_REL32_3"}, {"kind": "macro", "line": 576, "name": "IMAGE_REL_AMD64_REL32_4", "signature": "#define IMAGE_REL_AMD64_REL32_4"}, {"kind": "macro", "line": 577, "name": "IMAGE_REL_AMD64_REL32_5", "signature": "#define IMAGE_REL_AMD64_REL32_5"}, {"kind": "macro", "line": 578, "name": "IMAGE_REL_AMD64_SECTION", "signature": "#define IMAGE_REL_AMD64_SECTION"}, {"kind": "macro", "line": 579, "name": "IMAGE_REL_AMD64_SECREL", "signature": "#define IMAGE_REL_AMD64_SECREL"}, {"kind": "macro", "line": 580, "name": "IMAGE_REL_AMD64_SECREL7", "signature": "#define IMAGE_REL_AMD64_SECREL7"}, {"kind": "macro", "line": 581, "name": "IMAGE_REL_AMD64_TOKEN", "signature": "#define IMAGE_REL_AMD64_TOKEN"}, {"kind": "macro", "line": 582, "name": "IMAGE_REL_AMD64_SREL32", "signature": "#define IMAGE_REL_AMD64_SREL32"}, {"kind": "macro", "line": 583, "name": "IMAGE_REL_AMD64_PAIR", "signature": "#define IMAGE_REL_AMD64_PAIR"}, {"kind": "macro", "line": 584, "name": "IMAGE_REL_AMD64_SSPAN32", "signature": "#define IMAGE_REL_AMD64_SSPAN32"}]}, {"doc": "aes.c - tiny-AES-c (https://github.com/kokke/tiny-AES-c)", "id": "aes.c", "kind": "module", "label": "aes.c", "language": "c", "sha256": "12e247148b2d6453", "symbol_count": 43, "symbols": [{"kind": "function", "line": 13, "name": "getSBoxValue", "signature": "static uint8_t getSBoxValue(uint8_t num)"}, {"kind": "function", "line": 35, "name": "getSBoxInvert", "signature": "static uint8_t getSBoxInvert(uint8_t num)"}, {"kind": "function", "line": 57, "name": "Td0", "signature": "static uint8_t Td0(int x)"}, {"kind": "function", "line": 58, "name": "Td1", "signature": "static uint8_t Td1(int x)"}, {"kind": "function", "line": 59, "name": "Td2", "signature": "static uint8_t Td2(int x)"}, {"kind": "function", "line": 60, "name": "Td3", "signature": "static uint8_t Td3(int x)"}, {"kind": "function", "line": 61, "name": "Td4", "signature": "static uint8_t Td4(int x)"}, {"doc": "This function produces Nb(Nr+1) round keys. The round keys are used in each round to decrypt the states.", "kind": "function", "line": 166, "name": "KeyExpansion", "signature": "static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key)"}, {"kind": "function", "line": 239, "name": "AES_init_ctx", "signature": "void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key)"}, {"doc": "if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1))", "kind": "function", "line": 244, "name": "AES_init_ctx_iv", "signature": "void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv)"}, {"kind": "function", "line": 249, "name": "AES_ctx_set_iv", "signature": "void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv)"}, {"doc": "This function adds the round key to state. The round key is added to the state by an XOR function.", "kind": "function", "line": 257, "name": "AddRoundKey", "signature": "static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)"}, {"doc": "The SubBytes Function Substitutes the values in the state matrix with values in an S-box.", "kind": "function", "line": 271, "name": "SubBytes", "signature": "static void SubBytes(state_t* state)"}, {"doc": "The ShiftRows() function shifts the rows in the state to the left. Each row is shifted with different offset. Offset = Row number. So the first row is not shifted.", "kind": "function", "line": 286, "name": "ShiftRows", "signature": "static void ShiftRows(state_t* state)"}, {"kind": "function", "line": 314, "name": "xtime", "signature": "static uint8_t xtime(uint8_t x)"}, {"doc": "MixColumns function mixes the columns of the state matrix", "kind": "function", "line": 320, "name": "MixColumns", "signature": "static void MixColumns(state_t* state)"}, {"doc": "Multiply is used to multiply numbers in the field GF(2^8) Note: The last call to xtime() is unneeded, but often ends up generating a smaller binary The compiler seems to be able to vectorize the operation better this way. See https://github.com/kokke/tiny-AES-c/pull/34 if MULTIPLY_AS_A_FUNCTION", "kind": "function", "line": 340, "name": "Multiply", "signature": "static uint8_t Multiply(uint8_t x, uint8_t y)"}, {"doc": "MixColumns function mixes the columns of the state matrix. The method used to multiply may be difficult to understand for the inexperienced. Please use the references to gain more information.", "kind": "function", "line": 370, "name": "InvMixColumns", "signature": "static void InvMixColumns(state_t* state)"}, {"doc": "The SubBytes Function Substitutes the values in the state matrix with values in an S-box.", "kind": "function", "line": 391, "name": "InvSubBytes", "signature": "static void InvSubBytes(state_t* state)"}, {"kind": "function", "line": 403, "name": "InvShiftRows", "signature": "static void InvShiftRows(state_t* state)"}, {"doc": "Cipher is the main function that encrypts the PlainText.", "kind": "function", "line": 433, "name": "Cipher", "signature": "static void Cipher(state_t* state, const uint8_t* RoundKey)"}, {"doc": "if (defined(CBC) && CBC == 1) || (defined(ECB) && ECB == 1)", "kind": "function", "line": 459, "name": "InvCipher", "signature": "static void InvCipher(state_t* state, const uint8_t* RoundKey)"}, {"kind": "function", "line": 490, "name": "AES_ECB_encrypt", "signature": "void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf)"}, {"kind": "function", "line": 496, "name": "AES_ECB_decrypt", "signature": "void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf)"}, {"kind": "function", "line": 512, "name": "XorWithIv", "signature": "static void XorWithIv(uint8_t* buf, const uint8_t* Iv)"}, {"kind": "function", "line": 521, "name": "AES_CBC_encrypt_buffer", "signature": "void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length)"}, {"kind": "function", "line": 536, "name": "AES_CBC_decrypt_buffer", "signature": "void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)"}, {"doc": "XorWithIv(buf, ctx->Iv); memcpy(ctx->Iv, storeNextIv, AES_BLOCKLEN); buf += AES_BLOCKLEN; } } #endif // #if defined(CBC) && (CBC == 1) #if defined(CTR) && (CTR == 1) /* Symmetrical operation: same function for encrypting as for decrypting. Note any IV/nonce should never be reused with the same key", "kind": "function", "line": 558, "name": "AES_CTR_xcrypt_buffer", "signature": "void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)"}, {"kind": "macro", "line": 5, "name": "Nb", "signature": "#define Nb"}, {"kind": "macro", "line": 9, "name": "KEYLEN_256", "signature": "#define KEYLEN_256"}, {"kind": "macro", "line": 10, "name": "RKLENGTH", "signature": "#define RKLENGTH"}, {"kind": "macro", "line": 11, "name": "BLOCKLEN", "signature": "#define BLOCKLEN"}, {"kind": "macro", "line": 67, "name": "Nb", "signature": "#define Nb"}, {"kind": "macro", "line": 70, "name": "Nk", "signature": "#define Nk"}, {"kind": "macro", "line": 71, "name": "Nr", "signature": "#define Nr"}, {"kind": "macro", "line": 73, "name": "Nk", "signature": "#define Nk"}, {"kind": "macro", "line": 74, "name": "Nr", "signature": "#define Nr"}, {"kind": "macro", "line": 76, "name": "Nk", "signature": "#define Nk"}, {"kind": "macro", "line": 77, "name": "Nr", "signature": "#define Nr"}, {"kind": "macro", "line": 84, "name": "MULTIPLY_AS_A_FUNCTION", "signature": "#define MULTIPLY_AS_A_FUNCTION"}, {"kind": "macro", "line": 163, "name": "getSBoxValue", "signature": "#define getSBoxValue(num)"}, {"kind": "macro", "line": 349, "name": "Multiply", "signature": "#define Multiply(x, y)"}, {"kind": "macro", "line": 365, "name": "getSBoxInvert", "signature": "#define getSBoxInvert(num)"}]}, {"doc": "#define the macros below to 1/0 to enable/disable the mode of operation.", "id": "aes.h", "kind": "module", "label": "aes.h", "language": "h", "sha256": "e1e91ab2bbec246c", "symbol_count": 21, "symbols": [{"kind": "struct", "line": 33, "name": "AES_ctx"}, {"kind": "function", "line": 41, "name": "AES_init_ctx", "signature": "void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key);"}, {"doc": "if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1))", "kind": "function", "line": 43, "name": "AES_init_ctx_iv", "signature": "void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv);"}, {"kind": "function", "line": 44, "name": "AES_ctx_set_iv", "signature": "void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv);"}, {"doc": "if defined(ECB) && (ECB == 1)", "kind": "function", "line": 48, "name": "AES_ECB_encrypt", "signature": "void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf);"}, {"kind": "function", "line": 49, "name": "AES_ECB_decrypt", "signature": "void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf);"}, {"doc": "if defined(CBC) && (CBC == 1)", "kind": "function", "line": 53, "name": "AES_CBC_encrypt_buffer", "signature": "void AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);"}, {"kind": "function", "line": 54, "name": "AES_CBC_decrypt_buffer", "signature": "void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);"}, {"doc": "if defined(CTR) && (CTR == 1)", "kind": "function", "line": 58, "name": "AES_CTR_xcrypt_buffer", "signature": "void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);"}, {"kind": "macro", "line": 2, "name": "_AES_H_", "signature": "#define _AES_H_"}, {"kind": "macro", "line": 9, "name": "CBC", "signature": "#define CBC"}, {"kind": "macro", "line": 12, "name": "ECB", "signature": "#define ECB"}, {"kind": "macro", "line": 15, "name": "CTR", "signature": "#define CTR"}, {"kind": "macro", "line": 18, "name": "AES256", "signature": "#define AES256"}, {"kind": "macro", "line": 20, "name": "AES_BLOCKLEN", "signature": "#define AES_BLOCKLEN"}, {"kind": "macro", "line": 23, "name": "AES_KEYLEN", "signature": "#define AES_KEYLEN"}, {"kind": "macro", "line": 24, "name": "AES_keyExpSize", "signature": "#define AES_keyExpSize"}, {"kind": "macro", "line": 26, "name": "AES_KEYLEN", "signature": "#define AES_KEYLEN"}, {"kind": "macro", "line": 27, "name": "AES_keyExpSize", "signature": "#define AES_keyExpSize"}, {"kind": "macro", "line": 29, "name": "AES_KEYLEN", "signature": "#define AES_KEYLEN"}, {"kind": "macro", "line": 30, "name": "AES_keyExpSize", "signature": "#define AES_keyExpSize"}]}, {"doc": "This file is part of Black Basalt Beacon. Black Basalt Beacon is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Black Basalt Beacon is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Black Basalt Beacon. If not, see . Copyright (c) LazyOwn RedTeam 2025. All rights reserved.", "id": "app.py", "kind": "module", "label": "app.py", "language": "py", "sha256": "57b21bdb023585b8", "symbol_count": 0, "symbols": []}, {"id": "beacon.c", "kind": "module", "label": "beacon.c", "language": "c", "sha256": "f140730d0f0d3cde", "symbol_count": 160, "symbols": [{"kind": "struct", "line": 129, "name": "_PROCESS_BASIC_INFORMATION"}, {"doc": "=== ESTRUCTURAS NECESARIAS (MinGW-safe) ===", "kind": "struct", "line": 262, "name": "_UNICODE_STRING"}, {"kind": "struct", "line": 268, "name": "_LDR_DATA_TABLE_ENTRY"}, {"kind": "struct", "line": 278, "name": "_PEB_LDR_DATA"}, {"kind": "struct", "line": 287, "name": "_PEB"}, {"kind": "struct", "line": 139, "name": "ProxySession"}, {"kind": "struct", "line": 147, "name": "ProxyThreadData"}, {"kind": "struct", "line": 156, "name": "ReverseArgs"}, {"kind": "struct", "line": 161, "name": "PortScannerArgs"}, {"kind": "struct", "line": 168, "name": "LazyDataType"}, {"kind": "struct", "line": 176, "name": "ProxyListener"}, {"kind": "struct", "line": 329, "name": "PacketEncryptionContext"}, {"kind": "struct", "line": 343, "name": "PortResult"}, {"doc": "define CHECK_ERROR(cond, msg) do { if (!(cond)) { printf(\"[-] %s: %lu\\n\", msg, GetLastError()); return FALSE; } } while(0)", "kind": "type_alias", "line": 127, "name": "ExitStatus", "signature": "typedef struct _PROCESS_BASIC_INFORMATION { LONG ExitStatus;"}, {"doc": "=== ESTRUCTURAS NECESARIAS (MinGW-safe) ===", "kind": "type_alias", "line": 262, "name": "Length", "signature": "typedef struct _UNICODE_STRING { USHORT Length;"}, {"kind": "type_alias", "line": 267, "name": "InMemoryOrderLinks", "signature": "typedef struct _LDR_DATA_TABLE_ENTRY { LIST_ENTRY InMemoryOrderLinks;"}, {"kind": "type_alias", "line": 277, "name": "Length", "signature": "typedef struct _PEB_LDR_DATA { DWORD Length;"}, {"kind": "type_alias", "line": 286, "name": "Reserved1", "signature": "typedef struct _PEB { BYTE Reserved1[2];"}, {"doc": "ifndef NTSTATUS", "kind": "type_alias", "line": 296, "name": "NTSTATUS", "signature": "typedef LONG NTSTATUS;"}, {"kind": "type_alias", "line": 304, "name": "NTSTATUS", "signature": "typedef LONG NTSTATUS;"}, {"kind": "function", "line": 253, "name": "ExceptionFilter", "signature": "static LONG WINAPI ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo)"}, {"kind": "function", "line": 335, "name": "get_shell_cmd", "signature": "const char* get_shell_cmd()"}, {"kind": "function", "line": 417, "name": "__declspec", "signature": "__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size)"}, {"kind": "function", "line": 423, "name": "__declspec", "signature": "__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size)"}, {"kind": "function", "line": 431, "name": "__declspec", "signature": "__declspec(dllexport) int BeaconDataInt(datap * parser)"}, {"kind": "function", "line": 436, "name": "__declspec", "signature": "__declspec(dllexport) short BeaconDataShort(datap * parser)"}, {"kind": "function", "line": 441, "name": "__declspec", "signature": "__declspec(dllexport) int BeaconDataLength(datap * parser)"}, {"kind": "function", "line": 446, "name": "__declspec", "signature": "__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size)"}, {"kind": "function", "line": 456, "name": "__declspec", "signature": "__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...)"}, {"kind": "function", "line": 504, "name": "__declspec", "signature": "__declspec(dllexport) void BeaconOutput(int type, const char * data, int len)"}, {"doc": "=== MAP DLL NAME TO REAL DLL ===", "kind": "function", "line": 521, "name": "MapDllNameToModule", "signature": "HMODULE MapDllNameToModule(char* dllName)"}, {"kind": "function", "line": 549, "name": "GetSyscallNumber", "signature": "DWORD GetSyscallNumber(PVOID func_addr)"}, {"kind": "function", "line": 561, "name": "HellsGate", "signature": "DWORD HellsGate(DWORD ssn)"}, {"kind": "function", "line": 566, "name": "__attribute__", "signature": "__attribute__((naked))\nNTSTATUS HellDescent(\n DWORD64 arg1, DWORD64 arg2, DWORD64 arg3,\n DW..."}, {"kind": "function", "line": 582, "name": "GetProcessIdByName", "signature": "DWORD GetProcessIdByName(const char* processName)"}, {"doc": "=== EJECUTAR TLS CALLBACKS ===", "kind": "function", "line": 600, "name": "ExecuteTLSCallbacks", "signature": "void ExecuteTLSCallbacks(PVOID moduleBase)"}, {"doc": "=== Carga un módulo en memoria ===", "kind": "function", "line": 617, "name": "MapModuleToMemory", "signature": "PVOID MapModuleToMemory(unsigned char* fileBuffer, DWORD fileSize)"}, {"doc": "=== Ejecuta el módulo (DllMain o EntryPoint) ===", "kind": "function", "line": 706, "name": "ExecuteModule", "signature": "BOOL ExecuteModule(PVOID moduleBase)"}, {"doc": "=== Carga y ejecuta un módulo desde URL ===", "kind": "function", "line": 751, "name": "LoadModuleFromURL", "signature": "BOOL LoadModuleFromURL(const char* url)"}, {"doc": "=== XOR ===", "kind": "function", "line": 915, "name": "xor_string", "signature": "void xor_string(char* data, size_t len, char key)"}, {"doc": "=== ANTI-ANALYSIS ===", "kind": "function", "line": 922, "name": "anti_analysis", "signature": "BOOL anti_analysis()"}, {"kind": "function", "line": 946, "name": "load_lazyconf", "signature": "BOOL load_lazyconf()"}, {"kind": "function", "line": 1184, "name": "GetNtdllBase", "signature": "HMODULE GetNtdllBase()"}, {"kind": "function", "line": 1232, "name": "isVMByMAC", "signature": "BOOL isVMByMAC()"}, {"doc": "=== EXTRAER SHELLCODE ===", "kind": "function", "line": 1303, "name": "extract_shellcode", "signature": "int extract_shellcode(const char* input, size_t len, unsigned char** out)"}, {"doc": "Función para convertir hex a bytes", "kind": "function", "line": 1334, "name": "hex_char_to_byte", "signature": "BYTE hex_char_to_byte(char c)"}, {"kind": "function", "line": 1341, "name": "hex_to_bytes", "signature": "void hex_to_bytes(const char* hex, BYTE* output, size_t len)"}, {"doc": "=== executeLoader ===", "kind": "function", "line": 1348, "name": "executeLoader", "signature": "void executeLoader(void *arg)"}, {"doc": "======================== FUNCIÓN DE INYECCIÓN DE SHELL ========================", "kind": "function", "line": 1404, "name": "ReverseShell", "signature": "void __cdecl ReverseShell(void* arg)"}, {"doc": "=== Hilo para leer salida del proceso (como en el ejemplo que funciona) ===", "kind": "function", "line": 1513, "name": "ReadFromProcess", "signature": "DWORD WINAPI ReadFromProcess(LPVOID lpParam)"}, {"kind": "function", "line": 1587, "name": "GetJitteredSleep", "signature": "DWORD GetJitteredSleep(DWORD base_ms)"}, {"kind": "function", "line": 1592, "name": "GetUsefulSoftware", "signature": "char* GetUsefulSoftware()"}, {"kind": "function", "line": 1627, "name": "base64_encode", "signature": "char* base64_encode(const unsigned char* data, size_t inputLen)"}, {"kind": "function", "line": 1663, "name": "base64_decode", "signature": "char* base64_decode(const char* input, size_t* out_len)"}, {"kind": "function", "line": 1696, "name": "discoverLocalHosts", "signature": "void discoverLocalHosts()"}, {"kind": "function", "line": 1753, "name": "initProxy", "signature": "void initProxy()"}, {"doc": "Función para reenviar datos entre sockets", "kind": "function", "line": 1763, "name": "relay_thread", "signature": "void WINAPI relay_thread(void* param)"}, {"doc": "Tu función proxy_thread usando tus estructuras exactas", "kind": "function", "line": 1784, "name": "proxy_thread", "signature": "void WINAPI proxy_thread(void* param)"}, {"doc": "Thread para aceptar conexiones", "kind": "function", "line": 1855, "name": "proxy_accept_thread", "signature": "void WINAPI proxy_accept_thread(void* param)"}, {"kind": "function", "line": 1923, "name": "startProxy", "signature": "BOOL startProxy(const char* listenAddr, const char* targetAddr)"}, {"kind": "function", "line": 2010, "name": "stopProxy", "signature": "BOOL stopProxy(const char* listenAddr)"}, {"kind": "function", "line": 2062, "name": "cleanupProxy", "signature": "void cleanupProxy()"}, {"doc": "Función simplificada para compresión de directorios", "kind": "function", "line": 2094, "name": "compressDirectory", "signature": "BOOL compressDirectory(const char* dirPath)"}, {"doc": "Para netconfig", "kind": "function", "line": 2104, "name": "getNetworkConfig", "signature": "char* getNetworkConfig()"}, {"kind": "function", "line": 2108, "name": "UploadFileToC2", "signature": "BOOL UploadFileToC2(const char* url, const char* filePath)"}, {"doc": "=== handleUpload: envía del beacon al C2 ===", "kind": "function", "line": 2280, "name": "handleUpload", "signature": "BOOL handleUpload(const char* command)"}, {"doc": "Función para verificar si un archivo existe", "kind": "function", "line": 2301, "name": "FileExistsA", "signature": "BOOL FileExistsA(const char* filePath)"}, {"doc": "selfdestruct.c", "kind": "function", "line": 2306, "name": "selfDestruct", "signature": "void selfDestruct()"}, {"kind": "function", "line": 2362, "name": "stristr", "signature": "char* stristr(const char* str, const char* pattern)"}, {"kind": "function", "line": 2378, "name": "isSensitiveFile", "signature": "int isSensitiveFile(const char* filename)"}, {"kind": "function", "line": 2425, "name": "searchCredentials", "signature": "char* searchCredentials(const char* basePath)"}, {"doc": "Convierte UTF-8 a wide string", "kind": "function", "line": 2551, "name": "UTF8ToWide", "signature": "WCHAR* UTF8ToWide(const char* utf8)"}, {"doc": "Ofusca los timestamps de un archivo", "kind": "function", "line": 2562, "name": "obfuscateFileTimestamp", "signature": "BOOL obfuscateFileTimestamp(const char* filepath)"}, {"doc": "Recorre directorios buscando archivos sensibles", "kind": "function", "line": 2592, "name": "obfuscateFileTimestamps", "signature": "void obfuscateFileTimestamps(const char* basePath, int depth)"}, {"doc": "traffic.c", "kind": "function", "line": 2656, "name": "simulateLegitimateTraffic", "signature": "void simulateLegitimateTraffic(void* param)"}, {"kind": "function", "line": 2735, "name": "restartClient", "signature": "void restartClient()"}, {"kind": "function", "line": 2776, "name": "checkDebuggers", "signature": "BOOL checkDebuggers()"}, {"kind": "function", "line": 2838, "name": "MapPEToMemory", "signature": "unsigned char* MapPEToMemory(unsigned char* rawPE, DWORD rawSize, DWORD* mappedSize)"}, {"kind": "function", "line": 2861, "name": "downloadAndExecute", "signature": "BOOL downloadAndExecute(const char* url, const char* targetProcess)"}, {"kind": "function", "line": 2911, "name": "DecryptPacket", "signature": "BOOL DecryptPacket(BYTE* buffer, DWORD* buffer_len)"}, {"kind": "function", "line": 3007, "name": "GetIPs", "signature": "char* GetIPs()"}, {"kind": "function", "line": 3041, "name": "GetHostname", "signature": "char* GetHostname()"}, {"kind": "function", "line": 3057, "name": "GetUsername", "signature": "char* GetUsername()"}, {"kind": "function", "line": 3074, "name": "patchAMSI", "signature": "BOOL patchAMSI(void)"}, {"doc": "==================================================================== PE HELPERS (usando winnt.h) ====================================================================", "kind": "function", "line": 3092, "name": "get_nt_headers", "signature": "PIMAGE_NT_HEADERS get_nt_headers(BYTE* buffer)"}, {"kind": "function", "line": 3101, "name": "is_64bit", "signature": "BOOL is_64bit(BYTE* buffer)"}, {"kind": "function", "line": 3107, "name": "get_image_size", "signature": "DWORD get_image_size(BYTE* buffer)"}, {"kind": "function", "line": 3113, "name": "get_entry_point_rva", "signature": "DWORD get_entry_point_rva(BYTE* buffer)"}, {"kind": "function", "line": 3119, "name": "pe_buffer_to_virtual_image", "signature": "BYTE* pe_buffer_to_virtual_image(BYTE* raw_buffer, DWORD* out_size)"}, {"kind": "function", "line": 3149, "name": "create_suspended_process", "signature": "BOOL create_suspended_process(char* path, PROCESS_INFORMATION* pi)"}, {"kind": "function", "line": 3156, "name": "get_remote_image_base", "signature": "ULONGLONG get_remote_image_base(PROCESS_INFORMATION* pi, BOOL is_32bit_target)"}, {"kind": "function", "line": 3250, "name": "update_remote_entry_point", "signature": "BOOL update_remote_entry_point(PROCESS_INFORMATION* pi, ULONGLONG entry_point_va, BOOL is_32bit)"}, {"doc": "==================================================================== MAIN FUNCTION: overWrite ====================================================================", "kind": "function", "line": 3277, "name": "overWrite", "signature": "void overWrite(const char* targetPath, const char* payloadPath)"}, {"doc": "Limpia el historial de comandos de la consola actual", "kind": "function", "line": 3384, "name": "cleanSystemLogs", "signature": "void cleanSystemLogs()"}, {"doc": "ensurePersistence.c", "kind": "function", "line": 3421, "name": "ensurePersistence", "signature": "BOOL ensurePersistence()"}, {"doc": "isSandboxEnvironment.c", "kind": "function", "line": 3482, "name": "isSandboxEnvironment", "signature": "BOOL isSandboxEnvironment()"}, {"kind": "function", "line": 3552, "name": "tryPrivilegeEscalation", "signature": "void tryPrivilegeEscalation()"}, {"kind": "function", "line": 3557, "name": "executeUACBypass", "signature": "BOOL executeUACBypass(const char* payloadPath)"}, {"kind": "function", "line": 3610, "name": "scanPort", "signature": "void scanPort(void* arg)"}, {"doc": "PortScanner.c", "kind": "function", "line": 3661, "name": "PortScanner", "signature": "void PortScanner(char* targetIP, int* ports, int numPorts)"}, {"kind": "function", "line": 3706, "name": "PortScannerWrapper", "signature": "void PortScannerWrapper(void* arg)"}, {"doc": "=== INYECCIÓN EARLY BIRD + SYSCALL ===", "kind": "function", "line": 3729, "name": "EarlyBirdInject", "signature": "BOOL EarlyBirdInject(unsigned char* shellcode, int shellcode_len)"}, {"kind": "function", "line": 3900, "name": "init_aes_context", "signature": "PacketEncryptionContext* init_aes_context(const char* key_hex)"}, {"doc": "retry_http_request.c", "kind": "function", "line": 3918, "name": "retry_http_request", "signature": "char* retry_http_request(const char* url, const char* method, const char* data, int max_retries)"}, {"doc": "exec_cmd.c", "kind": "function", "line": 4172, "name": "exec_cmd", "signature": "char* exec_cmd(const char* cmd)"}, {"doc": "c2.c (reemplaza la función actual)", "kind": "function", "line": 4200, "name": "GetC2Command", "signature": "char* GetC2Command(const char* host, const char* path)"}, {"kind": "function", "line": 4347, "name": "DownloadToBuffer", "signature": "unsigned char* DownloadToBuffer(const char* url, DWORD* fileSize)"}, {"kind": "function", "line": 4423, "name": "DownloadFromURL", "signature": "BOOL DownloadFromURL(const char* url, const char* filepath)"}, {"kind": "function", "line": 4454, "name": "encrypt_data", "signature": "char* encrypt_data(const char* data)"}, {"kind": "function", "line": 4512, "name": "isValidUUID", "signature": "BOOL isValidUUID(const char* uuid)"}, {"kind": "function", "line": 4537, "name": "deleteFilesDelay", "signature": "void deleteFilesDelay(void* arg)"}, {"kind": "function", "line": 4551, "name": "executeCommand", "signature": "void executeCommand(void* cmdPtr)"}, {"kind": "function", "line": 4560, "name": "handleAtomic", "signature": "void handleAtomic(char* command)"}, {"doc": "=== handleDownload: descarga del C2 al beacon ===", "kind": "function", "line": 4683, "name": "handleDownload", "signature": "BOOL handleDownload(const char* command)"}, {"kind": "function", "line": 4703, "name": "SerializeBeaconString", "signature": "void SerializeBeaconString(char* buffer, int* offset, const char* str)"}, {"kind": "function", "line": 4712, "name": "BeaconDataSerializeString", "signature": "void BeaconDataSerializeString(char* buffer, int* offset, const char* str)"}, {"kind": "function", "line": 4720, "name": "go", "signature": "void go(unsigned char * bof_data, int bof_size, char * args, int args_len)"}, {"doc": "Función principal de manejo de comandos", "kind": "function", "line": 4738, "name": "handleAdversary", "signature": "void handleAdversary(char* command)"}, {"doc": "main.c", "kind": "function", "line": 5233, "name": "main", "signature": "int main()"}, {"kind": "macro", "line": 20, "name": "PSAPI_VERSION", "signature": "#define PSAPI_VERSION"}, {"kind": "macro", "line": 21, "name": "WIN32_LEAN_AND_MEAN", "signature": "#define WIN32_LEAN_AND_MEAN"}, {"kind": "macro", "line": 71, "name": "XOR_KEY", "signature": "#define XOR_KEY"}, {"kind": "macro", "line": 72, "name": "DEBUG", "signature": "#define DEBUG"}, {"kind": "macro", "line": 73, "name": "TIMEOUT", "signature": "#define TIMEOUT"}, {"kind": "macro", "line": 74, "name": "MAX_RESPONSE_SIZE", "signature": "#define MAX_RESPONSE_SIZE"}, {"kind": "macro", "line": 75, "name": "C2_URL", "signature": "#define C2_URL"}, {"kind": "macro", "line": 76, "name": "MALEABLE", "signature": "#define MALEABLE"}, {"kind": "macro", "line": 77, "name": "CLIENT_ID", "signature": "#define CLIENT_ID"}, {"kind": "macro", "line": 78, "name": "SLEEP_BASE", "signature": "#define SLEEP_BASE"}, {"kind": "macro", "line": 79, "name": "MIN_JITTER", "signature": "#define MIN_JITTER"}, {"kind": "macro", "line": 80, "name": "MAX_JITTER", "signature": "#define MAX_JITTER"}, {"kind": "macro", "line": 81, "name": "MAX_RETRIES", "signature": "#define MAX_RETRIES"}, {"kind": "macro", "line": 82, "name": "C2_HOST", "signature": "#define C2_HOST"}, {"kind": "macro", "line": 83, "name": "LC2_HOST", "signature": "#define LC2_HOST"}, {"kind": "macro", "line": 84, "name": "C2_USER", "signature": "#define C2_USER"}, {"kind": "macro", "line": 85, "name": "C2_PASS", "signature": "#define C2_PASS"}, {"kind": "macro", "line": 86, "name": "C2_PORT", "signature": "#define C2_PORT"}, {"kind": "macro", "line": 87, "name": "CONFIG_PATH", "signature": "#define CONFIG_PATH"}, {"kind": "macro", "line": 88, "name": "C2_PATH", "signature": "#define C2_PATH"}, {"kind": "macro", "line": 89, "name": "LC2_PATH", "signature": "#define LC2_PATH"}, {"kind": "macro", "line": 91, "name": "min", "signature": "#define min(a,b)"}, {"kind": "macro", "line": 94, "name": "SECURITY_FLAG_IGNORE_REVOCATION", "signature": "#define SECURITY_FLAG_IGNORE_REVOCATION"}, {"kind": "macro", "line": 97, "name": "INVALID_SOCKET", "signature": "#define INVALID_SOCKET"}, {"kind": "macro", "line": 99, "name": "USER_AGENT", "signature": "#define USER_AGENT"}, {"kind": "macro", "line": 100, "name": "USER_AGENT_A", "signature": "#define USER_AGENT_A"}, {"kind": "macro", "line": 101, "name": "IMAGE_DOS_SIGNATURE", "signature": "#define IMAGE_DOS_SIGNATURE"}, {"kind": "macro", "line": 102, "name": "IMAGE_NT_SIGNATURE", "signature": "#define IMAGE_NT_SIGNATURE"}, {"kind": "macro", "line": 103, "name": "IMAGE_NT_OPTIONAL_HDR32_MAGIC", "signature": "#define IMAGE_NT_OPTIONAL_HDR32_MAGIC"}, {"kind": "macro", "line": 104, "name": "IMAGE_NT_OPTIONAL_HDR64_MAGIC", "signature": "#define IMAGE_NT_OPTIONAL_HDR64_MAGIC"}, {"kind": "macro", "line": 106, "name": "SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE", "signature": "#define SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE"}, {"kind": "macro", "line": 109, "name": "SECURITY_FLAG_IGNORE_INVALID_POLICY", "signature": "#define SECURITY_FLAG_IGNORE_INVALID_POLICY"}, {"kind": "macro", "line": 112, "name": "_SECURITY_PACKAGE_DEFINITION_", "signature": "#define _SECURITY_PACKAGE_DEFINITION_"}, {"kind": "macro", "line": 115, "name": "_PROCESS_BASIC_INFORMATION_", "signature": "#define _PROCESS_BASIC_INFORMATION_"}, {"kind": "macro", "line": 117, "name": "_SP_LSA_MODE_INITIALIZE_DEFINED_", "signature": "#define _SP_LSA_MODE_INITIALIZE_DEFINED_"}, {"kind": "macro", "line": 123, "name": "ProcessBasicInformation", "signature": "#define ProcessBasicInformation"}, {"kind": "macro", "line": 126, "name": "CHECK_ERROR", "signature": "#define CHECK_ERROR(cond, msg)"}, {"kind": "macro", "line": 231, "name": "NUM_USER_AGENTS", "signature": "#define NUM_USER_AGENTS"}, {"kind": "macro", "line": 240, "name": "NUM_URLS", "signature": "#define NUM_URLS"}, {"kind": "macro", "line": 247, "name": "NUM_UAS", "signature": "#define NUM_UAS"}, {"kind": "macro", "line": 300, "name": "NT_SUCCESS", "signature": "#define NT_SUCCESS(Status)"}]}, {"id": "beacon.h", "kind": "module", "label": "beacon.h", "language": "h", "sha256": "7bf62900a9cdae47", "symbol_count": 4, "symbols": [{"kind": "struct", "line": 25, "name": "datap"}, {"kind": "macro", "line": 21, "name": "BEACON_H", "signature": "#define BEACON_H"}, {"kind": "macro", "line": 41, "name": "CALLBACK_OUTPUT", "signature": "#define CALLBACK_OUTPUT"}, {"kind": "macro", "line": 42, "name": "CALLBACK_ERROR", "signature": "#define CALLBACK_ERROR"}]}, {"id": "bof/calc/beacon.h", "kind": "module", "label": "beacon.h", "language": "h", "sha256": "999fd68c034ff4ab", "symbol_count": 4, "symbols": [{"kind": "struct", "line": 25, "name": "datap"}, {"kind": "macro", "line": 21, "name": "BEACON_H", "signature": "#define BEACON_H"}, {"kind": "macro", "line": 41, "name": "CALLBACK_OUTPUT", "signature": "#define CALLBACK_OUTPUT"}, {"kind": "macro", "line": 42, "name": "CALLBACK_ERROR", "signature": "#define CALLBACK_ERROR"}]}, {"id": "bof/calc/calc.c", "kind": "module", "label": "calc.c", "language": "c", "sha256": "0af0d47c3a77f7cd", "symbol_count": 6, "symbols": [{"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 34, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 26, "name": "__imp_GetModuleHandleA", "signature": "extern FARPROC __imp_GetModuleHandleA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern FARPROC __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_LoadLibraryA", "signature": "extern FARPROC __imp_LoadLibraryA;"}, {"kind": "variable", "line": 29, "name": "__imp_GetComputerNameA", "signature": "extern FARPROC __imp_GetComputerNameA;"}, {"kind": "variable", "line": 30, "name": "__imp_CloseHandle", "signature": "extern FARPROC __imp_CloseHandle;"}]}, {"id": "bof/etw/beacon.h", "kind": "module", "label": "beacon.h", "language": "h", "sha256": "73e4412ef1b359dd", "symbol_count": 4, "symbols": [{"kind": "struct", "line": 25, "name": "datap"}, {"kind": "macro", "line": 21, "name": "BEACON_H", "signature": "#define BEACON_H"}, {"kind": "macro", "line": 41, "name": "CALLBACK_OUTPUT", "signature": "#define CALLBACK_OUTPUT"}, {"kind": "macro", "line": 42, "name": "CALLBACK_ERROR", "signature": "#define CALLBACK_ERROR"}]}, {"id": "bof/etw/etw.c", "kind": "module", "label": "etw.c", "language": "c", "sha256": "5027fc7b285855b1", "symbol_count": 5, "symbols": [{"kind": "function", "line": 26, "name": "go", "signature": "void go(char *a,int l)"}, {"doc": "include include \"beacon.h\"", "kind": "variable", "line": 22, "name": "__imp_GetModuleHandleA", "signature": "extern PVOID __imp_GetModuleHandleA;"}, {"kind": "variable", "line": 23, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 24, "name": "__imp_VirtualProtect", "signature": "extern PVOID __imp_VirtualProtect;"}, {"kind": "variable", "line": 25, "name": "__imp_RtlCopyMemory", "signature": "extern PVOID __imp_RtlCopyMemory;"}]}, {"id": "bof/test/Test.c", "kind": "module", "label": "Test.c", "language": "c", "sha256": "67be641c41f23622", "symbol_count": 1, "symbols": [{"kind": "function", "line": 3, "name": "go", "signature": "void go(char *args, int alen)"}]}, {"id": "bof/test/amsibypass.c", "kind": "module", "label": "amsibypass.c", "language": "c", "sha256": "41ce083250555650", "symbol_count": 5, "symbols": [{"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 34, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 26, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_VirtualProtect", "signature": "extern PVOID __imp_VirtualProtect;"}, {"kind": "variable", "line": 29, "name": "__imp_RtlCopyMemory", "signature": "extern PVOID __imp_RtlCopyMemory;"}]}, {"id": "bof/test/beacon.h", "kind": "module", "label": "beacon.h", "language": "h", "sha256": "7544d638e4621997", "symbol_count": 4, "symbols": [{"kind": "struct", "line": 25, "name": "datap"}, {"kind": "macro", "line": 21, "name": "BEACON_H", "signature": "#define BEACON_H"}, {"kind": "macro", "line": 41, "name": "CALLBACK_OUTPUT", "signature": "#define CALLBACK_OUTPUT"}, {"kind": "macro", "line": 42, "name": "CALLBACK_ERROR", "signature": "#define CALLBACK_ERROR"}]}, {"id": "bof/test/cmdwhoami.c", "kind": "module", "label": "cmdwhoami.c", "language": "c", "sha256": "b9928caaa308aaaa", "symbol_count": 4, "symbols": [{"kind": "function", "line": 43, "name": "go", "signature": "void go(char *args, int alen)"}, {"kind": "variable", "line": 26, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}]}, {"id": "bof/test/disablelog.c", "kind": "module", "label": "disablelog.c", "language": "c", "sha256": "4ad92928c1a0bebd", "symbol_count": 9, "symbols": [{"kind": "function", "line": 37, "name": "my_wcscmp", "signature": "static int my_wcscmp(const wchar_t *s1, const wchar_t *s2)"}, {"kind": "function", "line": 69, "name": "go", "signature": "void go(char *args, int alen)"}, {"kind": "variable", "line": 27, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 28, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 29, "name": "__imp_GetModuleHandleA", "signature": "extern PVOID __imp_GetModuleHandleA;"}, {"kind": "variable", "line": 30, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}, {"kind": "variable", "line": 31, "name": "__imp_OpenProcess", "signature": "extern PVOID __imp_OpenProcess;"}, {"kind": "macro", "line": 20, "name": "WIN32_LEAN_AND_MEAN", "signature": "#define WIN32_LEAN_AND_MEAN"}, {"kind": "macro", "line": 34, "name": "NT_SUCCESS", "signature": "#define NT_SUCCESS(x)"}]}, {"id": "bof/test/getenv.c", "kind": "module", "label": "getenv.c", "language": "c", "sha256": "dd4b8a3dd497bb23", "symbol_count": 2, "symbols": [{"kind": "function", "line": 25, "name": "go", "signature": "void go(char *args, int alen)"}, {"kind": "variable", "line": 23, "name": "__imp_GetEnvironmentVariableA", "signature": "extern PVOID __imp_GetEnvironmentVariableA;"}]}, {"id": "bof/test/loadvnc.c", "kind": "module", "label": "loadvnc.c", "language": "c", "sha256": "f6f6eeee3831e0dd", "symbol_count": 8, "symbols": [{"kind": "struct", "line": 35, "name": "_PROCESSENTRY32"}, {"doc": "================================ DEFINICIONES MANUALES ================================ define TH32CS_SNAPPROCESS 0x00000002", "kind": "type_alias", "line": 34, "name": "dwSize", "signature": "typedef struct _PROCESSENTRY32 { DWORD dwSize;"}, {"doc": "================================ FUNCIÓN AUX: EJECUTAR COMANDO OCULTO ================================", "kind": "function", "line": 51, "name": "execute_cmd_hidden", "signature": "void execute_cmd_hidden(char* cmd)"}, {"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 81, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 26, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}, {"kind": "macro", "line": 33, "name": "TH32CS_SNAPPROCESS", "signature": "#define TH32CS_SNAPPROCESS"}]}, {"id": "bof/test/make_table.c", "kind": "module", "label": "make_table.c", "language": "c", "sha256": "327a669a69de5d0d", "symbol_count": 2, "symbols": [{"kind": "function", "line": 17, "name": "Copyright", "signature": "Copyright (c) LazyOwn RedTeam 2025. All rights reserved.\n*/\n\n#include \n#include #include \"beacon.h\" /* ===== DECLARACIONES QUE FALTABAN =====", "kind": "type_alias", "line": 6, "name": "SOCKET", "signature": "typedef unsigned __int64 SOCKET;"}, {"doc": "pragma pack(push,1)", "kind": "type_alias", "line": 16, "name": "wVersion", "signature": "typedef struct WSAData { WORD wVersion;"}, {"doc": "pragma pack(pop)", "kind": "type_alias", "line": 26, "name": "fd_count", "signature": "typedef struct fd_set { unsigned int fd_count;"}, {"kind": "type_alias", "line": 31, "name": "tv_sec", "signature": "typedef struct timeval { long tv_sec;"}, {"doc": "define FD_SETSIZE 64 define FD_CLR(fd,set) do { if ((set)->fd_count > 0) { u_int __i;for (__i=0;__i<(set)->fd_count;__i++) { if ((set)->fd_array[__i] == (fd)) { while (__i < (set)->fd_count-1) { (set)->fd_array[__i] = (set)->fd_array[__i+1];__i++;} (set)->fd_count--;break;}}}} while(0) define FD_SET(fd,set) do { if ((set)->fd_count < FD_SETSIZE) (set)->fd_array[(set)->fd_count++] = (fd); } while(0) define FD_ZERO(set) (((set)->fd_count = 0)) define FD_ISSET(fd,set) (__builtin_memchr((set)->fd_array,(fd),(set)->fd_count*sizeof(SOCKET))!=NULL)", "kind": "type_alias", "line": 42, "name": "u_short", "signature": "typedef unsigned short u_short;"}, {"kind": "type_alias", "line": 44, "name": "u_int", "signature": "typedef unsigned int u_int;"}, {"kind": "type_alias", "line": 45, "name": "u_long", "signature": "typedef unsigned long u_long;"}, {"doc": "typedef int (WINAPI *LISTEN)(SOCKET, int); typedef SOCKET (WINAPI *ACCEPT)(SOCKET, struct sockaddr*, int*); typedef int (WINAPI *CONNECT)(SOCKET, const struct sockaddr*, int); typedef int (WINAPI *RECV)(SOCKET, char*, int, int); typedef int (WINAPI *SEND)(SOCKET, const char*, int, int); typedef int (WINAPI *SELECT)(int, fd_set*, fd_set*, fd_set*, const struct timeval*); typedef int (WINAPI *CLOSESOCKET)(SOCKET); typedef int (WINAPI *WSACLEANUP)(void); typedef int (WINAPI *WSAGETLASTERROR)(void); typedef ULONG (WINAPI *HTONL)(ULONG); typedef USHORT (WINAPI *HTONS)(USHORT); typedef USHORT (WINAPI *NTOHS)(USHORT); /* ===== AUXILIARES =====", "kind": "function", "line": 107, "name": "my_FD_ISSET", "signature": "static int my_FD_ISSET(SOCKET s, fd_set *set)"}, {"doc": "typedef USHORT (WINAPI *NTOHS)(USHORT); /* ===== AUXILIARES ===== static int my_FD_ISSET(SOCKET s, fd_set *set) { if (!set) return 0; for (u_int i = 0; i < set->fd_count; ++i) if (set->fd_array[i] == s) return 1; return 0; } /* ===== VARIABLE GLOBAL ===== static HANDLE g_hShutdownEvent = NULL; /* ===== MANEJADOR SOCKS5 (solo después de handshake confirmado) =====", "kind": "function", "line": 118, "name": "HandleSocks5Connection", "signature": "static void HandleSocks5Connection(SOCKET client_sock,\n CONNECT pConnect, RECV pRecv, SEND pSe..."}, {"doc": "break; } if (pSend(client_sock, buf, n, 0) != n) { BeaconPrintf(CALLBACK_ERROR, \"[SOCKS5] Falló al reenviar al cliente\\n\"); break; } BeaconPrintf(CALLBACK_OUTPUT, \"[SOCKS5] Reenviados %d bytes destino→cliente\\n\", n); } } pCloseSocket(tgt); BeaconPrintf(CALLBACK_OUTPUT, \"[SOCKS5] Túnel cerrado\\n\"); } /* ===== HILO PRINCIPAL DEL PROXY =====", "kind": "function", "line": 261, "name": "ProxyThread", "signature": "DWORD WINAPI ProxyThread(LPVOID _)"}, {"doc": "cleanup_srv: pCloseSocket(srv); cleanup_wsa: pWSACleanup(); cleanup_event: if (g_hShutdownEvent) { ((BOOL (WINAPI*)(HANDLE))__imp_CloseHandle)(g_hShutdownEvent); g_hShutdownEvent = NULL; } return 0; } /* ===== ENTRY POINT BOF =====", "kind": "function", "line": 358, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "}; struct sockaddr { unsigned short sa_family; char sa_data[14]; }; struct hostent { char *h_name; char **h_aliases; short h_addrtype; short h_length; char **h_addr_list; #define h_addr h_addr_list[0] }; /* ===== DIRECT IMPORTS =====", "kind": "variable", "line": 68, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 69, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 70, "name": "__imp_VirtualAlloc", "signature": "extern PVOID __imp_VirtualAlloc;"}, {"kind": "variable", "line": 71, "name": "__imp_VirtualFree", "signature": "extern PVOID __imp_VirtualFree;"}, {"kind": "variable", "line": 72, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}, {"kind": "macro", "line": 1, "name": "WIN32_LEAN_AND_MEAN", "signature": "#define WIN32_LEAN_AND_MEAN"}, {"kind": "macro", "line": 7, "name": "INVALID_SOCKET", "signature": "#define INVALID_SOCKET"}, {"kind": "macro", "line": 8, "name": "SOCKET_ERROR", "signature": "#define SOCKET_ERROR"}, {"kind": "macro", "line": 9, "name": "AF_INET", "signature": "#define AF_INET"}, {"kind": "macro", "line": 10, "name": "SOCK_STREAM", "signature": "#define SOCK_STREAM"}, {"kind": "macro", "line": 11, "name": "IPPROTO_TCP", "signature": "#define IPPROTO_TCP"}, {"kind": "macro", "line": 12, "name": "INADDR_ANY", "signature": "#define INADDR_ANY"}, {"kind": "macro", "line": 13, "name": "INADDR_LOOPBACK", "signature": "#define INADDR_LOOPBACK"}, {"kind": "macro", "line": 37, "name": "FD_SETSIZE", "signature": "#define FD_SETSIZE"}, {"kind": "macro", "line": 38, "name": "FD_CLR", "signature": "#define FD_CLR(fd,set)"}, {"kind": "macro", "line": 39, "name": "FD_SET", "signature": "#define FD_SET(fd,set)"}, {"kind": "macro", "line": 40, "name": "FD_ZERO", "signature": "#define FD_ZERO(set)"}, {"kind": "macro", "line": 41, "name": "FD_ISSET", "signature": "#define FD_ISSET(fd,set)"}, {"kind": "macro", "line": 64, "name": "h_addr", "signature": "#define h_addr"}, {"kind": "macro", "line": 75, "name": "SOCKS5_LISTEN_PORT", "signature": "#define SOCKS5_LISTEN_PORT"}, {"kind": "macro", "line": 76, "name": "SOCKS5_CONTROL_PORT", "signature": "#define SOCKS5_CONTROL_PORT"}, {"kind": "macro", "line": 77, "name": "MAX_PENDING_CONNECTIONS", "signature": "#define MAX_PENDING_CONNECTIONS"}, {"kind": "macro", "line": 78, "name": "BUFFER_SIZE", "signature": "#define BUFFER_SIZE"}]}, {"id": "bof/test/tel.py", "kind": "module", "label": "tel.py", "language": "py", "sha256": "2c888a79357c13cd", "symbol_count": 6, "symbols": [{"kind": "function", "line": 8, "name": "get_machine_id", "signature": "def get_machine_id()"}, {"kind": "function", "line": 20, "name": "get_version", "signature": "def get_version()"}, {"doc": "Simula la función toNumbers de JavaScript", "kind": "function", "line": 31, "name": "to_numbers", "signature": "def to_numbers(hex_str)"}, {"doc": "Simula la función toHex de JavaScript", "kind": "function", "line": 35, "name": "to_hex", "signature": "def to_hex(byte_list)"}, {"doc": "Descifra usando AES en modo CBC (como slowAES.decrypt(c,2,a,b))", "kind": "function", "line": 39, "name": "decrypt_cookie", "signature": "def decrypt_cookie(encrypted, key, iv)"}, {"doc": "Sistema de telemetría de uso por instalación no invasiva.", "kind": "function", "line": 45, "name": "main", "signature": "def main()"}]}, {"id": "bof/test/uacbypass.c", "kind": "module", "label": "uacbypass.c", "language": "c", "sha256": "325c1fe07b9b6249", "symbol_count": 5, "symbols": [{"doc": "================================ FUNCIÓN AUX: EJECUTAR COMANDO OCULTO ================================", "kind": "function", "line": 33, "name": "execute_hidden_cmd", "signature": "void execute_hidden_cmd(char* cmd)"}, {"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 61, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS (solo si están en tu tabla) ================================", "kind": "variable", "line": 26, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}]}, {"doc": "================================ IMPORTS DIRECTOS ================================", "id": "bof/test/upload.c", "kind": "module", "label": "upload.c", "language": "c", "sha256": "ebd2a804d304f5af", "symbol_count": 41, "symbols": [{"kind": "struct", "line": 46, "name": "AES_ctx"}, {"doc": "================================ TIPOS MANUALES ================================", "kind": "type_alias", "line": 14, "name": "uint8_t", "signature": "typedef unsigned char uint8_t;"}, {"kind": "type_alias", "line": 15, "name": "uint32_t", "signature": "typedef unsigned int uint32_t;"}, {"kind": "type_alias", "line": 16, "name": "HINTERNET", "signature": "typedef void* HINTERNET;"}, {"kind": "type_alias", "line": 17, "name": "INTERNET_PORT", "signature": "typedef WORD INTERNET_PORT;"}, {"kind": "type_alias", "line": 18, "name": "HCRYPTPROV", "signature": "typedef ULONG_PTR HCRYPTPROV;"}, {"doc": "================================ FUNCIONES AUXILIARES ================================", "kind": "function", "line": 53, "name": "my_strlen", "signature": "static int my_strlen(const char *s)"}, {"kind": "function", "line": 59, "name": "my_memcpy", "signature": "static void* my_memcpy(void* dst, const void* src, size_t len)"}, {"kind": "function", "line": 66, "name": "my_memset", "signature": "static void* my_memset(void* dst, int val, size_t len)"}, {"kind": "function", "line": 72, "name": "my_contains_dotdot", "signature": "static BOOL my_contains_dotdot(const char* path)"}, {"kind": "function", "line": 81, "name": "my_strchr", "signature": "static char* my_strchr(const char *s, int c)"}, {"doc": "================================ AES (sin datos globales) ================================", "kind": "function", "line": 93, "name": "xtime", "signature": "static uint8_t xtime(uint8_t x)"}, {"kind": "function", "line": 99, "name": "AddRoundKey", "signature": "static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)"}, {"kind": "function", "line": 106, "name": "SubBytes", "signature": "static void SubBytes(state_t* state, const uint8_t* sbox)"}, {"kind": "function", "line": 113, "name": "ShiftRows", "signature": "static void ShiftRows(state_t* state)"}, {"kind": "function", "line": 121, "name": "MixColumns", "signature": "static void MixColumns(state_t* state)"}, {"kind": "function", "line": 133, "name": "Cipher", "signature": "static void Cipher(state_t* state, const uint8_t* RoundKey, const uint8_t* sbox)"}, {"kind": "function", "line": 146, "name": "KeyExpansion", "signature": "static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key, const uint8_t* sbox, const uint8_..."}, {"kind": "function", "line": 174, "name": "AES_init_ctx", "signature": "void AES_init_ctx(AES_ctx* ctx, const uint8_t* key, const uint8_t* sbox, const uint8_t* Rcon)"}, {"kind": "function", "line": 178, "name": "AES_CFB_encrypt_buffer", "signature": "void AES_CFB_encrypt_buffer(AES_ctx* ctx, uint8_t* iv, uint8_t* buf, uint32_t length, const uint8..."}, {"doc": "================================ BASE64 ================================", "kind": "function", "line": 205, "name": "my_base64_encode", "signature": "static char* my_base64_encode(const uint8_t* data, uint32_t len,\n LPVOID (WINAPI *pVirtualAllo..."}, {"kind": "function", "line": 231, "name": "ParseUploadArgs", "signature": "static void ParseUploadArgs(const char* args, int alen,\n char* local_p..."}, {"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 273, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 8, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 9, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "macro", "line": 1, "name": "WIN32_LEAN_AND_MEAN", "signature": "#define WIN32_LEAN_AND_MEAN"}, {"kind": "macro", "line": 20, "name": "PROV_RSA_AES", "signature": "#define PROV_RSA_AES"}, {"kind": "macro", "line": 21, "name": "CRYPT_VERIFYCONTEXT", "signature": "#define CRYPT_VERIFYCONTEXT"}, {"kind": "macro", "line": 23, "name": "AES_BLOCKLEN", "signature": "#define AES_BLOCKLEN"}, {"kind": "macro", "line": 24, "name": "AES256_KEYLEN", "signature": "#define AES256_KEYLEN"}, {"kind": "macro", "line": 25, "name": "Nr", "signature": "#define Nr"}, {"kind": "macro", "line": 26, "name": "Nk", "signature": "#define Nk"}, {"kind": "macro", "line": 27, "name": "Nb", "signature": "#define Nb"}, {"kind": "macro", "line": 29, "name": "SECURITY_FLAG_IGNORE_UNKNOWN_CA", "signature": "#define SECURITY_FLAG_IGNORE_UNKNOWN_CA"}, {"kind": "macro", "line": 30, "name": "SECURITY_FLAG_IGNORE_CERT_CN_INVALID", "signature": "#define SECURITY_FLAG_IGNORE_CERT_CN_INVALID"}, {"kind": "macro", "line": 31, "name": "SECURITY_FLAG_IGNORE_CERT_DATE_INVALID", "signature": "#define SECURITY_FLAG_IGNORE_CERT_DATE_INVALID"}, {"kind": "macro", "line": 32, "name": "WINHTTP_OPTION_SECURITY_FLAGS", "signature": "#define WINHTTP_OPTION_SECURITY_FLAGS"}, {"kind": "macro", "line": 35, "name": "WINHTTP_ACCESS_TYPE_NO_PROXY", "signature": "#define WINHTTP_ACCESS_TYPE_NO_PROXY"}, {"kind": "macro", "line": 39, "name": "WINHTTP_NO_PROXY_NAME", "signature": "#define WINHTTP_NO_PROXY_NAME"}, {"kind": "macro", "line": 43, "name": "WINHTTP_NO_PROXY_BYPASS", "signature": "#define WINHTTP_NO_PROXY_BYPASS"}, {"kind": "macro", "line": 244, "name": "NEXT_TOKEN", "signature": "#define NEXT_TOKEN(dst,lim)"}]}, {"id": "bof/test/vncrelay.c", "kind": "module", "label": "vncrelay.c", "language": "c", "sha256": "d42b5a03dac95df3", "symbol_count": 8, "symbols": [{"doc": "================================ FD_ISSET MANUAL ================================", "kind": "function", "line": 62, "name": "my_FD_ISSET", "signature": "int my_FD_ISSET(SOCKET sock, fd_set *set)"}, {"doc": "================================ RELAY TRAFFIC ================================", "kind": "function", "line": 75, "name": "relay_traffic", "signature": "void relay_traffic(SOCKET client_sock, SOCKET vnc_sock)"}, {"doc": "================================ FUNCIÓN PRINCIPAL — ¡CORREGIDO! ================================", "kind": "function", "line": 132, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 27, "name": "__imp_LoadLibraryA", "signature": "extern PVOID __imp_LoadLibraryA;"}, {"kind": "variable", "line": 28, "name": "__imp_GetProcAddress", "signature": "extern PVOID __imp_GetProcAddress;"}, {"kind": "variable", "line": 29, "name": "__imp_VirtualAlloc", "signature": "extern PVOID __imp_VirtualAlloc;"}, {"kind": "variable", "line": 30, "name": "__imp_VirtualFree", "signature": "extern PVOID __imp_VirtualFree;"}, {"kind": "variable", "line": 31, "name": "__imp_CloseHandle", "signature": "extern PVOID __imp_CloseHandle;"}]}, {"id": "bof/test/winver.c", "kind": "module", "label": "winver.c", "language": "c", "sha256": "a7ac4c07b5f48edd", "symbol_count": 2, "symbols": [{"kind": "function", "line": 25, "name": "go", "signature": "void go(char *args, int alen)"}, {"kind": "variable", "line": 23, "name": "__imp_GetVersionExA", "signature": "extern PVOID __imp_GetVersionExA;"}]}, {"id": "bof/whoami/beacon.h", "kind": "module", "label": "beacon.h", "language": "h", "sha256": "358a84ac7c8ce3d0", "symbol_count": 4, "symbols": [{"kind": "struct", "line": 25, "name": "datap"}, {"kind": "macro", "line": 21, "name": "BEACON_H", "signature": "#define BEACON_H"}, {"kind": "macro", "line": 41, "name": "CALLBACK_OUTPUT", "signature": "#define CALLBACK_OUTPUT"}, {"kind": "macro", "line": 42, "name": "CALLBACK_ERROR", "signature": "#define CALLBACK_ERROR"}]}, {"id": "bof/whoami/whoami.c", "kind": "module", "label": "whoami.c", "language": "c", "sha256": "2d9d017bba7589d7", "symbol_count": 5, "symbols": [{"doc": "================================ FUNCIÓN PRINCIPAL ================================", "kind": "function", "line": 34, "name": "go", "signature": "void go(char *args, int alen)"}, {"doc": "================================ IMPORTS DIRECTOS ================================", "kind": "variable", "line": 26, "name": "__imp_GetModuleHandleA", "signature": "extern FARPROC __imp_GetModuleHandleA;"}, {"kind": "variable", "line": 27, "name": "__imp_GetProcAddress", "signature": "extern FARPROC __imp_GetProcAddress;"}, {"kind": "variable", "line": 28, "name": "__imp_LoadLibraryA", "signature": "extern FARPROC __imp_LoadLibraryA;"}, {"kind": "variable", "line": 29, "name": "__imp_GetComputerNameA", "signature": "extern FARPROC __imp_GetComputerNameA;"}]}, {"id": "cJSON.c", "kind": "module", "label": "cJSON.c", "language": "c", "sha256": "1e87d4d42a8960cc", "symbol_count": 125, "symbols": [{"kind": "struct", "line": 157, "name": "internal_hooks"}, {"kind": "struct", "line": 88, "name": "error"}, {"kind": "struct", "line": 291, "name": "parse_buffer"}, {"kind": "struct", "line": 482, "name": "printbuffer"}, {"kind": "function", "line": 95, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void)"}, {"kind": "function", "line": 100, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item)"}, {"kind": "function", "line": 110, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item)"}, {"kind": "function", "line": 125, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(const char*) cJSON_Version(void)"}, {"doc": "/* This is a safeguard to prevent copy-pasters from using incompatible C and header files #if (CJSON_VERSION_MAJOR != 1) || (CJSON_VERSION_MINOR != 7) || (CJSON_VERSION_PATCH != 18) #error cJSON.h and cJSON.c have different versions. Make sure that both have the same. #endif CJSON_PUBLIC(const char*) cJSON_Version(void) { static char version[15]; sprintf(version, \"%i.%i.%i\", CJSON_VERSION_MAJOR, CJSON_VERSION_MINOR, CJSON_VERSION_PATCH); return version; } /* Case insensitive string comparison, doesn't consider two NULL pointers equal though", "kind": "function", "line": 134, "name": "case_insensitive_strcmp", "signature": "static int case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2)"}, {"doc": "} return tolower(*string1) - tolower(*string2); } typedef struct internal_hooks { void *(CJSON_CDECL *allocate)(size_t size); void (CJSON_CDECL *deallocate)(void *pointer); void *(CJSON_CDECL *reallocate)(void *pointer, size_t size); } internal_hooks; #if defined(_MSC_VER) /* work around MSVC error C2322: '...' address of dllimport '...' is not static", "kind": "function", "line": 166, "name": "internal_malloc", "signature": "static void * CJSON_CDECL internal_malloc(size_t size)"}, {"kind": "function", "line": 170, "name": "internal_free", "signature": "static void CJSON_CDECL internal_free(void *pointer)"}, {"kind": "function", "line": 174, "name": "internal_realloc", "signature": "static void * CJSON_CDECL internal_realloc(void *pointer, size_t size)"}, {"kind": "function", "line": 189, "name": "cJSON_strdup", "signature": "static unsigned char* cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks)"}, {"kind": "function", "line": 210, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks)"}, {"doc": "if (hooks->free_fn != NULL) { global_hooks.deallocate = hooks->free_fn; } /* use realloc only if both free and malloc are used global_hooks.reallocate = NULL; if ((global_hooks.allocate == malloc) && (global_hooks.deallocate == free)) { global_hooks.reallocate = realloc; } } /* Internal constructor.", "kind": "function", "line": 242, "name": "cJSON_New_Item", "signature": "static cJSON *cJSON_New_Item(const internal_hooks * const hooks)"}, {"doc": "item->valuestring = NULL; } if (!(item->type & cJSON_StringIsConst) && (item->string != NULL)) { global_hooks.deallocate(item->string); item->string = NULL; } global_hooks.deallocate(item); item = next; } } /* get the decimal point character of the current locale", "kind": "function", "line": 281, "name": "get_decimal_point", "signature": "static unsigned char get_decimal_point(void)"}, {"doc": "size_t offset; size_t depth; /* How deeply nested (in arrays/objects) is the input at the current offset. internal_hooks hooks; } parse_buffer; /* check if the given size is left to read in a given parse buffer (starting with 1) #define can_read(buffer, size) ((buffer != NULL) && (((buffer)->offset + size) <= (buffer)->length)) /* check if the buffer can be accessed at the given index (starting with 0) #define can_access_at_index(buffer, index) ((buffer != NULL) && (((buffer)->offset + index) < (buffer)->length)) #define cannot_access_at_index(buffer, index) (!can_access_at_index(buffer, index)) /* get a pointer to the buffer at the position #define buffer_at_offset(buffer) ((buffer)->content + (buffer)->offset) /* Parse the input text to generate a number, and populate the result into item.", "kind": "function", "line": 309, "name": "parse_number", "signature": "static cJSON_bool parse_number(cJSON * const item, parse_buffer * const input_buffer)"}, {"doc": "} typedef struct { unsigned char *buffer; size_t length; size_t offset; size_t depth; /* current nesting depth (for formatted printing) cJSON_bool noalloc; cJSON_bool format; /* is this print a formatted print internal_hooks hooks; } printbuffer; /* realloc printbuffer if necessary to have at least \"needed\" bytes more", "kind": "function", "line": 494, "name": "ensure", "signature": "static unsigned char* ensure(printbuffer * const p, size_t needed)"}, {"doc": "p->buffer = NULL; return NULL; } memcpy(newbuffer, p->buffer, p->offset + 1); p->hooks.deallocate(p->buffer); } p->length = newsize; p->buffer = newbuffer; return newbuffer + p->offset; } /* calculate the new length of the string in a printbuffer and update the offset", "kind": "function", "line": 579, "name": "update_offset", "signature": "static void update_offset(printbuffer * const buffer)"}, {"doc": "/* calculate the new length of the string in a printbuffer and update the offset static void update_offset(printbuffer * const buffer) { const unsigned char *buffer_pointer = NULL; if ((buffer == NULL) || (buffer->buffer == NULL)) { return; } buffer_pointer = buffer->buffer + buffer->offset; buffer->offset += strlen((const char*)buffer_pointer); } /* securely comparison of floating-point variables", "kind": "function", "line": 592, "name": "compare_double", "signature": "static cJSON_bool compare_double(double a, double b)"}, {"doc": "} buffer_pointer = buffer->buffer + buffer->offset; buffer->offset += strlen((const char*)buffer_pointer); } /* securely comparison of floating-point variables static cJSON_bool compare_double(double a, double b) { double maxVal = fabs(a) > fabs(b) ? fabs(a) : fabs(b); return (fabs(a - b) <= maxVal * DBL_EPSILON); } /* Render the number nicely from the given item into a string.", "kind": "function", "line": 599, "name": "print_number", "signature": "static cJSON_bool print_number(const cJSON * const item, printbuffer * const output_buffer)"}, {"doc": "output_pointer[i] = '.'; continue; } output_pointer[i] = number_buffer[i]; } output_pointer[i] = '\\0'; output_buffer->offset += (size_t)length; return true; } /* parse 4 digit hexadecimal number", "kind": "function", "line": 669, "name": "parse_hex4", "signature": "static unsigned parse_hex4(const unsigned char * const input)"}, {"doc": "converts a UTF-16 literal to UTF-8 * A literal can be one or two sequences of the form \\uXXXX", "kind": "function", "line": 706, "name": "utf16_literal_to_utf8", "signature": "static unsigned char utf16_literal_to_utf8(const unsigned char * const input_pointer, const unsig..."}, {"doc": "else { (*output_pointer)[0] = (unsigned char)(codepoint & 0x7F); } output_pointer += utf8_length; return sequence_length; fail: return 0; } /* Parse the input text into an unescaped cinput, and populate item.", "kind": "function", "line": 827, "name": "parse_string", "signature": "static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer)"}, {"doc": "{ input_buffer->hooks.deallocate(output); output = NULL; } if (input_pointer != NULL) { input_buffer->offset = (size_t)(input_pointer - input_buffer->content); } return false; } /* Render the cstring provided to an escaped version that can be printed.", "kind": "function", "line": 957, "name": "print_string_ptr", "signature": "static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffer * const output_..."}, {"doc": "/* escape and print as unicode codepoint sprintf((char*)output_pointer, \"u%04x\", *input_pointer); output_pointer += 4; break; } } } output[output_length + 1] = '\"'; output[output_length + 2] = '\\0'; return true; } /* Invoke print_string_ptr (which is useful) on an item.", "kind": "function", "line": 1079, "name": "print_string", "signature": "static cJSON_bool print_string(const cJSON * const item, printbuffer * const p)"}, {"doc": "static cJSON_bool print_string(const cJSON * const item, printbuffer * const p) { return print_string_ptr((unsigned char*)item->valuestring, p); } /* Predeclare these prototypes. static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer); static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer); static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer); /* Utility to jump whitespace and cr/lf", "kind": "function", "line": 1093, "name": "buffer_skip_whitespace", "signature": "static parse_buffer *buffer_skip_whitespace(parse_buffer * const buffer)"}, {"doc": "while (can_access_at_index(buffer, 0) && (buffer_at_offset(buffer)[0] <= 32)) { buffer->offset++; } if (buffer->offset == buffer->length) { buffer->offset--; } return buffer; } /* skip the UTF-8 BOM (byte order mark) if it is at the beginning of a buffer", "kind": "function", "line": 1119, "name": "skip_utf8_bom", "signature": "static parse_buffer *skip_utf8_bom(parse_buffer * const buffer)"}, {"kind": "function", "line": 1134, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_ParseWithOpts(const char *value, const char **return_parse_end, cJSON..."}, {"kind": "function", "line": 1236, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_ParseWithLength(const char *value, size_t buffer_length)"}, {"kind": "function", "line": 1243, "name": "print", "signature": "static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * c..."}, {"kind": "function", "line": 1316, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(char *) cJSON_PrintUnformatted(const cJSON *item)"}, {"kind": "function", "line": 1321, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(char *) cJSON_PrintBuffered(const cJSON *item, int prebuffer, cJSON_bool fmt)"}, {"kind": "function", "line": 1352, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_PrintPreallocated(cJSON *item, char *buffer, const int length, con..."}, {"doc": "return false; } p.buffer = (unsigned char*)buffer; p.length = (size_t)length; p.offset = 0; p.noalloc = true; p.format = format; p.hooks = global_hooks; return print_value(item, &p); } /* Parser core - when encountering text, process appropriately.", "kind": "function", "line": 1372, "name": "parse_value", "signature": "static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer)"}, {"doc": "if (can_access_at_index(input_buffer, 0) && (buffer_at_offset(input_buffer)[0] == '[')) { return parse_array(item, input_buffer); } /* object if (can_access_at_index(input_buffer, 0) && (buffer_at_offset(input_buffer)[0] == '{')) { return parse_object(item, input_buffer); } return false; } /* Render a value to text.", "kind": "function", "line": 1427, "name": "print_value", "signature": "static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer)"}, {"doc": "return print_string(item, output_buffer); case cJSON_Array: return print_array(item, output_buffer); case cJSON_Object: return print_object(item, output_buffer); default: return false; } } /* Build an array from input text.", "kind": "function", "line": 1501, "name": "parse_array", "signature": "static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer)"}, {"doc": "input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an array to text", "kind": "function", "line": 1599, "name": "print_array", "signature": "static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer)"}, {"doc": "output_pointer = ensure(output_buffer, 2); if (output_pointer == NULL) { return false; } output_pointer++ = ']'; output_pointer = '\\0'; output_buffer->depth--; return true; } /* Build an object from the text.", "kind": "function", "line": 1661, "name": "parse_object", "signature": "static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer)"}, {"doc": "input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an object to text.", "kind": "function", "line": 1780, "name": "print_object", "signature": "static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer)"}, {"kind": "function", "line": 1916, "name": "get_array_item", "signature": "static cJSON* get_array_item(const cJSON *array, size_t index)"}, {"kind": "function", "line": 1935, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_GetArrayItem(const cJSON *array, int index)"}, {"kind": "function", "line": 1945, "name": "get_object_item", "signature": "static cJSON *get_object_item(const cJSON * const object, const char * const name, const cJSON_bo..."}, {"kind": "function", "line": 1977, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_GetObjectItem(const cJSON * const object, const char * const string)"}, {"kind": "function", "line": 1982, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * c..."}, {"kind": "function", "line": 1987, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string)"}, {"doc": "return get_object_item(object, string, false); } CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * const string) { return get_object_item(object, string, true); } CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string) { return cJSON_GetObjectItem(object, string) ? 1 : 0; } /* Utility for array list handling.", "kind": "function", "line": 1993, "name": "suffix_object", "signature": "static void suffix_object(cJSON *prev, cJSON *item)"}, {"doc": "CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string) { return cJSON_GetObjectItem(object, string) ? 1 : 0; } /* Utility for array list handling. static void suffix_object(cJSON *prev, cJSON *item) { prev->next = item; item->prev = prev; } /* Utility for handling references.", "kind": "function", "line": 2000, "name": "create_reference", "signature": "static cJSON *create_reference(const cJSON *item, const internal_hooks * const hooks)"}, {"kind": "function", "line": 2021, "name": "add_item_to_array", "signature": "static cJSON_bool add_item_to_array(cJSON *array, cJSON *item)"}, {"doc": "/* Add item to array/object. CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToArray(cJSON *array, cJSON *item) { return add_item_to_array(array, item); } #if defined(__clang__) || (defined(__GNUC__) && ((__GNUC__ > 4) || ((__GNUC__ == 4) && (__GNUC__-MINOR__ > 5)))) #pragma GCC diagnostic push #endif #ifdef __GNUC__ #pragma GCC diagnostic ignored \"-Wcast-qual\" #endif /* helper function to cast away const", "kind": "function", "line": 2066, "name": "cast_away_const", "signature": "static void* cast_away_const(const void* string)"}, {"kind": "function", "line": 2075, "name": "add_item_to_object", "signature": "static cJSON_bool add_item_to_object(cJSON * const object, const char * const string, cJSON * con..."}, {"kind": "function", "line": 2112, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToObject(cJSON *object, const char *string, cJSON *item)"}, {"kind": "function", "line": 2123, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToArray(cJSON *array, cJSON *item)"}, {"kind": "function", "line": 2133, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToObject(cJSON *object, const char *string, cJSON ..."}, {"kind": "function", "line": 2143, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddNullToObject(cJSON * const object, const char * const name)"}, {"kind": "function", "line": 2155, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddTrueToObject(cJSON * const object, const char * const name)"}, {"kind": "function", "line": 2167, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddFalseToObject(cJSON * const object, const char * const name)"}, {"kind": "function", "line": 2179, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddBoolToObject(cJSON * const object, const char * const name, const c..."}, {"kind": "function", "line": 2191, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddNumberToObject(cJSON * const object, const char * const name, const..."}, {"kind": "function", "line": 2203, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddStringToObject(cJSON * const object, const char * const name, const..."}, {"kind": "function", "line": 2215, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddRawToObject(cJSON * const object, const char * const name, const ch..."}, {"kind": "function", "line": 2227, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddObjectToObject(cJSON * const object, const char * const name)"}, {"kind": "function", "line": 2239, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON*) cJSON_AddArrayToObject(cJSON * const object, const char * const name)"}, {"kind": "function", "line": 2251, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_DetachItemViaPointer(cJSON *parent, cJSON * const item)"}, {"kind": "function", "line": 2287, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromArray(cJSON *array, int which)"}, {"kind": "function", "line": 2297, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_DeleteItemFromArray(cJSON *array, int which)"}, {"kind": "function", "line": 2302, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObject(cJSON *object, const char *string)"}, {"kind": "function", "line": 2309, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObjectCaseSensitive(cJSON *object, const char *string)"}, {"kind": "function", "line": 2316, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_DeleteItemFromObject(cJSON *object, const char *string)"}, {"kind": "function", "line": 2321, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_DeleteItemFromObjectCaseSensitive(cJSON *object, const char *string)"}, {"kind": "function", "line": 2363, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemViaPointer(cJSON * const parent, cJSON * const item, cJ..."}, {"kind": "function", "line": 2413, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInArray(cJSON *array, int which, cJSON *newitem)"}, {"kind": "function", "line": 2423, "name": "replace_item_in_object", "signature": "static cJSON_bool replace_item_in_object(cJSON *object, const char *string, cJSON *replacement, c..."}, {"kind": "function", "line": 2446, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObject(cJSON *object, const char *string, cJSON *newi..."}, {"kind": "function", "line": 2451, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObjectCaseSensitive(cJSON *object, const char *string..."}, {"kind": "function", "line": 2468, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateTrue(void)"}, {"kind": "function", "line": 2479, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateFalse(void)"}, {"kind": "function", "line": 2490, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateBool(cJSON_bool boolean)"}, {"kind": "function", "line": 2501, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateNumber(double num)"}, {"kind": "function", "line": 2526, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateString(const char *string)"}, {"kind": "function", "line": 2543, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateStringReference(const char *string)"}, {"kind": "function", "line": 2555, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateObjectReference(const cJSON *child)"}, {"kind": "function", "line": 2567, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateArrayReference(const cJSON *child)"}, {"kind": "function", "line": 2579, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateRaw(const char *raw)"}, {"kind": "function", "line": 2596, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateArray(void)"}, {"kind": "function", "line": 2607, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateObject(void)"}, {"kind": "function", "line": 2659, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateFloatArray(const float *numbers, int count)"}, {"kind": "function", "line": 2699, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateDoubleArray(const double *numbers, int count)"}, {"kind": "function", "line": 2739, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON *) cJSON_CreateStringArray(const char *const *strings, int count)"}, {"kind": "function", "line": 2786, "name": "cJSON_Duplicate_rec", "signature": "cJSON * cJSON_Duplicate_rec(const cJSON *item, size_t depth, cJSON_bool recurse)"}, {"kind": "function", "line": 2873, "name": "skip_oneline_comment", "signature": "static void skip_oneline_comment(char **input)"}, {"kind": "function", "line": 2886, "name": "skip_multiline_comment", "signature": "static void skip_multiline_comment(char **input)"}, {"kind": "function", "line": 2900, "name": "minify_string", "signature": "static void minify_string(char **input, char **output)"}, {"kind": "function", "line": 2922, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_Minify(char *json)"}, {"kind": "function", "line": 2972, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsInvalid(const cJSON * const item)"}, {"kind": "function", "line": 2982, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsFalse(const cJSON * const item)"}, {"kind": "function", "line": 2992, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsTrue(const cJSON * const item)"}, {"kind": "function", "line": 3002, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsBool(const cJSON * const item)"}, {"kind": "function", "line": 3012, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsNull(const cJSON * const item)"}, {"kind": "function", "line": 3022, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsNumber(const cJSON * const item)"}, {"kind": "function", "line": 3032, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsString(const cJSON * const item)"}, {"kind": "function", "line": 3042, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsArray(const cJSON * const item)"}, {"kind": "function", "line": 3052, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsObject(const cJSON * const item)"}, {"kind": "function", "line": 3062, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_IsRaw(const cJSON * const item)"}, {"kind": "function", "line": 3072, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_..."}, {"kind": "function", "line": 3157, "name": "cJSON_ArrayForEach", "signature": "cJSON_ArrayForEach(a_element, a)"}, {"doc": "doing this twice, once on a and b to prevent true comparison if a subset of b * TODO: Do this the proper way, this is just a fix for now", "kind": "function", "line": 3173, "name": "cJSON_ArrayForEach", "signature": "cJSON_ArrayForEach(b_element, b)"}, {"kind": "function", "line": 3194, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void *) cJSON_malloc(size_t size)"}, {"kind": "function", "line": 3199, "name": "CJSON_PUBLIC", "signature": "CJSON_PUBLIC(void) cJSON_free(void *object)"}, {"kind": "macro", "line": 28, "name": "_CRT_SECURE_NO_DEPRECATE", "signature": "#define _CRT_SECURE_NO_DEPRECATE"}, {"kind": "macro", "line": 65, "name": "true", "signature": "#define true"}, {"kind": "macro", "line": 70, "name": "false", "signature": "#define false"}, {"kind": "macro", "line": 74, "name": "isinf", "signature": "#define isinf(d)"}, {"kind": "macro", "line": 77, "name": "isnan", "signature": "#define isnan(d)"}, {"kind": "macro", "line": 82, "name": "NAN", "signature": "#define NAN"}, {"kind": "macro", "line": 84, "name": "NAN", "signature": "#define NAN"}, {"kind": "macro", "line": 179, "name": "internal_malloc", "signature": "#define internal_malloc"}, {"kind": "macro", "line": 180, "name": "internal_free", "signature": "#define internal_free"}, {"kind": "macro", "line": 181, "name": "internal_realloc", "signature": "#define internal_realloc"}, {"kind": "macro", "line": 185, "name": "static_strlen", "signature": "#define static_strlen(string_literal)"}, {"kind": "macro", "line": 301, "name": "can_read", "signature": "#define can_read(buffer, size)"}, {"kind": "macro", "line": 303, "name": "can_access_at_index", "signature": "#define can_access_at_index(buffer, index)"}, {"kind": "macro", "line": 304, "name": "cannot_access_at_index", "signature": "#define cannot_access_at_index(buffer, index)"}, {"kind": "macro", "line": 306, "name": "buffer_at_offset", "signature": "#define buffer_at_offset(buffer)"}, {"kind": "macro", "line": 1241, "name": "cjson_min", "signature": "#define cjson_min(a, b)"}]}, {"id": "cJSON.h", "kind": "module", "label": "cJSON.h", "language": "h", "sha256": "b660b400b8461ea8", "symbol_count": 37, "symbols": [{"doc": "#define cJSON_Invalid (0) #define cJSON_False (1 << 0) #define cJSON_True (1 << 1) #define cJSON_NULL (1 << 2) #define cJSON_Number (1 << 3) #define cJSON_String (1 << 4) #define cJSON_Array (1 << 5) #define cJSON_Object (1 << 6) #define cJSON_Raw (1 << 7) /* raw json #define cJSON_IsReference 256 #define cJSON_StringIsConst 512 /* The cJSON structure:", "kind": "struct", "line": 92, "name": "cJSON"}, {"kind": "struct", "line": 114, "name": "cJSON_Hooks"}, {"kind": "type_alias", "line": 120, "name": "cJSON_bool", "signature": "typedef int cJSON_bool;"}, {"kind": "function", "line": 249, "name": "sensitive", "signature": "* case_sensitive determines if object keys are treated case sensitive (1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo"}, {"doc": "ifdef __cplusplus", "kind": "variable", "line": 27, "name": "next", "signature": "extern \"C\" { #endif #if !defined(__WINDOWS__) && (defined(WIN32) || defined(WIN64) || defined(_MSC_VER) || defined(_WIN32)) #define __WINDOWS__ #endif #ifdef __WINDOWS__ /* When compiling for windows,"}, {"kind": "macro", "line": 24, "name": "cJSON__h", "signature": "#define cJSON__h"}, {"kind": "macro", "line": 32, "name": "__WINDOWS__", "signature": "#define __WINDOWS__"}, {"kind": "macro", "line": 44, "name": "CJSON_CDECL", "signature": "#define CJSON_CDECL"}, {"kind": "macro", "line": 45, "name": "CJSON_STDCALL", "signature": "#define CJSON_STDCALL"}, {"kind": "macro", "line": 49, "name": "CJSON_EXPORT_SYMBOLS", "signature": "#define CJSON_EXPORT_SYMBOLS"}, {"kind": "macro", "line": 53, "name": "CJSON_PUBLIC", "signature": "#define CJSON_PUBLIC(type)"}, {"kind": "macro", "line": 55, "name": "CJSON_PUBLIC", "signature": "#define CJSON_PUBLIC(type)"}, {"kind": "macro", "line": 57, "name": "CJSON_PUBLIC", "signature": "#define CJSON_PUBLIC(type)"}, {"kind": "macro", "line": 60, "name": "CJSON_CDECL", "signature": "#define CJSON_CDECL"}, {"kind": "macro", "line": 61, "name": "CJSON_STDCALL", "signature": "#define CJSON_STDCALL"}, {"kind": "macro", "line": 64, "name": "CJSON_PUBLIC", "signature": "#define CJSON_PUBLIC(type)"}, {"kind": "macro", "line": 66, "name": "CJSON_PUBLIC", "signature": "#define CJSON_PUBLIC(type)"}, {"kind": "macro", "line": 71, "name": "CJSON_VERSION_MAJOR", "signature": "#define CJSON_VERSION_MAJOR"}, {"kind": "macro", "line": 72, "name": "CJSON_VERSION_MINOR", "signature": "#define CJSON_VERSION_MINOR"}, {"kind": "macro", "line": 73, "name": "CJSON_VERSION_PATCH", "signature": "#define CJSON_VERSION_PATCH"}, {"kind": "macro", "line": 78, "name": "cJSON_Invalid", "signature": "#define cJSON_Invalid"}, {"kind": "macro", "line": 79, "name": "cJSON_False", "signature": "#define cJSON_False"}, {"kind": "macro", "line": 80, "name": "cJSON_True", "signature": "#define cJSON_True"}, {"kind": "macro", "line": 81, "name": "cJSON_NULL", "signature": "#define cJSON_NULL"}, {"kind": "macro", "line": 82, "name": "cJSON_Number", "signature": "#define cJSON_Number"}, {"kind": "macro", "line": 83, "name": "cJSON_String", "signature": "#define cJSON_String"}, {"kind": "macro", "line": 84, "name": "cJSON_Array", "signature": "#define cJSON_Array"}, {"kind": "macro", "line": 85, "name": "cJSON_Object", "signature": "#define cJSON_Object"}, {"kind": "macro", "line": 86, "name": "cJSON_Raw", "signature": "#define cJSON_Raw"}, {"kind": "macro", "line": 88, "name": "cJSON_IsReference", "signature": "#define cJSON_IsReference"}, {"kind": "macro", "line": 89, "name": "cJSON_StringIsConst", "signature": "#define cJSON_StringIsConst"}, {"kind": "macro", "line": 126, "name": "CJSON_NESTING_LIMIT", "signature": "#define CJSON_NESTING_LIMIT"}, {"kind": "macro", "line": 132, "name": "CJSON_CIRCULAR_LIMIT", "signature": "#define CJSON_CIRCULAR_LIMIT"}, {"kind": "macro", "line": 270, "name": "cJSON_SetIntValue", "signature": "#define cJSON_SetIntValue(object, number)"}, {"kind": "macro", "line": 273, "name": "cJSON_SetNumberValue", "signature": "#define cJSON_SetNumberValue(object, number)"}, {"kind": "macro", "line": 278, "name": "cJSON_SetBoolValue", "signature": "#define cJSON_SetBoolValue(object, boolValue)"}, {"kind": "macro", "line": 285, "name": "cJSON_ArrayForEach", "signature": "#define cJSON_ArrayForEach(element, array)"}]}, {"doc": "=== beacon-GEN v1.2 ===", "id": "gen_beacon.sh", "kind": "module", "label": "gen_beacon.sh", "language": "sh", "sha256": "edb3968c6d56a01d", "symbol_count": 3, "symbols": [{"doc": "=== FUNCIONES ===", "kind": "function", "line": 34, "name": "show_help"}, {"doc": "=== XOR STRING TO BYTES ===", "kind": "function", "line": 138, "name": "xor_string"}, {"kind": "function", "line": 5916, "name": "crc32"}]}, {"doc": "1. Generar DLL", "id": "gen_dll.sh", "kind": "module", "label": "gen_dll.sh", "language": "sh", "sha256": "141d825c9678889d", "symbol_count": 0, "symbols": []}, {"doc": "=== CONFIGURACIÓN POR DEFECTO ===", "id": "gen_dll_rev.sh", "kind": "module", "label": "gen_dll_rev.sh", "language": "sh", "sha256": "cac4b7ee93482f34", "symbol_count": 1, "symbols": [{"doc": "=== USO ===", "kind": "function", "line": 12, "name": "usage"}]}, {"doc": "=== CONFIGURACIÓN POR DEFECTO ===", "id": "gen_dll_ss.sh", "kind": "module", "label": "gen_dll_ss.sh", "language": "sh", "sha256": "8e2701eb6df73daa", "symbol_count": 1, "symbols": [{"doc": "=== USO ===", "kind": "function", "line": 10, "name": "usage"}]}, {"doc": "=== CONFIGURACIÓN POR DEFECTO ===", "id": "gen_key.sh", "kind": "module", "label": "gen_key.sh", "language": "sh", "sha256": "ad30fa886634b88b", "symbol_count": 1, "symbols": [{"doc": "=== USO ===", "kind": "function", "line": 10, "name": "usage"}]}, {"doc": "=== gen_cmd_dll.sh v1.0 === Genera DLL y shellcode ofuscado para ejecutar un comando Uso: ./gen_cmd_dll.sh --cmd \"powershell...\" [--key 0x33] [--output payload]", "id": "gen_module.sh", "kind": "module", "label": "gen_module.sh", "language": "sh", "sha256": "5100dba85d246ece", "symbol_count": 2, "symbols": [{"doc": "=== FUNCIONES ===", "kind": "function", "line": 18, "name": "show_help"}, {"doc": "Función para ofuscar binario con XOR y convertir a \\x..", "kind": "function", "line": 35, "name": "xor_obfuscate"}]}, {"doc": "BOF Bindings Generator for Cobalt Strike Author: Gris Iscomeback Email: grisiscomeback@gmail.com Creation Date: 13/08/2024 License: GPL v3 Generates: - COFFLoader3.c: full COFF loader with DJB2 hash table - bof_test.c: ready-to-compile BOF with all imports and example", "id": "generate_hashs.py", "kind": "module", "label": "generate_hashs.py", "language": "py", "sha256": "023ebad2d7b8e8cd", "symbol_count": 4, "symbols": [{"kind": "function", "line": 23, "name": "djb2", "signature": "def djb2(s)"}, {"kind": "function", "line": 223, "name": "generate_coff_loader", "signature": "def generate_coff_loader()"}, {"kind": "function", "line": 491, "name": "generate_bof_test", "signature": "def generate_bof_test()"}, {"kind": "function", "line": 553, "name": "main", "signature": "def main()"}]}, {"id": "install.sh", "kind": "module", "label": "install.sh", "language": "sh", "sha256": "c907d80fd6734993", "symbol_count": 0, "symbols": []}], "type": "CodePropertyGraph", "version": "1.0"} +``` + +--- + +## Architecture Reference + +### C (23 files) + +#### `COFFLoader3.c` +**Path:** `COFFLoader3.c` + +**Functions:** +- `djb2_hash` (line 632) `static uint32_t djb2_hash(const char* str)` - *=== Función hash DJB2 ===* +- `create_trampoline` (line 913) `static void* create_trampoline(void* target)` +- `handle_relocation` (line 940) `BOOL handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ...` +- `get_symbol_name` (line 1080) `static char* get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size)` +- `__attribute__` (line 1103) `__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2)` +- `RunCOFF` (line 1112) `int RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*...` - *=== Cargador COFF ===* + +**Macros:** +- `IMAGE_REL_AMD64_ABSOLUTE` (line 568) `#define IMAGE_REL_AMD64_ABSOLUTE` +- `IMAGE_REL_AMD64_ADDR64` (line 569) `#define IMAGE_REL_AMD64_ADDR64` +- `IMAGE_REL_AMD64_ADDR32` (line 570) `#define IMAGE_REL_AMD64_ADDR32` +- `IMAGE_REL_AMD64_ADDR32NB` (line 571) `#define IMAGE_REL_AMD64_ADDR32NB` +- `IMAGE_REL_AMD64_REL32` (line 572) `#define IMAGE_REL_AMD64_REL32` +- `IMAGE_REL_AMD64_REL32_1` (line 573) `#define IMAGE_REL_AMD64_REL32_1` +- `IMAGE_REL_AMD64_REL32_2` (line 574) `#define IMAGE_REL_AMD64_REL32_2` +- `IMAGE_REL_AMD64_REL32_3` (line 575) `#define IMAGE_REL_AMD64_REL32_3` +- `IMAGE_REL_AMD64_REL32_4` (line 576) `#define IMAGE_REL_AMD64_REL32_4` +- `IMAGE_REL_AMD64_REL32_5` (line 577) `#define IMAGE_REL_AMD64_REL32_5` +- `IMAGE_REL_AMD64_SECTION` (line 578) `#define IMAGE_REL_AMD64_SECTION` +- `IMAGE_REL_AMD64_SECREL` (line 579) `#define IMAGE_REL_AMD64_SECREL` +- `IMAGE_REL_AMD64_SECREL7` (line 580) `#define IMAGE_REL_AMD64_SECREL7` +- `IMAGE_REL_AMD64_TOKEN` (line 581) `#define IMAGE_REL_AMD64_TOKEN` +- `IMAGE_REL_AMD64_SREL32` (line 582) `#define IMAGE_REL_AMD64_SREL32` +- `IMAGE_REL_AMD64_PAIR` (line 583) `#define IMAGE_REL_AMD64_PAIR` +- `IMAGE_REL_AMD64_SSPAN32` (line 584) `#define IMAGE_REL_AMD64_SSPAN32` + +**Structs:** +- `COFFSection` (line 586) +- `COFFRelocation` (line 599) +- `COFFHeader` (line 620) +- `SymbolHash` (line 642) - *=== Tabla de símbolos por hash ===* + +**Variables:** +- `__imp_BeaconPrintf` (line 332) `extern PVOID __imp_BeaconPrintf;` +- `__imp_BeaconOutput` (line 333) `extern PVOID __imp_BeaconOutput;` +- `__imp_BeaconDataParse` (line 334) `extern PVOID __imp_BeaconDataParse;` +- `__imp_BeaconDataInt` (line 335) `extern PVOID __imp_BeaconDataInt;` +- `__imp_BeaconDataShort` (line 336) `extern PVOID __imp_BeaconDataShort;` +- `__imp_BeaconDataExtract` (line 337) `extern PVOID __imp_BeaconDataExtract;` +- `__imp_LoadLibraryA` (line 338) `extern PVOID __imp_LoadLibraryA;` +- `__imp_LoadLibraryW` (line 339) `extern PVOID __imp_LoadLibraryW;` +- `__imp_GetModuleHandleA` (line 340) `extern PVOID __imp_GetModuleHandleA;` +- `__imp_GetModuleHandleW` (line 341) `extern PVOID __imp_GetModuleHandleW;` +- `__imp_GetProcAddress` (line 342) `extern PVOID __imp_GetProcAddress;` +- `__imp_GetLastError` (line 343) `extern PVOID __imp_GetLastError;` +- `__imp_CloseHandle` (line 344) `extern PVOID __imp_CloseHandle;` +- `__imp_ExitProcess` (line 345) `extern PVOID __imp_ExitProcess;` +- `__imp_ExitThread` (line 346) `extern PVOID __imp_ExitThread;` +- `__imp_Sleep` (line 347) `extern PVOID __imp_Sleep;` +- `__imp_CreateThread` (line 348) `extern PVOID __imp_CreateThread;` +- `__imp_GetCurrentProcess` (line 349) `extern PVOID __imp_GetCurrentProcess;` +- `__imp_GetCurrentProcessId` (line 350) `extern PVOID __imp_GetCurrentProcessId;` +- `__imp_GetCurrentThreadId` (line 351) `extern PVOID __imp_GetCurrentThreadId;` +- `__imp_GetTickCount` (line 352) `extern PVOID __imp_GetTickCount;` +- `__imp_GetTickCount64` (line 353) `extern PVOID __imp_GetTickCount64;` +- `__imp_CreateFileA` (line 354) `extern PVOID __imp_CreateFileA;` +- `__imp_CreateFileW` (line 355) `extern PVOID __imp_CreateFileW;` +- `__imp_ReadFile` (line 356) `extern PVOID __imp_ReadFile;` +- `__imp_WriteFile` (line 357) `extern PVOID __imp_WriteFile;` +- `__imp_SetFilePointer` (line 358) `extern PVOID __imp_SetFilePointer;` +- `__imp_SetEndOfFile` (line 359) `extern PVOID __imp_SetEndOfFile;` +- `__imp_DeleteFileA` (line 360) `extern PVOID __imp_DeleteFileA;` +- `__imp_DeleteFileW` (line 361) `extern PVOID __imp_DeleteFileW;` +- `__imp_MoveFileA` (line 362) `extern PVOID __imp_MoveFileA;` +- `__imp_MoveFileW` (line 363) `extern PVOID __imp_MoveFileW;` +- `__imp_CopyFileA` (line 364) `extern PVOID __imp_CopyFileA;` +- `__imp_CopyFileW` (line 365) `extern PVOID __imp_CopyFileW;` +- `__imp_GetFileSize` (line 366) `extern PVOID __imp_GetFileSize;` +- `__imp_GetFileSizeEx` (line 367) `extern PVOID __imp_GetFileSizeEx;` +- `__imp_CreateDirectoryA` (line 368) `extern PVOID __imp_CreateDirectoryA;` +- `__imp_CreateDirectoryW` (line 369) `extern PVOID __imp_CreateDirectoryW;` +- `__imp_RemoveDirectoryA` (line 370) `extern PVOID __imp_RemoveDirectoryA;` +- `__imp_RemoveDirectoryW` (line 371) `extern PVOID __imp_RemoveDirectoryW;` +- `__imp_FindFirstFileA` (line 372) `extern PVOID __imp_FindFirstFileA;` +- `__imp_FindFirstFileW` (line 373) `extern PVOID __imp_FindFirstFileW;` +- `__imp_FindNextFileA` (line 374) `extern PVOID __imp_FindNextFileA;` +- `__imp_FindNextFileW` (line 375) `extern PVOID __imp_FindNextFileW;` +- `__imp_FindClose` (line 376) `extern PVOID __imp_FindClose;` +- `__imp_GetFileAttributesA` (line 377) `extern PVOID __imp_GetFileAttributesA;` +- `__imp_GetFileAttributesW` (line 378) `extern PVOID __imp_GetFileAttributesW;` +- `__imp_SetFileAttributesA` (line 379) `extern PVOID __imp_SetFileAttributesA;` +- `__imp_SetFileAttributesW` (line 380) `extern PVOID __imp_SetFileAttributesW;` +- `__imp_GetSystemDirectoryA` (line 381) `extern PVOID __imp_GetSystemDirectoryA;` +- `__imp_GetSystemDirectoryW` (line 382) `extern PVOID __imp_GetSystemDirectoryW;` +- `__imp_GetWindowsDirectoryA` (line 383) `extern PVOID __imp_GetWindowsDirectoryA;` +- `__imp_GetWindowsDirectoryW` (line 384) `extern PVOID __imp_GetWindowsDirectoryW;` +- `__imp_GetTempPathA` (line 385) `extern PVOID __imp_GetTempPathA;` +- `__imp_GetTempPathW` (line 386) `extern PVOID __imp_GetTempPathW;` +- `__imp_GetComputerNameA` (line 387) `extern PVOID __imp_GetComputerNameA;` +- `__imp_GetComputerNameW` (line 388) `extern PVOID __imp_GetComputerNameW;` +- `__imp_GetUserNameA` (line 389) `extern PVOID __imp_GetUserNameA;` +- `__imp_GetUserNameW` (line 390) `extern PVOID __imp_GetUserNameW;` +- `__imp_GetVersionExA` (line 391) `extern PVOID __imp_GetVersionExA;` +- `__imp_GetVersionExW` (line 392) `extern PVOID __imp_GetVersionExW;` +- `__imp_GetNativeSystemInfo` (line 393) `extern PVOID __imp_GetNativeSystemInfo;` +- `__imp_VirtualAlloc` (line 394) `extern PVOID __imp_VirtualAlloc;` +- `__imp_VirtualFree` (line 395) `extern PVOID __imp_VirtualFree;` +- `__imp_VirtualProtect` (line 396) `extern PVOID __imp_VirtualProtect;` +- `__imp_VirtualQuery` (line 397) `extern PVOID __imp_VirtualQuery;` +- `__imp_HeapAlloc` (line 398) `extern PVOID __imp_HeapAlloc;` +- `__imp_HeapFree` (line 399) `extern PVOID __imp_HeapFree;` +- `__imp_LocalAlloc` (line 400) `extern PVOID __imp_LocalAlloc;` +- `__imp_LocalFree` (line 401) `extern PVOID __imp_LocalFree;` +- `__imp_GlobalAlloc` (line 402) `extern PVOID __imp_GlobalAlloc;` +- `__imp_GlobalFree` (line 403) `extern PVOID __imp_GlobalFree;` +- `__imp_RtlMoveMemory` (line 404) `extern PVOID __imp_RtlMoveMemory;` +- `__imp_RtlCopyMemory` (line 405) `extern PVOID __imp_RtlCopyMemory;` +- `__imp_RtlFillMemory` (line 406) `extern PVOID __imp_RtlFillMemory;` +- `__imp_RtlZeroMemory` (line 407) `extern PVOID __imp_RtlZeroMemory;` +- `__imp_lstrlenA` (line 408) `extern PVOID __imp_lstrlenA;` +- `__imp_lstrlenW` (line 409) `extern PVOID __imp_lstrlenW;` +- `__imp_lstrcpyA` (line 410) `extern PVOID __imp_lstrcpyA;` +- `__imp_lstrcpyW` (line 411) `extern PVOID __imp_lstrcpyW;` +- `__imp_lstrcatA` (line 412) `extern PVOID __imp_lstrcatA;` +- `__imp_lstrcatW` (line 413) `extern PVOID __imp_lstrcatW;` +- `__imp_lstrcmpA` (line 414) `extern PVOID __imp_lstrcmpA;` +- `__imp_lstrcmpW` (line 415) `extern PVOID __imp_lstrcmpW;` +- `__imp_lstrcmpiA` (line 416) `extern PVOID __imp_lstrcmpiA;` +- `__imp_lstrcmpiW` (line 417) `extern PVOID __imp_lstrcmpiW;` +- `__imp_MultiByteToWideChar` (line 418) `extern PVOID __imp_MultiByteToWideChar;` +- `__imp_WideCharToMultiByte` (line 419) `extern PVOID __imp_WideCharToMultiByte;` +- `__imp_FormatMessageA` (line 420) `extern PVOID __imp_FormatMessageA;` +- `__imp_FormatMessageW` (line 421) `extern PVOID __imp_FormatMessageW;` +- `__imp_GetEnvironmentVariableA` (line 422) `extern PVOID __imp_GetEnvironmentVariableA;` +- `__imp_GetEnvironmentVariableW` (line 423) `extern PVOID __imp_GetEnvironmentVariableW;` +- `__imp_SetEnvironmentVariableA` (line 424) `extern PVOID __imp_SetEnvironmentVariableA;` +- `__imp_SetEnvironmentVariableW` (line 425) `extern PVOID __imp_SetEnvironmentVariableW;` +- `__imp_ExpandEnvironmentStringsA` (line 426) `extern PVOID __imp_ExpandEnvironmentStringsA;` +- `__imp_ExpandEnvironmentStringsW` (line 427) `extern PVOID __imp_ExpandEnvironmentStringsW;` +- `__imp_GetCommandLineA` (line 428) `extern PVOID __imp_GetCommandLineA;` +- `__imp_GetCommandLineW` (line 429) `extern PVOID __imp_GetCommandLineW;` +- `__imp_GetModuleFileNameA` (line 430) `extern PVOID __imp_GetModuleFileNameA;` +- `__imp_GetModuleFileNameW` (line 431) `extern PVOID __imp_GetModuleFileNameW;` +- `__imp_GetStartupInfoA` (line 432) `extern PVOID __imp_GetStartupInfoA;` +- `__imp_GetStartupInfoW` (line 433) `extern PVOID __imp_GetStartupInfoW;` +- `__imp_FreeLibrary` (line 434) `extern PVOID __imp_FreeLibrary;` +- `__imp_GetConsoleWindow` (line 435) `extern PVOID __imp_GetConsoleWindow;` +- `__imp_AllocConsole` (line 436) `extern PVOID __imp_AllocConsole;` +- `__imp_FreeConsole` (line 437) `extern PVOID __imp_FreeConsole;` +- `__imp_AttachConsole` (line 438) `extern PVOID __imp_AttachConsole;` +- `__imp_IsDebuggerPresent` (line 439) `extern PVOID __imp_IsDebuggerPresent;` +- `__imp_CheckRemoteDebuggerPresent` (line 440) `extern PVOID __imp_CheckRemoteDebuggerPresent;` +- `__imp_OutputDebugStringA` (line 441) `extern PVOID __imp_OutputDebugStringA;` +- `__imp_OutputDebugStringW` (line 442) `extern PVOID __imp_OutputDebugStringW;` +- `__imp_OpenProcess` (line 443) `extern PVOID __imp_OpenProcess;` +- `__imp_OpenProcessToken` (line 444) `extern PVOID __imp_OpenProcessToken;` +- `__imp_DuplicateTokenEx` (line 445) `extern PVOID __imp_DuplicateTokenEx;` +- `__imp_ImpersonateLoggedOnUser` (line 446) `extern PVOID __imp_ImpersonateLoggedOnUser;` +- `__imp_RevertToSelf` (line 447) `extern PVOID __imp_RevertToSelf;` +- `__imp_LookupPrivilegeValueA` (line 448) `extern PVOID __imp_LookupPrivilegeValueA;` +- `__imp_LookupPrivilegeValueW` (line 449) `extern PVOID __imp_LookupPrivilegeValueW;` +- `__imp_AdjustTokenPrivileges` (line 450) `extern PVOID __imp_AdjustTokenPrivileges;` +- `__imp_CreateProcessAsUserA` (line 451) `extern PVOID __imp_CreateProcessAsUserA;` +- `__imp_CreateProcessAsUserW` (line 452) `extern PVOID __imp_CreateProcessAsUserW;` +- `__imp_RegOpenKeyExA` (line 453) `extern PVOID __imp_RegOpenKeyExA;` +- `__imp_RegOpenKeyExW` (line 454) `extern PVOID __imp_RegOpenKeyExW;` +- `__imp_RegCreateKeyExA` (line 455) `extern PVOID __imp_RegCreateKeyExA;` +- `__imp_RegCreateKeyExW` (line 456) `extern PVOID __imp_RegCreateKeyExW;` +- `__imp_RegSetValueExA` (line 457) `extern PVOID __imp_RegSetValueExA;` +- `__imp_RegSetValueExW` (line 458) `extern PVOID __imp_RegSetValueExW;` +- `__imp_RegQueryValueExA` (line 459) `extern PVOID __imp_RegQueryValueExA;` +- `__imp_RegQueryValueExW` (line 460) `extern PVOID __imp_RegQueryValueExW;` +- `__imp_RegDeleteValueA` (line 461) `extern PVOID __imp_RegDeleteValueA;` +- `__imp_RegDeleteValueW` (line 462) `extern PVOID __imp_RegDeleteValueW;` +- `__imp_RegCloseKey` (line 463) `extern PVOID __imp_RegCloseKey;` +- `__imp_RegEnumKeyExA` (line 464) `extern PVOID __imp_RegEnumKeyExA;` +- `__imp_RegEnumKeyExW` (line 465) `extern PVOID __imp_RegEnumKeyExW;` +- `__imp_RegEnumValueA` (line 466) `extern PVOID __imp_RegEnumValueA;` +- `__imp_RegEnumValueW` (line 467) `extern PVOID __imp_RegEnumValueW;` +- `__imp_CryptAcquireContextA` (line 468) `extern PVOID __imp_CryptAcquireContextA;` +- `__imp_CryptAcquireContextW` (line 469) `extern PVOID __imp_CryptAcquireContextW;` +- `__imp_CryptCreateHash` (line 470) `extern PVOID __imp_CryptCreateHash;` +- `__imp_CryptHashData` (line 471) `extern PVOID __imp_CryptHashData;` +- `__imp_CryptDeriveKey` (line 472) `extern PVOID __imp_CryptDeriveKey;` +- `__imp_CryptEncrypt` (line 473) `extern PVOID __imp_CryptEncrypt;` +- `__imp_CryptDecrypt` (line 474) `extern PVOID __imp_CryptDecrypt;` +- `__imp_CryptReleaseContext` (line 475) `extern PVOID __imp_CryptReleaseContext;` +- `__imp_CryptDestroyHash` (line 476) `extern PVOID __imp_CryptDestroyHash;` +- `__imp_CryptDestroyKey` (line 477) `extern PVOID __imp_CryptDestroyKey;` +- `__imp_CryptGenRandom` (line 478) `extern PVOID __imp_CryptGenRandom;` +- `__imp_CoInitializeEx` (line 479) `extern PVOID __imp_CoInitializeEx;` +- `__imp_CoUninitialize` (line 480) `extern PVOID __imp_CoUninitialize;` +- `__imp_CoCreateInstance` (line 481) `extern PVOID __imp_CoCreateInstance;` +- `__imp_CoTaskMemFree` (line 482) `extern PVOID __imp_CoTaskMemFree;` +- `__imp_IIDFromString` (line 483) `extern PVOID __imp_IIDFromString;` +- `__imp_StringFromGUID2` (line 484) `extern PVOID __imp_StringFromGUID2;` +- `__imp_VariantInit` (line 485) `extern PVOID __imp_VariantInit;` +- `__imp_VariantClear` (line 486) `extern PVOID __imp_VariantClear;` +- `__imp_VariantChangeType` (line 487) `extern PVOID __imp_VariantChangeType;` +- `__imp_SysAllocString` (line 488) `extern PVOID __imp_SysAllocString;` +- `__imp_SysFreeString` (line 489) `extern PVOID __imp_SysFreeString;` +- `__imp_SysStringLen` (line 490) `extern PVOID __imp_SysStringLen;` +- `__imp_SHGetFolderPathA` (line 491) `extern PVOID __imp_SHGetFolderPathA;` +- `__imp_SHGetFolderPathW` (line 492) `extern PVOID __imp_SHGetFolderPathW;` +- `__imp_SHGetKnownFolderPath` (line 493) `extern PVOID __imp_SHGetKnownFolderPath;` +- `__imp_PathFileExistsA` (line 494) `extern PVOID __imp_PathFileExistsA;` +- `__imp_PathFileExistsW` (line 495) `extern PVOID __imp_PathFileExistsW;` +- `__imp_PathCombineA` (line 496) `extern PVOID __imp_PathCombineA;` +- `__imp_PathCombineW` (line 497) `extern PVOID __imp_PathCombineW;` +- `__imp_GetDesktopWindow` (line 498) `extern PVOID __imp_GetDesktopWindow;` +- `__imp_GetShellWindow` (line 499) `extern PVOID __imp_GetShellWindow;` +- `__imp_FindWindowA` (line 500) `extern PVOID __imp_FindWindowA;` +- `__imp_FindWindowW` (line 501) `extern PVOID __imp_FindWindowW;` +- `__imp_EnumWindows` (line 502) `extern PVOID __imp_EnumWindows;` +- `__imp_GetWindowTextA` (line 503) `extern PVOID __imp_GetWindowTextA;` +- `__imp_GetWindowTextW` (line 504) `extern PVOID __imp_GetWindowTextW;` +- `__imp_GetClassNameA` (line 505) `extern PVOID __imp_GetClassNameA;` +- `__imp_GetClassNameW` (line 506) `extern PVOID __imp_GetClassNameW;` +- `__imp_SendMessageA` (line 507) `extern PVOID __imp_SendMessageA;` +- `__imp_SendMessageW` (line 508) `extern PVOID __imp_SendMessageW;` +- `__imp_EnumProcesses` (line 509) `extern PVOID __imp_EnumProcesses;` +- `__imp_EnumProcessModules` (line 510) `extern PVOID __imp_EnumProcessModules;` +- `__imp_GetModuleBaseNameA` (line 511) `extern PVOID __imp_GetModuleBaseNameA;` +- `__imp_GetModuleBaseNameW` (line 512) `extern PVOID __imp_GetModuleBaseNameW;` +- `__imp_GetModuleInformation` (line 513) `extern PVOID __imp_GetModuleInformation;` +- `__imp_WSASocketA` (line 514) `extern PVOID __imp_WSASocketA;` +- `__imp_WSASocketW` (line 515) `extern PVOID __imp_WSASocketW;` +- `__imp_WSAStartup` (line 516) `extern PVOID __imp_WSAStartup;` +- `__imp_WSACleanup` (line 517) `extern PVOID __imp_WSACleanup;` +- `__imp_bind` (line 518) `extern PVOID __imp_bind;` +- `__imp_listen` (line 519) `extern PVOID __imp_listen;` +- `__imp_accept` (line 520) `extern PVOID __imp_accept;` +- `__imp_connect` (line 521) `extern PVOID __imp_connect;` +- `__imp_send` (line 522) `extern PVOID __imp_send;` +- `__imp_recv` (line 523) `extern PVOID __imp_recv;` +- `__imp_closesocket` (line 524) `extern PVOID __imp_closesocket;` +- `__imp_ioctlsocket` (line 525) `extern PVOID __imp_ioctlsocket;` +- `__imp_gethostname` (line 526) `extern PVOID __imp_gethostname;` +- `__imp_gethostbyname` (line 527) `extern PVOID __imp_gethostbyname;` +- `__imp_getaddrinfo` (line 528) `extern PVOID __imp_getaddrinfo;` +- `__imp_freeaddrinfo` (line 529) `extern PVOID __imp_freeaddrinfo;` +- `__imp_htons` (line 530) `extern PVOID __imp_htons;` +- `__imp_ntohs` (line 531) `extern PVOID __imp_ntohs;` +- `__imp_htonl` (line 532) `extern PVOID __imp_htonl;` +- `__imp_ntohl` (line 533) `extern PVOID __imp_ntohl;` +- `__imp_NetUserEnum` (line 534) `extern PVOID __imp_NetUserEnum;` +- `__imp_NetLocalGroupEnum` (line 535) `extern PVOID __imp_NetLocalGroupEnum;` +- `__imp_NetShareEnum` (line 536) `extern PVOID __imp_NetShareEnum;` +- `__imp_NetWkstaUserEnum` (line 537) `extern PVOID __imp_NetWkstaUserEnum;` +- `__imp_NetSessionEnum` (line 538) `extern PVOID __imp_NetSessionEnum;` +- `__imp_NetApiBufferFree` (line 539) `extern PVOID __imp_NetApiBufferFree;` +- `__imp_WNetOpenEnumA` (line 540) `extern PVOID __imp_WNetOpenEnumA;` +- `__imp_WNetOpenEnumW` (line 541) `extern PVOID __imp_WNetOpenEnumW;` +- `__imp_WNetEnumResourceA` (line 542) `extern PVOID __imp_WNetEnumResourceA;` +- `__imp_WNetEnumResourceW` (line 543) `extern PVOID __imp_WNetEnumResourceW;` +- `__imp_WNetCloseEnum` (line 544) `extern PVOID __imp_WNetCloseEnum;` +- `__imp__stricmp` (line 545) `extern PVOID __imp__stricmp;` +- `__imp_Process32Next` (line 546) `extern PVOID __imp_Process32Next;` +- `__imp_IsWow64Process` (line 547) `extern PVOID __imp_IsWow64Process;` +- `__imp_Process32First` (line 548) `extern PVOID __imp_Process32First;` +- `__imp_CreateToolhelp32Snapshot` (line 549) `extern PVOID __imp_CreateToolhelp32Snapshot;` +- `__imp_select` (line 550) `extern PVOID __imp_select;` +- `__imp_CreateProcessA` (line 551) `extern PVOID __imp_CreateProcessA;` +- `__imp_CreateProcessW` (line 552) `extern PVOID __imp_CreateProcessW;` +- `__imp_SuspendThread` (line 553) `extern PVOID __imp_SuspendThread;` +- `__imp_OpenThread` (line 554) `extern PVOID __imp_OpenThread;` +- `__imp_Thread32First` (line 555) `extern PVOID __imp_Thread32First;` +- `__imp_Thread32Next` (line 556) `extern PVOID __imp_Thread32Next;` +- `__imp_NtQueryInformationThread` (line 557) `extern PVOID __imp_NtQueryInformationThread;` +- `g_pNtCreateFileUnhooked` (line 561) `extern PVOID g_pNtCreateFileUnhooked;` +- `g_pNtWriteVirtualMemoryUnhooked` (line 562) `extern PVOID g_pNtWriteVirtualMemoryUnhooked;` +- `g_pNtProtectVirtualMemoryUnhooked` (line 563) `extern PVOID g_pNtProtectVirtualMemoryUnhooked;` +- `g_pNtResumeThreadUnhooked` (line 564) `extern PVOID g_pNtResumeThreadUnhooked;` +- `g_pNtCreateThreadExUnhooked` (line 565) `extern PVOID g_pNtCreateThreadExUnhooked;` + +#### `aes.c` +**Path:** `aes.c` +**File Doc:** *aes.c - tiny-AES-c (https://github.com/kokke/tiny-AES-c)* + +**Functions:** +- `getSBoxValue` (line 13) `static uint8_t getSBoxValue(uint8_t num)` +- `getSBoxInvert` (line 35) `static uint8_t getSBoxInvert(uint8_t num)` +- `Td0` (line 57) `static uint8_t Td0(int x)` +- `Td1` (line 58) `static uint8_t Td1(int x)` +- `Td2` (line 59) `static uint8_t Td2(int x)` +- `Td3` (line 60) `static uint8_t Td3(int x)` +- `Td4` (line 61) `static uint8_t Td4(int x)` +- `KeyExpansion` (line 166) `static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key)` - *This function produces Nb(Nr+1) round keys. The round keys are used in each round to decrypt the states.* +- `AES_init_ctx` (line 239) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key)` +- `AES_init_ctx_iv` (line 244) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv)` - *if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1))* +- `AES_ctx_set_iv` (line 249) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv)` +- `AddRoundKey` (line 257) `static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)` - *This function adds the round key to state. The round key is added to the state by an XOR function.* +- `SubBytes` (line 271) `static void SubBytes(state_t* state)` - *The SubBytes Function Substitutes the values in the state matrix with values in an S-box.* +- `ShiftRows` (line 286) `static void ShiftRows(state_t* state)` - *The ShiftRows() function shifts the rows in the state to the left. Each row is shifted with different offset. Offset = Row number. So the first row is not shifted.* +- `xtime` (line 314) `static uint8_t xtime(uint8_t x)` +- `MixColumns` (line 320) `static void MixColumns(state_t* state)` - *MixColumns function mixes the columns of the state matrix* +- `Multiply` (line 340) `static uint8_t Multiply(uint8_t x, uint8_t y)` - *Multiply is used to multiply numbers in the field GF(2^8) Note: The last call to xtime() is unneeded, but often ends up generating a smaller binary The compiler seems to be able to vectorize the operation better this way. See https://github.com/kokke/tiny-AES-c/pull/34 if MULTIPLY_AS_A_FUNCTION* +- `InvMixColumns` (line 370) `static void InvMixColumns(state_t* state)` - *MixColumns function mixes the columns of the state matrix. The method used to multiply may be difficult to understand for the inexperienced. Please use the references to gain more information.* +- `InvSubBytes` (line 391) `static void InvSubBytes(state_t* state)` - *The SubBytes Function Substitutes the values in the state matrix with values in an S-box.* +- `InvShiftRows` (line 403) `static void InvShiftRows(state_t* state)` +- `Cipher` (line 433) `static void Cipher(state_t* state, const uint8_t* RoundKey)` - *Cipher is the main function that encrypts the PlainText.* +- `InvCipher` (line 459) `static void InvCipher(state_t* state, const uint8_t* RoundKey)` - *if (defined(CBC) && CBC == 1) || (defined(ECB) && ECB == 1)* +- `AES_ECB_encrypt` (line 490) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf)` +- `AES_ECB_decrypt` (line 496) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf)` +- `XorWithIv` (line 512) `static void XorWithIv(uint8_t* buf, const uint8_t* Iv)` +- `AES_CBC_encrypt_buffer` (line 521) `void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length)` +- `AES_CBC_decrypt_buffer` (line 536) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` +- `AES_CTR_xcrypt_buffer` (line 558) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` - *XorWithIv(buf, ctx->Iv); memcpy(ctx->Iv, storeNextIv, AES_BLOCKLEN); buf += AES_BLOCKLEN; } } #endif // #if defined(CBC) && (CBC == 1) #if defined(CTR) && (CTR == 1) /* Symmetrical operation: same function for encrypting as for decrypting. Note any IV/nonce should never be reused with the same key* + +**Macros:** +- `Nb` (line 5) `#define Nb` +- `KEYLEN_256` (line 9) `#define KEYLEN_256` +- `RKLENGTH` (line 10) `#define RKLENGTH` +- `BLOCKLEN` (line 11) `#define BLOCKLEN` +- `Nb` (line 67) `#define Nb` +- `Nk` (line 70) `#define Nk` +- `Nr` (line 71) `#define Nr` +- `Nk` (line 73) `#define Nk` +- `Nr` (line 74) `#define Nr` +- `Nk` (line 76) `#define Nk` +- `Nr` (line 77) `#define Nr` +- `MULTIPLY_AS_A_FUNCTION` (line 84) `#define MULTIPLY_AS_A_FUNCTION` +- `getSBoxValue` (line 163) `#define getSBoxValue(num)` +- `Multiply` (line 349) `#define Multiply(x, y)` +- `getSBoxInvert` (line 365) `#define getSBoxInvert(num)` + +#### `beacon.c` +**Path:** `beacon.c` + +**Functions:** +- `ExceptionFilter` (line 253) `static LONG WINAPI ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo)` +- `get_shell_cmd` (line 335) `const char* get_shell_cmd()` +- `__declspec` (line 417) `__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size)` +- `__declspec` (line 423) `__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size)` +- `__declspec` (line 431) `__declspec(dllexport) int BeaconDataInt(datap * parser)` +- `__declspec` (line 436) `__declspec(dllexport) short BeaconDataShort(datap * parser)` +- `__declspec` (line 441) `__declspec(dllexport) int BeaconDataLength(datap * parser)` +- `__declspec` (line 446) `__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size)` +- `__declspec` (line 456) `__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...)` +- `__declspec` (line 504) `__declspec(dllexport) void BeaconOutput(int type, const char * data, int len)` +- `MapDllNameToModule` (line 521) `HMODULE MapDllNameToModule(char* dllName)` - *=== MAP DLL NAME TO REAL DLL ===* +- `GetSyscallNumber` (line 549) `DWORD GetSyscallNumber(PVOID func_addr)` +- `HellsGate` (line 561) `DWORD HellsGate(DWORD ssn)` +- `__attribute__` (line 566) `__attribute__((naked)) +NTSTATUS HellDescent( + DWORD64 arg1, DWORD64 arg2, DWORD64 arg3, + DW...` +- `GetProcessIdByName` (line 582) `DWORD GetProcessIdByName(const char* processName)` +- `ExecuteTLSCallbacks` (line 600) `void ExecuteTLSCallbacks(PVOID moduleBase)` - *=== EJECUTAR TLS CALLBACKS ===* +- `MapModuleToMemory` (line 617) `PVOID MapModuleToMemory(unsigned char* fileBuffer, DWORD fileSize)` - *=== Carga un módulo en memoria ===* +- `ExecuteModule` (line 706) `BOOL ExecuteModule(PVOID moduleBase)` - *=== Ejecuta el módulo (DllMain o EntryPoint) ===* +- `LoadModuleFromURL` (line 751) `BOOL LoadModuleFromURL(const char* url)` - *=== Carga y ejecuta un módulo desde URL ===* +- `xor_string` (line 915) `void xor_string(char* data, size_t len, char key)` - *=== XOR ===* +- `anti_analysis` (line 922) `BOOL anti_analysis()` - *=== ANTI-ANALYSIS ===* +- `load_lazyconf` (line 946) `BOOL load_lazyconf()` +- `GetNtdllBase` (line 1184) `HMODULE GetNtdllBase()` +- `isVMByMAC` (line 1232) `BOOL isVMByMAC()` +- `extract_shellcode` (line 1303) `int extract_shellcode(const char* input, size_t len, unsigned char** out)` - *=== EXTRAER SHELLCODE ===* +- `hex_char_to_byte` (line 1334) `BYTE hex_char_to_byte(char c)` - *Función para convertir hex a bytes* +- `hex_to_bytes` (line 1341) `void hex_to_bytes(const char* hex, BYTE* output, size_t len)` +- `executeLoader` (line 1348) `void executeLoader(void *arg)` - *=== executeLoader ===* +- `ReverseShell` (line 1404) `void __cdecl ReverseShell(void* arg)` - *======================== FUNCIÓN DE INYECCIÓN DE SHELL ========================* +- `ReadFromProcess` (line 1513) `DWORD WINAPI ReadFromProcess(LPVOID lpParam)` - *=== Hilo para leer salida del proceso (como en el ejemplo que funciona) ===* +- `GetJitteredSleep` (line 1587) `DWORD GetJitteredSleep(DWORD base_ms)` +- `GetUsefulSoftware` (line 1592) `char* GetUsefulSoftware()` +- `base64_encode` (line 1627) `char* base64_encode(const unsigned char* data, size_t inputLen)` +- `base64_decode` (line 1663) `char* base64_decode(const char* input, size_t* out_len)` +- `discoverLocalHosts` (line 1696) `void discoverLocalHosts()` +- `initProxy` (line 1753) `void initProxy()` +- `relay_thread` (line 1763) `void WINAPI relay_thread(void* param)` - *Función para reenviar datos entre sockets* +- `proxy_thread` (line 1784) `void WINAPI proxy_thread(void* param)` - *Tu función proxy_thread usando tus estructuras exactas* +- `proxy_accept_thread` (line 1855) `void WINAPI proxy_accept_thread(void* param)` - *Thread para aceptar conexiones* +- `startProxy` (line 1923) `BOOL startProxy(const char* listenAddr, const char* targetAddr)` +- `stopProxy` (line 2010) `BOOL stopProxy(const char* listenAddr)` +- `cleanupProxy` (line 2062) `void cleanupProxy()` +- `compressDirectory` (line 2094) `BOOL compressDirectory(const char* dirPath)` - *Función simplificada para compresión de directorios* +- `getNetworkConfig` (line 2104) `char* getNetworkConfig()` - *Para netconfig* +- `UploadFileToC2` (line 2108) `BOOL UploadFileToC2(const char* url, const char* filePath)` +- `handleUpload` (line 2280) `BOOL handleUpload(const char* command)` - *=== handleUpload: envía del beacon al C2 ===* +- `FileExistsA` (line 2301) `BOOL FileExistsA(const char* filePath)` - *Función para verificar si un archivo existe* +- `selfDestruct` (line 2306) `void selfDestruct()` - *selfdestruct.c* +- `stristr` (line 2362) `char* stristr(const char* str, const char* pattern)` +- `isSensitiveFile` (line 2378) `int isSensitiveFile(const char* filename)` +- `searchCredentials` (line 2425) `char* searchCredentials(const char* basePath)` +- `UTF8ToWide` (line 2551) `WCHAR* UTF8ToWide(const char* utf8)` - *Convierte UTF-8 a wide string* +- `obfuscateFileTimestamp` (line 2562) `BOOL obfuscateFileTimestamp(const char* filepath)` - *Ofusca los timestamps de un archivo* +- `obfuscateFileTimestamps` (line 2592) `void obfuscateFileTimestamps(const char* basePath, int depth)` - *Recorre directorios buscando archivos sensibles* +- `simulateLegitimateTraffic` (line 2656) `void simulateLegitimateTraffic(void* param)` - *traffic.c* +- `restartClient` (line 2735) `void restartClient()` +- `checkDebuggers` (line 2776) `BOOL checkDebuggers()` +- `MapPEToMemory` (line 2838) `unsigned char* MapPEToMemory(unsigned char* rawPE, DWORD rawSize, DWORD* mappedSize)` +- `downloadAndExecute` (line 2861) `BOOL downloadAndExecute(const char* url, const char* targetProcess)` +- `DecryptPacket` (line 2911) `BOOL DecryptPacket(BYTE* buffer, DWORD* buffer_len)` +- `GetIPs` (line 3007) `char* GetIPs()` +- `GetHostname` (line 3041) `char* GetHostname()` +- `GetUsername` (line 3057) `char* GetUsername()` +- `patchAMSI` (line 3074) `BOOL patchAMSI(void)` +- `get_nt_headers` (line 3092) `PIMAGE_NT_HEADERS get_nt_headers(BYTE* buffer)` - *==================================================================== PE HELPERS (usando winnt.h) ====================================================================* +- `is_64bit` (line 3101) `BOOL is_64bit(BYTE* buffer)` +- `get_image_size` (line 3107) `DWORD get_image_size(BYTE* buffer)` +- `get_entry_point_rva` (line 3113) `DWORD get_entry_point_rva(BYTE* buffer)` +- `pe_buffer_to_virtual_image` (line 3119) `BYTE* pe_buffer_to_virtual_image(BYTE* raw_buffer, DWORD* out_size)` +- `create_suspended_process` (line 3149) `BOOL create_suspended_process(char* path, PROCESS_INFORMATION* pi)` +- `get_remote_image_base` (line 3156) `ULONGLONG get_remote_image_base(PROCESS_INFORMATION* pi, BOOL is_32bit_target)` +- `update_remote_entry_point` (line 3250) `BOOL update_remote_entry_point(PROCESS_INFORMATION* pi, ULONGLONG entry_point_va, BOOL is_32bit)` +- `overWrite` (line 3277) `void overWrite(const char* targetPath, const char* payloadPath)` - *==================================================================== MAIN FUNCTION: overWrite ====================================================================* +- `cleanSystemLogs` (line 3384) `void cleanSystemLogs()` - *Limpia el historial de comandos de la consola actual* +- `ensurePersistence` (line 3421) `BOOL ensurePersistence()` - *ensurePersistence.c* +- `isSandboxEnvironment` (line 3482) `BOOL isSandboxEnvironment()` - *isSandboxEnvironment.c* +- `tryPrivilegeEscalation` (line 3552) `void tryPrivilegeEscalation()` +- `executeUACBypass` (line 3557) `BOOL executeUACBypass(const char* payloadPath)` +- `scanPort` (line 3610) `void scanPort(void* arg)` +- `PortScanner` (line 3661) `void PortScanner(char* targetIP, int* ports, int numPorts)` - *PortScanner.c* +- `PortScannerWrapper` (line 3706) `void PortScannerWrapper(void* arg)` +- `EarlyBirdInject` (line 3729) `BOOL EarlyBirdInject(unsigned char* shellcode, int shellcode_len)` - *=== INYECCIÓN EARLY BIRD + SYSCALL ===* +- `init_aes_context` (line 3900) `PacketEncryptionContext* init_aes_context(const char* key_hex)` +- `retry_http_request` (line 3918) `char* retry_http_request(const char* url, const char* method, const char* data, int max_retries)` - *retry_http_request.c* +- `exec_cmd` (line 4172) `char* exec_cmd(const char* cmd)` - *exec_cmd.c* +- `GetC2Command` (line 4200) `char* GetC2Command(const char* host, const char* path)` - *c2.c (reemplaza la función actual)* +- `DownloadToBuffer` (line 4347) `unsigned char* DownloadToBuffer(const char* url, DWORD* fileSize)` +- `DownloadFromURL` (line 4423) `BOOL DownloadFromURL(const char* url, const char* filepath)` +- `encrypt_data` (line 4454) `char* encrypt_data(const char* data)` +- `isValidUUID` (line 4512) `BOOL isValidUUID(const char* uuid)` +- `deleteFilesDelay` (line 4537) `void deleteFilesDelay(void* arg)` +- `executeCommand` (line 4551) `void executeCommand(void* cmdPtr)` +- `handleAtomic` (line 4560) `void handleAtomic(char* command)` +- `handleDownload` (line 4683) `BOOL handleDownload(const char* command)` - *=== handleDownload: descarga del C2 al beacon ===* +- `SerializeBeaconString` (line 4703) `void SerializeBeaconString(char* buffer, int* offset, const char* str)` +- `BeaconDataSerializeString` (line 4712) `void BeaconDataSerializeString(char* buffer, int* offset, const char* str)` +- `go` (line 4720) `void go(unsigned char * bof_data, int bof_size, char * args, int args_len)` +- `handleAdversary` (line 4738) `void handleAdversary(char* command)` - *Función principal de manejo de comandos* +- `main` (line 5233) `int main()` - *main.c* + +**Macros:** +- `PSAPI_VERSION` (line 20) `#define PSAPI_VERSION` +- `WIN32_LEAN_AND_MEAN` (line 21) `#define WIN32_LEAN_AND_MEAN` +- `XOR_KEY` (line 71) `#define XOR_KEY` +- `DEBUG` (line 72) `#define DEBUG` +- `TIMEOUT` (line 73) `#define TIMEOUT` +- `MAX_RESPONSE_SIZE` (line 74) `#define MAX_RESPONSE_SIZE` +- `C2_URL` (line 75) `#define C2_URL` +- `MALEABLE` (line 76) `#define MALEABLE` +- `CLIENT_ID` (line 77) `#define CLIENT_ID` +- `SLEEP_BASE` (line 78) `#define SLEEP_BASE` +- `MIN_JITTER` (line 79) `#define MIN_JITTER` +- `MAX_JITTER` (line 80) `#define MAX_JITTER` +- `MAX_RETRIES` (line 81) `#define MAX_RETRIES` +- `C2_HOST` (line 82) `#define C2_HOST` +- `LC2_HOST` (line 83) `#define LC2_HOST` +- `C2_USER` (line 84) `#define C2_USER` +- `C2_PASS` (line 85) `#define C2_PASS` +- `C2_PORT` (line 86) `#define C2_PORT` +- `CONFIG_PATH` (line 87) `#define CONFIG_PATH` +- `C2_PATH` (line 88) `#define C2_PATH` +- `LC2_PATH` (line 89) `#define LC2_PATH` +- `min` (line 91) `#define min(a,b)` +- `SECURITY_FLAG_IGNORE_REVOCATION` (line 94) `#define SECURITY_FLAG_IGNORE_REVOCATION` +- `INVALID_SOCKET` (line 97) `#define INVALID_SOCKET` +- `USER_AGENT` (line 99) `#define USER_AGENT` +- `USER_AGENT_A` (line 100) `#define USER_AGENT_A` +- `IMAGE_DOS_SIGNATURE` (line 101) `#define IMAGE_DOS_SIGNATURE` +- `IMAGE_NT_SIGNATURE` (line 102) `#define IMAGE_NT_SIGNATURE` +- `IMAGE_NT_OPTIONAL_HDR32_MAGIC` (line 103) `#define IMAGE_NT_OPTIONAL_HDR32_MAGIC` +- `IMAGE_NT_OPTIONAL_HDR64_MAGIC` (line 104) `#define IMAGE_NT_OPTIONAL_HDR64_MAGIC` +- `SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` (line 106) `#define SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` +- `SECURITY_FLAG_IGNORE_INVALID_POLICY` (line 109) `#define SECURITY_FLAG_IGNORE_INVALID_POLICY` +- `_SECURITY_PACKAGE_DEFINITION_` (line 112) `#define _SECURITY_PACKAGE_DEFINITION_` +- `_PROCESS_BASIC_INFORMATION_` (line 115) `#define _PROCESS_BASIC_INFORMATION_` +- `_SP_LSA_MODE_INITIALIZE_DEFINED_` (line 117) `#define _SP_LSA_MODE_INITIALIZE_DEFINED_` +- `ProcessBasicInformation` (line 123) `#define ProcessBasicInformation` +- `CHECK_ERROR` (line 126) `#define CHECK_ERROR(cond, msg)` +- `NUM_USER_AGENTS` (line 231) `#define NUM_USER_AGENTS` +- `NUM_URLS` (line 240) `#define NUM_URLS` +- `NUM_UAS` (line 247) `#define NUM_UAS` +- `NT_SUCCESS` (line 300) `#define NT_SUCCESS(Status)` + +**Structs:** +- `_PROCESS_BASIC_INFORMATION` (line 129) +- `_UNICODE_STRING` (line 262) - *=== ESTRUCTURAS NECESARIAS (MinGW-safe) ===* +- `_LDR_DATA_TABLE_ENTRY` (line 268) +- `_PEB_LDR_DATA` (line 278) +- `_PEB` (line 287) +- `ProxySession` (line 139) +- `ProxyThreadData` (line 147) +- `ReverseArgs` (line 156) +- `PortScannerArgs` (line 161) +- `LazyDataType` (line 168) +- `ProxyListener` (line 176) +- `PacketEncryptionContext` (line 329) +- `PortResult` (line 343) + +**Type_Aliases:** +- `ExitStatus` (line 127) `typedef struct _PROCESS_BASIC_INFORMATION { LONG ExitStatus;` - *define CHECK_ERROR(cond, msg) do { if (!(cond)) { printf("[-] %s: %lu\n", msg, GetLastError()); return FALSE; } } while(0)* +- `Length` (line 262) `typedef struct _UNICODE_STRING { USHORT Length;` - *=== ESTRUCTURAS NECESARIAS (MinGW-safe) ===* +- `InMemoryOrderLinks` (line 267) `typedef struct _LDR_DATA_TABLE_ENTRY { LIST_ENTRY InMemoryOrderLinks;` +- `Length` (line 277) `typedef struct _PEB_LDR_DATA { DWORD Length;` +- `Reserved1` (line 286) `typedef struct _PEB { BYTE Reserved1[2];` +- `NTSTATUS` (line 296) `typedef LONG NTSTATUS;` - *ifndef NTSTATUS* +- `NTSTATUS` (line 304) `typedef LONG NTSTATUS;` + +#### `calc.c` +**Path:** `bof/calc/calc.c` + +**Functions:** +- `go` (line 34) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Variables:** +- `__imp_GetModuleHandleA` (line 26) `extern FARPROC __imp_GetModuleHandleA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 27) `extern FARPROC __imp_GetProcAddress;` +- `__imp_LoadLibraryA` (line 28) `extern FARPROC __imp_LoadLibraryA;` +- `__imp_GetComputerNameA` (line 29) `extern FARPROC __imp_GetComputerNameA;` +- `__imp_CloseHandle` (line 30) `extern FARPROC __imp_CloseHandle;` + +#### `etw.c` +**Path:** `bof/etw/etw.c` + +**Functions:** +- `go` (line 26) `void go(char *a,int l)` + +**Variables:** +- `__imp_GetModuleHandleA` (line 22) `extern PVOID __imp_GetModuleHandleA;` - *include include "beacon.h"* +- `__imp_GetProcAddress` (line 23) `extern PVOID __imp_GetProcAddress;` +- `__imp_VirtualProtect` (line 24) `extern PVOID __imp_VirtualProtect;` +- `__imp_RtlCopyMemory` (line 25) `extern PVOID __imp_RtlCopyMemory;` + +#### `Test.c` +**Path:** `bof/test/Test.c` + +**Functions:** +- `go` (line 3) `void go(char *args, int alen)` + +#### `amsibypass.c` +**Path:** `bof/test/amsibypass.c` + +**Functions:** +- `go` (line 34) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Variables:** +- `__imp_LoadLibraryA` (line 26) `extern PVOID __imp_LoadLibraryA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 27) `extern PVOID __imp_GetProcAddress;` +- `__imp_VirtualProtect` (line 28) `extern PVOID __imp_VirtualProtect;` +- `__imp_RtlCopyMemory` (line 29) `extern PVOID __imp_RtlCopyMemory;` + +#### `cmdwhoami.c` +**Path:** `bof/test/cmdwhoami.c` + +**Functions:** +- `go` (line 43) `void go(char *args, int alen)` + +**Variables:** +- `__imp_LoadLibraryA` (line 26) `extern PVOID __imp_LoadLibraryA;` +- `__imp_GetProcAddress` (line 27) `extern PVOID __imp_GetProcAddress;` +- `__imp_CloseHandle` (line 28) `extern PVOID __imp_CloseHandle;` + +#### `disablelog.c` +**Path:** `bof/test/disablelog.c` + +**Functions:** +- `my_wcscmp` (line 37) `static int my_wcscmp(const wchar_t *s1, const wchar_t *s2)` +- `go` (line 69) `void go(char *args, int alen)` + +**Macros:** +- `WIN32_LEAN_AND_MEAN` (line 20) `#define WIN32_LEAN_AND_MEAN` +- `NT_SUCCESS` (line 34) `#define NT_SUCCESS(x)` + +**Variables:** +- `__imp_LoadLibraryA` (line 27) `extern PVOID __imp_LoadLibraryA;` +- `__imp_GetProcAddress` (line 28) `extern PVOID __imp_GetProcAddress;` +- `__imp_GetModuleHandleA` (line 29) `extern PVOID __imp_GetModuleHandleA;` +- `__imp_CloseHandle` (line 30) `extern PVOID __imp_CloseHandle;` +- `__imp_OpenProcess` (line 31) `extern PVOID __imp_OpenProcess;` + +#### `getenv.c` +**Path:** `bof/test/getenv.c` + +**Functions:** +- `go` (line 25) `void go(char *args, int alen)` + +**Variables:** +- `__imp_GetEnvironmentVariableA` (line 23) `extern PVOID __imp_GetEnvironmentVariableA;` + +#### `loadvnc.c` +**Path:** `bof/test/loadvnc.c` + +**Functions:** +- `execute_cmd_hidden` (line 51) `void execute_cmd_hidden(char* cmd)` - *================================ FUNCIÓN AUX: EJECUTAR COMANDO OCULTO ================================* +- `go` (line 81) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Macros:** +- `TH32CS_SNAPPROCESS` (line 33) `#define TH32CS_SNAPPROCESS` + +**Structs:** +- `_PROCESSENTRY32` (line 35) + +**Type_Aliases:** +- `dwSize` (line 34) `typedef struct _PROCESSENTRY32 { DWORD dwSize;` - *================================ DEFINICIONES MANUALES ================================ define TH32CS_SNAPPROCESS 0x00000002* + +**Variables:** +- `__imp_LoadLibraryA` (line 26) `extern PVOID __imp_LoadLibraryA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 27) `extern PVOID __imp_GetProcAddress;` +- `__imp_CloseHandle` (line 28) `extern PVOID __imp_CloseHandle;` + +#### `make_table.c` +**Path:** `bof/test/make_table.c` + +**Functions:** +- `Copyright` (line 17) `Copyright (c) LazyOwn RedTeam 2025. All rights reserved. +*/ + +#include +#include fd_count; ++i) if (set->fd_array[i] == s) return 1; return 0; } /* ===== VARIABLE GLOBAL ===== static HANDLE g_hShutdownEvent = NULL; /* ===== MANEJADOR SOCKS5 (solo después de handshake confirmado) =====* +- `ProxyThread` (line 261) `DWORD WINAPI ProxyThread(LPVOID _)` - *break; } if (pSend(client_sock, buf, n, 0) != n) { BeaconPrintf(CALLBACK_ERROR, "[SOCKS5] Falló al reenviar al cliente\n"); break; } BeaconPrintf(CALLBACK_OUTPUT, "[SOCKS5] Reenviados %d bytes destino→cliente\n", n); } } pCloseSocket(tgt); BeaconPrintf(CALLBACK_OUTPUT, "[SOCKS5] Túnel cerrado\n"); } /* ===== HILO PRINCIPAL DEL PROXY =====* +- `go` (line 358) `void go(char *args, int alen)` - *cleanup_srv: pCloseSocket(srv); cleanup_wsa: pWSACleanup(); cleanup_event: if (g_hShutdownEvent) { ((BOOL (WINAPI*)(HANDLE))__imp_CloseHandle)(g_hShutdownEvent); g_hShutdownEvent = NULL; } return 0; } /* ===== ENTRY POINT BOF =====* + +**Macros:** +- `WIN32_LEAN_AND_MEAN` (line 1) `#define WIN32_LEAN_AND_MEAN` +- `INVALID_SOCKET` (line 7) `#define INVALID_SOCKET` +- `SOCKET_ERROR` (line 8) `#define SOCKET_ERROR` +- `AF_INET` (line 9) `#define AF_INET` +- `SOCK_STREAM` (line 10) `#define SOCK_STREAM` +- `IPPROTO_TCP` (line 11) `#define IPPROTO_TCP` +- `INADDR_ANY` (line 12) `#define INADDR_ANY` +- `INADDR_LOOPBACK` (line 13) `#define INADDR_LOOPBACK` +- `FD_SETSIZE` (line 37) `#define FD_SETSIZE` +- `FD_CLR` (line 38) `#define FD_CLR(fd,set)` +- `FD_SET` (line 39) `#define FD_SET(fd,set)` +- `FD_ZERO` (line 40) `#define FD_ZERO(set)` +- `FD_ISSET` (line 41) `#define FD_ISSET(fd,set)` +- `h_addr` (line 64) `#define h_addr` +- `SOCKS5_LISTEN_PORT` (line 75) `#define SOCKS5_LISTEN_PORT` +- `SOCKS5_CONTROL_PORT` (line 76) `#define SOCKS5_CONTROL_PORT` +- `MAX_PENDING_CONNECTIONS` (line 77) `#define MAX_PENDING_CONNECTIONS` +- `BUFFER_SIZE` (line 78) `#define BUFFER_SIZE` + +**Structs:** +- `WSAData` (line 16) - *pragma pack(push,1)* +- `fd_set` (line 27) +- `timeval` (line 32) +- `in_addr` (line 47) +- `sockaddr_in` (line 49) +- `sockaddr` (line 56) +- `hostent` (line 58) + +**Type_Aliases:** +- `SOCKET` (line 6) `typedef unsigned __int64 SOCKET;` - *#define WIN32_LEAN_AND_MEAN #include #include "beacon.h" /* ===== DECLARACIONES QUE FALTABAN =====* +- `wVersion` (line 16) `typedef struct WSAData { WORD wVersion;` - *pragma pack(push,1)* +- `fd_count` (line 26) `typedef struct fd_set { unsigned int fd_count;` - *pragma pack(pop)* +- `tv_sec` (line 31) `typedef struct timeval { long tv_sec;` +- `u_short` (line 42) `typedef unsigned short u_short;` - *define FD_SETSIZE 64 define FD_CLR(fd,set) do { if ((set)->fd_count > 0) { u_int __i;for (__i=0;__i<(set)->fd_count;__i++) { if ((set)->fd_array[__i] == (fd)) { while (__i < (set)->fd_count-1) { (set)->fd_array[__i] = (set)->fd_array[__i+1];__i++;} (set)->fd_count--;break;}}}} while(0) define FD_SET(fd,set) do { if ((set)->fd_count < FD_SETSIZE) (set)->fd_array[(set)->fd_count++] = (fd); } while(0) define FD_ZERO(set) (((set)->fd_count = 0)) define FD_ISSET(fd,set) (__builtin_memchr((set)->fd_array,(fd),(set)->fd_count*sizeof(SOCKET))!=NULL)* +- `u_int` (line 44) `typedef unsigned int u_int;` +- `u_long` (line 45) `typedef unsigned long u_long;` + +**Variables:** +- `__imp_LoadLibraryA` (line 68) `extern PVOID __imp_LoadLibraryA;` - *}; struct sockaddr { unsigned short sa_family; char sa_data[14]; }; struct hostent { char *h_name; char **h_aliases; short h_addrtype; short h_length; char **h_addr_list; #define h_addr h_addr_list[0] }; /* ===== DIRECT IMPORTS =====* +- `__imp_GetProcAddress` (line 69) `extern PVOID __imp_GetProcAddress;` +- `__imp_VirtualAlloc` (line 70) `extern PVOID __imp_VirtualAlloc;` +- `__imp_VirtualFree` (line 71) `extern PVOID __imp_VirtualFree;` +- `__imp_CloseHandle` (line 72) `extern PVOID __imp_CloseHandle;` + +#### `uacbypass.c` +**Path:** `bof/test/uacbypass.c` + +**Functions:** +- `execute_hidden_cmd` (line 33) `void execute_hidden_cmd(char* cmd)` - *================================ FUNCIÓN AUX: EJECUTAR COMANDO OCULTO ================================* +- `go` (line 61) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Variables:** +- `__imp_LoadLibraryA` (line 26) `extern PVOID __imp_LoadLibraryA;` - *================================ IMPORTS DIRECTOS (solo si están en tu tabla) ================================* +- `__imp_GetProcAddress` (line 27) `extern PVOID __imp_GetProcAddress;` +- `__imp_CloseHandle` (line 28) `extern PVOID __imp_CloseHandle;` + +#### `upload.c` +**Path:** `bof/test/upload.c` +**File Doc:** *================================ IMPORTS DIRECTOS ================================* + +**Functions:** +- `my_strlen` (line 53) `static int my_strlen(const char *s)` - *================================ FUNCIONES AUXILIARES ================================* +- `my_memcpy` (line 59) `static void* my_memcpy(void* dst, const void* src, size_t len)` +- `my_memset` (line 66) `static void* my_memset(void* dst, int val, size_t len)` +- `my_contains_dotdot` (line 72) `static BOOL my_contains_dotdot(const char* path)` +- `my_strchr` (line 81) `static char* my_strchr(const char *s, int c)` +- `xtime` (line 93) `static uint8_t xtime(uint8_t x)` - *================================ AES (sin datos globales) ================================* +- `AddRoundKey` (line 99) `static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)` +- `SubBytes` (line 106) `static void SubBytes(state_t* state, const uint8_t* sbox)` +- `ShiftRows` (line 113) `static void ShiftRows(state_t* state)` +- `MixColumns` (line 121) `static void MixColumns(state_t* state)` +- `Cipher` (line 133) `static void Cipher(state_t* state, const uint8_t* RoundKey, const uint8_t* sbox)` +- `KeyExpansion` (line 146) `static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key, const uint8_t* sbox, const uint8_...` +- `AES_init_ctx` (line 174) `void AES_init_ctx(AES_ctx* ctx, const uint8_t* key, const uint8_t* sbox, const uint8_t* Rcon)` +- `AES_CFB_encrypt_buffer` (line 178) `void AES_CFB_encrypt_buffer(AES_ctx* ctx, uint8_t* iv, uint8_t* buf, uint32_t length, const uint8...` +- `my_base64_encode` (line 205) `static char* my_base64_encode(const uint8_t* data, uint32_t len, + LPVOID (WINAPI *pVirtualAllo...` - *================================ BASE64 ================================* +- `ParseUploadArgs` (line 231) `static void ParseUploadArgs(const char* args, int alen, + char* local_p...` +- `go` (line 273) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Macros:** +- `WIN32_LEAN_AND_MEAN` (line 1) `#define WIN32_LEAN_AND_MEAN` +- `PROV_RSA_AES` (line 20) `#define PROV_RSA_AES` +- `CRYPT_VERIFYCONTEXT` (line 21) `#define CRYPT_VERIFYCONTEXT` +- `AES_BLOCKLEN` (line 23) `#define AES_BLOCKLEN` +- `AES256_KEYLEN` (line 24) `#define AES256_KEYLEN` +- `Nr` (line 25) `#define Nr` +- `Nk` (line 26) `#define Nk` +- `Nb` (line 27) `#define Nb` +- `SECURITY_FLAG_IGNORE_UNKNOWN_CA` (line 29) `#define SECURITY_FLAG_IGNORE_UNKNOWN_CA` +- `SECURITY_FLAG_IGNORE_CERT_CN_INVALID` (line 30) `#define SECURITY_FLAG_IGNORE_CERT_CN_INVALID` +- `SECURITY_FLAG_IGNORE_CERT_DATE_INVALID` (line 31) `#define SECURITY_FLAG_IGNORE_CERT_DATE_INVALID` +- `WINHTTP_OPTION_SECURITY_FLAGS` (line 32) `#define WINHTTP_OPTION_SECURITY_FLAGS` +- `WINHTTP_ACCESS_TYPE_NO_PROXY` (line 35) `#define WINHTTP_ACCESS_TYPE_NO_PROXY` +- `WINHTTP_NO_PROXY_NAME` (line 39) `#define WINHTTP_NO_PROXY_NAME` +- `WINHTTP_NO_PROXY_BYPASS` (line 43) `#define WINHTTP_NO_PROXY_BYPASS` +- `NEXT_TOKEN` (line 244) `#define NEXT_TOKEN(dst,lim)` + +**Structs:** +- `AES_ctx` (line 46) + +**Type_Aliases:** +- `uint8_t` (line 14) `typedef unsigned char uint8_t;` - *================================ TIPOS MANUALES ================================* +- `uint32_t` (line 15) `typedef unsigned int uint32_t;` +- `HINTERNET` (line 16) `typedef void* HINTERNET;` +- `INTERNET_PORT` (line 17) `typedef WORD INTERNET_PORT;` +- `HCRYPTPROV` (line 18) `typedef ULONG_PTR HCRYPTPROV;` + +**Variables:** +- `__imp_LoadLibraryA` (line 8) `extern PVOID __imp_LoadLibraryA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 9) `extern PVOID __imp_GetProcAddress;` + +#### `vncrelay.c` +**Path:** `bof/test/vncrelay.c` + +**Functions:** +- `my_FD_ISSET` (line 62) `int my_FD_ISSET(SOCKET sock, fd_set *set)` - *================================ FD_ISSET MANUAL ================================* +- `relay_traffic` (line 75) `void relay_traffic(SOCKET client_sock, SOCKET vnc_sock)` - *================================ RELAY TRAFFIC ================================* +- `go` (line 132) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL — ¡CORREGIDO! ================================* + +**Variables:** +- `__imp_LoadLibraryA` (line 27) `extern PVOID __imp_LoadLibraryA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 28) `extern PVOID __imp_GetProcAddress;` +- `__imp_VirtualAlloc` (line 29) `extern PVOID __imp_VirtualAlloc;` +- `__imp_VirtualFree` (line 30) `extern PVOID __imp_VirtualFree;` +- `__imp_CloseHandle` (line 31) `extern PVOID __imp_CloseHandle;` + +#### `winver.c` +**Path:** `bof/test/winver.c` + +**Functions:** +- `go` (line 25) `void go(char *args, int alen)` + +**Variables:** +- `__imp_GetVersionExA` (line 23) `extern PVOID __imp_GetVersionExA;` + +#### `whoami.c` +**Path:** `bof/whoami/whoami.c` + +**Functions:** +- `go` (line 34) `void go(char *args, int alen)` - *================================ FUNCIÓN PRINCIPAL ================================* + +**Variables:** +- `__imp_GetModuleHandleA` (line 26) `extern FARPROC __imp_GetModuleHandleA;` - *================================ IMPORTS DIRECTOS ================================* +- `__imp_GetProcAddress` (line 27) `extern FARPROC __imp_GetProcAddress;` +- `__imp_LoadLibraryA` (line 28) `extern FARPROC __imp_LoadLibraryA;` +- `__imp_GetComputerNameA` (line 29) `extern FARPROC __imp_GetComputerNameA;` + +#### `cJSON.c` +**Path:** `cJSON.c` + +**Functions:** +- `CJSON_PUBLIC` (line 95) `CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void)` +- `CJSON_PUBLIC` (line 100) `CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item)` +- `CJSON_PUBLIC` (line 110) `CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item)` +- `CJSON_PUBLIC` (line 125) `CJSON_PUBLIC(const char*) cJSON_Version(void)` +- `case_insensitive_strcmp` (line 134) `static int case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2)` - */* This is a safeguard to prevent copy-pasters from using incompatible C and header files #if (CJSON_VERSION_MAJOR != 1) || (CJSON_VERSION_MINOR != 7) || (CJSON_VERSION_PATCH != 18) #error cJSON.h and cJSON.c have different versions. Make sure that both have the same. #endif CJSON_PUBLIC(const char*) cJSON_Version(void) { static char version[15]; sprintf(version, "%i.%i.%i", CJSON_VERSION_MAJOR, CJSON_VERSION_MINOR, CJSON_VERSION_PATCH); return version; } /* Case insensitive string comparison, doesn't consider two NULL pointers equal though* +- `internal_malloc` (line 166) `static void * CJSON_CDECL internal_malloc(size_t size)` - *} return tolower(*string1) - tolower(*string2); } typedef struct internal_hooks { void *(CJSON_CDECL *allocate)(size_t size); void (CJSON_CDECL *deallocate)(void *pointer); void *(CJSON_CDECL *reallocate)(void *pointer, size_t size); } internal_hooks; #if defined(_MSC_VER) /* work around MSVC error C2322: '...' address of dllimport '...' is not static* +- `internal_free` (line 170) `static void CJSON_CDECL internal_free(void *pointer)` +- `internal_realloc` (line 174) `static void * CJSON_CDECL internal_realloc(void *pointer, size_t size)` +- `cJSON_strdup` (line 189) `static unsigned char* cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks)` +- `CJSON_PUBLIC` (line 210) `CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks)` +- `cJSON_New_Item` (line 242) `static cJSON *cJSON_New_Item(const internal_hooks * const hooks)` - *if (hooks->free_fn != NULL) { global_hooks.deallocate = hooks->free_fn; } /* use realloc only if both free and malloc are used global_hooks.reallocate = NULL; if ((global_hooks.allocate == malloc) && (global_hooks.deallocate == free)) { global_hooks.reallocate = realloc; } } /* Internal constructor.* +- `get_decimal_point` (line 281) `static unsigned char get_decimal_point(void)` - *item->valuestring = NULL; } if (!(item->type & cJSON_StringIsConst) && (item->string != NULL)) { global_hooks.deallocate(item->string); item->string = NULL; } global_hooks.deallocate(item); item = next; } } /* get the decimal point character of the current locale* +- `parse_number` (line 309) `static cJSON_bool parse_number(cJSON * const item, parse_buffer * const input_buffer)` - *size_t offset; size_t depth; /* How deeply nested (in arrays/objects) is the input at the current offset. internal_hooks hooks; } parse_buffer; /* check if the given size is left to read in a given parse buffer (starting with 1) #define can_read(buffer, size) ((buffer != NULL) && (((buffer)->offset + size) <= (buffer)->length)) /* check if the buffer can be accessed at the given index (starting with 0) #define can_access_at_index(buffer, index) ((buffer != NULL) && (((buffer)->offset + index) < (buffer)->length)) #define cannot_access_at_index(buffer, index) (!can_access_at_index(buffer, index)) /* get a pointer to the buffer at the position #define buffer_at_offset(buffer) ((buffer)->content + (buffer)->offset) /* Parse the input text to generate a number, and populate the result into item.* +- `ensure` (line 494) `static unsigned char* ensure(printbuffer * const p, size_t needed)` - *} typedef struct { unsigned char *buffer; size_t length; size_t offset; size_t depth; /* current nesting depth (for formatted printing) cJSON_bool noalloc; cJSON_bool format; /* is this print a formatted print internal_hooks hooks; } printbuffer; /* realloc printbuffer if necessary to have at least "needed" bytes more* +- `update_offset` (line 579) `static void update_offset(printbuffer * const buffer)` - *p->buffer = NULL; return NULL; } memcpy(newbuffer, p->buffer, p->offset + 1); p->hooks.deallocate(p->buffer); } p->length = newsize; p->buffer = newbuffer; return newbuffer + p->offset; } /* calculate the new length of the string in a printbuffer and update the offset* +- `compare_double` (line 592) `static cJSON_bool compare_double(double a, double b)` - */* calculate the new length of the string in a printbuffer and update the offset static void update_offset(printbuffer * const buffer) { const unsigned char *buffer_pointer = NULL; if ((buffer == NULL) || (buffer->buffer == NULL)) { return; } buffer_pointer = buffer->buffer + buffer->offset; buffer->offset += strlen((const char*)buffer_pointer); } /* securely comparison of floating-point variables* +- `print_number` (line 599) `static cJSON_bool print_number(const cJSON * const item, printbuffer * const output_buffer)` - *} buffer_pointer = buffer->buffer + buffer->offset; buffer->offset += strlen((const char*)buffer_pointer); } /* securely comparison of floating-point variables static cJSON_bool compare_double(double a, double b) { double maxVal = fabs(a) > fabs(b) ? fabs(a) : fabs(b); return (fabs(a - b) <= maxVal * DBL_EPSILON); } /* Render the number nicely from the given item into a string.* +- `parse_hex4` (line 669) `static unsigned parse_hex4(const unsigned char * const input)` - *output_pointer[i] = '.'; continue; } output_pointer[i] = number_buffer[i]; } output_pointer[i] = '\0'; output_buffer->offset += (size_t)length; return true; } /* parse 4 digit hexadecimal number* +- `utf16_literal_to_utf8` (line 706) `static unsigned char utf16_literal_to_utf8(const unsigned char * const input_pointer, const unsig...` - *converts a UTF-16 literal to UTF-8 * A literal can be one or two sequences of the form \uXXXX* +- `parse_string` (line 827) `static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer)` - *else { (*output_pointer)[0] = (unsigned char)(codepoint & 0x7F); } output_pointer += utf8_length; return sequence_length; fail: return 0; } /* Parse the input text into an unescaped cinput, and populate item.* +- `print_string_ptr` (line 957) `static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffer * const output_...` - *{ input_buffer->hooks.deallocate(output); output = NULL; } if (input_pointer != NULL) { input_buffer->offset = (size_t)(input_pointer - input_buffer->content); } return false; } /* Render the cstring provided to an escaped version that can be printed.* +- `print_string` (line 1079) `static cJSON_bool print_string(const cJSON * const item, printbuffer * const p)` - */* escape and print as unicode codepoint sprintf((char*)output_pointer, "u%04x", *input_pointer); output_pointer += 4; break; } } } output[output_length + 1] = '"'; output[output_length + 2] = '\0'; return true; } /* Invoke print_string_ptr (which is useful) on an item.* +- `buffer_skip_whitespace` (line 1093) `static parse_buffer *buffer_skip_whitespace(parse_buffer * const buffer)` - *static cJSON_bool print_string(const cJSON * const item, printbuffer * const p) { return print_string_ptr((unsigned char*)item->valuestring, p); } /* Predeclare these prototypes. static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer); static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer); static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer); static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer); /* Utility to jump whitespace and cr/lf* +- `skip_utf8_bom` (line 1119) `static parse_buffer *skip_utf8_bom(parse_buffer * const buffer)` - *while (can_access_at_index(buffer, 0) && (buffer_at_offset(buffer)[0] <= 32)) { buffer->offset++; } if (buffer->offset == buffer->length) { buffer->offset--; } return buffer; } /* skip the UTF-8 BOM (byte order mark) if it is at the beginning of a buffer* +- `CJSON_PUBLIC` (line 1134) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithOpts(const char *value, const char **return_parse_end, cJSON...` +- `CJSON_PUBLIC` (line 1236) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithLength(const char *value, size_t buffer_length)` +- `print` (line 1243) `static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * c...` +- `CJSON_PUBLIC` (line 1316) `CJSON_PUBLIC(char *) cJSON_PrintUnformatted(const cJSON *item)` +- `CJSON_PUBLIC` (line 1321) `CJSON_PUBLIC(char *) cJSON_PrintBuffered(const cJSON *item, int prebuffer, cJSON_bool fmt)` +- `CJSON_PUBLIC` (line 1352) `CJSON_PUBLIC(cJSON_bool) cJSON_PrintPreallocated(cJSON *item, char *buffer, const int length, con...` +- `parse_value` (line 1372) `static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer)` - *return false; } p.buffer = (unsigned char*)buffer; p.length = (size_t)length; p.offset = 0; p.noalloc = true; p.format = format; p.hooks = global_hooks; return print_value(item, &p); } /* Parser core - when encountering text, process appropriately.* +- `print_value` (line 1427) `static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer)` - *if (can_access_at_index(input_buffer, 0) && (buffer_at_offset(input_buffer)[0] == '[')) { return parse_array(item, input_buffer); } /* object if (can_access_at_index(input_buffer, 0) && (buffer_at_offset(input_buffer)[0] == '{')) { return parse_object(item, input_buffer); } return false; } /* Render a value to text.* +- `parse_array` (line 1501) `static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer)` - *return print_string(item, output_buffer); case cJSON_Array: return print_array(item, output_buffer); case cJSON_Object: return print_object(item, output_buffer); default: return false; } } /* Build an array from input text.* +- `print_array` (line 1599) `static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer)` - *input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an array to text* +- `parse_object` (line 1661) `static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer)` - *output_pointer = ensure(output_buffer, 2); if (output_pointer == NULL) { return false; } output_pointer++ = ']'; output_pointer = '\0'; output_buffer->depth--; return true; } /* Build an object from the text.* +- `print_object` (line 1780) `static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer)` - *input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an object to text.* +- `get_array_item` (line 1916) `static cJSON* get_array_item(const cJSON *array, size_t index)` +- `CJSON_PUBLIC` (line 1935) `CJSON_PUBLIC(cJSON *) cJSON_GetArrayItem(const cJSON *array, int index)` +- `get_object_item` (line 1945) `static cJSON *get_object_item(const cJSON * const object, const char * const name, const cJSON_bo...` +- `CJSON_PUBLIC` (line 1977) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItem(const cJSON * const object, const char * const string)` +- `CJSON_PUBLIC` (line 1982) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * c...` +- `CJSON_PUBLIC` (line 1987) `CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string)` +- `suffix_object` (line 1993) `static void suffix_object(cJSON *prev, cJSON *item)` - *return get_object_item(object, string, false); } CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * const string) { return get_object_item(object, string, true); } CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string) { return cJSON_GetObjectItem(object, string) ? 1 : 0; } /* Utility for array list handling.* +- `create_reference` (line 2000) `static cJSON *create_reference(const cJSON *item, const internal_hooks * const hooks)` - *CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string) { return cJSON_GetObjectItem(object, string) ? 1 : 0; } /* Utility for array list handling. static void suffix_object(cJSON *prev, cJSON *item) { prev->next = item; item->prev = prev; } /* Utility for handling references.* +- `add_item_to_array` (line 2021) `static cJSON_bool add_item_to_array(cJSON *array, cJSON *item)` +- `cast_away_const` (line 2066) `static void* cast_away_const(const void* string)` - */* Add item to array/object. CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToArray(cJSON *array, cJSON *item) { return add_item_to_array(array, item); } #if defined(__clang__) || (defined(__GNUC__) && ((__GNUC__ > 4) || ((__GNUC__ == 4) && (__GNUC__-MINOR__ > 5)))) #pragma GCC diagnostic push #endif #ifdef __GNUC__ #pragma GCC diagnostic ignored "-Wcast-qual" #endif /* helper function to cast away const* +- `add_item_to_object` (line 2075) `static cJSON_bool add_item_to_object(cJSON * const object, const char * const string, cJSON * con...` +- `CJSON_PUBLIC` (line 2112) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToObject(cJSON *object, const char *string, cJSON *item)` +- `CJSON_PUBLIC` (line 2123) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToArray(cJSON *array, cJSON *item)` +- `CJSON_PUBLIC` (line 2133) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToObject(cJSON *object, const char *string, cJSON ...` +- `CJSON_PUBLIC` (line 2143) `CJSON_PUBLIC(cJSON*) cJSON_AddNullToObject(cJSON * const object, const char * const name)` +- `CJSON_PUBLIC` (line 2155) `CJSON_PUBLIC(cJSON*) cJSON_AddTrueToObject(cJSON * const object, const char * const name)` +- `CJSON_PUBLIC` (line 2167) `CJSON_PUBLIC(cJSON*) cJSON_AddFalseToObject(cJSON * const object, const char * const name)` +- `CJSON_PUBLIC` (line 2179) `CJSON_PUBLIC(cJSON*) cJSON_AddBoolToObject(cJSON * const object, const char * const name, const c...` +- `CJSON_PUBLIC` (line 2191) `CJSON_PUBLIC(cJSON*) cJSON_AddNumberToObject(cJSON * const object, const char * const name, const...` +- `CJSON_PUBLIC` (line 2203) `CJSON_PUBLIC(cJSON*) cJSON_AddStringToObject(cJSON * const object, const char * const name, const...` +- `CJSON_PUBLIC` (line 2215) `CJSON_PUBLIC(cJSON*) cJSON_AddRawToObject(cJSON * const object, const char * const name, const ch...` +- `CJSON_PUBLIC` (line 2227) `CJSON_PUBLIC(cJSON*) cJSON_AddObjectToObject(cJSON * const object, const char * const name)` +- `CJSON_PUBLIC` (line 2239) `CJSON_PUBLIC(cJSON*) cJSON_AddArrayToObject(cJSON * const object, const char * const name)` +- `CJSON_PUBLIC` (line 2251) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemViaPointer(cJSON *parent, cJSON * const item)` +- `CJSON_PUBLIC` (line 2287) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromArray(cJSON *array, int which)` +- `CJSON_PUBLIC` (line 2297) `CJSON_PUBLIC(void) cJSON_DeleteItemFromArray(cJSON *array, int which)` +- `CJSON_PUBLIC` (line 2302) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObject(cJSON *object, const char *string)` +- `CJSON_PUBLIC` (line 2309) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObjectCaseSensitive(cJSON *object, const char *string)` +- `CJSON_PUBLIC` (line 2316) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObject(cJSON *object, const char *string)` +- `CJSON_PUBLIC` (line 2321) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObjectCaseSensitive(cJSON *object, const char *string)` +- `CJSON_PUBLIC` (line 2363) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemViaPointer(cJSON * const parent, cJSON * const item, cJ...` +- `CJSON_PUBLIC` (line 2413) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInArray(cJSON *array, int which, cJSON *newitem)` +- `replace_item_in_object` (line 2423) `static cJSON_bool replace_item_in_object(cJSON *object, const char *string, cJSON *replacement, c...` +- `CJSON_PUBLIC` (line 2446) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObject(cJSON *object, const char *string, cJSON *newi...` +- `CJSON_PUBLIC` (line 2451) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObjectCaseSensitive(cJSON *object, const char *string...` +- `CJSON_PUBLIC` (line 2468) `CJSON_PUBLIC(cJSON *) cJSON_CreateTrue(void)` +- `CJSON_PUBLIC` (line 2479) `CJSON_PUBLIC(cJSON *) cJSON_CreateFalse(void)` +- `CJSON_PUBLIC` (line 2490) `CJSON_PUBLIC(cJSON *) cJSON_CreateBool(cJSON_bool boolean)` +- `CJSON_PUBLIC` (line 2501) `CJSON_PUBLIC(cJSON *) cJSON_CreateNumber(double num)` +- `CJSON_PUBLIC` (line 2526) `CJSON_PUBLIC(cJSON *) cJSON_CreateString(const char *string)` +- `CJSON_PUBLIC` (line 2543) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringReference(const char *string)` +- `CJSON_PUBLIC` (line 2555) `CJSON_PUBLIC(cJSON *) cJSON_CreateObjectReference(const cJSON *child)` +- `CJSON_PUBLIC` (line 2567) `CJSON_PUBLIC(cJSON *) cJSON_CreateArrayReference(const cJSON *child)` +- `CJSON_PUBLIC` (line 2579) `CJSON_PUBLIC(cJSON *) cJSON_CreateRaw(const char *raw)` +- `CJSON_PUBLIC` (line 2596) `CJSON_PUBLIC(cJSON *) cJSON_CreateArray(void)` +- `CJSON_PUBLIC` (line 2607) `CJSON_PUBLIC(cJSON *) cJSON_CreateObject(void)` +- `CJSON_PUBLIC` (line 2659) `CJSON_PUBLIC(cJSON *) cJSON_CreateFloatArray(const float *numbers, int count)` +- `CJSON_PUBLIC` (line 2699) `CJSON_PUBLIC(cJSON *) cJSON_CreateDoubleArray(const double *numbers, int count)` +- `CJSON_PUBLIC` (line 2739) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringArray(const char *const *strings, int count)` +- `cJSON_Duplicate_rec` (line 2786) `cJSON * cJSON_Duplicate_rec(const cJSON *item, size_t depth, cJSON_bool recurse)` +- `skip_oneline_comment` (line 2873) `static void skip_oneline_comment(char **input)` +- `skip_multiline_comment` (line 2886) `static void skip_multiline_comment(char **input)` +- `minify_string` (line 2900) `static void minify_string(char **input, char **output)` +- `CJSON_PUBLIC` (line 2922) `CJSON_PUBLIC(void) cJSON_Minify(char *json)` +- `CJSON_PUBLIC` (line 2972) `CJSON_PUBLIC(cJSON_bool) cJSON_IsInvalid(const cJSON * const item)` +- `CJSON_PUBLIC` (line 2982) `CJSON_PUBLIC(cJSON_bool) cJSON_IsFalse(const cJSON * const item)` +- `CJSON_PUBLIC` (line 2992) `CJSON_PUBLIC(cJSON_bool) cJSON_IsTrue(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3002) `CJSON_PUBLIC(cJSON_bool) cJSON_IsBool(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3012) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNull(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3022) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNumber(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3032) `CJSON_PUBLIC(cJSON_bool) cJSON_IsString(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3042) `CJSON_PUBLIC(cJSON_bool) cJSON_IsArray(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3052) `CJSON_PUBLIC(cJSON_bool) cJSON_IsObject(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3062) `CJSON_PUBLIC(cJSON_bool) cJSON_IsRaw(const cJSON * const item)` +- `CJSON_PUBLIC` (line 3072) `CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_...` +- `cJSON_ArrayForEach` (line 3157) `cJSON_ArrayForEach(a_element, a)` +- `cJSON_ArrayForEach` (line 3173) `cJSON_ArrayForEach(b_element, b)` - *doing this twice, once on a and b to prevent true comparison if a subset of b * TODO: Do this the proper way, this is just a fix for now* +- `CJSON_PUBLIC` (line 3194) `CJSON_PUBLIC(void *) cJSON_malloc(size_t size)` +- `CJSON_PUBLIC` (line 3199) `CJSON_PUBLIC(void) cJSON_free(void *object)` + +**Macros:** +- `_CRT_SECURE_NO_DEPRECATE` (line 28) `#define _CRT_SECURE_NO_DEPRECATE` +- `true` (line 65) `#define true` +- `false` (line 70) `#define false` +- `isinf` (line 74) `#define isinf(d)` +- `isnan` (line 77) `#define isnan(d)` +- `NAN` (line 82) `#define NAN` +- `NAN` (line 84) `#define NAN` +- `internal_malloc` (line 179) `#define internal_malloc` +- `internal_free` (line 180) `#define internal_free` +- `internal_realloc` (line 181) `#define internal_realloc` +- `static_strlen` (line 185) `#define static_strlen(string_literal)` +- `can_read` (line 301) `#define can_read(buffer, size)` +- `can_access_at_index` (line 303) `#define can_access_at_index(buffer, index)` +- `cannot_access_at_index` (line 304) `#define cannot_access_at_index(buffer, index)` +- `buffer_at_offset` (line 306) `#define buffer_at_offset(buffer)` +- `cjson_min` (line 1241) `#define cjson_min(a, b)` + +**Structs:** +- `internal_hooks` (line 157) +- `error` (line 88) +- `parse_buffer` (line 291) +- `printbuffer` (line 482) + +### H (8 files) + +#### `COFFLoader.h` +**Path:** `COFFLoader.h` + +**Imported by:** `beacon.c` + +**Macros:** +- `COFFLOADER_H` (line 21) `#define COFFLOADER_H` + +#### `aes.h` +**Path:** `aes.h` +**File Doc:** *#define the macros below to 1/0 to enable/disable the mode of operation.* + +**Imported by:** `aes.c`, `beacon.c` + +**Functions:** +- `AES_init_ctx` (line 41) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key);` +- `AES_init_ctx_iv` (line 43) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv);` - *if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1))* +- `AES_ctx_set_iv` (line 44) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv);` +- `AES_ECB_encrypt` (line 48) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf);` - *if defined(ECB) && (ECB == 1)* +- `AES_ECB_decrypt` (line 49) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf);` +- `AES_CBC_encrypt_buffer` (line 53) `void AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` - *if defined(CBC) && (CBC == 1)* +- `AES_CBC_decrypt_buffer` (line 54) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` +- `AES_CTR_xcrypt_buffer` (line 58) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` - *if defined(CTR) && (CTR == 1)* + +**Macros:** +- `_AES_H_` (line 2) `#define _AES_H_` +- `CBC` (line 9) `#define CBC` +- `ECB` (line 12) `#define ECB` +- `CTR` (line 15) `#define CTR` +- `AES256` (line 18) `#define AES256` +- `AES_BLOCKLEN` (line 20) `#define AES_BLOCKLEN` +- `AES_KEYLEN` (line 23) `#define AES_KEYLEN` +- `AES_keyExpSize` (line 24) `#define AES_keyExpSize` +- `AES_KEYLEN` (line 26) `#define AES_KEYLEN` +- `AES_keyExpSize` (line 27) `#define AES_keyExpSize` +- `AES_KEYLEN` (line 29) `#define AES_KEYLEN` +- `AES_keyExpSize` (line 30) `#define AES_keyExpSize` + +**Structs:** +- `AES_ctx` (line 33) + +#### `beacon.h` +**Path:** `beacon.h` + +**Imported by:** `COFFLoader3.c`, `Test.c`, `beacon.c`, `calc.c`, `etw.c` + +**Macros:** +- `BEACON_H` (line 21) `#define BEACON_H` +- `CALLBACK_OUTPUT` (line 41) `#define CALLBACK_OUTPUT` +- `CALLBACK_ERROR` (line 42) `#define CALLBACK_ERROR` + +**Structs:** +- `datap` (line 25) + +#### `beacon.h` +**Path:** `bof/calc/beacon.h` + +**Macros:** +- `BEACON_H` (line 21) `#define BEACON_H` +- `CALLBACK_OUTPUT` (line 41) `#define CALLBACK_OUTPUT` +- `CALLBACK_ERROR` (line 42) `#define CALLBACK_ERROR` + +**Structs:** +- `datap` (line 25) + +#### `beacon.h` +**Path:** `bof/etw/beacon.h` + +**Macros:** +- `BEACON_H` (line 21) `#define BEACON_H` +- `CALLBACK_OUTPUT` (line 41) `#define CALLBACK_OUTPUT` +- `CALLBACK_ERROR` (line 42) `#define CALLBACK_ERROR` + +**Structs:** +- `datap` (line 25) + +#### `beacon.h` +**Path:** `bof/test/beacon.h` + +**Macros:** +- `BEACON_H` (line 21) `#define BEACON_H` +- `CALLBACK_OUTPUT` (line 41) `#define CALLBACK_OUTPUT` +- `CALLBACK_ERROR` (line 42) `#define CALLBACK_ERROR` + +**Structs:** +- `datap` (line 25) + +#### `beacon.h` +**Path:** `bof/whoami/beacon.h` + +**Macros:** +- `BEACON_H` (line 21) `#define BEACON_H` +- `CALLBACK_OUTPUT` (line 41) `#define CALLBACK_OUTPUT` +- `CALLBACK_ERROR` (line 42) `#define CALLBACK_ERROR` + +**Structs:** +- `datap` (line 25) + +#### `cJSON.h` +**Path:** `cJSON.h` + +**Imported by:** `beacon.c`, `cJSON.c` + +**Functions:** +- `sensitive` (line 249) `* case_sensitive determines if object keys are treated case sensitive (1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo` + +**Macros:** +- `cJSON__h` (line 24) `#define cJSON__h` +- `__WINDOWS__` (line 32) `#define __WINDOWS__` +- `CJSON_CDECL` (line 44) `#define CJSON_CDECL` +- `CJSON_STDCALL` (line 45) `#define CJSON_STDCALL` +- `CJSON_EXPORT_SYMBOLS` (line 49) `#define CJSON_EXPORT_SYMBOLS` +- `CJSON_PUBLIC` (line 53) `#define CJSON_PUBLIC(type)` +- `CJSON_PUBLIC` (line 55) `#define CJSON_PUBLIC(type)` +- `CJSON_PUBLIC` (line 57) `#define CJSON_PUBLIC(type)` +- `CJSON_CDECL` (line 60) `#define CJSON_CDECL` +- `CJSON_STDCALL` (line 61) `#define CJSON_STDCALL` +- `CJSON_PUBLIC` (line 64) `#define CJSON_PUBLIC(type)` +- `CJSON_PUBLIC` (line 66) `#define CJSON_PUBLIC(type)` +- `CJSON_VERSION_MAJOR` (line 71) `#define CJSON_VERSION_MAJOR` +- `CJSON_VERSION_MINOR` (line 72) `#define CJSON_VERSION_MINOR` +- `CJSON_VERSION_PATCH` (line 73) `#define CJSON_VERSION_PATCH` +- `cJSON_Invalid` (line 78) `#define cJSON_Invalid` +- `cJSON_False` (line 79) `#define cJSON_False` +- `cJSON_True` (line 80) `#define cJSON_True` +- `cJSON_NULL` (line 81) `#define cJSON_NULL` +- `cJSON_Number` (line 82) `#define cJSON_Number` +- `cJSON_String` (line 83) `#define cJSON_String` +- `cJSON_Array` (line 84) `#define cJSON_Array` +- `cJSON_Object` (line 85) `#define cJSON_Object` +- `cJSON_Raw` (line 86) `#define cJSON_Raw` +- `cJSON_IsReference` (line 88) `#define cJSON_IsReference` +- `cJSON_StringIsConst` (line 89) `#define cJSON_StringIsConst` +- `CJSON_NESTING_LIMIT` (line 126) `#define CJSON_NESTING_LIMIT` +- `CJSON_CIRCULAR_LIMIT` (line 132) `#define CJSON_CIRCULAR_LIMIT` +- `cJSON_SetIntValue` (line 270) `#define cJSON_SetIntValue(object, number)` +- `cJSON_SetNumberValue` (line 273) `#define cJSON_SetNumberValue(object, number)` +- `cJSON_SetBoolValue` (line 278) `#define cJSON_SetBoolValue(object, boolValue)` +- `cJSON_ArrayForEach` (line 285) `#define cJSON_ArrayForEach(element, array)` + +**Structs:** +- `cJSON` (line 92) - *#define cJSON_Invalid (0) #define cJSON_False (1 << 0) #define cJSON_True (1 << 1) #define cJSON_NULL (1 << 2) #define cJSON_Number (1 << 3) #define cJSON_String (1 << 4) #define cJSON_Array (1 << 5) #define cJSON_Object (1 << 6) #define cJSON_Raw (1 << 7) /* raw json #define cJSON_IsReference 256 #define cJSON_StringIsConst 512 /* The cJSON structure:* +- `cJSON_Hooks` (line 114) + +**Type_Aliases:** +- `cJSON_bool` (line 120) `typedef int cJSON_bool;` + +**Variables:** +- `next` (line 27) `extern "C" { #endif #if !defined(__WINDOWS__) && (defined(WIN32) || defined(WIN64) || defined(_MSC_VER) || defined(_WIN32)) #define __WINDOWS__ #endif #ifdef __WINDOWS__ /* When compiling for windows,` - *ifdef __cplusplus* + +### PY (3 files) + +#### `app.py` +**Path:** `app.py` +**File Doc:** *This file is part of Black Basalt Beacon. Black Basalt Beacon is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Black Basalt Beacon is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Black Basalt Beacon. If not, see . Copyright (c) LazyOwn RedTeam 2025. All rights reserved.* + +*No symbols extracted* + +#### `tel.py` +**Path:** `bof/test/tel.py` + +**Functions:** +- `get_machine_id` (line 8) `def get_machine_id()` +- `get_version` (line 20) `def get_version()` +- `to_numbers` (line 31) `def to_numbers(hex_str)` - *Simula la función toNumbers de JavaScript* +- `to_hex` (line 35) `def to_hex(byte_list)` - *Simula la función toHex de JavaScript* +- `decrypt_cookie` (line 39) `def decrypt_cookie(encrypted, key, iv)` - *Descifra usando AES en modo CBC (como slowAES.decrypt(c,2,a,b))* +- `main` (line 45) `def main()` - *Sistema de telemetría de uso por instalación no invasiva.* + +#### `generate_hashs.py` +**Path:** `generate_hashs.py` +**File Doc:** *BOF Bindings Generator for Cobalt Strike Author: Gris Iscomeback Email: grisiscomeback@gmail.com Creation Date: 13/08/2024 License: GPL v3 Generates: - COFFLoader3.c: full COFF loader with DJB2 hash table - bof_test.c: ready-to-compile BOF with all imports and example* + +**Functions:** +- `djb2` (line 23) `def djb2(s)` +- `generate_coff_loader` (line 223) `def generate_coff_loader()` +- `generate_bof_test` (line 491) `def generate_bof_test()` +- `main` (line 553) `def main()` + +### SH (7 files) + +#### `gen_beacon.sh` +**Path:** `gen_beacon.sh` +**File Doc:** *=== beacon-GEN v1.2 ===* + +**Functions:** +- `show_help` (line 34) - *=== FUNCIONES ===* +- `xor_string` (line 138) - *=== XOR STRING TO BYTES ===* +- `crc32` (line 5916) + +#### `gen_dll.sh` +**Path:** `gen_dll.sh` +**File Doc:** *1. Generar DLL* + +*No symbols extracted* + +#### `gen_dll_rev.sh` +**Path:** `gen_dll_rev.sh` +**File Doc:** *=== CONFIGURACIÓN POR DEFECTO ===* + +**Functions:** +- `usage` (line 12) - *=== USO ===* + +#### `gen_dll_ss.sh` +**Path:** `gen_dll_ss.sh` +**File Doc:** *=== CONFIGURACIÓN POR DEFECTO ===* + +**Functions:** +- `usage` (line 10) - *=== USO ===* + +#### `gen_key.sh` +**Path:** `gen_key.sh` +**File Doc:** *=== CONFIGURACIÓN POR DEFECTO ===* + +**Functions:** +- `usage` (line 10) - *=== USO ===* + +#### `gen_module.sh` +**Path:** `gen_module.sh` +**File Doc:** *=== gen_cmd_dll.sh v1.0 === Genera DLL y shellcode ofuscado para ejecutar un comando Uso: ./gen_cmd_dll.sh --cmd "powershell..." [--key 0x33] [--output payload]* + +**Functions:** +- `show_help` (line 18) - *=== FUNCIONES ===* +- `xor_obfuscate` (line 35) - *Función para ofuscar binario con XOR y convertir a \x..* + +#### `install.sh` +**Path:** `install.sh` + +*No symbols extracted* diff --git a/README.md b/README.md index 5c328ee..ce0adec 100644 --- a/README.md +++ b/README.md @@ -440,3 +440,35 @@ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLI ![Python](https://img.shields.io/badge/python-3670A0?style=for-the-badge&logo=python&logoColor=ffdd54) ![Shell Script](https://img.shields.io/badge/shell_script-%23121011.svg?style=for-the-badge&logo=gnu-bash&logoColor=white) ![Flask](https://img.shields.io/badge/flask-%23000.svg?style=for-the-badge&logo=flask&logoColor=white) [![License: GPL v3](https://img.shields.io/badge/License-GPLv3-blue.svg)](https://www.gnu.org/licenses/gpl-3.0) [![ko-fi](https://ko-fi.com/img/githubbutton_sm.svg)](https://ko-fi.com/Y8Y2Z73AV) + + +--- +### Grisuno Offensive Security Ecosystem +This tool is part of a broader, synergistic RedTeam workflow: +- [LazyOwn](https://github.com/grisuno/LazyOwn): RedTeam/APT framework with AI-powered C&C, rootkits and malleable implants (Windows/Linux/Mac). +- [LazyOwnBT](https://github.com/grisuno/LazyOwnBT): Advanced complementary toolkit for BlueTeam professionals. +- [Lazymapd](https://github.com/grisuno/Lazymapd): Fast, customizable port scanner for firewall evasion. + + +## Knowledge Base + +This project has been analyzed by [ReadMenator](https://github.com/grisuno/ReadMenator), +a zero-token polyglot static analysis tool. Analysis outputs are available: + +- **[KNOWLEDGE_BASE.md](./KNOWLEDGE_BASE.md)** -- Full architecture reference with all + classes, functions, imports, dependency graphs, UML class diagrams, security + audit findings, community analysis, and more. +- **[readmenator-agent/](./readmenator-agent/)** -- Agent-friendly, grep-optimized index. + - `INDEX.md` -- Quick reference: what each file does + - `API.md` -- Public function contracts + - `GOTCHAS.md` -- Change warnings + - `SECURITY.md` -- Findings by severity +- **[readmenator-wiki/](./readmenator-wiki/)** -- Navigable wiki (start here for the big picture). + - `index.md` -- Entry point: overview, reading order, god nodes, connections + - `community_*.md` -- One synthesis page per code community + - `REPORT.md` -- Honest audit: coverage, confidence, limits + +AI agents: Read `readmenator-wiki/index.md` first for the big picture, then `readmenator-agent/INDEX.md` for grep-friendly lookup. +Developers: Read `KNOWLEDGE_BASE.md` for full architecture reference. + + diff --git a/issues/README.md b/issues/README.md new file mode 100644 index 0000000..f227f54 --- /dev/null +++ b/issues/README.md @@ -0,0 +1,22 @@ +# Repository: beacon + +**Description:** Experimental Lightweight Windows pure C Beacon CodeName: BlackBasalt for LazyOwn RedTeam Framework C2 + +| Metric | Value | +|--------|-------| +| Stars | 13 | +| Clones (last 14 days) | 99 | +| Open Issues | 2 | +| Total Issues | 0 | +| Dependabot Open Alerts | 1 | +| CodeScan Open Alerts | 1 | + +## Issues + +## Dependabot Alerts +- [Dependabot #0](./dependabot/alert_0.md) - unknown (N/A) - unknown + +## Code Scanning Alerts +- [CodeScan #0](./codescan/alert_0.md) - N/A (N/A) - unknown + +Total issues downloaded: 0 diff --git a/issues/codescan/alert_0.md b/issues/codescan/alert_0.md new file mode 100644 index 0000000..ff8739e --- /dev/null +++ b/issues/codescan/alert_0.md @@ -0,0 +1,10 @@ +# Code Scanning Alert #0: N/A + +- **State:** unknown +- **Severity:** N/A +- **Tool:** unknown +- **Created:** +- **URL:** + +## Description + diff --git a/issues/dependabot/alert_0.md b/issues/dependabot/alert_0.md new file mode 100644 index 0000000..e57e89b --- /dev/null +++ b/issues/dependabot/alert_0.md @@ -0,0 +1,13 @@ +# Dependabot Alert #0: unknown + +- **State:** unknown +- **Severity:** N/A +- **CVE:** N/A +- **Created:** +- **URL:** + +## Summary + + +## Description + diff --git a/readmenator-agent/API.md b/readmenator-agent/API.md new file mode 100644 index 0000000..c2d4324 --- /dev/null +++ b/readmenator-agent/API.md @@ -0,0 +1,1431 @@ +# API + +## COFFLoader3.c + +### djb2_hash (function) `static uint32_t djb2_hash(const char* str)` +- Defined: `COFFLoader3.c:632` +- Doc: === Función hash DJB2 === +- Depends on: `beacon.h` + +### create_trampoline (function) `static void* create_trampoline(void* target)` +- Defined: `COFFLoader3.c:913` +- Depends on: `beacon.h` + +### handle_relocation (function) `BOOL handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ...` +- Defined: `COFFLoader3.c:940` +- Depends on: `beacon.h` + +### get_symbol_name (function) `static char* get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size)` +- Defined: `COFFLoader3.c:1080` +- Depends on: `beacon.h` + +### __attribute__ (function) `__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2)` +- Defined: `COFFLoader3.c:1103` +- Depends on: `beacon.h` + +### RunCOFF (function) `int RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*...` +- Defined: `COFFLoader3.c:1112` +- Doc: === Cargador COFF === +- Depends on: `beacon.h` + +## aes.c + +### getSBoxValue (function) `static uint8_t getSBoxValue(uint8_t num)` +- Defined: `aes.c:13` +- Depends on: `aes.h` + +### getSBoxInvert (function) `static uint8_t getSBoxInvert(uint8_t num)` +- Defined: `aes.c:35` +- Depends on: `aes.h` + +### Td0 (function) `static uint8_t Td0(int x)` +- Defined: `aes.c:57` +- Depends on: `aes.h` + +### Td1 (function) `static uint8_t Td1(int x)` +- Defined: `aes.c:58` +- Depends on: `aes.h` + +### Td2 (function) `static uint8_t Td2(int x)` +- Defined: `aes.c:59` +- Depends on: `aes.h` + +### Td3 (function) `static uint8_t Td3(int x)` +- Defined: `aes.c:60` +- Depends on: `aes.h` + +### Td4 (function) `static uint8_t Td4(int x)` +- Defined: `aes.c:61` +- Depends on: `aes.h` + +### KeyExpansion (function) `static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key)` +- Defined: `aes.c:166` +- Doc: This function produces Nb(Nr+1) round keys. The round keys are used in each round to decrypt the states. +- Depends on: `aes.h` + +### AES_init_ctx (function) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key)` +- Defined: `aes.c:239` +- Depends on: `aes.h` + +### AES_init_ctx_iv (function) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv)` +- Defined: `aes.c:244` +- Doc: if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1)) +- Depends on: `aes.h` + +### AES_ctx_set_iv (function) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv)` +- Defined: `aes.c:249` +- Depends on: `aes.h` + +### AddRoundKey (function) `static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)` +- Defined: `aes.c:257` +- Doc: This function adds the round key to state. The round key is added to the state by an XOR function. +- Depends on: `aes.h` + +### SubBytes (function) `static void SubBytes(state_t* state)` +- Defined: `aes.c:271` +- Doc: The SubBytes Function Substitutes the values in the state matrix with values in an S-box. +- Depends on: `aes.h` + +### ShiftRows (function) `static void ShiftRows(state_t* state)` +- Defined: `aes.c:286` +- Doc: The ShiftRows() function shifts the rows in the state to the left. Each row is shifted with different offset. Offset = R +- Depends on: `aes.h` + +### xtime (function) `static uint8_t xtime(uint8_t x)` +- Defined: `aes.c:314` +- Depends on: `aes.h` + +### MixColumns (function) `static void MixColumns(state_t* state)` +- Defined: `aes.c:320` +- Doc: MixColumns function mixes the columns of the state matrix +- Depends on: `aes.h` + +### Multiply (function) `static uint8_t Multiply(uint8_t x, uint8_t y)` +- Defined: `aes.c:340` +- Doc: Multiply is used to multiply numbers in the field GF(2^8) Note: The last call to xtime() is unneeded, but often ends up +- Depends on: `aes.h` + +### InvMixColumns (function) `static void InvMixColumns(state_t* state)` +- Defined: `aes.c:370` +- Doc: MixColumns function mixes the columns of the state matrix. The method used to multiply may be difficult to understand fo +- Depends on: `aes.h` + +### InvSubBytes (function) `static void InvSubBytes(state_t* state)` +- Defined: `aes.c:391` +- Doc: The SubBytes Function Substitutes the values in the state matrix with values in an S-box. +- Depends on: `aes.h` + +### InvShiftRows (function) `static void InvShiftRows(state_t* state)` +- Defined: `aes.c:403` +- Depends on: `aes.h` + +### Cipher (function) `static void Cipher(state_t* state, const uint8_t* RoundKey)` +- Defined: `aes.c:433` +- Doc: Cipher is the main function that encrypts the PlainText. +- Depends on: `aes.h` + +### InvCipher (function) `static void InvCipher(state_t* state, const uint8_t* RoundKey)` +- Defined: `aes.c:459` +- Doc: if (defined(CBC) && CBC == 1) || (defined(ECB) && ECB == 1) +- Depends on: `aes.h` + +### AES_ECB_encrypt (function) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf)` +- Defined: `aes.c:490` +- Depends on: `aes.h` + +### AES_ECB_decrypt (function) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf)` +- Defined: `aes.c:496` +- Depends on: `aes.h` + +### XorWithIv (function) `static void XorWithIv(uint8_t* buf, const uint8_t* Iv)` +- Defined: `aes.c:512` +- Depends on: `aes.h` + +### AES_CBC_encrypt_buffer (function) `void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length)` +- Defined: `aes.c:521` +- Depends on: `aes.h` + +### AES_CBC_decrypt_buffer (function) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` +- Defined: `aes.c:536` +- Depends on: `aes.h` + +### AES_CTR_xcrypt_buffer (function) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` +- Defined: `aes.c:558` +- Doc: XorWithIv(buf, ctx->Iv); memcpy(ctx->Iv, storeNextIv, AES_BLOCKLEN); buf += AES_BLOCKLEN; } } #endif // #if defined(CBC) +- Depends on: `aes.h` + +## aes.h + +### AES_init_ctx (function) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key);` +- Defined: `aes.h:41` +- Imported by: `aes.c`, `beacon.c` + +### AES_init_ctx_iv (function) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv);` +- Defined: `aes.h:43` +- Doc: if (defined(CBC) && (CBC == 1)) || (defined(CTR) && (CTR == 1)) +- Imported by: `aes.c`, `beacon.c` + +### AES_ctx_set_iv (function) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv);` +- Defined: `aes.h:44` +- Imported by: `aes.c`, `beacon.c` + +### AES_ECB_encrypt (function) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf);` +- Defined: `aes.h:48` +- Doc: if defined(ECB) && (ECB == 1) +- Imported by: `aes.c`, `beacon.c` + +### AES_ECB_decrypt (function) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf);` +- Defined: `aes.h:49` +- Imported by: `aes.c`, `beacon.c` + +### AES_CBC_encrypt_buffer (function) `void AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` +- Defined: `aes.h:53` +- Doc: if defined(CBC) && (CBC == 1) +- Imported by: `aes.c`, `beacon.c` + +### AES_CBC_decrypt_buffer (function) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` +- Defined: `aes.h:54` +- Imported by: `aes.c`, `beacon.c` + +### AES_CTR_xcrypt_buffer (function) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` +- Defined: `aes.h:58` +- Doc: if defined(CTR) && (CTR == 1) +- Imported by: `aes.c`, `beacon.c` + +## beacon.c + +### ExceptionFilter (function) `static LONG WINAPI ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo)` +- Defined: `beacon.c:253` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### get_shell_cmd (function) `const char* get_shell_cmd()` +- Defined: `beacon.c:335` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size)` +- Defined: `beacon.c:417` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size)` +- Defined: `beacon.c:423` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) int BeaconDataInt(datap * parser)` +- Defined: `beacon.c:431` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) short BeaconDataShort(datap * parser)` +- Defined: `beacon.c:436` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) int BeaconDataLength(datap * parser)` +- Defined: `beacon.c:441` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size)` +- Defined: `beacon.c:446` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...)` +- Defined: `beacon.c:456` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __declspec (function) `__declspec(dllexport) void BeaconOutput(int type, const char * data, int len)` +- Defined: `beacon.c:504` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### MapDllNameToModule (function) `HMODULE MapDllNameToModule(char* dllName)` +- Defined: `beacon.c:521` +- Doc: === MAP DLL NAME TO REAL DLL === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetSyscallNumber (function) `DWORD GetSyscallNumber(PVOID func_addr)` +- Defined: `beacon.c:549` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### HellsGate (function) `DWORD HellsGate(DWORD ssn)` +- Defined: `beacon.c:561` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### __attribute__ (function) `__attribute__((naked)) +NTSTATUS HellDescent( + DWORD64 arg1, DWORD64 arg2, DWORD64 arg3, + DW...` +- Defined: `beacon.c:566` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetProcessIdByName (function) `DWORD GetProcessIdByName(const char* processName)` +- Defined: `beacon.c:582` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### ExecuteTLSCallbacks (function) `void ExecuteTLSCallbacks(PVOID moduleBase)` +- Defined: `beacon.c:600` +- Doc: === EJECUTAR TLS CALLBACKS === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### MapModuleToMemory (function) `PVOID MapModuleToMemory(unsigned char* fileBuffer, DWORD fileSize)` +- Defined: `beacon.c:617` +- Doc: === Carga un módulo en memoria === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### ExecuteModule (function) `BOOL ExecuteModule(PVOID moduleBase)` +- Defined: `beacon.c:706` +- Doc: === Ejecuta el módulo (DllMain o EntryPoint) === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### LoadModuleFromURL (function) `BOOL LoadModuleFromURL(const char* url)` +- Defined: `beacon.c:751` +- Doc: === Carga y ejecuta un módulo desde URL === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### xor_string (function) `void xor_string(char* data, size_t len, char key)` +- Defined: `beacon.c:915` +- Doc: === XOR === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### anti_analysis (function) `BOOL anti_analysis()` +- Defined: `beacon.c:922` +- Doc: === ANTI-ANALYSIS === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### load_lazyconf (function) `BOOL load_lazyconf()` +- Defined: `beacon.c:946` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetNtdllBase (function) `HMODULE GetNtdllBase()` +- Defined: `beacon.c:1184` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### isVMByMAC (function) `BOOL isVMByMAC()` +- Defined: `beacon.c:1232` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### extract_shellcode (function) `int extract_shellcode(const char* input, size_t len, unsigned char** out)` +- Defined: `beacon.c:1303` +- Doc: === EXTRAER SHELLCODE === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### hex_char_to_byte (function) `BYTE hex_char_to_byte(char c)` +- Defined: `beacon.c:1334` +- Doc: Función para convertir hex a bytes +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### hex_to_bytes (function) `void hex_to_bytes(const char* hex, BYTE* output, size_t len)` +- Defined: `beacon.c:1341` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### executeLoader (function) `void executeLoader(void *arg)` +- Defined: `beacon.c:1348` +- Doc: === executeLoader === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### ReverseShell (function) `void __cdecl ReverseShell(void* arg)` +- Defined: `beacon.c:1404` +- Doc: ======================== FUNCIÓN DE INYECCIÓN DE SHELL ======================== +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### ReadFromProcess (function) `DWORD WINAPI ReadFromProcess(LPVOID lpParam)` +- Defined: `beacon.c:1513` +- Doc: === Hilo para leer salida del proceso (como en el ejemplo que funciona) === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetJitteredSleep (function) `DWORD GetJitteredSleep(DWORD base_ms)` +- Defined: `beacon.c:1587` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetUsefulSoftware (function) `char* GetUsefulSoftware()` +- Defined: `beacon.c:1592` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### base64_encode (function) `char* base64_encode(const unsigned char* data, size_t inputLen)` +- Defined: `beacon.c:1627` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### base64_decode (function) `char* base64_decode(const char* input, size_t* out_len)` +- Defined: `beacon.c:1663` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### discoverLocalHosts (function) `void discoverLocalHosts()` +- Defined: `beacon.c:1696` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### initProxy (function) `void initProxy()` +- Defined: `beacon.c:1753` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### relay_thread (function) `void WINAPI relay_thread(void* param)` +- Defined: `beacon.c:1763` +- Doc: Función para reenviar datos entre sockets +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### proxy_thread (function) `void WINAPI proxy_thread(void* param)` +- Defined: `beacon.c:1784` +- Doc: Tu función proxy_thread usando tus estructuras exactas +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### proxy_accept_thread (function) `void WINAPI proxy_accept_thread(void* param)` +- Defined: `beacon.c:1855` +- Doc: Thread para aceptar conexiones +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### startProxy (function) `BOOL startProxy(const char* listenAddr, const char* targetAddr)` +- Defined: `beacon.c:1923` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### stopProxy (function) `BOOL stopProxy(const char* listenAddr)` +- Defined: `beacon.c:2010` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### cleanupProxy (function) `void cleanupProxy()` +- Defined: `beacon.c:2062` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### compressDirectory (function) `BOOL compressDirectory(const char* dirPath)` +- Defined: `beacon.c:2094` +- Doc: Función simplificada para compresión de directorios +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### getNetworkConfig (function) `char* getNetworkConfig()` +- Defined: `beacon.c:2104` +- Doc: Para netconfig +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### UploadFileToC2 (function) `BOOL UploadFileToC2(const char* url, const char* filePath)` +- Defined: `beacon.c:2108` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### handleUpload (function) `BOOL handleUpload(const char* command)` +- Defined: `beacon.c:2280` +- Doc: === handleUpload: envía del beacon al C2 === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### FileExistsA (function) `BOOL FileExistsA(const char* filePath)` +- Defined: `beacon.c:2301` +- Doc: Función para verificar si un archivo existe +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### selfDestruct (function) `void selfDestruct()` +- Defined: `beacon.c:2306` +- Doc: selfdestruct.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### stristr (function) `char* stristr(const char* str, const char* pattern)` +- Defined: `beacon.c:2362` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### isSensitiveFile (function) `int isSensitiveFile(const char* filename)` +- Defined: `beacon.c:2378` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### searchCredentials (function) `char* searchCredentials(const char* basePath)` +- Defined: `beacon.c:2425` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### UTF8ToWide (function) `WCHAR* UTF8ToWide(const char* utf8)` +- Defined: `beacon.c:2551` +- Doc: Convierte UTF-8 a wide string +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### obfuscateFileTimestamp (function) `BOOL obfuscateFileTimestamp(const char* filepath)` +- Defined: `beacon.c:2562` +- Doc: Ofusca los timestamps de un archivo +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### obfuscateFileTimestamps (function) `void obfuscateFileTimestamps(const char* basePath, int depth)` +- Defined: `beacon.c:2592` +- Doc: Recorre directorios buscando archivos sensibles +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### simulateLegitimateTraffic (function) `void simulateLegitimateTraffic(void* param)` +- Defined: `beacon.c:2656` +- Doc: traffic.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### restartClient (function) `void restartClient()` +- Defined: `beacon.c:2735` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### checkDebuggers (function) `BOOL checkDebuggers()` +- Defined: `beacon.c:2776` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### MapPEToMemory (function) `unsigned char* MapPEToMemory(unsigned char* rawPE, DWORD rawSize, DWORD* mappedSize)` +- Defined: `beacon.c:2838` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### downloadAndExecute (function) `BOOL downloadAndExecute(const char* url, const char* targetProcess)` +- Defined: `beacon.c:2861` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### DecryptPacket (function) `BOOL DecryptPacket(BYTE* buffer, DWORD* buffer_len)` +- Defined: `beacon.c:2911` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetIPs (function) `char* GetIPs()` +- Defined: `beacon.c:3007` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetHostname (function) `char* GetHostname()` +- Defined: `beacon.c:3041` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetUsername (function) `char* GetUsername()` +- Defined: `beacon.c:3057` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### patchAMSI (function) `BOOL patchAMSI(void)` +- Defined: `beacon.c:3074` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### get_nt_headers (function) `PIMAGE_NT_HEADERS get_nt_headers(BYTE* buffer)` +- Defined: `beacon.c:3092` +- Doc: ==================================================================== PE HELPERS (usando winnt.h) ======================= +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### is_64bit (function) `BOOL is_64bit(BYTE* buffer)` +- Defined: `beacon.c:3101` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### get_image_size (function) `DWORD get_image_size(BYTE* buffer)` +- Defined: `beacon.c:3107` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### get_entry_point_rva (function) `DWORD get_entry_point_rva(BYTE* buffer)` +- Defined: `beacon.c:3113` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### pe_buffer_to_virtual_image (function) `BYTE* pe_buffer_to_virtual_image(BYTE* raw_buffer, DWORD* out_size)` +- Defined: `beacon.c:3119` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### create_suspended_process (function) `BOOL create_suspended_process(char* path, PROCESS_INFORMATION* pi)` +- Defined: `beacon.c:3149` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### get_remote_image_base (function) `ULONGLONG get_remote_image_base(PROCESS_INFORMATION* pi, BOOL is_32bit_target)` +- Defined: `beacon.c:3156` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### update_remote_entry_point (function) `BOOL update_remote_entry_point(PROCESS_INFORMATION* pi, ULONGLONG entry_point_va, BOOL is_32bit)` +- Defined: `beacon.c:3250` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### overWrite (function) `void overWrite(const char* targetPath, const char* payloadPath)` +- Defined: `beacon.c:3277` +- Doc: ==================================================================== MAIN FUNCTION: overWrite ========================== +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### cleanSystemLogs (function) `void cleanSystemLogs()` +- Defined: `beacon.c:3384` +- Doc: Limpia el historial de comandos de la consola actual +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### ensurePersistence (function) `BOOL ensurePersistence()` +- Defined: `beacon.c:3421` +- Doc: ensurePersistence.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### isSandboxEnvironment (function) `BOOL isSandboxEnvironment()` +- Defined: `beacon.c:3482` +- Doc: isSandboxEnvironment.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### tryPrivilegeEscalation (function) `void tryPrivilegeEscalation()` +- Defined: `beacon.c:3552` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### executeUACBypass (function) `BOOL executeUACBypass(const char* payloadPath)` +- Defined: `beacon.c:3557` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### scanPort (function) `void scanPort(void* arg)` +- Defined: `beacon.c:3610` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### PortScanner (function) `void PortScanner(char* targetIP, int* ports, int numPorts)` +- Defined: `beacon.c:3661` +- Doc: PortScanner.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### PortScannerWrapper (function) `void PortScannerWrapper(void* arg)` +- Defined: `beacon.c:3706` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### EarlyBirdInject (function) `BOOL EarlyBirdInject(unsigned char* shellcode, int shellcode_len)` +- Defined: `beacon.c:3729` +- Doc: === INYECCIÓN EARLY BIRD + SYSCALL === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### init_aes_context (function) `PacketEncryptionContext* init_aes_context(const char* key_hex)` +- Defined: `beacon.c:3900` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### retry_http_request (function) `char* retry_http_request(const char* url, const char* method, const char* data, int max_retries)` +- Defined: `beacon.c:3918` +- Doc: retry_http_request.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### exec_cmd (function) `char* exec_cmd(const char* cmd)` +- Defined: `beacon.c:4172` +- Doc: exec_cmd.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### GetC2Command (function) `char* GetC2Command(const char* host, const char* path)` +- Defined: `beacon.c:4200` +- Doc: c2.c (reemplaza la función actual) +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### DownloadToBuffer (function) `unsigned char* DownloadToBuffer(const char* url, DWORD* fileSize)` +- Defined: `beacon.c:4347` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### DownloadFromURL (function) `BOOL DownloadFromURL(const char* url, const char* filepath)` +- Defined: `beacon.c:4423` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### encrypt_data (function) `char* encrypt_data(const char* data)` +- Defined: `beacon.c:4454` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### isValidUUID (function) `BOOL isValidUUID(const char* uuid)` +- Defined: `beacon.c:4512` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### deleteFilesDelay (function) `void deleteFilesDelay(void* arg)` +- Defined: `beacon.c:4537` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### executeCommand (function) `void executeCommand(void* cmdPtr)` +- Defined: `beacon.c:4551` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### handleAtomic (function) `void handleAtomic(char* command)` +- Defined: `beacon.c:4560` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### handleDownload (function) `BOOL handleDownload(const char* command)` +- Defined: `beacon.c:4683` +- Doc: === handleDownload: descarga del C2 al beacon === +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### SerializeBeaconString (function) `void SerializeBeaconString(char* buffer, int* offset, const char* str)` +- Defined: `beacon.c:4703` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### BeaconDataSerializeString (function) `void BeaconDataSerializeString(char* buffer, int* offset, const char* str)` +- Defined: `beacon.c:4712` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### go (function) `void go(unsigned char * bof_data, int bof_size, char * args, int args_len)` +- Defined: `beacon.c:4720` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### handleAdversary (function) `void handleAdversary(char* command)` +- Defined: `beacon.c:4738` +- Doc: Función principal de manejo de comandos +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +### main (function) `int main()` +- Defined: `beacon.c:5233` +- Doc: main.c +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +## bof/calc/calc.c + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/calc/calc.c:34` +- Doc: ================================ FUNCIÓN PRINCIPAL ================================ +- Depends on: `bof/calc/beacon.h` + +## bof/etw/etw.c + +### go (function) `void go(char *a,int l)` +- Defined: `bof/etw/etw.c:26` +- Depends on: `bof/etw/beacon.h` + +## bof/test/Test.c + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/Test.c:3` +- Depends on: `bof/test/beacon.h` + +## bof/test/amsibypass.c + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/amsibypass.c:34` +- Doc: ================================ FUNCIÓN PRINCIPAL ================================ +- Depends on: `bof/test/beacon.h` + +## bof/test/cmdwhoami.c + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/cmdwhoami.c:43` +- Depends on: `bof/test/beacon.h` + +## bof/test/disablelog.c + +### my_wcscmp (function) `static int my_wcscmp(const wchar_t *s1, const wchar_t *s2)` +- Defined: `bof/test/disablelog.c:37` +- Depends on: `bof/test/beacon.h` + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/disablelog.c:69` +- Depends on: `bof/test/beacon.h` + +## bof/test/getenv.c + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/getenv.c:25` +- Depends on: `bof/test/beacon.h` + +## bof/test/loadvnc.c + +### execute_cmd_hidden (function) `void execute_cmd_hidden(char* cmd)` +- Defined: `bof/test/loadvnc.c:51` +- Doc: ================================ FUNCIÓN AUX: EJECUTAR COMANDO OCULTO ================================ +- Depends on: `bof/test/beacon.h` + +### go (function) `void go(char *args, int alen)` +- Defined: `bof/test/loadvnc.c:81` +- Doc: ================================ FUNCIÓN PRINCIPAL ================================ +- Depends on: `bof/test/beacon.h` + +## bof/test/make_table.c + +### Copyright (function) `Copyright (c) LazyOwn RedTeam 2025. All rights reserved. +*/ + +#include +#include free_fn != NULL) { global_hooks.deallocate = hooks->free_fn; } /* use realloc only if both free and malloc ar +- Depends on: `cJSON.h` + +### get_decimal_point (function) `static unsigned char get_decimal_point(void)` +- Defined: `cJSON.c:281` +- Doc: item->valuestring = NULL; } if (!(item->type & cJSON_StringIsConst) && (item->string != NULL)) { global_hooks.deallocate +- Depends on: `cJSON.h` + +### parse_number (function) `static cJSON_bool parse_number(cJSON * const item, parse_buffer * const input_buffer)` +- Defined: `cJSON.c:309` +- Doc: size_t offset; size_t depth; /* How deeply nested (in arrays/objects) is the input at the current offset. internal_hooks +- Depends on: `cJSON.h` + +### ensure (function) `static unsigned char* ensure(printbuffer * const p, size_t needed)` +- Defined: `cJSON.c:494` +- Doc: } typedef struct { unsigned char *buffer; size_t length; size_t offset; size_t depth; /* current nesting depth (for form +- Depends on: `cJSON.h` + +### update_offset (function) `static void update_offset(printbuffer * const buffer)` +- Defined: `cJSON.c:579` +- Doc: p->buffer = NULL; return NULL; } memcpy(newbuffer, p->buffer, p->offset + 1); p->hooks.deallocate(p->buffer); } p->lengt +- Depends on: `cJSON.h` + +### compare_double (function) `static cJSON_bool compare_double(double a, double b)` +- Defined: `cJSON.c:592` +- Doc: /* calculate the new length of the string in a printbuffer and update the offset static void update_offset(printbuffer * +- Depends on: `cJSON.h` + +### print_number (function) `static cJSON_bool print_number(const cJSON * const item, printbuffer * const output_buffer)` +- Defined: `cJSON.c:599` +- Doc: } buffer_pointer = buffer->buffer + buffer->offset; buffer->offset += strlen((const char*)buffer_pointer); } /* securely +- Depends on: `cJSON.h` + +### parse_hex4 (function) `static unsigned parse_hex4(const unsigned char * const input)` +- Defined: `cJSON.c:669` +- Doc: output_pointer[i] = '.'; continue; } output_pointer[i] = number_buffer[i]; } output_pointer[i] = '\0'; output_buffer->of +- Depends on: `cJSON.h` + +### utf16_literal_to_utf8 (function) `static unsigned char utf16_literal_to_utf8(const unsigned char * const input_pointer, const unsig...` +- Defined: `cJSON.c:706` +- Doc: converts a UTF-16 literal to UTF-8 * A literal can be one or two sequences of the form \uXXXX +- Depends on: `cJSON.h` + +### parse_string (function) `static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer)` +- Defined: `cJSON.c:827` +- Doc: else { (*output_pointer)[0] = (unsigned char)(codepoint & 0x7F); } output_pointer += utf8_length; return sequence_length +- Depends on: `cJSON.h` + +### print_string_ptr (function) `static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffer * const output_...` +- Defined: `cJSON.c:957` +- Doc: { input_buffer->hooks.deallocate(output); output = NULL; } if (input_pointer != NULL) { input_buffer->offset = (size_t)( +- Depends on: `cJSON.h` + +### print_string (function) `static cJSON_bool print_string(const cJSON * const item, printbuffer * const p)` +- Defined: `cJSON.c:1079` +- Doc: /* escape and print as unicode codepoint sprintf((char*)output_pointer, "u%04x", *input_pointer); output_pointer += 4; b +- Depends on: `cJSON.h` + +### buffer_skip_whitespace (function) `static parse_buffer *buffer_skip_whitespace(parse_buffer * const buffer)` +- Defined: `cJSON.c:1093` +- Doc: static cJSON_bool print_string(const cJSON * const item, printbuffer * const p) { return print_string_ptr((unsigned char +- Depends on: `cJSON.h` + +### skip_utf8_bom (function) `static parse_buffer *skip_utf8_bom(parse_buffer * const buffer)` +- Defined: `cJSON.c:1119` +- Doc: while (can_access_at_index(buffer, 0) && (buffer_at_offset(buffer)[0] <= 32)) { buffer->offset++; } if (buffer->offset = +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithOpts(const char *value, const char **return_parse_end, cJSON...` +- Defined: `cJSON.c:1134` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithLength(const char *value, size_t buffer_length)` +- Defined: `cJSON.c:1236` +- Depends on: `cJSON.h` + +### print (function) `static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * c...` +- Defined: `cJSON.c:1243` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(char *) cJSON_PrintUnformatted(const cJSON *item)` +- Defined: `cJSON.c:1316` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(char *) cJSON_PrintBuffered(const cJSON *item, int prebuffer, cJSON_bool fmt)` +- Defined: `cJSON.c:1321` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_PrintPreallocated(cJSON *item, char *buffer, const int length, con...` +- Defined: `cJSON.c:1352` +- Depends on: `cJSON.h` + +### parse_value (function) `static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer)` +- Defined: `cJSON.c:1372` +- Doc: return false; } p.buffer = (unsigned char*)buffer; p.length = (size_t)length; p.offset = 0; p.noalloc = true; p.format = +- Depends on: `cJSON.h` + +### print_value (function) `static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer)` +- Defined: `cJSON.c:1427` +- Doc: if (can_access_at_index(input_buffer, 0) && (buffer_at_offset(input_buffer)[0] == '[')) { return parse_array(item, input +- Depends on: `cJSON.h` + +### parse_array (function) `static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer)` +- Defined: `cJSON.c:1501` +- Doc: return print_string(item, output_buffer); case cJSON_Array: return print_array(item, output_buffer); case cJSON_Object: +- Depends on: `cJSON.h` + +### print_array (function) `static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer)` +- Defined: `cJSON.c:1599` +- Doc: input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an array +- Depends on: `cJSON.h` + +### parse_object (function) `static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer)` +- Defined: `cJSON.c:1661` +- Doc: output_pointer = ensure(output_buffer, 2); if (output_pointer == NULL) { return false; } output_pointer++ = ']'; output_ +- Depends on: `cJSON.h` + +### print_object (function) `static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer)` +- Defined: `cJSON.c:1780` +- Doc: input_buffer->offset++; return true; fail: if (head != NULL) { cJSON_Delete(head); } return false; } /* Render an object +- Depends on: `cJSON.h` + +### get_array_item (function) `static cJSON* get_array_item(const cJSON *array, size_t index)` +- Defined: `cJSON.c:1916` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_GetArrayItem(const cJSON *array, int index)` +- Defined: `cJSON.c:1935` +- Depends on: `cJSON.h` + +### get_object_item (function) `static cJSON *get_object_item(const cJSON * const object, const char * const name, const cJSON_bo...` +- Defined: `cJSON.c:1945` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItem(const cJSON * const object, const char * const string)` +- Defined: `cJSON.c:1977` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * c...` +- Defined: `cJSON.c:1982` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string)` +- Defined: `cJSON.c:1987` +- Depends on: `cJSON.h` + +### suffix_object (function) `static void suffix_object(cJSON *prev, cJSON *item)` +- Defined: `cJSON.c:1993` +- Doc: return get_object_item(object, string, false); } CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * co +- Depends on: `cJSON.h` + +### create_reference (function) `static cJSON *create_reference(const cJSON *item, const internal_hooks * const hooks)` +- Defined: `cJSON.c:2000` +- Doc: CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string) { return cJSON_GetObjectItem(objec +- Depends on: `cJSON.h` + +### add_item_to_array (function) `static cJSON_bool add_item_to_array(cJSON *array, cJSON *item)` +- Defined: `cJSON.c:2021` +- Depends on: `cJSON.h` + +### cast_away_const (function) `static void* cast_away_const(const void* string)` +- Defined: `cJSON.c:2066` +- Doc: /* Add item to array/object. CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToArray(cJSON *array, cJSON *item) { return add_item_ +- Depends on: `cJSON.h` + +### add_item_to_object (function) `static cJSON_bool add_item_to_object(cJSON * const object, const char * const string, cJSON * con...` +- Defined: `cJSON.c:2075` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToObject(cJSON *object, const char *string, cJSON *item)` +- Defined: `cJSON.c:2112` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToArray(cJSON *array, cJSON *item)` +- Defined: `cJSON.c:2123` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToObject(cJSON *object, const char *string, cJSON ...` +- Defined: `cJSON.c:2133` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddNullToObject(cJSON * const object, const char * const name)` +- Defined: `cJSON.c:2143` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddTrueToObject(cJSON * const object, const char * const name)` +- Defined: `cJSON.c:2155` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddFalseToObject(cJSON * const object, const char * const name)` +- Defined: `cJSON.c:2167` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddBoolToObject(cJSON * const object, const char * const name, const c...` +- Defined: `cJSON.c:2179` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddNumberToObject(cJSON * const object, const char * const name, const...` +- Defined: `cJSON.c:2191` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddStringToObject(cJSON * const object, const char * const name, const...` +- Defined: `cJSON.c:2203` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddRawToObject(cJSON * const object, const char * const name, const ch...` +- Defined: `cJSON.c:2215` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddObjectToObject(cJSON * const object, const char * const name)` +- Defined: `cJSON.c:2227` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON*) cJSON_AddArrayToObject(cJSON * const object, const char * const name)` +- Defined: `cJSON.c:2239` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemViaPointer(cJSON *parent, cJSON * const item)` +- Defined: `cJSON.c:2251` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromArray(cJSON *array, int which)` +- Defined: `cJSON.c:2287` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void) cJSON_DeleteItemFromArray(cJSON *array, int which)` +- Defined: `cJSON.c:2297` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObject(cJSON *object, const char *string)` +- Defined: `cJSON.c:2302` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObjectCaseSensitive(cJSON *object, const char *string)` +- Defined: `cJSON.c:2309` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObject(cJSON *object, const char *string)` +- Defined: `cJSON.c:2316` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObjectCaseSensitive(cJSON *object, const char *string)` +- Defined: `cJSON.c:2321` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemViaPointer(cJSON * const parent, cJSON * const item, cJ...` +- Defined: `cJSON.c:2363` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInArray(cJSON *array, int which, cJSON *newitem)` +- Defined: `cJSON.c:2413` +- Depends on: `cJSON.h` + +### replace_item_in_object (function) `static cJSON_bool replace_item_in_object(cJSON *object, const char *string, cJSON *replacement, c...` +- Defined: `cJSON.c:2423` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObject(cJSON *object, const char *string, cJSON *newi...` +- Defined: `cJSON.c:2446` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObjectCaseSensitive(cJSON *object, const char *string...` +- Defined: `cJSON.c:2451` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateTrue(void)` +- Defined: `cJSON.c:2468` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateFalse(void)` +- Defined: `cJSON.c:2479` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateBool(cJSON_bool boolean)` +- Defined: `cJSON.c:2490` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateNumber(double num)` +- Defined: `cJSON.c:2501` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateString(const char *string)` +- Defined: `cJSON.c:2526` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringReference(const char *string)` +- Defined: `cJSON.c:2543` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateObjectReference(const cJSON *child)` +- Defined: `cJSON.c:2555` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateArrayReference(const cJSON *child)` +- Defined: `cJSON.c:2567` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateRaw(const char *raw)` +- Defined: `cJSON.c:2579` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateArray(void)` +- Defined: `cJSON.c:2596` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateObject(void)` +- Defined: `cJSON.c:2607` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateFloatArray(const float *numbers, int count)` +- Defined: `cJSON.c:2659` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateDoubleArray(const double *numbers, int count)` +- Defined: `cJSON.c:2699` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringArray(const char *const *strings, int count)` +- Defined: `cJSON.c:2739` +- Depends on: `cJSON.h` + +### cJSON_Duplicate_rec (function) `cJSON * cJSON_Duplicate_rec(const cJSON *item, size_t depth, cJSON_bool recurse)` +- Defined: `cJSON.c:2786` +- Depends on: `cJSON.h` + +### skip_oneline_comment (function) `static void skip_oneline_comment(char **input)` +- Defined: `cJSON.c:2873` +- Depends on: `cJSON.h` + +### skip_multiline_comment (function) `static void skip_multiline_comment(char **input)` +- Defined: `cJSON.c:2886` +- Depends on: `cJSON.h` + +### minify_string (function) `static void minify_string(char **input, char **output)` +- Defined: `cJSON.c:2900` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void) cJSON_Minify(char *json)` +- Defined: `cJSON.c:2922` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsInvalid(const cJSON * const item)` +- Defined: `cJSON.c:2972` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsFalse(const cJSON * const item)` +- Defined: `cJSON.c:2982` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsTrue(const cJSON * const item)` +- Defined: `cJSON.c:2992` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsBool(const cJSON * const item)` +- Defined: `cJSON.c:3002` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNull(const cJSON * const item)` +- Defined: `cJSON.c:3012` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNumber(const cJSON * const item)` +- Defined: `cJSON.c:3022` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsString(const cJSON * const item)` +- Defined: `cJSON.c:3032` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsArray(const cJSON * const item)` +- Defined: `cJSON.c:3042` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsObject(const cJSON * const item)` +- Defined: `cJSON.c:3052` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_IsRaw(const cJSON * const item)` +- Defined: `cJSON.c:3062` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_...` +- Defined: `cJSON.c:3072` +- Depends on: `cJSON.h` + +### cJSON_ArrayForEach (function) `cJSON_ArrayForEach(a_element, a)` +- Defined: `cJSON.c:3157` +- Depends on: `cJSON.h` + +### cJSON_ArrayForEach (function) `cJSON_ArrayForEach(b_element, b)` +- Defined: `cJSON.c:3173` +- Doc: doing this twice, once on a and b to prevent true comparison if a subset of b * TODO: Do this the proper way, this is ju +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void *) cJSON_malloc(size_t size)` +- Defined: `cJSON.c:3194` +- Depends on: `cJSON.h` + +### CJSON_PUBLIC (function) `CJSON_PUBLIC(void) cJSON_free(void *object)` +- Defined: `cJSON.c:3199` +- Depends on: `cJSON.h` + +## cJSON.h + +### sensitive (function) `* case_sensitive determines if object keys are treated case sensitive (1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo` +- Defined: `cJSON.h:249` +- Imported by: `beacon.c`, `cJSON.c` + +## gen_beacon.sh + +### show_help (function) +- Defined: `gen_beacon.sh:34` +- Doc: === FUNCIONES === + +### xor_string (function) +- Defined: `gen_beacon.sh:138` +- Doc: === XOR STRING TO BYTES === + +### crc32 (function) +- Defined: `gen_beacon.sh:5916` + +## gen_dll_rev.sh + +### usage (function) +- Defined: `gen_dll_rev.sh:12` +- Doc: === USO === + +## gen_dll_ss.sh + +### usage (function) +- Defined: `gen_dll_ss.sh:10` +- Doc: === USO === + +## gen_key.sh + +### usage (function) +- Defined: `gen_key.sh:10` +- Doc: === USO === + +## gen_module.sh + +### show_help (function) +- Defined: `gen_module.sh:18` +- Doc: === FUNCIONES === + +### xor_obfuscate (function) +- Defined: `gen_module.sh:35` +- Doc: Función para ofuscar binario con XOR y convertir a \x.. + +## generate_hashs.py + +### djb2 (function) `def djb2(s)` +- Defined: `generate_hashs.py:23` + +### generate_coff_loader (function) `def generate_coff_loader()` +- Defined: `generate_hashs.py:223` + +### generate_bof_test (function) `def generate_bof_test()` +- Defined: `generate_hashs.py:491` + +### main (function) `def main()` +- Defined: `generate_hashs.py:553` diff --git a/readmenator-agent/ARCHITECTURE.md b/readmenator-agent/ARCHITECTURE.md new file mode 100644 index 0000000..d12849f --- /dev/null +++ b/readmenator-agent/ARCHITECTURE.md @@ -0,0 +1,114 @@ +# Architecture + +## Internal Dependencies + +- `COFFLoader3.c` -> `beacon.h` +- `aes.c` -> `aes.h` +- `beacon.c` -> `COFFLoader.h` +- `beacon.c` -> `aes.h` +- `beacon.c` -> `beacon.h` +- `beacon.c` -> `cJSON.h` +- `bof/calc/calc.c` -> `bof/calc/beacon.h` +- `bof/etw/etw.c` -> `bof/etw/beacon.h` +- `bof/test/Test.c` -> `bof/test/beacon.h` +- `bof/test/amsibypass.c` -> `bof/test/beacon.h` +- `bof/test/cmdwhoami.c` -> `bof/test/beacon.h` +- `bof/test/disablelog.c` -> `bof/test/beacon.h` +- `bof/test/getenv.c` -> `bof/test/beacon.h` +- `bof/test/loadvnc.c` -> `bof/test/beacon.h` +- `bof/test/persist.c` -> `bof/test/beacon.h` +- `bof/test/persistsvc.c` -> `bof/test/beacon.h` +- `bof/test/scan_shellcode.c` -> `bof/test/beacon.h` +- `bof/test/shellcode.c` -> `bof/test/beacon.h` +- `bof/test/sock5.c` -> `bof/test/beacon.h` +- `bof/test/uacbypass.c` -> `bof/test/beacon.h` +- `bof/test/upload.c` -> `bof/test/beacon.h` +- `bof/test/vncrelay.c` -> `bof/test/beacon.h` +- `bof/test/winver.c` -> `bof/test/beacon.h` +- `bof/whoami/whoami.c` -> `bof/whoami/beacon.h` +- `cJSON.c` -> `cJSON.h` + +## External Imports + +- `COFFLoader.h` -> `windows.h` +- `COFFLoader3.c` -> `stdint.h` +- `COFFLoader3.c` -> `stdio.h` +- `COFFLoader3.c` -> `stdlib.h` +- `COFFLoader3.c` -> `string.h` +- `COFFLoader3.c` -> `windows.h` +- `aes.c` -> `string.h` +- `aes.h` -> `stddef.h` +- `aes.h` -> `stdint.h` +- `app.py` -> `os` +- `beacon.c` -> `bcrypt.h` +- `beacon.c` -> `icmpapi.h` +- `beacon.c` -> `io.h` +- `beacon.c` -> `iphlpapi.h` +- `beacon.c` -> `ntstatus.h` +- `beacon.c` -> `objbase.h` +- `beacon.c` -> `process.h` +- `beacon.c` -> `setjmp.h` +- `beacon.c` -> `shellapi.h` +- `beacon.c` -> `shlobj.h` +- `beacon.c` -> `stdio.h` +- `beacon.c` -> `stdlib.h` +- `beacon.c` -> `string.h` +- `beacon.c` -> `time.h` +- `beacon.c` -> `tlhelp32.h` +- `beacon.c` -> `wincrypt.h` +- `beacon.c` -> `windows.h` +- `beacon.c` -> `winhttp.h` +- `beacon.c` -> `winioctl.h` +- `beacon.c` -> `winnt.h` +- `beacon.c` -> `winsock2.h` +- `beacon.c` -> `ws2tcpip.h` +- `beacon.h` -> `windows.h` +- `bof/calc/beacon.h` -> `windows.h` +- `bof/calc/calc.c` -> `windows.h` +- `bof/etw/beacon.h` -> `windows.h` +- `bof/etw/etw.c` -> `windows.h` +- `bof/test/amsibypass.c` -> `windows.h` +- `bof/test/beacon.h` -> `windows.h` +- `bof/test/cmdwhoami.c` -> `windows.h` +- `bof/test/disablelog.c` -> `psapi.h` +- `bof/test/disablelog.c` -> `tlhelp32.h` +- `bof/test/disablelog.c` -> `windows.h` +- `bof/test/disablelog.c` -> `winternl.h` +- `bof/test/getenv.c` -> `windows.h` +- `bof/test/loadvnc.c` -> `windows.h` +- `bof/test/make_table.c` -> `stdint.h` +- `bof/test/make_table.c` -> `stdio.h` +- `bof/test/persist.c` -> `windows.h` +- `bof/test/persistsvc.c` -> `windows.h` +- `bof/test/scan_shellcode.c` -> `tlhelp32.h` +- `bof/test/scan_shellcode.c` -> `windows.h` +- `bof/test/shellcode.c` -> `windows.h` +- `bof/test/sock5.c` -> `windows.h` +- `bof/test/tel.py` -> `Crypto.Cipher` +- `bof/test/tel.py` -> `datetime` +- `bof/test/tel.py` -> `json` +- `bof/test/tel.py` -> `re` +- `bof/test/tel.py` -> `requests` +- `bof/test/tel.py` -> `uuid` +- `bof/test/uacbypass.c` -> `windows.h` +- `bof/test/upload.c` -> `windows.h` +- `bof/test/vncrelay.c` -> `windows.h` +- `bof/test/vncrelay.c` -> `winsock2.h` +- `bof/test/winver.c` -> `windows.h` +- `bof/whoami/beacon.h` -> `windows.h` +- `bof/whoami/whoami.c` -> `windows.h` +- `cJSON.c` -> `ctype.h` +- `cJSON.c` -> `float.h` +- `cJSON.c` -> `limits.h` +- `cJSON.c` -> `locale.h` +- `cJSON.c` -> `math.h` +- `cJSON.c` -> `stdio.h` +- `cJSON.c` -> `stdlib.h` +- `cJSON.c` -> `string.h` +- `cJSON.h` -> `stddef.h` +- `generate_hashs.py` -> `argparse` +- `generate_hashs.py` -> `pygments` +- `generate_hashs.py` -> `pygments.formatters` +- `generate_hashs.py` -> `pygments.lexers` +- `generate_hashs.py` -> `re` +- `generate_hashs.py` -> `sys` diff --git a/readmenator-agent/GOTCHAS.md b/readmenator-agent/GOTCHAS.md new file mode 100644 index 0000000..5b9f3b0 --- /dev/null +++ b/readmenator-agent/GOTCHAS.md @@ -0,0 +1,42 @@ +# Gotchas + +## God Nodes (high connectivity) + +These files have the most connections. Changes here have high blast radius. + +- `beacon.h` (score: 40.40) +- `bof/test/beacon.h` (score: 30.40) +- `COFFLoader3.c` (score: 27.80) +- `beacon.c` (score: 24.00) +- `cJSON.c` (score: 14.50) +- `bof/test/sock5.c` (score: 8.10) +- `bof/test/upload.c` (score: 8.10) +- `cJSON.h` (score: 7.70) +- `aes.c` (score: 6.30) +- `aes.h` (score: 6.10) + +## Hotspots (complexity + centrality) + +- `beacon.c` -- complexity: 0.6, centrality: 1.0, combined: 0.8 +- `COFFLoader3.c` -- complexity: 1.0, centrality: 0.2, combined: 0.5 +- `beacon.h` -- complexity: 0.0, centrality: 0.8, combined: 0.5 +- `cJSON.c` -- complexity: 0.5, centrality: 0.3, combined: 0.4 +- `bof/test/beacon.h` -- complexity: 0.0, centrality: 0.5, combined: 0.3 +- `cJSON.h` -- complexity: 0.1, centrality: 0.2, combined: 0.2 +- `aes.h` -- complexity: 0.1, centrality: 0.2, combined: 0.2 +- `bof/test/disablelog.c` -- complexity: 0.0, centrality: 0.2, combined: 0.1 +- `bof/test/tel.py` -- complexity: 0.0, centrality: 0.2, combined: 0.1 +- `aes.c` -- complexity: 0.2, centrality: 0.1, combined: 0.1 + +## Dataflow Issues (INFERRED, review each lead) + +- `beacon.c:1305` `extract_shellcode` [UNCHECKED_ALLOC] `sc`: Result of allocator stored in `sc` is never checked against NULL. +- `beacon.c:1429` `ReverseShell` [UNCHECKED_ALLOC] `s`: Result of allocator stored in `s` is never checked against NULL. +- `beacon.c:1730` `discoverLocalHosts` [UNCHECKED_ALLOC] `reply`: Result of allocator stored in `reply` is never checked against NULL. +- `beacon.c:1788` `proxy_thread` [UNCHECKED_ALLOC] `server`: Result of allocator stored in `server` is never checked against NULL. +- `beacon.c:1968` `startProxy` [UNCHECKED_ALLOC] `listenSock`: Result of allocator stored in `listenSock` is never checked against NULL. +- `beacon.c:3570` `executeUACBypass` [DEAD_STORE] `maliciousCmd`: `maliciousCmd` assigned at line 3570 but never read afterwards. +- `beacon.c:3621` `scanPort` [UNCHECKED_ALLOC] `s`: Result of allocator stored in `s` is never checked against NULL. +- `cJSON.c:1654` `print_array` [DEAD_STORE] `output_pointer`: `output_pointer` assigned at line 1654 but never read afterwards. +- `cJSON.c:1887` `print_object` [DEAD_STORE] `output_pointer`: `output_pointer` assigned at line 1887 but never read afterwards. +- `gen_beacon.sh:4053` `xor_string` [DEAD_STORE] `maliciousCmd`: `maliciousCmd` assigned at line 4053 but never read afterwards. diff --git a/readmenator-agent/INDEX.md b/readmenator-agent/INDEX.md new file mode 100644 index 0000000..7f52137 --- /dev/null +++ b/readmenator-agent/INDEX.md @@ -0,0 +1,45 @@ +# Index + +| File | Purpose | Subsystem | Symbols | +|------|---------|-----------|---------| +| `COFFLoader.h` | - | root | 1 | +| `COFFLoader3.c` | - | root | 258 | +| `aes.c` | aes.c - tiny-AES-c (https://github.com/kokke/tiny-AES-c) | root | 43 | +| `aes.h` | #define the macros below to 1/0 to enable/disable the mode of operation. | root | 21 | +| `app.py` | This file is part of Black Basalt Beacon. Black Basalt Beacon is free software: | root | 0 | +| `beacon.c` | - | root | 160 | +| `beacon.h` | - | root | 4 | +| `bof/calc/beacon.h` | - | calc | 4 | +| `bof/calc/calc.c` | - | calc | 6 | +| `bof/etw/beacon.h` | - | etw | 4 | +| `bof/etw/etw.c` | - | etw | 5 | +| `bof/test/Test.c` | - | test | 1 | +| `bof/test/amsibypass.c` | - | test | 5 | +| `bof/test/beacon.h` | - | test | 4 | +| `bof/test/cmdwhoami.c` | - | test | 4 | +| `bof/test/disablelog.c` | - | test | 9 | +| `bof/test/getenv.c` | - | test | 2 | +| `bof/test/loadvnc.c` | - | test | 8 | +| `bof/test/make_table.c` | - | test | 2 | +| `bof/test/persist.c` | - | test | 4 | +| `bof/test/persistsvc.c` | - | test | 13 | +| `bof/test/scan_shellcode.c` | - | test | 9 | +| `bof/test/shellcode.c` | - | test | 3 | +| `bof/test/sock5.c` | ===== DECLARACIONES QUE FALTABAN ===== | test | 41 | +| `bof/test/tel.py` | - | test | 6 | +| `bof/test/uacbypass.c` | - | test | 5 | +| `bof/test/upload.c` | ================================ IMPORTS DIRECTOS ============================== | test | 41 | +| `bof/test/vncrelay.c` | - | test | 8 | +| `bof/test/winver.c` | - | test | 2 | +| `bof/whoami/beacon.h` | - | whoami | 4 | +| `bof/whoami/whoami.c` | - | whoami | 5 | +| `cJSON.c` | - | root | 125 | +| `cJSON.h` | - | root | 37 | +| `gen_beacon.sh` | === beacon-GEN v1.2 === | root | 3 | +| `gen_dll.sh` | 1. Generar DLL | root | 0 | +| `gen_dll_rev.sh` | === CONFIGURACIÓN POR DEFECTO === | root | 1 | +| `gen_dll_ss.sh` | === CONFIGURACIÓN POR DEFECTO === | root | 1 | +| `gen_key.sh` | === CONFIGURACIÓN POR DEFECTO === | root | 1 | +| `gen_module.sh` | === gen_cmd_dll.sh v1.0 === Genera DLL y shellcode ofuscado para ejecutar un com | root | 2 | +| `generate_hashs.py` | BOF Bindings Generator for Cobalt Strike Author: Gris Iscomeback Email: grisisco | root | 4 | +| `install.sh` | - | root | 0 | diff --git a/readmenator-agent/KB_calc.md b/readmenator-agent/KB_calc.md new file mode 100644 index 0000000..6b0a7b3 --- /dev/null +++ b/readmenator-agent/KB_calc.md @@ -0,0 +1,23 @@ +# Subsystem: calc + +## bof/calc/beacon.h +- Layer: utility +- Language: h +- Symbols: + - `datap` (struct, line 25) + - `BEACON_H` (macro, line 21) `#define BEACON_H` + - `CALLBACK_OUTPUT` (macro, line 41) `#define CALLBACK_OUTPUT` + - `CALLBACK_ERROR` (macro, line 42) `#define CALLBACK_ERROR` +- Imported by: `bof/calc/calc.c` + +## bof/calc/calc.c +- Layer: utility +- Language: c +- Symbols: + - `go` (function, line 34) `void go(char *args, int alen)` + - `__imp_GetModuleHandleA` (variable, line 26) `extern FARPROC __imp_GetModuleHandleA;` + - `__imp_GetProcAddress` (variable, line 27) `extern FARPROC __imp_GetProcAddress;` + - `__imp_LoadLibraryA` (variable, line 28) `extern FARPROC __imp_LoadLibraryA;` + - `__imp_GetComputerNameA` (variable, line 29) `extern FARPROC __imp_GetComputerNameA;` + - `__imp_CloseHandle` (variable, line 30) `extern FARPROC __imp_CloseHandle;` +- Depends on: `bof/calc/beacon.h` diff --git a/readmenator-agent/KB_etw.md b/readmenator-agent/KB_etw.md new file mode 100644 index 0000000..d07ff6a --- /dev/null +++ b/readmenator-agent/KB_etw.md @@ -0,0 +1,22 @@ +# Subsystem: etw + +## bof/etw/beacon.h +- Layer: utility +- Language: h +- Symbols: + - `datap` (struct, line 25) + - `BEACON_H` (macro, line 21) `#define BEACON_H` + - `CALLBACK_OUTPUT` (macro, line 41) `#define CALLBACK_OUTPUT` + - `CALLBACK_ERROR` (macro, line 42) `#define CALLBACK_ERROR` +- Imported by: `bof/etw/etw.c` + +## bof/etw/etw.c +- Layer: utility +- Language: c +- Symbols: + - `go` (function, line 26) `void go(char *a,int l)` + - `__imp_GetModuleHandleA` (variable, line 22) `extern PVOID __imp_GetModuleHandleA;` + - `__imp_GetProcAddress` (variable, line 23) `extern PVOID __imp_GetProcAddress;` + - `__imp_VirtualProtect` (variable, line 24) `extern PVOID __imp_VirtualProtect;` + - `__imp_RtlCopyMemory` (variable, line 25) `extern PVOID __imp_RtlCopyMemory;` +- Depends on: `bof/etw/beacon.h` diff --git a/readmenator-agent/KB_root.md b/readmenator-agent/KB_root.md new file mode 100644 index 0000000..e1a893e --- /dev/null +++ b/readmenator-agent/KB_root.md @@ -0,0 +1,767 @@ +# Subsystem: root + +## COFFLoader.h +- Layer: utility +- Language: h +- Symbols: + - `COFFLOADER_H` (macro, line 21) `#define COFFLOADER_H` +- Imported by: `beacon.c` + +## COFFLoader3.c +- Layer: utility +- Language: c +- Symbols: + - `COFFSection` (struct, line 586) + - `COFFRelocation` (struct, line 599) + - `COFFHeader` (struct, line 620) + - `SymbolHash` (struct, line 642) + - `djb2_hash` (function, line 632) `static uint32_t djb2_hash(const char* str)` + - `create_trampoline` (function, line 913) `static void* create_trampoline(void* target)` + - `handle_relocation` (function, line 940) `BOOL handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ...` + - `get_symbol_name` (function, line 1080) `static char* get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size)` + - `__attribute__` (function, line 1103) `__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2)` + - `RunCOFF` (function, line 1112) `int RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*...` + - `__imp_BeaconPrintf` (variable, line 332) `extern PVOID __imp_BeaconPrintf;` + - `__imp_BeaconOutput` (variable, line 333) `extern PVOID __imp_BeaconOutput;` + - `__imp_BeaconDataParse` (variable, line 334) `extern PVOID __imp_BeaconDataParse;` + - `__imp_BeaconDataInt` (variable, line 335) `extern PVOID __imp_BeaconDataInt;` + - `__imp_BeaconDataShort` (variable, line 336) `extern PVOID __imp_BeaconDataShort;` + - `__imp_BeaconDataExtract` (variable, line 337) `extern PVOID __imp_BeaconDataExtract;` + - `__imp_LoadLibraryA` (variable, line 338) `extern PVOID __imp_LoadLibraryA;` + - `__imp_LoadLibraryW` (variable, line 339) `extern PVOID __imp_LoadLibraryW;` + - `__imp_GetModuleHandleA` (variable, line 340) `extern PVOID __imp_GetModuleHandleA;` + - `__imp_GetModuleHandleW` (variable, line 341) `extern PVOID __imp_GetModuleHandleW;` + - `__imp_GetProcAddress` (variable, line 342) `extern PVOID __imp_GetProcAddress;` + - `__imp_GetLastError` (variable, line 343) `extern PVOID __imp_GetLastError;` + - `__imp_CloseHandle` (variable, line 344) `extern PVOID __imp_CloseHandle;` + - `__imp_ExitProcess` (variable, line 345) `extern PVOID __imp_ExitProcess;` + - `__imp_ExitThread` (variable, line 346) `extern PVOID __imp_ExitThread;` + - `__imp_Sleep` (variable, line 347) `extern PVOID __imp_Sleep;` + - `__imp_CreateThread` (variable, line 348) `extern PVOID __imp_CreateThread;` + - `__imp_GetCurrentProcess` (variable, line 349) `extern PVOID __imp_GetCurrentProcess;` + - `__imp_GetCurrentProcessId` (variable, line 350) `extern PVOID __imp_GetCurrentProcessId;` + - `__imp_GetCurrentThreadId` (variable, line 351) `extern PVOID __imp_GetCurrentThreadId;` + - `__imp_GetTickCount` (variable, line 352) `extern PVOID __imp_GetTickCount;` + - `__imp_GetTickCount64` (variable, line 353) `extern PVOID __imp_GetTickCount64;` + - `__imp_CreateFileA` (variable, line 354) `extern PVOID __imp_CreateFileA;` + - `__imp_CreateFileW` (variable, line 355) `extern PVOID __imp_CreateFileW;` + - `__imp_ReadFile` (variable, line 356) `extern PVOID __imp_ReadFile;` + - `__imp_WriteFile` (variable, line 357) `extern PVOID __imp_WriteFile;` + - `__imp_SetFilePointer` (variable, line 358) `extern PVOID __imp_SetFilePointer;` + - `__imp_SetEndOfFile` (variable, line 359) `extern PVOID __imp_SetEndOfFile;` + - `__imp_DeleteFileA` (variable, line 360) `extern PVOID __imp_DeleteFileA;` + - `__imp_DeleteFileW` (variable, line 361) `extern PVOID __imp_DeleteFileW;` + - `__imp_MoveFileA` (variable, line 362) `extern PVOID __imp_MoveFileA;` + - `__imp_MoveFileW` (variable, line 363) `extern PVOID __imp_MoveFileW;` + - `__imp_CopyFileA` (variable, line 364) `extern PVOID __imp_CopyFileA;` + - `__imp_CopyFileW` (variable, line 365) `extern PVOID __imp_CopyFileW;` + - `__imp_GetFileSize` (variable, line 366) `extern PVOID __imp_GetFileSize;` + - `__imp_GetFileSizeEx` (variable, line 367) `extern PVOID __imp_GetFileSizeEx;` + - `__imp_CreateDirectoryA` (variable, line 368) `extern PVOID __imp_CreateDirectoryA;` + - `__imp_CreateDirectoryW` (variable, line 369) `extern PVOID __imp_CreateDirectoryW;` + - `__imp_RemoveDirectoryA` (variable, line 370) `extern PVOID __imp_RemoveDirectoryA;` + - `__imp_RemoveDirectoryW` (variable, line 371) `extern PVOID __imp_RemoveDirectoryW;` + - `__imp_FindFirstFileA` (variable, line 372) `extern PVOID __imp_FindFirstFileA;` + - `__imp_FindFirstFileW` (variable, line 373) `extern PVOID __imp_FindFirstFileW;` + - `__imp_FindNextFileA` (variable, line 374) `extern PVOID __imp_FindNextFileA;` + - `__imp_FindNextFileW` (variable, line 375) `extern PVOID __imp_FindNextFileW;` + - `__imp_FindClose` (variable, line 376) `extern PVOID __imp_FindClose;` + - `__imp_GetFileAttributesA` (variable, line 377) `extern PVOID __imp_GetFileAttributesA;` + - `__imp_GetFileAttributesW` (variable, line 378) `extern PVOID __imp_GetFileAttributesW;` + - `__imp_SetFileAttributesA` (variable, line 379) `extern PVOID __imp_SetFileAttributesA;` + - `__imp_SetFileAttributesW` (variable, line 380) `extern PVOID __imp_SetFileAttributesW;` + - `__imp_GetSystemDirectoryA` (variable, line 381) `extern PVOID __imp_GetSystemDirectoryA;` + - `__imp_GetSystemDirectoryW` (variable, line 382) `extern PVOID __imp_GetSystemDirectoryW;` + - `__imp_GetWindowsDirectoryA` (variable, line 383) `extern PVOID __imp_GetWindowsDirectoryA;` + - `__imp_GetWindowsDirectoryW` (variable, line 384) `extern PVOID __imp_GetWindowsDirectoryW;` + - `__imp_GetTempPathA` (variable, line 385) `extern PVOID __imp_GetTempPathA;` + - `__imp_GetTempPathW` (variable, line 386) `extern PVOID __imp_GetTempPathW;` + - `__imp_GetComputerNameA` (variable, line 387) `extern PVOID __imp_GetComputerNameA;` + - `__imp_GetComputerNameW` (variable, line 388) `extern PVOID __imp_GetComputerNameW;` + - `__imp_GetUserNameA` (variable, line 389) `extern PVOID __imp_GetUserNameA;` + - `__imp_GetUserNameW` (variable, line 390) `extern PVOID __imp_GetUserNameW;` + - `__imp_GetVersionExA` (variable, line 391) `extern PVOID __imp_GetVersionExA;` + - `__imp_GetVersionExW` (variable, line 392) `extern PVOID __imp_GetVersionExW;` + - `__imp_GetNativeSystemInfo` (variable, line 393) `extern PVOID __imp_GetNativeSystemInfo;` + - `__imp_VirtualAlloc` (variable, line 394) `extern PVOID __imp_VirtualAlloc;` + - `__imp_VirtualFree` (variable, line 395) `extern PVOID __imp_VirtualFree;` + - `__imp_VirtualProtect` (variable, line 396) `extern PVOID __imp_VirtualProtect;` + - `__imp_VirtualQuery` (variable, line 397) `extern PVOID __imp_VirtualQuery;` + - `__imp_HeapAlloc` (variable, line 398) `extern PVOID __imp_HeapAlloc;` + - `__imp_HeapFree` (variable, line 399) `extern PVOID __imp_HeapFree;` + - `__imp_LocalAlloc` (variable, line 400) `extern PVOID __imp_LocalAlloc;` + - `__imp_LocalFree` (variable, line 401) `extern PVOID __imp_LocalFree;` + - `__imp_GlobalAlloc` (variable, line 402) `extern PVOID __imp_GlobalAlloc;` + - `__imp_GlobalFree` (variable, line 403) `extern PVOID __imp_GlobalFree;` + - `__imp_RtlMoveMemory` (variable, line 404) `extern PVOID __imp_RtlMoveMemory;` + - `__imp_RtlCopyMemory` (variable, line 405) `extern PVOID __imp_RtlCopyMemory;` + - `__imp_RtlFillMemory` (variable, line 406) `extern PVOID __imp_RtlFillMemory;` + - `__imp_RtlZeroMemory` (variable, line 407) `extern PVOID __imp_RtlZeroMemory;` + - `__imp_lstrlenA` (variable, line 408) `extern PVOID __imp_lstrlenA;` + - `__imp_lstrlenW` (variable, line 409) `extern PVOID __imp_lstrlenW;` + - `__imp_lstrcpyA` (variable, line 410) `extern PVOID __imp_lstrcpyA;` + - `__imp_lstrcpyW` (variable, line 411) `extern PVOID __imp_lstrcpyW;` + - `__imp_lstrcatA` (variable, line 412) `extern PVOID __imp_lstrcatA;` + - `__imp_lstrcatW` (variable, line 413) `extern PVOID __imp_lstrcatW;` + - `__imp_lstrcmpA` (variable, line 414) `extern PVOID __imp_lstrcmpA;` + - `__imp_lstrcmpW` (variable, line 415) `extern PVOID __imp_lstrcmpW;` + - `__imp_lstrcmpiA` (variable, line 416) `extern PVOID __imp_lstrcmpiA;` + - `__imp_lstrcmpiW` (variable, line 417) `extern PVOID __imp_lstrcmpiW;` + - `__imp_MultiByteToWideChar` (variable, line 418) `extern PVOID __imp_MultiByteToWideChar;` + - `__imp_WideCharToMultiByte` (variable, line 419) `extern PVOID __imp_WideCharToMultiByte;` + - `__imp_FormatMessageA` (variable, line 420) `extern PVOID __imp_FormatMessageA;` + - `__imp_FormatMessageW` (variable, line 421) `extern PVOID __imp_FormatMessageW;` + - `__imp_GetEnvironmentVariableA` (variable, line 422) `extern PVOID __imp_GetEnvironmentVariableA;` + - `__imp_GetEnvironmentVariableW` (variable, line 423) `extern PVOID __imp_GetEnvironmentVariableW;` + - `__imp_SetEnvironmentVariableA` (variable, line 424) `extern PVOID __imp_SetEnvironmentVariableA;` + - `__imp_SetEnvironmentVariableW` (variable, line 425) `extern PVOID __imp_SetEnvironmentVariableW;` + - `__imp_ExpandEnvironmentStringsA` (variable, line 426) `extern PVOID __imp_ExpandEnvironmentStringsA;` + - `__imp_ExpandEnvironmentStringsW` (variable, line 427) `extern PVOID __imp_ExpandEnvironmentStringsW;` + - `__imp_GetCommandLineA` (variable, line 428) `extern PVOID __imp_GetCommandLineA;` + - `__imp_GetCommandLineW` (variable, line 429) `extern PVOID __imp_GetCommandLineW;` + - `__imp_GetModuleFileNameA` (variable, line 430) `extern PVOID __imp_GetModuleFileNameA;` + - `__imp_GetModuleFileNameW` (variable, line 431) `extern PVOID __imp_GetModuleFileNameW;` + - `__imp_GetStartupInfoA` (variable, line 432) `extern PVOID __imp_GetStartupInfoA;` + - `__imp_GetStartupInfoW` (variable, line 433) `extern PVOID __imp_GetStartupInfoW;` + - `__imp_FreeLibrary` (variable, line 434) `extern PVOID __imp_FreeLibrary;` + - `__imp_GetConsoleWindow` (variable, line 435) `extern PVOID __imp_GetConsoleWindow;` + - `__imp_AllocConsole` (variable, line 436) `extern PVOID __imp_AllocConsole;` + - `__imp_FreeConsole` (variable, line 437) `extern PVOID __imp_FreeConsole;` + - `__imp_AttachConsole` (variable, line 438) `extern PVOID __imp_AttachConsole;` + - `__imp_IsDebuggerPresent` (variable, line 439) `extern PVOID __imp_IsDebuggerPresent;` + - `__imp_CheckRemoteDebuggerPresent` (variable, line 440) `extern PVOID __imp_CheckRemoteDebuggerPresent;` + - `__imp_OutputDebugStringA` (variable, line 441) `extern PVOID __imp_OutputDebugStringA;` + - `__imp_OutputDebugStringW` (variable, line 442) `extern PVOID __imp_OutputDebugStringW;` + - `__imp_OpenProcess` (variable, line 443) `extern PVOID __imp_OpenProcess;` + - `__imp_OpenProcessToken` (variable, line 444) `extern PVOID __imp_OpenProcessToken;` + - `__imp_DuplicateTokenEx` (variable, line 445) `extern PVOID __imp_DuplicateTokenEx;` + - `__imp_ImpersonateLoggedOnUser` (variable, line 446) `extern PVOID __imp_ImpersonateLoggedOnUser;` + - `__imp_RevertToSelf` (variable, line 447) `extern PVOID __imp_RevertToSelf;` + - `__imp_LookupPrivilegeValueA` (variable, line 448) `extern PVOID __imp_LookupPrivilegeValueA;` + - `__imp_LookupPrivilegeValueW` (variable, line 449) `extern PVOID __imp_LookupPrivilegeValueW;` + - `__imp_AdjustTokenPrivileges` (variable, line 450) `extern PVOID __imp_AdjustTokenPrivileges;` + - `__imp_CreateProcessAsUserA` (variable, line 451) `extern PVOID __imp_CreateProcessAsUserA;` + - `__imp_CreateProcessAsUserW` (variable, line 452) `extern PVOID __imp_CreateProcessAsUserW;` + - `__imp_RegOpenKeyExA` (variable, line 453) `extern PVOID __imp_RegOpenKeyExA;` + - `__imp_RegOpenKeyExW` (variable, line 454) `extern PVOID __imp_RegOpenKeyExW;` + - `__imp_RegCreateKeyExA` (variable, line 455) `extern PVOID __imp_RegCreateKeyExA;` + - `__imp_RegCreateKeyExW` (variable, line 456) `extern PVOID __imp_RegCreateKeyExW;` + - `__imp_RegSetValueExA` (variable, line 457) `extern PVOID __imp_RegSetValueExA;` + - `__imp_RegSetValueExW` (variable, line 458) `extern PVOID __imp_RegSetValueExW;` + - `__imp_RegQueryValueExA` (variable, line 459) `extern PVOID __imp_RegQueryValueExA;` + - `__imp_RegQueryValueExW` (variable, line 460) `extern PVOID __imp_RegQueryValueExW;` + - `__imp_RegDeleteValueA` (variable, line 461) `extern PVOID __imp_RegDeleteValueA;` + - `__imp_RegDeleteValueW` (variable, line 462) `extern PVOID __imp_RegDeleteValueW;` + - `__imp_RegCloseKey` (variable, line 463) `extern PVOID __imp_RegCloseKey;` + - `__imp_RegEnumKeyExA` (variable, line 464) `extern PVOID __imp_RegEnumKeyExA;` + - `__imp_RegEnumKeyExW` (variable, line 465) `extern PVOID __imp_RegEnumKeyExW;` + - `__imp_RegEnumValueA` (variable, line 466) `extern PVOID __imp_RegEnumValueA;` + - `__imp_RegEnumValueW` (variable, line 467) `extern PVOID __imp_RegEnumValueW;` + - `__imp_CryptAcquireContextA` (variable, line 468) `extern PVOID __imp_CryptAcquireContextA;` + - `__imp_CryptAcquireContextW` (variable, line 469) `extern PVOID __imp_CryptAcquireContextW;` + - `__imp_CryptCreateHash` (variable, line 470) `extern PVOID __imp_CryptCreateHash;` + - `__imp_CryptHashData` (variable, line 471) `extern PVOID __imp_CryptHashData;` + - `__imp_CryptDeriveKey` (variable, line 472) `extern PVOID __imp_CryptDeriveKey;` + - `__imp_CryptEncrypt` (variable, line 473) `extern PVOID __imp_CryptEncrypt;` + - `__imp_CryptDecrypt` (variable, line 474) `extern PVOID __imp_CryptDecrypt;` + - `__imp_CryptReleaseContext` (variable, line 475) `extern PVOID __imp_CryptReleaseContext;` + - `__imp_CryptDestroyHash` (variable, line 476) `extern PVOID __imp_CryptDestroyHash;` + - `__imp_CryptDestroyKey` (variable, line 477) `extern PVOID __imp_CryptDestroyKey;` + - `__imp_CryptGenRandom` (variable, line 478) `extern PVOID __imp_CryptGenRandom;` + - `__imp_CoInitializeEx` (variable, line 479) `extern PVOID __imp_CoInitializeEx;` + - `__imp_CoUninitialize` (variable, line 480) `extern PVOID __imp_CoUninitialize;` + - `__imp_CoCreateInstance` (variable, line 481) `extern PVOID __imp_CoCreateInstance;` + - `__imp_CoTaskMemFree` (variable, line 482) `extern PVOID __imp_CoTaskMemFree;` + - `__imp_IIDFromString` (variable, line 483) `extern PVOID __imp_IIDFromString;` + - `__imp_StringFromGUID2` (variable, line 484) `extern PVOID __imp_StringFromGUID2;` + - `__imp_VariantInit` (variable, line 485) `extern PVOID __imp_VariantInit;` + - `__imp_VariantClear` (variable, line 486) `extern PVOID __imp_VariantClear;` + - `__imp_VariantChangeType` (variable, line 487) `extern PVOID __imp_VariantChangeType;` + - `__imp_SysAllocString` (variable, line 488) `extern PVOID __imp_SysAllocString;` + - `__imp_SysFreeString` (variable, line 489) `extern PVOID __imp_SysFreeString;` + - `__imp_SysStringLen` (variable, line 490) `extern PVOID __imp_SysStringLen;` + - `__imp_SHGetFolderPathA` (variable, line 491) `extern PVOID __imp_SHGetFolderPathA;` + - `__imp_SHGetFolderPathW` (variable, line 492) `extern PVOID __imp_SHGetFolderPathW;` + - `__imp_SHGetKnownFolderPath` (variable, line 493) `extern PVOID __imp_SHGetKnownFolderPath;` + - `__imp_PathFileExistsA` (variable, line 494) `extern PVOID __imp_PathFileExistsA;` + - `__imp_PathFileExistsW` (variable, line 495) `extern PVOID __imp_PathFileExistsW;` + - `__imp_PathCombineA` (variable, line 496) `extern PVOID __imp_PathCombineA;` + - `__imp_PathCombineW` (variable, line 497) `extern PVOID __imp_PathCombineW;` + - `__imp_GetDesktopWindow` (variable, line 498) `extern PVOID __imp_GetDesktopWindow;` + - `__imp_GetShellWindow` (variable, line 499) `extern PVOID __imp_GetShellWindow;` + - `__imp_FindWindowA` (variable, line 500) `extern PVOID __imp_FindWindowA;` + - `__imp_FindWindowW` (variable, line 501) `extern PVOID __imp_FindWindowW;` + - `__imp_EnumWindows` (variable, line 502) `extern PVOID __imp_EnumWindows;` + - `__imp_GetWindowTextA` (variable, line 503) `extern PVOID __imp_GetWindowTextA;` + - `__imp_GetWindowTextW` (variable, line 504) `extern PVOID __imp_GetWindowTextW;` + - `__imp_GetClassNameA` (variable, line 505) `extern PVOID __imp_GetClassNameA;` + - `__imp_GetClassNameW` (variable, line 506) `extern PVOID __imp_GetClassNameW;` + - `__imp_SendMessageA` (variable, line 507) `extern PVOID __imp_SendMessageA;` + - `__imp_SendMessageW` (variable, line 508) `extern PVOID __imp_SendMessageW;` + - `__imp_EnumProcesses` (variable, line 509) `extern PVOID __imp_EnumProcesses;` + - `__imp_EnumProcessModules` (variable, line 510) `extern PVOID __imp_EnumProcessModules;` + - `__imp_GetModuleBaseNameA` (variable, line 511) `extern PVOID __imp_GetModuleBaseNameA;` + - `__imp_GetModuleBaseNameW` (variable, line 512) `extern PVOID __imp_GetModuleBaseNameW;` + - `__imp_GetModuleInformation` (variable, line 513) `extern PVOID __imp_GetModuleInformation;` + - `__imp_WSASocketA` (variable, line 514) `extern PVOID __imp_WSASocketA;` + - `__imp_WSASocketW` (variable, line 515) `extern PVOID __imp_WSASocketW;` + - `__imp_WSAStartup` (variable, line 516) `extern PVOID __imp_WSAStartup;` + - `__imp_WSACleanup` (variable, line 517) `extern PVOID __imp_WSACleanup;` + - `__imp_bind` (variable, line 518) `extern PVOID __imp_bind;` + - `__imp_listen` (variable, line 519) `extern PVOID __imp_listen;` + - `__imp_accept` (variable, line 520) `extern PVOID __imp_accept;` + - `__imp_connect` (variable, line 521) `extern PVOID __imp_connect;` + - `__imp_send` (variable, line 522) `extern PVOID __imp_send;` + - `__imp_recv` (variable, line 523) `extern PVOID __imp_recv;` + - `__imp_closesocket` (variable, line 524) `extern PVOID __imp_closesocket;` + - `__imp_ioctlsocket` (variable, line 525) `extern PVOID __imp_ioctlsocket;` + - `__imp_gethostname` (variable, line 526) `extern PVOID __imp_gethostname;` + - `__imp_gethostbyname` (variable, line 527) `extern PVOID __imp_gethostbyname;` + - `__imp_getaddrinfo` (variable, line 528) `extern PVOID __imp_getaddrinfo;` + - `__imp_freeaddrinfo` (variable, line 529) `extern PVOID __imp_freeaddrinfo;` + - `__imp_htons` (variable, line 530) `extern PVOID __imp_htons;` + - `__imp_ntohs` (variable, line 531) `extern PVOID __imp_ntohs;` + - `__imp_htonl` (variable, line 532) `extern PVOID __imp_htonl;` + - `__imp_ntohl` (variable, line 533) `extern PVOID __imp_ntohl;` + - `__imp_NetUserEnum` (variable, line 534) `extern PVOID __imp_NetUserEnum;` + - `__imp_NetLocalGroupEnum` (variable, line 535) `extern PVOID __imp_NetLocalGroupEnum;` + - `__imp_NetShareEnum` (variable, line 536) `extern PVOID __imp_NetShareEnum;` + - `__imp_NetWkstaUserEnum` (variable, line 537) `extern PVOID __imp_NetWkstaUserEnum;` + - `__imp_NetSessionEnum` (variable, line 538) `extern PVOID __imp_NetSessionEnum;` + - `__imp_NetApiBufferFree` (variable, line 539) `extern PVOID __imp_NetApiBufferFree;` + - `__imp_WNetOpenEnumA` (variable, line 540) `extern PVOID __imp_WNetOpenEnumA;` + - `__imp_WNetOpenEnumW` (variable, line 541) `extern PVOID __imp_WNetOpenEnumW;` + - `__imp_WNetEnumResourceA` (variable, line 542) `extern PVOID __imp_WNetEnumResourceA;` + - `__imp_WNetEnumResourceW` (variable, line 543) `extern PVOID __imp_WNetEnumResourceW;` + - `__imp_WNetCloseEnum` (variable, line 544) `extern PVOID __imp_WNetCloseEnum;` + - `__imp__stricmp` (variable, line 545) `extern PVOID __imp__stricmp;` + - `__imp_Process32Next` (variable, line 546) `extern PVOID __imp_Process32Next;` + - `__imp_IsWow64Process` (variable, line 547) `extern PVOID __imp_IsWow64Process;` + - `__imp_Process32First` (variable, line 548) `extern PVOID __imp_Process32First;` + - `__imp_CreateToolhelp32Snapshot` (variable, line 549) `extern PVOID __imp_CreateToolhelp32Snapshot;` + - `__imp_select` (variable, line 550) `extern PVOID __imp_select;` + - `__imp_CreateProcessA` (variable, line 551) `extern PVOID __imp_CreateProcessA;` + - `__imp_CreateProcessW` (variable, line 552) `extern PVOID __imp_CreateProcessW;` + - `__imp_SuspendThread` (variable, line 553) `extern PVOID __imp_SuspendThread;` + - `__imp_OpenThread` (variable, line 554) `extern PVOID __imp_OpenThread;` + - `__imp_Thread32First` (variable, line 555) `extern PVOID __imp_Thread32First;` + - `__imp_Thread32Next` (variable, line 556) `extern PVOID __imp_Thread32Next;` + - `__imp_NtQueryInformationThread` (variable, line 557) `extern PVOID __imp_NtQueryInformationThread;` + - `g_pNtCreateFileUnhooked` (variable, line 561) `extern PVOID g_pNtCreateFileUnhooked;` + - `g_pNtWriteVirtualMemoryUnhooked` (variable, line 562) `extern PVOID g_pNtWriteVirtualMemoryUnhooked;` + - `g_pNtProtectVirtualMemoryUnhooked` (variable, line 563) `extern PVOID g_pNtProtectVirtualMemoryUnhooked;` + - `g_pNtResumeThreadUnhooked` (variable, line 564) `extern PVOID g_pNtResumeThreadUnhooked;` + - `g_pNtCreateThreadExUnhooked` (variable, line 565) `extern PVOID g_pNtCreateThreadExUnhooked;` + - `IMAGE_REL_AMD64_ABSOLUTE` (macro, line 568) `#define IMAGE_REL_AMD64_ABSOLUTE` + - `IMAGE_REL_AMD64_ADDR64` (macro, line 569) `#define IMAGE_REL_AMD64_ADDR64` + - `IMAGE_REL_AMD64_ADDR32` (macro, line 570) `#define IMAGE_REL_AMD64_ADDR32` + - `IMAGE_REL_AMD64_ADDR32NB` (macro, line 571) `#define IMAGE_REL_AMD64_ADDR32NB` + - `IMAGE_REL_AMD64_REL32` (macro, line 572) `#define IMAGE_REL_AMD64_REL32` + - `IMAGE_REL_AMD64_REL32_1` (macro, line 573) `#define IMAGE_REL_AMD64_REL32_1` + - `IMAGE_REL_AMD64_REL32_2` (macro, line 574) `#define IMAGE_REL_AMD64_REL32_2` + - `IMAGE_REL_AMD64_REL32_3` (macro, line 575) `#define IMAGE_REL_AMD64_REL32_3` + - `IMAGE_REL_AMD64_REL32_4` (macro, line 576) `#define IMAGE_REL_AMD64_REL32_4` + - `IMAGE_REL_AMD64_REL32_5` (macro, line 577) `#define IMAGE_REL_AMD64_REL32_5` + - `IMAGE_REL_AMD64_SECTION` (macro, line 578) `#define IMAGE_REL_AMD64_SECTION` + - `IMAGE_REL_AMD64_SECREL` (macro, line 579) `#define IMAGE_REL_AMD64_SECREL` + - `IMAGE_REL_AMD64_SECREL7` (macro, line 580) `#define IMAGE_REL_AMD64_SECREL7` + - `IMAGE_REL_AMD64_TOKEN` (macro, line 581) `#define IMAGE_REL_AMD64_TOKEN` + - `IMAGE_REL_AMD64_SREL32` (macro, line 582) `#define IMAGE_REL_AMD64_SREL32` + - `IMAGE_REL_AMD64_PAIR` (macro, line 583) `#define IMAGE_REL_AMD64_PAIR` + - `IMAGE_REL_AMD64_SSPAN32` (macro, line 584) `#define IMAGE_REL_AMD64_SSPAN32` +- Depends on: `beacon.h` + +## aes.c +- Layer: utility +- Doc: aes.c - tiny-AES-c (https://github.com/kokke/tiny-AES-c) +- Language: c +- Symbols: + - `getSBoxValue` (function, line 13) `static uint8_t getSBoxValue(uint8_t num)` + - `getSBoxInvert` (function, line 35) `static uint8_t getSBoxInvert(uint8_t num)` + - `Td0` (function, line 57) `static uint8_t Td0(int x)` + - `Td1` (function, line 58) `static uint8_t Td1(int x)` + - `Td2` (function, line 59) `static uint8_t Td2(int x)` + - `Td3` (function, line 60) `static uint8_t Td3(int x)` + - `Td4` (function, line 61) `static uint8_t Td4(int x)` + - `KeyExpansion` (function, line 166) `static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key)` + - `AES_init_ctx` (function, line 239) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key)` + - `AES_init_ctx_iv` (function, line 244) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv)` + - `AES_ctx_set_iv` (function, line 249) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv)` + - `AddRoundKey` (function, line 257) `static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)` + - `SubBytes` (function, line 271) `static void SubBytes(state_t* state)` + - `ShiftRows` (function, line 286) `static void ShiftRows(state_t* state)` + - `xtime` (function, line 314) `static uint8_t xtime(uint8_t x)` + - `MixColumns` (function, line 320) `static void MixColumns(state_t* state)` + - `Multiply` (function, line 340) `static uint8_t Multiply(uint8_t x, uint8_t y)` + - `InvMixColumns` (function, line 370) `static void InvMixColumns(state_t* state)` + - `InvSubBytes` (function, line 391) `static void InvSubBytes(state_t* state)` + - `InvShiftRows` (function, line 403) `static void InvShiftRows(state_t* state)` + - `Cipher` (function, line 433) `static void Cipher(state_t* state, const uint8_t* RoundKey)` + - `InvCipher` (function, line 459) `static void InvCipher(state_t* state, const uint8_t* RoundKey)` + - `AES_ECB_encrypt` (function, line 490) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf)` + - `AES_ECB_decrypt` (function, line 496) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf)` + - `XorWithIv` (function, line 512) `static void XorWithIv(uint8_t* buf, const uint8_t* Iv)` + - `AES_CBC_encrypt_buffer` (function, line 521) `void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length)` + - `AES_CBC_decrypt_buffer` (function, line 536) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` + - `AES_CTR_xcrypt_buffer` (function, line 558) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` + - `Nb` (macro, line 5) `#define Nb` + - `KEYLEN_256` (macro, line 9) `#define KEYLEN_256` + - `RKLENGTH` (macro, line 10) `#define RKLENGTH` + - `BLOCKLEN` (macro, line 11) `#define BLOCKLEN` + - `Nb` (macro, line 67) `#define Nb` + - `Nk` (macro, line 70) `#define Nk` + - `Nr` (macro, line 71) `#define Nr` + - `Nk` (macro, line 73) `#define Nk` + - `Nr` (macro, line 74) `#define Nr` + - `Nk` (macro, line 76) `#define Nk` + - `Nr` (macro, line 77) `#define Nr` + - `MULTIPLY_AS_A_FUNCTION` (macro, line 84) `#define MULTIPLY_AS_A_FUNCTION` + - `getSBoxValue` (macro, line 163) `#define getSBoxValue(num)` + - `Multiply` (macro, line 349) `#define Multiply(x, y)` + - `getSBoxInvert` (macro, line 365) `#define getSBoxInvert(num)` +- Depends on: `aes.h` + +## aes.h +- Layer: utility +- Doc: #define the macros below to 1/0 to enable/disable the mode of operation. +- Language: h +- Symbols: + - `AES_ctx` (struct, line 33) + - `AES_init_ctx` (function, line 41) `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key);` + - `AES_init_ctx_iv` (function, line 43) `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv);` + - `AES_ctx_set_iv` (function, line 44) `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv);` + - `AES_ECB_encrypt` (function, line 48) `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf);` + - `AES_ECB_decrypt` (function, line 49) `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf);` + - `AES_CBC_encrypt_buffer` (function, line 53) `void AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` + - `AES_CBC_decrypt_buffer` (function, line 54) `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` + - `AES_CTR_xcrypt_buffer` (function, line 58) `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` + - `_AES_H_` (macro, line 2) `#define _AES_H_` + - `CBC` (macro, line 9) `#define CBC` + - `ECB` (macro, line 12) `#define ECB` + - `CTR` (macro, line 15) `#define CTR` + - `AES256` (macro, line 18) `#define AES256` + - `AES_BLOCKLEN` (macro, line 20) `#define AES_BLOCKLEN` + - `AES_KEYLEN` (macro, line 23) `#define AES_KEYLEN` + - `AES_keyExpSize` (macro, line 24) `#define AES_keyExpSize` + - `AES_KEYLEN` (macro, line 26) `#define AES_KEYLEN` + - `AES_keyExpSize` (macro, line 27) `#define AES_keyExpSize` + - `AES_KEYLEN` (macro, line 29) `#define AES_KEYLEN` + - `AES_keyExpSize` (macro, line 30) `#define AES_keyExpSize` +- Imported by: `aes.c`, `beacon.c` + +## app.py +- Layer: utility +- Doc: This file is part of Black Basalt Beacon. Black Basalt Beacon is free software: you can redistribute it and/or modify i +- Language: py + +## beacon.c +- Layer: utility +- Language: c +- Symbols: + - `_PROCESS_BASIC_INFORMATION` (struct, line 129) + - `_UNICODE_STRING` (struct, line 262) + - `_LDR_DATA_TABLE_ENTRY` (struct, line 268) + - `_PEB_LDR_DATA` (struct, line 278) + - `_PEB` (struct, line 287) + - `ProxySession` (struct, line 139) + - `ProxyThreadData` (struct, line 147) + - `ReverseArgs` (struct, line 156) + - `PortScannerArgs` (struct, line 161) + - `LazyDataType` (struct, line 168) + - `ProxyListener` (struct, line 176) + - `PacketEncryptionContext` (struct, line 329) + - `PortResult` (struct, line 343) + - `ExitStatus` (type_alias, line 127) `typedef struct _PROCESS_BASIC_INFORMATION { LONG ExitStatus;` + - `Length` (type_alias, line 262) `typedef struct _UNICODE_STRING { USHORT Length;` + - `InMemoryOrderLinks` (type_alias, line 267) `typedef struct _LDR_DATA_TABLE_ENTRY { LIST_ENTRY InMemoryOrderLinks;` + - `Length` (type_alias, line 277) `typedef struct _PEB_LDR_DATA { DWORD Length;` + - `Reserved1` (type_alias, line 286) `typedef struct _PEB { BYTE Reserved1[2];` + - `NTSTATUS` (type_alias, line 296) `typedef LONG NTSTATUS;` + - `NTSTATUS` (type_alias, line 304) `typedef LONG NTSTATUS;` + - `ExceptionFilter` (function, line 253) `static LONG WINAPI ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo)` + - `get_shell_cmd` (function, line 335) `const char* get_shell_cmd()` + - `__declspec` (function, line 417) `__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size)` + - `__declspec` (function, line 423) `__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size)` + - `__declspec` (function, line 431) `__declspec(dllexport) int BeaconDataInt(datap * parser)` + - `__declspec` (function, line 436) `__declspec(dllexport) short BeaconDataShort(datap * parser)` + - `__declspec` (function, line 441) `__declspec(dllexport) int BeaconDataLength(datap * parser)` + - `__declspec` (function, line 446) `__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size)` + - `__declspec` (function, line 456) `__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...)` + - `__declspec` (function, line 504) `__declspec(dllexport) void BeaconOutput(int type, const char * data, int len)` + - `MapDllNameToModule` (function, line 521) `HMODULE MapDllNameToModule(char* dllName)` + - `GetSyscallNumber` (function, line 549) `DWORD GetSyscallNumber(PVOID func_addr)` + - `HellsGate` (function, line 561) `DWORD HellsGate(DWORD ssn)` + - `__attribute__` (function, line 566) `__attribute__((naked)) +NTSTATUS HellDescent( + DWORD64 arg1, DWORD64 arg2, DWORD64 arg3, + DW...` + - `GetProcessIdByName` (function, line 582) `DWORD GetProcessIdByName(const char* processName)` + - `ExecuteTLSCallbacks` (function, line 600) `void ExecuteTLSCallbacks(PVOID moduleBase)` + - `MapModuleToMemory` (function, line 617) `PVOID MapModuleToMemory(unsigned char* fileBuffer, DWORD fileSize)` + - `ExecuteModule` (function, line 706) `BOOL ExecuteModule(PVOID moduleBase)` + - `LoadModuleFromURL` (function, line 751) `BOOL LoadModuleFromURL(const char* url)` + - `xor_string` (function, line 915) `void xor_string(char* data, size_t len, char key)` + - `anti_analysis` (function, line 922) `BOOL anti_analysis()` + - `load_lazyconf` (function, line 946) `BOOL load_lazyconf()` + - `GetNtdllBase` (function, line 1184) `HMODULE GetNtdllBase()` + - `isVMByMAC` (function, line 1232) `BOOL isVMByMAC()` + - `extract_shellcode` (function, line 1303) `int extract_shellcode(const char* input, size_t len, unsigned char** out)` + - `hex_char_to_byte` (function, line 1334) `BYTE hex_char_to_byte(char c)` + - `hex_to_bytes` (function, line 1341) `void hex_to_bytes(const char* hex, BYTE* output, size_t len)` + - `executeLoader` (function, line 1348) `void executeLoader(void *arg)` + - `ReverseShell` (function, line 1404) `void __cdecl ReverseShell(void* arg)` + - `ReadFromProcess` (function, line 1513) `DWORD WINAPI ReadFromProcess(LPVOID lpParam)` + - `GetJitteredSleep` (function, line 1587) `DWORD GetJitteredSleep(DWORD base_ms)` + - `GetUsefulSoftware` (function, line 1592) `char* GetUsefulSoftware()` + - `base64_encode` (function, line 1627) `char* base64_encode(const unsigned char* data, size_t inputLen)` + - `base64_decode` (function, line 1663) `char* base64_decode(const char* input, size_t* out_len)` + - `discoverLocalHosts` (function, line 1696) `void discoverLocalHosts()` + - `initProxy` (function, line 1753) `void initProxy()` + - `relay_thread` (function, line 1763) `void WINAPI relay_thread(void* param)` + - `proxy_thread` (function, line 1784) `void WINAPI proxy_thread(void* param)` + - `proxy_accept_thread` (function, line 1855) `void WINAPI proxy_accept_thread(void* param)` + - `startProxy` (function, line 1923) `BOOL startProxy(const char* listenAddr, const char* targetAddr)` + - `stopProxy` (function, line 2010) `BOOL stopProxy(const char* listenAddr)` + - `cleanupProxy` (function, line 2062) `void cleanupProxy()` + - `compressDirectory` (function, line 2094) `BOOL compressDirectory(const char* dirPath)` + - `getNetworkConfig` (function, line 2104) `char* getNetworkConfig()` + - `UploadFileToC2` (function, line 2108) `BOOL UploadFileToC2(const char* url, const char* filePath)` + - `handleUpload` (function, line 2280) `BOOL handleUpload(const char* command)` + - `FileExistsA` (function, line 2301) `BOOL FileExistsA(const char* filePath)` + - `selfDestruct` (function, line 2306) `void selfDestruct()` + - `stristr` (function, line 2362) `char* stristr(const char* str, const char* pattern)` + - `isSensitiveFile` (function, line 2378) `int isSensitiveFile(const char* filename)` + - `searchCredentials` (function, line 2425) `char* searchCredentials(const char* basePath)` + - `UTF8ToWide` (function, line 2551) `WCHAR* UTF8ToWide(const char* utf8)` + - `obfuscateFileTimestamp` (function, line 2562) `BOOL obfuscateFileTimestamp(const char* filepath)` + - `obfuscateFileTimestamps` (function, line 2592) `void obfuscateFileTimestamps(const char* basePath, int depth)` + - `simulateLegitimateTraffic` (function, line 2656) `void simulateLegitimateTraffic(void* param)` + - `restartClient` (function, line 2735) `void restartClient()` + - `checkDebuggers` (function, line 2776) `BOOL checkDebuggers()` + - `MapPEToMemory` (function, line 2838) `unsigned char* MapPEToMemory(unsigned char* rawPE, DWORD rawSize, DWORD* mappedSize)` + - `downloadAndExecute` (function, line 2861) `BOOL downloadAndExecute(const char* url, const char* targetProcess)` + - `DecryptPacket` (function, line 2911) `BOOL DecryptPacket(BYTE* buffer, DWORD* buffer_len)` + - `GetIPs` (function, line 3007) `char* GetIPs()` + - `GetHostname` (function, line 3041) `char* GetHostname()` + - `GetUsername` (function, line 3057) `char* GetUsername()` + - `patchAMSI` (function, line 3074) `BOOL patchAMSI(void)` + - `get_nt_headers` (function, line 3092) `PIMAGE_NT_HEADERS get_nt_headers(BYTE* buffer)` + - `is_64bit` (function, line 3101) `BOOL is_64bit(BYTE* buffer)` + - `get_image_size` (function, line 3107) `DWORD get_image_size(BYTE* buffer)` + - `get_entry_point_rva` (function, line 3113) `DWORD get_entry_point_rva(BYTE* buffer)` + - `pe_buffer_to_virtual_image` (function, line 3119) `BYTE* pe_buffer_to_virtual_image(BYTE* raw_buffer, DWORD* out_size)` + - `create_suspended_process` (function, line 3149) `BOOL create_suspended_process(char* path, PROCESS_INFORMATION* pi)` + - `get_remote_image_base` (function, line 3156) `ULONGLONG get_remote_image_base(PROCESS_INFORMATION* pi, BOOL is_32bit_target)` + - `update_remote_entry_point` (function, line 3250) `BOOL update_remote_entry_point(PROCESS_INFORMATION* pi, ULONGLONG entry_point_va, BOOL is_32bit)` + - `overWrite` (function, line 3277) `void overWrite(const char* targetPath, const char* payloadPath)` + - `cleanSystemLogs` (function, line 3384) `void cleanSystemLogs()` + - `ensurePersistence` (function, line 3421) `BOOL ensurePersistence()` + - `isSandboxEnvironment` (function, line 3482) `BOOL isSandboxEnvironment()` + - `tryPrivilegeEscalation` (function, line 3552) `void tryPrivilegeEscalation()` + - `executeUACBypass` (function, line 3557) `BOOL executeUACBypass(const char* payloadPath)` + - `scanPort` (function, line 3610) `void scanPort(void* arg)` + - `PortScanner` (function, line 3661) `void PortScanner(char* targetIP, int* ports, int numPorts)` + - `PortScannerWrapper` (function, line 3706) `void PortScannerWrapper(void* arg)` + - `EarlyBirdInject` (function, line 3729) `BOOL EarlyBirdInject(unsigned char* shellcode, int shellcode_len)` + - `init_aes_context` (function, line 3900) `PacketEncryptionContext* init_aes_context(const char* key_hex)` + - `retry_http_request` (function, line 3918) `char* retry_http_request(const char* url, const char* method, const char* data, int max_retries)` + - `exec_cmd` (function, line 4172) `char* exec_cmd(const char* cmd)` + - `GetC2Command` (function, line 4200) `char* GetC2Command(const char* host, const char* path)` + - `DownloadToBuffer` (function, line 4347) `unsigned char* DownloadToBuffer(const char* url, DWORD* fileSize)` + - `DownloadFromURL` (function, line 4423) `BOOL DownloadFromURL(const char* url, const char* filepath)` + - `encrypt_data` (function, line 4454) `char* encrypt_data(const char* data)` + - `isValidUUID` (function, line 4512) `BOOL isValidUUID(const char* uuid)` + - `deleteFilesDelay` (function, line 4537) `void deleteFilesDelay(void* arg)` + - `executeCommand` (function, line 4551) `void executeCommand(void* cmdPtr)` + - `handleAtomic` (function, line 4560) `void handleAtomic(char* command)` + - `handleDownload` (function, line 4683) `BOOL handleDownload(const char* command)` + - `SerializeBeaconString` (function, line 4703) `void SerializeBeaconString(char* buffer, int* offset, const char* str)` + - `BeaconDataSerializeString` (function, line 4712) `void BeaconDataSerializeString(char* buffer, int* offset, const char* str)` + - `go` (function, line 4720) `void go(unsigned char * bof_data, int bof_size, char * args, int args_len)` + - `handleAdversary` (function, line 4738) `void handleAdversary(char* command)` + - `main` (function, line 5233) `int main()` + - `PSAPI_VERSION` (macro, line 20) `#define PSAPI_VERSION` + - `WIN32_LEAN_AND_MEAN` (macro, line 21) `#define WIN32_LEAN_AND_MEAN` + - `XOR_KEY` (macro, line 71) `#define XOR_KEY` + - `DEBUG` (macro, line 72) `#define DEBUG` + - `TIMEOUT` (macro, line 73) `#define TIMEOUT` + - `MAX_RESPONSE_SIZE` (macro, line 74) `#define MAX_RESPONSE_SIZE` + - `C2_URL` (macro, line 75) `#define C2_URL` + - `MALEABLE` (macro, line 76) `#define MALEABLE` + - `CLIENT_ID` (macro, line 77) `#define CLIENT_ID` + - `SLEEP_BASE` (macro, line 78) `#define SLEEP_BASE` + - `MIN_JITTER` (macro, line 79) `#define MIN_JITTER` + - `MAX_JITTER` (macro, line 80) `#define MAX_JITTER` + - `MAX_RETRIES` (macro, line 81) `#define MAX_RETRIES` + - `C2_HOST` (macro, line 82) `#define C2_HOST` + - `LC2_HOST` (macro, line 83) `#define LC2_HOST` + - `C2_USER` (macro, line 84) `#define C2_USER` + - `C2_PASS` (macro, line 85) `#define C2_PASS` + - `C2_PORT` (macro, line 86) `#define C2_PORT` + - `CONFIG_PATH` (macro, line 87) `#define CONFIG_PATH` + - `C2_PATH` (macro, line 88) `#define C2_PATH` + - `LC2_PATH` (macro, line 89) `#define LC2_PATH` + - `min` (macro, line 91) `#define min(a,b)` + - `SECURITY_FLAG_IGNORE_REVOCATION` (macro, line 94) `#define SECURITY_FLAG_IGNORE_REVOCATION` + - `INVALID_SOCKET` (macro, line 97) `#define INVALID_SOCKET` + - `USER_AGENT` (macro, line 99) `#define USER_AGENT` + - `USER_AGENT_A` (macro, line 100) `#define USER_AGENT_A` + - `IMAGE_DOS_SIGNATURE` (macro, line 101) `#define IMAGE_DOS_SIGNATURE` + - `IMAGE_NT_SIGNATURE` (macro, line 102) `#define IMAGE_NT_SIGNATURE` + - `IMAGE_NT_OPTIONAL_HDR32_MAGIC` (macro, line 103) `#define IMAGE_NT_OPTIONAL_HDR32_MAGIC` + - `IMAGE_NT_OPTIONAL_HDR64_MAGIC` (macro, line 104) `#define IMAGE_NT_OPTIONAL_HDR64_MAGIC` + - `SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` (macro, line 106) `#define SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` + - `SECURITY_FLAG_IGNORE_INVALID_POLICY` (macro, line 109) `#define SECURITY_FLAG_IGNORE_INVALID_POLICY` + - `_SECURITY_PACKAGE_DEFINITION_` (macro, line 112) `#define _SECURITY_PACKAGE_DEFINITION_` + - `_PROCESS_BASIC_INFORMATION_` (macro, line 115) `#define _PROCESS_BASIC_INFORMATION_` + - `_SP_LSA_MODE_INITIALIZE_DEFINED_` (macro, line 117) `#define _SP_LSA_MODE_INITIALIZE_DEFINED_` + - `ProcessBasicInformation` (macro, line 123) `#define ProcessBasicInformation` + - `CHECK_ERROR` (macro, line 126) `#define CHECK_ERROR(cond, msg)` + - `NUM_USER_AGENTS` (macro, line 231) `#define NUM_USER_AGENTS` + - `NUM_URLS` (macro, line 240) `#define NUM_URLS` + - `NUM_UAS` (macro, line 247) `#define NUM_UAS` + - `NT_SUCCESS` (macro, line 300) `#define NT_SUCCESS(Status)` +- Depends on: `COFFLoader.h`, `aes.h`, `beacon.h`, `cJSON.h` + +## beacon.h +- Layer: utility +- Language: h +- Symbols: + - `datap` (struct, line 25) + - `BEACON_H` (macro, line 21) `#define BEACON_H` + - `CALLBACK_OUTPUT` (macro, line 41) `#define CALLBACK_OUTPUT` + - `CALLBACK_ERROR` (macro, line 42) `#define CALLBACK_ERROR` +- Imported by: `COFFLoader3.c`, `beacon.c` + +## cJSON.c +- Layer: utility +- Language: c +- Symbols: + - `internal_hooks` (struct, line 157) + - `error` (struct, line 88) + - `parse_buffer` (struct, line 291) + - `printbuffer` (struct, line 482) + - `CJSON_PUBLIC` (function, line 95) `CJSON_PUBLIC(const char *) cJSON_GetErrorPtr(void)` + - `CJSON_PUBLIC` (function, line 100) `CJSON_PUBLIC(char *) cJSON_GetStringValue(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 110) `CJSON_PUBLIC(double) cJSON_GetNumberValue(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 125) `CJSON_PUBLIC(const char*) cJSON_Version(void)` + - `case_insensitive_strcmp` (function, line 134) `static int case_insensitive_strcmp(const unsigned char *string1, const unsigned char *string2)` + - `internal_malloc` (function, line 166) `static void * CJSON_CDECL internal_malloc(size_t size)` + - `internal_free` (function, line 170) `static void CJSON_CDECL internal_free(void *pointer)` + - `internal_realloc` (function, line 174) `static void * CJSON_CDECL internal_realloc(void *pointer, size_t size)` + - `cJSON_strdup` (function, line 189) `static unsigned char* cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks)` + - `CJSON_PUBLIC` (function, line 210) `CJSON_PUBLIC(void) cJSON_InitHooks(cJSON_Hooks* hooks)` + - `cJSON_New_Item` (function, line 242) `static cJSON *cJSON_New_Item(const internal_hooks * const hooks)` + - `get_decimal_point` (function, line 281) `static unsigned char get_decimal_point(void)` + - `parse_number` (function, line 309) `static cJSON_bool parse_number(cJSON * const item, parse_buffer * const input_buffer)` + - `ensure` (function, line 494) `static unsigned char* ensure(printbuffer * const p, size_t needed)` + - `update_offset` (function, line 579) `static void update_offset(printbuffer * const buffer)` + - `compare_double` (function, line 592) `static cJSON_bool compare_double(double a, double b)` + - `print_number` (function, line 599) `static cJSON_bool print_number(const cJSON * const item, printbuffer * const output_buffer)` + - `parse_hex4` (function, line 669) `static unsigned parse_hex4(const unsigned char * const input)` + - `utf16_literal_to_utf8` (function, line 706) `static unsigned char utf16_literal_to_utf8(const unsigned char * const input_pointer, const unsig...` + - `parse_string` (function, line 827) `static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer)` + - `print_string_ptr` (function, line 957) `static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffer * const output_...` + - `print_string` (function, line 1079) `static cJSON_bool print_string(const cJSON * const item, printbuffer * const p)` + - `buffer_skip_whitespace` (function, line 1093) `static parse_buffer *buffer_skip_whitespace(parse_buffer * const buffer)` + - `skip_utf8_bom` (function, line 1119) `static parse_buffer *skip_utf8_bom(parse_buffer * const buffer)` + - `CJSON_PUBLIC` (function, line 1134) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithOpts(const char *value, const char **return_parse_end, cJSON...` + - `CJSON_PUBLIC` (function, line 1236) `CJSON_PUBLIC(cJSON *) cJSON_ParseWithLength(const char *value, size_t buffer_length)` + - `print` (function, line 1243) `static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * c...` + - `CJSON_PUBLIC` (function, line 1316) `CJSON_PUBLIC(char *) cJSON_PrintUnformatted(const cJSON *item)` + - `CJSON_PUBLIC` (function, line 1321) `CJSON_PUBLIC(char *) cJSON_PrintBuffered(const cJSON *item, int prebuffer, cJSON_bool fmt)` + - `CJSON_PUBLIC` (function, line 1352) `CJSON_PUBLIC(cJSON_bool) cJSON_PrintPreallocated(cJSON *item, char *buffer, const int length, con...` + - `parse_value` (function, line 1372) `static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buffer)` + - `print_value` (function, line 1427) `static cJSON_bool print_value(const cJSON * const item, printbuffer * const output_buffer)` + - `parse_array` (function, line 1501) `static cJSON_bool parse_array(cJSON * const item, parse_buffer * const input_buffer)` + - `print_array` (function, line 1599) `static cJSON_bool print_array(const cJSON * const item, printbuffer * const output_buffer)` + - `parse_object` (function, line 1661) `static cJSON_bool parse_object(cJSON * const item, parse_buffer * const input_buffer)` + - `print_object` (function, line 1780) `static cJSON_bool print_object(const cJSON * const item, printbuffer * const output_buffer)` + - `get_array_item` (function, line 1916) `static cJSON* get_array_item(const cJSON *array, size_t index)` + - `CJSON_PUBLIC` (function, line 1935) `CJSON_PUBLIC(cJSON *) cJSON_GetArrayItem(const cJSON *array, int index)` + - `get_object_item` (function, line 1945) `static cJSON *get_object_item(const cJSON * const object, const char * const name, const cJSON_bo...` + - `CJSON_PUBLIC` (function, line 1977) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItem(const cJSON * const object, const char * const string)` + - `CJSON_PUBLIC` (function, line 1982) `CJSON_PUBLIC(cJSON *) cJSON_GetObjectItemCaseSensitive(const cJSON * const object, const char * c...` + - `CJSON_PUBLIC` (function, line 1987) `CJSON_PUBLIC(cJSON_bool) cJSON_HasObjectItem(const cJSON *object, const char *string)` + - `suffix_object` (function, line 1993) `static void suffix_object(cJSON *prev, cJSON *item)` + - `create_reference` (function, line 2000) `static cJSON *create_reference(const cJSON *item, const internal_hooks * const hooks)` + - `add_item_to_array` (function, line 2021) `static cJSON_bool add_item_to_array(cJSON *array, cJSON *item)` + - `cast_away_const` (function, line 2066) `static void* cast_away_const(const void* string)` + - `add_item_to_object` (function, line 2075) `static cJSON_bool add_item_to_object(cJSON * const object, const char * const string, cJSON * con...` + - `CJSON_PUBLIC` (function, line 2112) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemToObject(cJSON *object, const char *string, cJSON *item)` + - `CJSON_PUBLIC` (function, line 2123) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToArray(cJSON *array, cJSON *item)` + - `CJSON_PUBLIC` (function, line 2133) `CJSON_PUBLIC(cJSON_bool) cJSON_AddItemReferenceToObject(cJSON *object, const char *string, cJSON ...` + - `CJSON_PUBLIC` (function, line 2143) `CJSON_PUBLIC(cJSON*) cJSON_AddNullToObject(cJSON * const object, const char * const name)` + - `CJSON_PUBLIC` (function, line 2155) `CJSON_PUBLIC(cJSON*) cJSON_AddTrueToObject(cJSON * const object, const char * const name)` + - `CJSON_PUBLIC` (function, line 2167) `CJSON_PUBLIC(cJSON*) cJSON_AddFalseToObject(cJSON * const object, const char * const name)` + - `CJSON_PUBLIC` (function, line 2179) `CJSON_PUBLIC(cJSON*) cJSON_AddBoolToObject(cJSON * const object, const char * const name, const c...` + - `CJSON_PUBLIC` (function, line 2191) `CJSON_PUBLIC(cJSON*) cJSON_AddNumberToObject(cJSON * const object, const char * const name, const...` + - `CJSON_PUBLIC` (function, line 2203) `CJSON_PUBLIC(cJSON*) cJSON_AddStringToObject(cJSON * const object, const char * const name, const...` + - `CJSON_PUBLIC` (function, line 2215) `CJSON_PUBLIC(cJSON*) cJSON_AddRawToObject(cJSON * const object, const char * const name, const ch...` + - `CJSON_PUBLIC` (function, line 2227) `CJSON_PUBLIC(cJSON*) cJSON_AddObjectToObject(cJSON * const object, const char * const name)` + - `CJSON_PUBLIC` (function, line 2239) `CJSON_PUBLIC(cJSON*) cJSON_AddArrayToObject(cJSON * const object, const char * const name)` + - `CJSON_PUBLIC` (function, line 2251) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemViaPointer(cJSON *parent, cJSON * const item)` + - `CJSON_PUBLIC` (function, line 2287) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromArray(cJSON *array, int which)` + - `CJSON_PUBLIC` (function, line 2297) `CJSON_PUBLIC(void) cJSON_DeleteItemFromArray(cJSON *array, int which)` + - `CJSON_PUBLIC` (function, line 2302) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObject(cJSON *object, const char *string)` + - `CJSON_PUBLIC` (function, line 2309) `CJSON_PUBLIC(cJSON *) cJSON_DetachItemFromObjectCaseSensitive(cJSON *object, const char *string)` + - `CJSON_PUBLIC` (function, line 2316) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObject(cJSON *object, const char *string)` + - `CJSON_PUBLIC` (function, line 2321) `CJSON_PUBLIC(void) cJSON_DeleteItemFromObjectCaseSensitive(cJSON *object, const char *string)` + - `CJSON_PUBLIC` (function, line 2363) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemViaPointer(cJSON * const parent, cJSON * const item, cJ...` + - `CJSON_PUBLIC` (function, line 2413) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInArray(cJSON *array, int which, cJSON *newitem)` + - `replace_item_in_object` (function, line 2423) `static cJSON_bool replace_item_in_object(cJSON *object, const char *string, cJSON *replacement, c...` + - `CJSON_PUBLIC` (function, line 2446) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObject(cJSON *object, const char *string, cJSON *newi...` + - `CJSON_PUBLIC` (function, line 2451) `CJSON_PUBLIC(cJSON_bool) cJSON_ReplaceItemInObjectCaseSensitive(cJSON *object, const char *string...` + - `CJSON_PUBLIC` (function, line 2468) `CJSON_PUBLIC(cJSON *) cJSON_CreateTrue(void)` + - `CJSON_PUBLIC` (function, line 2479) `CJSON_PUBLIC(cJSON *) cJSON_CreateFalse(void)` + - `CJSON_PUBLIC` (function, line 2490) `CJSON_PUBLIC(cJSON *) cJSON_CreateBool(cJSON_bool boolean)` + - `CJSON_PUBLIC` (function, line 2501) `CJSON_PUBLIC(cJSON *) cJSON_CreateNumber(double num)` + - `CJSON_PUBLIC` (function, line 2526) `CJSON_PUBLIC(cJSON *) cJSON_CreateString(const char *string)` + - `CJSON_PUBLIC` (function, line 2543) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringReference(const char *string)` + - `CJSON_PUBLIC` (function, line 2555) `CJSON_PUBLIC(cJSON *) cJSON_CreateObjectReference(const cJSON *child)` + - `CJSON_PUBLIC` (function, line 2567) `CJSON_PUBLIC(cJSON *) cJSON_CreateArrayReference(const cJSON *child)` + - `CJSON_PUBLIC` (function, line 2579) `CJSON_PUBLIC(cJSON *) cJSON_CreateRaw(const char *raw)` + - `CJSON_PUBLIC` (function, line 2596) `CJSON_PUBLIC(cJSON *) cJSON_CreateArray(void)` + - `CJSON_PUBLIC` (function, line 2607) `CJSON_PUBLIC(cJSON *) cJSON_CreateObject(void)` + - `CJSON_PUBLIC` (function, line 2659) `CJSON_PUBLIC(cJSON *) cJSON_CreateFloatArray(const float *numbers, int count)` + - `CJSON_PUBLIC` (function, line 2699) `CJSON_PUBLIC(cJSON *) cJSON_CreateDoubleArray(const double *numbers, int count)` + - `CJSON_PUBLIC` (function, line 2739) `CJSON_PUBLIC(cJSON *) cJSON_CreateStringArray(const char *const *strings, int count)` + - `cJSON_Duplicate_rec` (function, line 2786) `cJSON * cJSON_Duplicate_rec(const cJSON *item, size_t depth, cJSON_bool recurse)` + - `skip_oneline_comment` (function, line 2873) `static void skip_oneline_comment(char **input)` + - `skip_multiline_comment` (function, line 2886) `static void skip_multiline_comment(char **input)` + - `minify_string` (function, line 2900) `static void minify_string(char **input, char **output)` + - `CJSON_PUBLIC` (function, line 2922) `CJSON_PUBLIC(void) cJSON_Minify(char *json)` + - `CJSON_PUBLIC` (function, line 2972) `CJSON_PUBLIC(cJSON_bool) cJSON_IsInvalid(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 2982) `CJSON_PUBLIC(cJSON_bool) cJSON_IsFalse(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 2992) `CJSON_PUBLIC(cJSON_bool) cJSON_IsTrue(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3002) `CJSON_PUBLIC(cJSON_bool) cJSON_IsBool(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3012) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNull(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3022) `CJSON_PUBLIC(cJSON_bool) cJSON_IsNumber(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3032) `CJSON_PUBLIC(cJSON_bool) cJSON_IsString(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3042) `CJSON_PUBLIC(cJSON_bool) cJSON_IsArray(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3052) `CJSON_PUBLIC(cJSON_bool) cJSON_IsObject(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3062) `CJSON_PUBLIC(cJSON_bool) cJSON_IsRaw(const cJSON * const item)` + - `CJSON_PUBLIC` (function, line 3072) `CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_...` + - `cJSON_ArrayForEach` (function, line 3157) `cJSON_ArrayForEach(a_element, a)` + - `cJSON_ArrayForEach` (function, line 3173) `cJSON_ArrayForEach(b_element, b)` + - `CJSON_PUBLIC` (function, line 3194) `CJSON_PUBLIC(void *) cJSON_malloc(size_t size)` + - `CJSON_PUBLIC` (function, line 3199) `CJSON_PUBLIC(void) cJSON_free(void *object)` + - `_CRT_SECURE_NO_DEPRECATE` (macro, line 28) `#define _CRT_SECURE_NO_DEPRECATE` + - `true` (macro, line 65) `#define true` + - `false` (macro, line 70) `#define false` + - `isinf` (macro, line 74) `#define isinf(d)` + - `isnan` (macro, line 77) `#define isnan(d)` + - `NAN` (macro, line 82) `#define NAN` + - `NAN` (macro, line 84) `#define NAN` + - `internal_malloc` (macro, line 179) `#define internal_malloc` + - `internal_free` (macro, line 180) `#define internal_free` + - `internal_realloc` (macro, line 181) `#define internal_realloc` + - `static_strlen` (macro, line 185) `#define static_strlen(string_literal)` + - `can_read` (macro, line 301) `#define can_read(buffer, size)` + - `can_access_at_index` (macro, line 303) `#define can_access_at_index(buffer, index)` + - `cannot_access_at_index` (macro, line 304) `#define cannot_access_at_index(buffer, index)` + - `buffer_at_offset` (macro, line 306) `#define buffer_at_offset(buffer)` + - `cjson_min` (macro, line 1241) `#define cjson_min(a, b)` +- Depends on: `cJSON.h` + +## cJSON.h +- Layer: utility +- Language: h +- Symbols: + - `cJSON` (struct, line 92) + - `cJSON_Hooks` (struct, line 114) + - `cJSON_bool` (type_alias, line 120) `typedef int cJSON_bool;` + - `sensitive` (function, line 249) `* case_sensitive determines if object keys are treated case sensitive (1) or case insensitive (0) */ CJSON_PUBLIC(cJSON_bool) cJSON_Compare(const cJSON * const a, const cJSON * const b, const cJSON_bo` + - `next` (variable, line 27) `extern "C" { #endif #if !defined(__WINDOWS__) && (defined(WIN32) || defined(WIN64) || defined(_MSC_VER) || defined(_WIN32)) #define __WINDOWS__ #endif #ifdef __WINDOWS__ /* When compiling for windows,` + - `cJSON__h` (macro, line 24) `#define cJSON__h` + - `__WINDOWS__` (macro, line 32) `#define __WINDOWS__` + - `CJSON_CDECL` (macro, line 44) `#define CJSON_CDECL` + - `CJSON_STDCALL` (macro, line 45) `#define CJSON_STDCALL` + - `CJSON_EXPORT_SYMBOLS` (macro, line 49) `#define CJSON_EXPORT_SYMBOLS` + - `CJSON_PUBLIC` (macro, line 53) `#define CJSON_PUBLIC(type)` + - `CJSON_PUBLIC` (macro, line 55) `#define CJSON_PUBLIC(type)` + - `CJSON_PUBLIC` (macro, line 57) `#define CJSON_PUBLIC(type)` + - `CJSON_CDECL` (macro, line 60) `#define CJSON_CDECL` + - `CJSON_STDCALL` (macro, line 61) `#define CJSON_STDCALL` + - `CJSON_PUBLIC` (macro, line 64) `#define CJSON_PUBLIC(type)` + - `CJSON_PUBLIC` (macro, line 66) `#define CJSON_PUBLIC(type)` + - `CJSON_VERSION_MAJOR` (macro, line 71) `#define CJSON_VERSION_MAJOR` + - `CJSON_VERSION_MINOR` (macro, line 72) `#define CJSON_VERSION_MINOR` + - `CJSON_VERSION_PATCH` (macro, line 73) `#define CJSON_VERSION_PATCH` + - `cJSON_Invalid` (macro, line 78) `#define cJSON_Invalid` + - `cJSON_False` (macro, line 79) `#define cJSON_False` + - `cJSON_True` (macro, line 80) `#define cJSON_True` + - `cJSON_NULL` (macro, line 81) `#define cJSON_NULL` + - `cJSON_Number` (macro, line 82) `#define cJSON_Number` + - `cJSON_String` (macro, line 83) `#define cJSON_String` + - `cJSON_Array` (macro, line 84) `#define cJSON_Array` + - `cJSON_Object` (macro, line 85) `#define cJSON_Object` + - `cJSON_Raw` (macro, line 86) `#define cJSON_Raw` + - `cJSON_IsReference` (macro, line 88) `#define cJSON_IsReference` + - `cJSON_StringIsConst` (macro, line 89) `#define cJSON_StringIsConst` + - `CJSON_NESTING_LIMIT` (macro, line 126) `#define CJSON_NESTING_LIMIT` + - `CJSON_CIRCULAR_LIMIT` (macro, line 132) `#define CJSON_CIRCULAR_LIMIT` + - `cJSON_SetIntValue` (macro, line 270) `#define cJSON_SetIntValue(object, number)` + - `cJSON_SetNumberValue` (macro, line 273) `#define cJSON_SetNumberValue(object, number)` + - `cJSON_SetBoolValue` (macro, line 278) `#define cJSON_SetBoolValue(object, boolValue)` + - `cJSON_ArrayForEach` (macro, line 285) `#define cJSON_ArrayForEach(element, array)` +- Imported by: `beacon.c`, `cJSON.c` + +## gen_beacon.sh +- Layer: utility +- Doc: === beacon-GEN v1.2 === +- Language: sh +- Symbols: + - `show_help` (function, line 34) + - `xor_string` (function, line 138) + - `crc32` (function, line 5916) + +## gen_dll.sh +- Layer: utility +- Doc: 1. Generar DLL +- Language: sh + +## gen_dll_rev.sh +- Layer: utility +- Doc: === CONFIGURACIÓN POR DEFECTO === +- Language: sh +- Symbols: + - `usage` (function, line 12) + +## gen_dll_ss.sh +- Layer: utility +- Doc: === CONFIGURACIÓN POR DEFECTO === +- Language: sh +- Symbols: + - `usage` (function, line 10) + +## gen_key.sh +- Layer: utility +- Doc: === CONFIGURACIÓN POR DEFECTO === +- Language: sh +- Symbols: + - `usage` (function, line 10) + +## gen_module.sh +- Layer: utility +- Doc: === gen_cmd_dll.sh v1.0 === Genera DLL y shellcode ofuscado para ejecutar un comando Uso: ./gen_cmd_dll.sh --cmd "powers +- Language: sh +- Symbols: + - `show_help` (function, line 18) + - `xor_obfuscate` (function, line 35) + +## generate_hashs.py +- Layer: utility +- Doc: BOF Bindings Generator for Cobalt Strike Author: Gris Iscomeback Email: grisiscomeback@gmail.com Creation Date: 13/08/20 +- Language: py +- Symbols: + - `djb2` (function, line 23) `def djb2(s)` + - `generate_coff_loader` (function, line 223) `def generate_coff_loader()` + - `generate_bof_test` (function, line 491) `def generate_bof_test()` + - `main` (function, line 553) `def main()` + +## install.sh +- Layer: utility +- Language: sh diff --git a/readmenator-agent/KB_test.md b/readmenator-agent/KB_test.md new file mode 100644 index 0000000..7aa23ef --- /dev/null +++ b/readmenator-agent/KB_test.md @@ -0,0 +1,283 @@ +# Subsystem: test + +## bof/test/Test.c +- Layer: testing +- Language: c +- Symbols: + - `go` (function, line 3) `void go(char *args, int alen)` +- Depends on: `bof/test/beacon.h` + +## bof/test/amsibypass.c +- Layer: testing +- Language: c +- Symbols: + - `go` (function, line 34) `void go(char *args, int alen)` + - `__imp_LoadLibraryA` (variable, line 26) `extern PVOID __imp_LoadLibraryA;` + - `__imp_GetProcAddress` (variable, line 27) `extern PVOID __imp_GetProcAddress;` + - `__imp_VirtualProtect` (variable, line 28) `extern PVOID __imp_VirtualProtect;` + - `__imp_RtlCopyMemory` (variable, line 29) `extern PVOID __imp_RtlCopyMemory;` +- Depends on: `bof/test/beacon.h` + +## bof/test/beacon.h +- Layer: testing +- Language: h +- Symbols: + - `datap` (struct, line 25) + - `BEACON_H` (macro, line 21) `#define BEACON_H` + - `CALLBACK_OUTPUT` (macro, line 41) `#define CALLBACK_OUTPUT` + - `CALLBACK_ERROR` (macro, line 42) `#define CALLBACK_ERROR` +- Imported by: `bof/test/Test.c`, `bof/test/amsibypass.c`, `bof/test/cmdwhoami.c`, `bof/test/disablelog.c`, `bof/test/getenv.c`, `bof/test/loadvnc.c`, `bof/test/persist.c`, `bof/test/persistsvc.c`, `bof/test/scan_shellcode.c`, `bof/test/shellcode.c`, `bof/test/sock5.c`, `bof/test/uacbypass.c`, `bof/test/upload.c`, `bof/test/vncrelay.c`, `bof/test/winver.c` + +## bof/test/cmdwhoami.c +- Layer: testing +- Language: c +- Symbols: + - `go` (function, line 43) `void go(char *args, int alen)` + - `__imp_LoadLibraryA` (variable, line 26) `extern PVOID __imp_LoadLibraryA;` + - `__imp_GetProcAddress` (variable, line 27) `extern PVOID __imp_GetProcAddress;` + - `__imp_CloseHandle` (variable, line 28) `extern PVOID __imp_CloseHandle;` +- Depends on: `bof/test/beacon.h` + +## bof/test/disablelog.c +- Layer: infrastructure +- Language: c +- Symbols: + - `my_wcscmp` (function, line 37) `static int my_wcscmp(const wchar_t *s1, const wchar_t *s2)` + - `go` (function, line 69) `void go(char *args, int alen)` + - `__imp_LoadLibraryA` (variable, line 27) `extern PVOID __imp_LoadLibraryA;` + - `__imp_GetProcAddress` (variable, line 28) `extern PVOID __imp_GetProcAddress;` + - `__imp_GetModuleHandleA` (variable, line 29) `extern PVOID __imp_GetModuleHandleA;` + - `__imp_CloseHandle` (variable, line 30) `extern PVOID __imp_CloseHandle;` + - `__imp_OpenProcess` (variable, line 31) `extern PVOID __imp_OpenProcess;` + - `WIN32_LEAN_AND_MEAN` (macro, line 20) `#define WIN32_LEAN_AND_MEAN` + - `NT_SUCCESS` (macro, line 34) `#define NT_SUCCESS(x)` +- Depends on: `bof/test/beacon.h` + +## bof/test/getenv.c +- Layer: infrastructure +- Language: c +- Symbols: + - `go` (function, line 25) `void go(char *args, int alen)` + - `__imp_GetEnvironmentVariableA` (variable, line 23) `extern PVOID __imp_GetEnvironmentVariableA;` +- Depends on: `bof/test/beacon.h` + +## bof/test/loadvnc.c +- Layer: testing +- Language: c +- Symbols: + - `_PROCESSENTRY32` (struct, line 35) + - `dwSize` (type_alias, line 34) `typedef struct _PROCESSENTRY32 { DWORD dwSize;` + - `execute_cmd_hidden` (function, line 51) `void execute_cmd_hidden(char* cmd)` + - `go` (function, line 81) `void go(char *args, int alen)` + - `__imp_LoadLibraryA` (variable, line 26) `extern PVOID __imp_LoadLibraryA;` + - `__imp_GetProcAddress` (variable, line 27) `extern PVOID __imp_GetProcAddress;` + - `__imp_CloseHandle` (variable, line 28) `extern PVOID __imp_CloseHandle;` + - `TH32CS_SNAPPROCESS` (macro, line 33) `#define TH32CS_SNAPPROCESS` +- Depends on: `bof/test/beacon.h` + +## bof/test/make_table.c +- Layer: testing +- Language: c +- Symbols: + - `Copyright` (function, line 17) `Copyright (c) LazyOwn RedTeam 2025. All rights reserved. +*/ + +#include +#include ' INDEX.md", + "cat KB_.md", + "grep -n '' ARCHITECTURE.md SYMBOLS.md" + ], + "regenerate": "readmenator . --rebuild" +} \ No newline at end of file diff --git a/readmenator-agent/SECURITY.md b/readmenator-agent/SECURITY.md new file mode 100644 index 0000000..e552b09 --- /dev/null +++ b/readmenator-agent/SECURITY.md @@ -0,0 +1,3 @@ +# Security Findings + +No security findings. \ No newline at end of file diff --git a/readmenator-agent/SYMBOLS.md b/readmenator-agent/SYMBOLS.md new file mode 100644 index 0000000..f1c416e --- /dev/null +++ b/readmenator-agent/SYMBOLS.md @@ -0,0 +1,872 @@ +# Symbols + +| Symbol | Kind | File:Line | Signature | +|--------|------|-----------|-----------| +| `COFFLOADER_H` | macro | `COFFLoader.h:21` | `#define COFFLOADER_H` | +| `COFFHeader` | struct | `COFFLoader3.c:620` | `` | +| `COFFRelocation` | struct | `COFFLoader3.c:599` | `` | +| `COFFSection` | struct | `COFFLoader3.c:586` | `` | +| `IMAGE_REL_AMD64_ABSOLUTE` | macro | `COFFLoader3.c:568` | `#define IMAGE_REL_AMD64_ABSOLUTE` | +| `IMAGE_REL_AMD64_ADDR32` | macro | `COFFLoader3.c:570` | `#define IMAGE_REL_AMD64_ADDR32` | +| `IMAGE_REL_AMD64_ADDR32NB` | macro | `COFFLoader3.c:571` | `#define IMAGE_REL_AMD64_ADDR32NB` | +| `IMAGE_REL_AMD64_ADDR64` | macro | `COFFLoader3.c:569` | `#define IMAGE_REL_AMD64_ADDR64` | +| `IMAGE_REL_AMD64_PAIR` | macro | `COFFLoader3.c:583` | `#define IMAGE_REL_AMD64_PAIR` | +| `IMAGE_REL_AMD64_REL32` | macro | `COFFLoader3.c:572` | `#define IMAGE_REL_AMD64_REL32` | +| `IMAGE_REL_AMD64_REL32_1` | macro | `COFFLoader3.c:573` | `#define IMAGE_REL_AMD64_REL32_1` | +| `IMAGE_REL_AMD64_REL32_2` | macro | `COFFLoader3.c:574` | `#define IMAGE_REL_AMD64_REL32_2` | +| `IMAGE_REL_AMD64_REL32_3` | macro | `COFFLoader3.c:575` | `#define IMAGE_REL_AMD64_REL32_3` | +| `IMAGE_REL_AMD64_REL32_4` | macro | `COFFLoader3.c:576` | `#define IMAGE_REL_AMD64_REL32_4` | +| `IMAGE_REL_AMD64_REL32_5` | macro | `COFFLoader3.c:577` | `#define IMAGE_REL_AMD64_REL32_5` | +| `IMAGE_REL_AMD64_SECREL` | macro | `COFFLoader3.c:579` | `#define IMAGE_REL_AMD64_SECREL` | +| `IMAGE_REL_AMD64_SECREL7` | macro | `COFFLoader3.c:580` | `#define IMAGE_REL_AMD64_SECREL7` | +| `IMAGE_REL_AMD64_SECTION` | macro | `COFFLoader3.c:578` | `#define IMAGE_REL_AMD64_SECTION` | +| `IMAGE_REL_AMD64_SREL32` | macro | `COFFLoader3.c:582` | `#define IMAGE_REL_AMD64_SREL32` | +| `IMAGE_REL_AMD64_SSPAN32` | macro | `COFFLoader3.c:584` | `#define IMAGE_REL_AMD64_SSPAN32` | +| `IMAGE_REL_AMD64_TOKEN` | macro | `COFFLoader3.c:581` | `#define IMAGE_REL_AMD64_TOKEN` | +| `RunCOFF` | function | `COFFLoader3.c:1112` | `int RunCOFF(const char* functionname, unsigned char* coff_data, uint32_t filesize, unsigned char*...` | +| `SymbolHash` | struct | `COFFLoader3.c:642` | `` | +| `__attribute__` | function | `COFFLoader3.c:1103` | `__attribute__((noinline)) +static void call_go_aligned(void* func, char* arg1, int arg2)` | +| `__imp_AdjustTokenPrivileges` | variable | `COFFLoader3.c:450` | `extern PVOID __imp_AdjustTokenPrivileges;` | +| `__imp_AllocConsole` | variable | `COFFLoader3.c:436` | `extern PVOID __imp_AllocConsole;` | +| `__imp_AttachConsole` | variable | `COFFLoader3.c:438` | `extern PVOID __imp_AttachConsole;` | +| `__imp_BeaconDataExtract` | variable | `COFFLoader3.c:337` | `extern PVOID __imp_BeaconDataExtract;` | +| `__imp_BeaconDataInt` | variable | `COFFLoader3.c:335` | `extern PVOID __imp_BeaconDataInt;` | +| `__imp_BeaconDataParse` | variable | `COFFLoader3.c:334` | `extern PVOID __imp_BeaconDataParse;` | +| `__imp_BeaconDataShort` | variable | `COFFLoader3.c:336` | `extern PVOID __imp_BeaconDataShort;` | +| `__imp_BeaconOutput` | variable | `COFFLoader3.c:333` | `extern PVOID __imp_BeaconOutput;` | +| `__imp_BeaconPrintf` | variable | `COFFLoader3.c:332` | `extern PVOID __imp_BeaconPrintf;` | +| `__imp_CheckRemoteDebuggerPresent` | variable | `COFFLoader3.c:440` | `extern PVOID __imp_CheckRemoteDebuggerPresent;` | +| `__imp_CloseHandle` | variable | `COFFLoader3.c:344` | `extern PVOID __imp_CloseHandle;` | +| `__imp_CoCreateInstance` | variable | `COFFLoader3.c:481` | `extern PVOID __imp_CoCreateInstance;` | +| `__imp_CoInitializeEx` | variable | `COFFLoader3.c:479` | `extern PVOID __imp_CoInitializeEx;` | +| `__imp_CoTaskMemFree` | variable | `COFFLoader3.c:482` | `extern PVOID __imp_CoTaskMemFree;` | +| `__imp_CoUninitialize` | variable | `COFFLoader3.c:480` | `extern PVOID __imp_CoUninitialize;` | +| `__imp_CopyFileA` | variable | `COFFLoader3.c:364` | `extern PVOID __imp_CopyFileA;` | +| `__imp_CopyFileW` | variable | `COFFLoader3.c:365` | `extern PVOID __imp_CopyFileW;` | +| `__imp_CreateDirectoryA` | variable | `COFFLoader3.c:368` | `extern PVOID __imp_CreateDirectoryA;` | +| `__imp_CreateDirectoryW` | variable | `COFFLoader3.c:369` | `extern PVOID __imp_CreateDirectoryW;` | +| `__imp_CreateFileA` | variable | `COFFLoader3.c:354` | `extern PVOID __imp_CreateFileA;` | +| `__imp_CreateFileW` | variable | `COFFLoader3.c:355` | `extern PVOID __imp_CreateFileW;` | +| `__imp_CreateProcessA` | variable | `COFFLoader3.c:551` | `extern PVOID __imp_CreateProcessA;` | +| `__imp_CreateProcessAsUserA` | variable | `COFFLoader3.c:451` | `extern PVOID __imp_CreateProcessAsUserA;` | +| `__imp_CreateProcessAsUserW` | variable | `COFFLoader3.c:452` | `extern PVOID __imp_CreateProcessAsUserW;` | +| `__imp_CreateProcessW` | variable | `COFFLoader3.c:552` | `extern PVOID __imp_CreateProcessW;` | +| `__imp_CreateThread` | variable | `COFFLoader3.c:348` | `extern PVOID __imp_CreateThread;` | +| `__imp_CreateToolhelp32Snapshot` | variable | `COFFLoader3.c:549` | `extern PVOID __imp_CreateToolhelp32Snapshot;` | +| `__imp_CryptAcquireContextA` | variable | `COFFLoader3.c:468` | `extern PVOID __imp_CryptAcquireContextA;` | +| `__imp_CryptAcquireContextW` | variable | `COFFLoader3.c:469` | `extern PVOID __imp_CryptAcquireContextW;` | +| `__imp_CryptCreateHash` | variable | `COFFLoader3.c:470` | `extern PVOID __imp_CryptCreateHash;` | +| `__imp_CryptDecrypt` | variable | `COFFLoader3.c:474` | `extern PVOID __imp_CryptDecrypt;` | +| `__imp_CryptDeriveKey` | variable | `COFFLoader3.c:472` | `extern PVOID __imp_CryptDeriveKey;` | +| `__imp_CryptDestroyHash` | variable | `COFFLoader3.c:476` | `extern PVOID __imp_CryptDestroyHash;` | +| `__imp_CryptDestroyKey` | variable | `COFFLoader3.c:477` | `extern PVOID __imp_CryptDestroyKey;` | +| `__imp_CryptEncrypt` | variable | `COFFLoader3.c:473` | `extern PVOID __imp_CryptEncrypt;` | +| `__imp_CryptGenRandom` | variable | `COFFLoader3.c:478` | `extern PVOID __imp_CryptGenRandom;` | +| `__imp_CryptHashData` | variable | `COFFLoader3.c:471` | `extern PVOID __imp_CryptHashData;` | +| `__imp_CryptReleaseContext` | variable | `COFFLoader3.c:475` | `extern PVOID __imp_CryptReleaseContext;` | +| `__imp_DeleteFileA` | variable | `COFFLoader3.c:360` | `extern PVOID __imp_DeleteFileA;` | +| `__imp_DeleteFileW` | variable | `COFFLoader3.c:361` | `extern PVOID __imp_DeleteFileW;` | +| `__imp_DuplicateTokenEx` | variable | `COFFLoader3.c:445` | `extern PVOID __imp_DuplicateTokenEx;` | +| `__imp_EnumProcessModules` | variable | `COFFLoader3.c:510` | `extern PVOID __imp_EnumProcessModules;` | +| `__imp_EnumProcesses` | variable | `COFFLoader3.c:509` | `extern PVOID __imp_EnumProcesses;` | +| `__imp_EnumWindows` | variable | `COFFLoader3.c:502` | `extern PVOID __imp_EnumWindows;` | +| `__imp_ExitProcess` | variable | `COFFLoader3.c:345` | `extern PVOID __imp_ExitProcess;` | +| `__imp_ExitThread` | variable | `COFFLoader3.c:346` | `extern PVOID __imp_ExitThread;` | +| `__imp_ExpandEnvironmentStringsA` | variable | `COFFLoader3.c:426` | `extern PVOID __imp_ExpandEnvironmentStringsA;` | +| `__imp_ExpandEnvironmentStringsW` | variable | `COFFLoader3.c:427` | `extern PVOID __imp_ExpandEnvironmentStringsW;` | +| `__imp_FindClose` | variable | `COFFLoader3.c:376` | `extern PVOID __imp_FindClose;` | +| `__imp_FindFirstFileA` | variable | `COFFLoader3.c:372` | `extern PVOID __imp_FindFirstFileA;` | +| `__imp_FindFirstFileW` | variable | `COFFLoader3.c:373` | `extern PVOID __imp_FindFirstFileW;` | +| `__imp_FindNextFileA` | variable | `COFFLoader3.c:374` | `extern PVOID __imp_FindNextFileA;` | +| `__imp_FindNextFileW` | variable | `COFFLoader3.c:375` | `extern PVOID __imp_FindNextFileW;` | +| `__imp_FindWindowA` | variable | `COFFLoader3.c:500` | `extern PVOID __imp_FindWindowA;` | +| `__imp_FindWindowW` | variable | `COFFLoader3.c:501` | `extern PVOID __imp_FindWindowW;` | +| `__imp_FormatMessageA` | variable | `COFFLoader3.c:420` | `extern PVOID __imp_FormatMessageA;` | +| `__imp_FormatMessageW` | variable | `COFFLoader3.c:421` | `extern PVOID __imp_FormatMessageW;` | +| `__imp_FreeConsole` | variable | `COFFLoader3.c:437` | `extern PVOID __imp_FreeConsole;` | +| `__imp_FreeLibrary` | variable | `COFFLoader3.c:434` | `extern PVOID __imp_FreeLibrary;` | +| `__imp_GetClassNameA` | variable | `COFFLoader3.c:505` | `extern PVOID __imp_GetClassNameA;` | +| `__imp_GetClassNameW` | variable | `COFFLoader3.c:506` | `extern PVOID __imp_GetClassNameW;` | +| `__imp_GetCommandLineA` | variable | `COFFLoader3.c:428` | `extern PVOID __imp_GetCommandLineA;` | +| `__imp_GetCommandLineW` | variable | `COFFLoader3.c:429` | `extern PVOID __imp_GetCommandLineW;` | +| `__imp_GetComputerNameA` | variable | `COFFLoader3.c:387` | `extern PVOID __imp_GetComputerNameA;` | +| `__imp_GetComputerNameW` | variable | `COFFLoader3.c:388` | `extern PVOID __imp_GetComputerNameW;` | +| `__imp_GetConsoleWindow` | variable | `COFFLoader3.c:435` | `extern PVOID __imp_GetConsoleWindow;` | +| `__imp_GetCurrentProcess` | variable | `COFFLoader3.c:349` | `extern PVOID __imp_GetCurrentProcess;` | +| `__imp_GetCurrentProcessId` | variable | `COFFLoader3.c:350` | `extern PVOID __imp_GetCurrentProcessId;` | +| `__imp_GetCurrentThreadId` | variable | `COFFLoader3.c:351` | `extern PVOID __imp_GetCurrentThreadId;` | +| `__imp_GetDesktopWindow` | variable | `COFFLoader3.c:498` | `extern PVOID __imp_GetDesktopWindow;` | +| `__imp_GetEnvironmentVariableA` | variable | `COFFLoader3.c:422` | `extern PVOID __imp_GetEnvironmentVariableA;` | +| `__imp_GetEnvironmentVariableW` | variable | `COFFLoader3.c:423` | `extern PVOID __imp_GetEnvironmentVariableW;` | +| `__imp_GetFileAttributesA` | variable | `COFFLoader3.c:377` | `extern PVOID __imp_GetFileAttributesA;` | +| `__imp_GetFileAttributesW` | variable | `COFFLoader3.c:378` | `extern PVOID __imp_GetFileAttributesW;` | +| `__imp_GetFileSize` | variable | `COFFLoader3.c:366` | `extern PVOID __imp_GetFileSize;` | +| `__imp_GetFileSizeEx` | variable | `COFFLoader3.c:367` | `extern PVOID __imp_GetFileSizeEx;` | +| `__imp_GetLastError` | variable | `COFFLoader3.c:343` | `extern PVOID __imp_GetLastError;` | +| `__imp_GetModuleBaseNameA` | variable | `COFFLoader3.c:511` | `extern PVOID __imp_GetModuleBaseNameA;` | +| `__imp_GetModuleBaseNameW` | variable | `COFFLoader3.c:512` | `extern PVOID __imp_GetModuleBaseNameW;` | +| `__imp_GetModuleFileNameA` | variable | `COFFLoader3.c:430` | `extern PVOID __imp_GetModuleFileNameA;` | +| `__imp_GetModuleFileNameW` | variable | `COFFLoader3.c:431` | `extern PVOID __imp_GetModuleFileNameW;` | +| `__imp_GetModuleHandleA` | variable | `COFFLoader3.c:340` | `extern PVOID __imp_GetModuleHandleA;` | +| `__imp_GetModuleHandleW` | variable | `COFFLoader3.c:341` | `extern PVOID __imp_GetModuleHandleW;` | +| `__imp_GetModuleInformation` | variable | `COFFLoader3.c:513` | `extern PVOID __imp_GetModuleInformation;` | +| `__imp_GetNativeSystemInfo` | variable | `COFFLoader3.c:393` | `extern PVOID __imp_GetNativeSystemInfo;` | +| `__imp_GetProcAddress` | variable | `COFFLoader3.c:342` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_GetShellWindow` | variable | `COFFLoader3.c:499` | `extern PVOID __imp_GetShellWindow;` | +| `__imp_GetStartupInfoA` | variable | `COFFLoader3.c:432` | `extern PVOID __imp_GetStartupInfoA;` | +| `__imp_GetStartupInfoW` | variable | `COFFLoader3.c:433` | `extern PVOID __imp_GetStartupInfoW;` | +| `__imp_GetSystemDirectoryA` | variable | `COFFLoader3.c:381` | `extern PVOID __imp_GetSystemDirectoryA;` | +| `__imp_GetSystemDirectoryW` | variable | `COFFLoader3.c:382` | `extern PVOID __imp_GetSystemDirectoryW;` | +| `__imp_GetTempPathA` | variable | `COFFLoader3.c:385` | `extern PVOID __imp_GetTempPathA;` | +| `__imp_GetTempPathW` | variable | `COFFLoader3.c:386` | `extern PVOID __imp_GetTempPathW;` | +| `__imp_GetTickCount` | variable | `COFFLoader3.c:352` | `extern PVOID __imp_GetTickCount;` | +| `__imp_GetTickCount64` | variable | `COFFLoader3.c:353` | `extern PVOID __imp_GetTickCount64;` | +| `__imp_GetUserNameA` | variable | `COFFLoader3.c:389` | `extern PVOID __imp_GetUserNameA;` | +| `__imp_GetUserNameW` | variable | `COFFLoader3.c:390` | `extern PVOID __imp_GetUserNameW;` | +| `__imp_GetVersionExA` | variable | `COFFLoader3.c:391` | `extern PVOID __imp_GetVersionExA;` | +| `__imp_GetVersionExW` | variable | `COFFLoader3.c:392` | `extern PVOID __imp_GetVersionExW;` | +| `__imp_GetWindowTextA` | variable | `COFFLoader3.c:503` | `extern PVOID __imp_GetWindowTextA;` | +| `__imp_GetWindowTextW` | variable | `COFFLoader3.c:504` | `extern PVOID __imp_GetWindowTextW;` | +| `__imp_GetWindowsDirectoryA` | variable | `COFFLoader3.c:383` | `extern PVOID __imp_GetWindowsDirectoryA;` | +| `__imp_GetWindowsDirectoryW` | variable | `COFFLoader3.c:384` | `extern PVOID __imp_GetWindowsDirectoryW;` | +| `__imp_GlobalAlloc` | variable | `COFFLoader3.c:402` | `extern PVOID __imp_GlobalAlloc;` | +| `__imp_GlobalFree` | variable | `COFFLoader3.c:403` | `extern PVOID __imp_GlobalFree;` | +| `__imp_HeapAlloc` | variable | `COFFLoader3.c:398` | `extern PVOID __imp_HeapAlloc;` | +| `__imp_HeapFree` | variable | `COFFLoader3.c:399` | `extern PVOID __imp_HeapFree;` | +| `__imp_IIDFromString` | variable | `COFFLoader3.c:483` | `extern PVOID __imp_IIDFromString;` | +| `__imp_ImpersonateLoggedOnUser` | variable | `COFFLoader3.c:446` | `extern PVOID __imp_ImpersonateLoggedOnUser;` | +| `__imp_IsDebuggerPresent` | variable | `COFFLoader3.c:439` | `extern PVOID __imp_IsDebuggerPresent;` | +| `__imp_IsWow64Process` | variable | `COFFLoader3.c:547` | `extern PVOID __imp_IsWow64Process;` | +| `__imp_LoadLibraryA` | variable | `COFFLoader3.c:338` | `extern PVOID __imp_LoadLibraryA;` | +| `__imp_LoadLibraryW` | variable | `COFFLoader3.c:339` | `extern PVOID __imp_LoadLibraryW;` | +| `__imp_LocalAlloc` | variable | `COFFLoader3.c:400` | `extern PVOID __imp_LocalAlloc;` | +| `__imp_LocalFree` | variable | `COFFLoader3.c:401` | `extern PVOID __imp_LocalFree;` | +| `__imp_LookupPrivilegeValueA` | variable | `COFFLoader3.c:448` | `extern PVOID __imp_LookupPrivilegeValueA;` | +| `__imp_LookupPrivilegeValueW` | variable | `COFFLoader3.c:449` | `extern PVOID __imp_LookupPrivilegeValueW;` | +| `__imp_MoveFileA` | variable | `COFFLoader3.c:362` | `extern PVOID __imp_MoveFileA;` | +| `__imp_MoveFileW` | variable | `COFFLoader3.c:363` | `extern PVOID __imp_MoveFileW;` | +| `__imp_MultiByteToWideChar` | variable | `COFFLoader3.c:418` | `extern PVOID __imp_MultiByteToWideChar;` | +| `__imp_NetApiBufferFree` | variable | `COFFLoader3.c:539` | `extern PVOID __imp_NetApiBufferFree;` | +| `__imp_NetLocalGroupEnum` | variable | `COFFLoader3.c:535` | `extern PVOID __imp_NetLocalGroupEnum;` | +| `__imp_NetSessionEnum` | variable | `COFFLoader3.c:538` | `extern PVOID __imp_NetSessionEnum;` | +| `__imp_NetShareEnum` | variable | `COFFLoader3.c:536` | `extern PVOID __imp_NetShareEnum;` | +| `__imp_NetUserEnum` | variable | `COFFLoader3.c:534` | `extern PVOID __imp_NetUserEnum;` | +| `__imp_NetWkstaUserEnum` | variable | `COFFLoader3.c:537` | `extern PVOID __imp_NetWkstaUserEnum;` | +| `__imp_NtQueryInformationThread` | variable | `COFFLoader3.c:557` | `extern PVOID __imp_NtQueryInformationThread;` | +| `__imp_OpenProcess` | variable | `COFFLoader3.c:443` | `extern PVOID __imp_OpenProcess;` | +| `__imp_OpenProcessToken` | variable | `COFFLoader3.c:444` | `extern PVOID __imp_OpenProcessToken;` | +| `__imp_OpenThread` | variable | `COFFLoader3.c:554` | `extern PVOID __imp_OpenThread;` | +| `__imp_OutputDebugStringA` | variable | `COFFLoader3.c:441` | `extern PVOID __imp_OutputDebugStringA;` | +| `__imp_OutputDebugStringW` | variable | `COFFLoader3.c:442` | `extern PVOID __imp_OutputDebugStringW;` | +| `__imp_PathCombineA` | variable | `COFFLoader3.c:496` | `extern PVOID __imp_PathCombineA;` | +| `__imp_PathCombineW` | variable | `COFFLoader3.c:497` | `extern PVOID __imp_PathCombineW;` | +| `__imp_PathFileExistsA` | variable | `COFFLoader3.c:494` | `extern PVOID __imp_PathFileExistsA;` | +| `__imp_PathFileExistsW` | variable | `COFFLoader3.c:495` | `extern PVOID __imp_PathFileExistsW;` | +| `__imp_Process32First` | variable | `COFFLoader3.c:548` | `extern PVOID __imp_Process32First;` | +| `__imp_Process32Next` | variable | `COFFLoader3.c:546` | `extern PVOID __imp_Process32Next;` | +| `__imp_ReadFile` | variable | `COFFLoader3.c:356` | `extern PVOID __imp_ReadFile;` | +| `__imp_RegCloseKey` | variable | `COFFLoader3.c:463` | `extern PVOID __imp_RegCloseKey;` | +| `__imp_RegCreateKeyExA` | variable | `COFFLoader3.c:455` | `extern PVOID __imp_RegCreateKeyExA;` | +| `__imp_RegCreateKeyExW` | variable | `COFFLoader3.c:456` | `extern PVOID __imp_RegCreateKeyExW;` | +| `__imp_RegDeleteValueA` | variable | `COFFLoader3.c:461` | `extern PVOID __imp_RegDeleteValueA;` | +| `__imp_RegDeleteValueW` | variable | `COFFLoader3.c:462` | `extern PVOID __imp_RegDeleteValueW;` | +| `__imp_RegEnumKeyExA` | variable | `COFFLoader3.c:464` | `extern PVOID __imp_RegEnumKeyExA;` | +| `__imp_RegEnumKeyExW` | variable | `COFFLoader3.c:465` | `extern PVOID __imp_RegEnumKeyExW;` | +| `__imp_RegEnumValueA` | variable | `COFFLoader3.c:466` | `extern PVOID __imp_RegEnumValueA;` | +| `__imp_RegEnumValueW` | variable | `COFFLoader3.c:467` | `extern PVOID __imp_RegEnumValueW;` | +| `__imp_RegOpenKeyExA` | variable | `COFFLoader3.c:453` | `extern PVOID __imp_RegOpenKeyExA;` | +| `__imp_RegOpenKeyExW` | variable | `COFFLoader3.c:454` | `extern PVOID __imp_RegOpenKeyExW;` | +| `__imp_RegQueryValueExA` | variable | `COFFLoader3.c:459` | `extern PVOID __imp_RegQueryValueExA;` | +| `__imp_RegQueryValueExW` | variable | `COFFLoader3.c:460` | `extern PVOID __imp_RegQueryValueExW;` | +| `__imp_RegSetValueExA` | variable | `COFFLoader3.c:457` | `extern PVOID __imp_RegSetValueExA;` | +| `__imp_RegSetValueExW` | variable | `COFFLoader3.c:458` | `extern PVOID __imp_RegSetValueExW;` | +| `__imp_RemoveDirectoryA` | variable | `COFFLoader3.c:370` | `extern PVOID __imp_RemoveDirectoryA;` | +| `__imp_RemoveDirectoryW` | variable | `COFFLoader3.c:371` | `extern PVOID __imp_RemoveDirectoryW;` | +| `__imp_RevertToSelf` | variable | `COFFLoader3.c:447` | `extern PVOID __imp_RevertToSelf;` | +| `__imp_RtlCopyMemory` | variable | `COFFLoader3.c:405` | `extern PVOID __imp_RtlCopyMemory;` | +| `__imp_RtlFillMemory` | variable | `COFFLoader3.c:406` | `extern PVOID __imp_RtlFillMemory;` | +| `__imp_RtlMoveMemory` | variable | `COFFLoader3.c:404` | `extern PVOID __imp_RtlMoveMemory;` | +| `__imp_RtlZeroMemory` | variable | `COFFLoader3.c:407` | `extern PVOID __imp_RtlZeroMemory;` | +| `__imp_SHGetFolderPathA` | variable | `COFFLoader3.c:491` | `extern PVOID __imp_SHGetFolderPathA;` | +| `__imp_SHGetFolderPathW` | variable | `COFFLoader3.c:492` | `extern PVOID __imp_SHGetFolderPathW;` | +| `__imp_SHGetKnownFolderPath` | variable | `COFFLoader3.c:493` | `extern PVOID __imp_SHGetKnownFolderPath;` | +| `__imp_SendMessageA` | variable | `COFFLoader3.c:507` | `extern PVOID __imp_SendMessageA;` | +| `__imp_SendMessageW` | variable | `COFFLoader3.c:508` | `extern PVOID __imp_SendMessageW;` | +| `__imp_SetEndOfFile` | variable | `COFFLoader3.c:359` | `extern PVOID __imp_SetEndOfFile;` | +| `__imp_SetEnvironmentVariableA` | variable | `COFFLoader3.c:424` | `extern PVOID __imp_SetEnvironmentVariableA;` | +| `__imp_SetEnvironmentVariableW` | variable | `COFFLoader3.c:425` | `extern PVOID __imp_SetEnvironmentVariableW;` | +| `__imp_SetFileAttributesA` | variable | `COFFLoader3.c:379` | `extern PVOID __imp_SetFileAttributesA;` | +| `__imp_SetFileAttributesW` | variable | `COFFLoader3.c:380` | `extern PVOID __imp_SetFileAttributesW;` | +| `__imp_SetFilePointer` | variable | `COFFLoader3.c:358` | `extern PVOID __imp_SetFilePointer;` | +| `__imp_Sleep` | variable | `COFFLoader3.c:347` | `extern PVOID __imp_Sleep;` | +| `__imp_StringFromGUID2` | variable | `COFFLoader3.c:484` | `extern PVOID __imp_StringFromGUID2;` | +| `__imp_SuspendThread` | variable | `COFFLoader3.c:553` | `extern PVOID __imp_SuspendThread;` | +| `__imp_SysAllocString` | variable | `COFFLoader3.c:488` | `extern PVOID __imp_SysAllocString;` | +| `__imp_SysFreeString` | variable | `COFFLoader3.c:489` | `extern PVOID __imp_SysFreeString;` | +| `__imp_SysStringLen` | variable | `COFFLoader3.c:490` | `extern PVOID __imp_SysStringLen;` | +| `__imp_Thread32First` | variable | `COFFLoader3.c:555` | `extern PVOID __imp_Thread32First;` | +| `__imp_Thread32Next` | variable | `COFFLoader3.c:556` | `extern PVOID __imp_Thread32Next;` | +| `__imp_VariantChangeType` | variable | `COFFLoader3.c:487` | `extern PVOID __imp_VariantChangeType;` | +| `__imp_VariantClear` | variable | `COFFLoader3.c:486` | `extern PVOID __imp_VariantClear;` | +| `__imp_VariantInit` | variable | `COFFLoader3.c:485` | `extern PVOID __imp_VariantInit;` | +| `__imp_VirtualAlloc` | variable | `COFFLoader3.c:394` | `extern PVOID __imp_VirtualAlloc;` | +| `__imp_VirtualFree` | variable | `COFFLoader3.c:395` | `extern PVOID __imp_VirtualFree;` | +| `__imp_VirtualProtect` | variable | `COFFLoader3.c:396` | `extern PVOID __imp_VirtualProtect;` | +| `__imp_VirtualQuery` | variable | `COFFLoader3.c:397` | `extern PVOID __imp_VirtualQuery;` | +| `__imp_WNetCloseEnum` | variable | `COFFLoader3.c:544` | `extern PVOID __imp_WNetCloseEnum;` | +| `__imp_WNetEnumResourceA` | variable | `COFFLoader3.c:542` | `extern PVOID __imp_WNetEnumResourceA;` | +| `__imp_WNetEnumResourceW` | variable | `COFFLoader3.c:543` | `extern PVOID __imp_WNetEnumResourceW;` | +| `__imp_WNetOpenEnumA` | variable | `COFFLoader3.c:540` | `extern PVOID __imp_WNetOpenEnumA;` | +| `__imp_WNetOpenEnumW` | variable | `COFFLoader3.c:541` | `extern PVOID __imp_WNetOpenEnumW;` | +| `__imp_WSACleanup` | variable | `COFFLoader3.c:517` | `extern PVOID __imp_WSACleanup;` | +| `__imp_WSASocketA` | variable | `COFFLoader3.c:514` | `extern PVOID __imp_WSASocketA;` | +| `__imp_WSASocketW` | variable | `COFFLoader3.c:515` | `extern PVOID __imp_WSASocketW;` | +| `__imp_WSAStartup` | variable | `COFFLoader3.c:516` | `extern PVOID __imp_WSAStartup;` | +| `__imp_WideCharToMultiByte` | variable | `COFFLoader3.c:419` | `extern PVOID __imp_WideCharToMultiByte;` | +| `__imp_WriteFile` | variable | `COFFLoader3.c:357` | `extern PVOID __imp_WriteFile;` | +| `__imp__stricmp` | variable | `COFFLoader3.c:545` | `extern PVOID __imp__stricmp;` | +| `__imp_accept` | variable | `COFFLoader3.c:520` | `extern PVOID __imp_accept;` | +| `__imp_bind` | variable | `COFFLoader3.c:518` | `extern PVOID __imp_bind;` | +| `__imp_closesocket` | variable | `COFFLoader3.c:524` | `extern PVOID __imp_closesocket;` | +| `__imp_connect` | variable | `COFFLoader3.c:521` | `extern PVOID __imp_connect;` | +| `__imp_freeaddrinfo` | variable | `COFFLoader3.c:529` | `extern PVOID __imp_freeaddrinfo;` | +| `__imp_getaddrinfo` | variable | `COFFLoader3.c:528` | `extern PVOID __imp_getaddrinfo;` | +| `__imp_gethostbyname` | variable | `COFFLoader3.c:527` | `extern PVOID __imp_gethostbyname;` | +| `__imp_gethostname` | variable | `COFFLoader3.c:526` | `extern PVOID __imp_gethostname;` | +| `__imp_htonl` | variable | `COFFLoader3.c:532` | `extern PVOID __imp_htonl;` | +| `__imp_htons` | variable | `COFFLoader3.c:530` | `extern PVOID __imp_htons;` | +| `__imp_ioctlsocket` | variable | `COFFLoader3.c:525` | `extern PVOID __imp_ioctlsocket;` | +| `__imp_listen` | variable | `COFFLoader3.c:519` | `extern PVOID __imp_listen;` | +| `__imp_lstrcatA` | variable | `COFFLoader3.c:412` | `extern PVOID __imp_lstrcatA;` | +| `__imp_lstrcatW` | variable | `COFFLoader3.c:413` | `extern PVOID __imp_lstrcatW;` | +| `__imp_lstrcmpA` | variable | `COFFLoader3.c:414` | `extern PVOID __imp_lstrcmpA;` | +| `__imp_lstrcmpW` | variable | `COFFLoader3.c:415` | `extern PVOID __imp_lstrcmpW;` | +| `__imp_lstrcmpiA` | variable | `COFFLoader3.c:416` | `extern PVOID __imp_lstrcmpiA;` | +| `__imp_lstrcmpiW` | variable | `COFFLoader3.c:417` | `extern PVOID __imp_lstrcmpiW;` | +| `__imp_lstrcpyA` | variable | `COFFLoader3.c:410` | `extern PVOID __imp_lstrcpyA;` | +| `__imp_lstrcpyW` | variable | `COFFLoader3.c:411` | `extern PVOID __imp_lstrcpyW;` | +| `__imp_lstrlenA` | variable | `COFFLoader3.c:408` | `extern PVOID __imp_lstrlenA;` | +| `__imp_lstrlenW` | variable | `COFFLoader3.c:409` | `extern PVOID __imp_lstrlenW;` | +| `__imp_ntohl` | variable | `COFFLoader3.c:533` | `extern PVOID __imp_ntohl;` | +| `__imp_ntohs` | variable | `COFFLoader3.c:531` | `extern PVOID __imp_ntohs;` | +| `__imp_recv` | variable | `COFFLoader3.c:523` | `extern PVOID __imp_recv;` | +| `__imp_select` | variable | `COFFLoader3.c:550` | `extern PVOID __imp_select;` | +| `__imp_send` | variable | `COFFLoader3.c:522` | `extern PVOID __imp_send;` | +| `create_trampoline` | function | `COFFLoader3.c:913` | `static void* create_trampoline(void* target)` | +| `djb2_hash` | function | `COFFLoader3.c:632` | `static uint32_t djb2_hash(const char* str)` | +| `g_pNtCreateFileUnhooked` | variable | `COFFLoader3.c:561` | `extern PVOID g_pNtCreateFileUnhooked;` | +| `g_pNtCreateThreadExUnhooked` | variable | `COFFLoader3.c:565` | `extern PVOID g_pNtCreateThreadExUnhooked;` | +| `g_pNtProtectVirtualMemoryUnhooked` | variable | `COFFLoader3.c:563` | `extern PVOID g_pNtProtectVirtualMemoryUnhooked;` | +| `g_pNtResumeThreadUnhooked` | variable | `COFFLoader3.c:564` | `extern PVOID g_pNtResumeThreadUnhooked;` | +| `g_pNtWriteVirtualMemoryUnhooked` | variable | `COFFLoader3.c:562` | `extern PVOID g_pNtWriteVirtualMemoryUnhooked;` | +| `get_symbol_name` | function | `COFFLoader3.c:1080` | `static char* get_symbol_name(COFFSymbol* s, char* strtab, uint32_t strtab_size)` | +| `handle_relocation` | function | `COFFLoader3.c:940` | `BOOL handle_relocation(COFFRelocation* rel, void* patch_addr, void* target, + ...` | +| `AES_CBC_decrypt_buffer` | function | `aes.c:536` | `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` | +| `AES_CBC_encrypt_buffer` | function | `aes.c:521` | `void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length)` | +| `AES_CTR_xcrypt_buffer` | function | `aes.c:558` | `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length)` | +| `AES_ECB_decrypt` | function | `aes.c:496` | `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf)` | +| `AES_ECB_encrypt` | function | `aes.c:490` | `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf)` | +| `AES_ctx_set_iv` | function | `aes.c:249` | `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv)` | +| `AES_init_ctx` | function | `aes.c:239` | `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key)` | +| `AES_init_ctx_iv` | function | `aes.c:244` | `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv)` | +| `AddRoundKey` | function | `aes.c:257` | `static void AddRoundKey(uint8_t round, state_t* state, const uint8_t* RoundKey)` | +| `BLOCKLEN` | macro | `aes.c:11` | `#define BLOCKLEN` | +| `Cipher` | function | `aes.c:433` | `static void Cipher(state_t* state, const uint8_t* RoundKey)` | +| `InvCipher` | function | `aes.c:459` | `static void InvCipher(state_t* state, const uint8_t* RoundKey)` | +| `InvMixColumns` | function | `aes.c:370` | `static void InvMixColumns(state_t* state)` | +| `InvShiftRows` | function | `aes.c:403` | `static void InvShiftRows(state_t* state)` | +| `InvSubBytes` | function | `aes.c:391` | `static void InvSubBytes(state_t* state)` | +| `KEYLEN_256` | macro | `aes.c:9` | `#define KEYLEN_256` | +| `KeyExpansion` | function | `aes.c:166` | `static void KeyExpansion(uint8_t* RoundKey, const uint8_t* Key)` | +| `MULTIPLY_AS_A_FUNCTION` | macro | `aes.c:84` | `#define MULTIPLY_AS_A_FUNCTION` | +| `MixColumns` | function | `aes.c:320` | `static void MixColumns(state_t* state)` | +| `Multiply` | function | `aes.c:340` | `static uint8_t Multiply(uint8_t x, uint8_t y)` | +| `Multiply` | macro | `aes.c:349` | `#define Multiply(x, y)` | +| `Nb` | macro | `aes.c:5` | `#define Nb` | +| `Nb` | macro | `aes.c:67` | `#define Nb` | +| `Nk` | macro | `aes.c:70` | `#define Nk` | +| `Nk` | macro | `aes.c:73` | `#define Nk` | +| `Nk` | macro | `aes.c:76` | `#define Nk` | +| `Nr` | macro | `aes.c:71` | `#define Nr` | +| `Nr` | macro | `aes.c:74` | `#define Nr` | +| `Nr` | macro | `aes.c:77` | `#define Nr` | +| `RKLENGTH` | macro | `aes.c:10` | `#define RKLENGTH` | +| `ShiftRows` | function | `aes.c:286` | `static void ShiftRows(state_t* state)` | +| `SubBytes` | function | `aes.c:271` | `static void SubBytes(state_t* state)` | +| `Td0` | function | `aes.c:57` | `static uint8_t Td0(int x)` | +| `Td1` | function | `aes.c:58` | `static uint8_t Td1(int x)` | +| `Td2` | function | `aes.c:59` | `static uint8_t Td2(int x)` | +| `Td3` | function | `aes.c:60` | `static uint8_t Td3(int x)` | +| `Td4` | function | `aes.c:61` | `static uint8_t Td4(int x)` | +| `XorWithIv` | function | `aes.c:512` | `static void XorWithIv(uint8_t* buf, const uint8_t* Iv)` | +| `getSBoxInvert` | function | `aes.c:35` | `static uint8_t getSBoxInvert(uint8_t num)` | +| `getSBoxInvert` | macro | `aes.c:365` | `#define getSBoxInvert(num)` | +| `getSBoxValue` | function | `aes.c:13` | `static uint8_t getSBoxValue(uint8_t num)` | +| `getSBoxValue` | macro | `aes.c:163` | `#define getSBoxValue(num)` | +| `xtime` | function | `aes.c:314` | `static uint8_t xtime(uint8_t x)` | +| `AES256` | macro | `aes.h:18` | `#define AES256` | +| `AES_BLOCKLEN` | macro | `aes.h:20` | `#define AES_BLOCKLEN` | +| `AES_CBC_decrypt_buffer` | function | `aes.h:54` | `void AES_CBC_decrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` | +| `AES_CBC_encrypt_buffer` | function | `aes.h:53` | `void AES_CBC_encrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` | +| `AES_CTR_xcrypt_buffer` | function | `aes.h:58` | `void AES_CTR_xcrypt_buffer(struct AES_ctx* ctx, uint8_t* buf, size_t length);` | +| `AES_ECB_decrypt` | function | `aes.h:49` | `void AES_ECB_decrypt(const struct AES_ctx* ctx, uint8_t* buf);` | +| `AES_ECB_encrypt` | function | `aes.h:48` | `void AES_ECB_encrypt(const struct AES_ctx* ctx, uint8_t* buf);` | +| `AES_KEYLEN` | macro | `aes.h:23` | `#define AES_KEYLEN` | +| `AES_KEYLEN` | macro | `aes.h:26` | `#define AES_KEYLEN` | +| `AES_KEYLEN` | macro | `aes.h:29` | `#define AES_KEYLEN` | +| `AES_ctx` | struct | `aes.h:33` | `` | +| `AES_ctx_set_iv` | function | `aes.h:44` | `void AES_ctx_set_iv(struct AES_ctx* ctx, const uint8_t* iv);` | +| `AES_init_ctx` | function | `aes.h:41` | `void AES_init_ctx(struct AES_ctx* ctx, const uint8_t* key);` | +| `AES_init_ctx_iv` | function | `aes.h:43` | `void AES_init_ctx_iv(struct AES_ctx* ctx, const uint8_t* key, const uint8_t* iv);` | +| `AES_keyExpSize` | macro | `aes.h:24` | `#define AES_keyExpSize` | +| `AES_keyExpSize` | macro | `aes.h:27` | `#define AES_keyExpSize` | +| `AES_keyExpSize` | macro | `aes.h:30` | `#define AES_keyExpSize` | +| `CBC` | macro | `aes.h:9` | `#define CBC` | +| `CTR` | macro | `aes.h:15` | `#define CTR` | +| `ECB` | macro | `aes.h:12` | `#define ECB` | +| `_AES_H_` | macro | `aes.h:2` | `#define _AES_H_` | +| `BeaconDataSerializeString` | function | `beacon.c:4712` | `void BeaconDataSerializeString(char* buffer, int* offset, const char* str)` | +| `C2_HOST` | macro | `beacon.c:82` | `#define C2_HOST` | +| `C2_PASS` | macro | `beacon.c:85` | `#define C2_PASS` | +| `C2_PATH` | macro | `beacon.c:88` | `#define C2_PATH` | +| `C2_PORT` | macro | `beacon.c:86` | `#define C2_PORT` | +| `C2_URL` | macro | `beacon.c:75` | `#define C2_URL` | +| `C2_USER` | macro | `beacon.c:84` | `#define C2_USER` | +| `CHECK_ERROR` | macro | `beacon.c:126` | `#define CHECK_ERROR(cond, msg)` | +| `CLIENT_ID` | macro | `beacon.c:77` | `#define CLIENT_ID` | +| `CONFIG_PATH` | macro | `beacon.c:87` | `#define CONFIG_PATH` | +| `DEBUG` | macro | `beacon.c:72` | `#define DEBUG` | +| `DecryptPacket` | function | `beacon.c:2911` | `BOOL DecryptPacket(BYTE* buffer, DWORD* buffer_len)` | +| `DownloadFromURL` | function | `beacon.c:4423` | `BOOL DownloadFromURL(const char* url, const char* filepath)` | +| `DownloadToBuffer` | function | `beacon.c:4347` | `unsigned char* DownloadToBuffer(const char* url, DWORD* fileSize)` | +| `EarlyBirdInject` | function | `beacon.c:3729` | `BOOL EarlyBirdInject(unsigned char* shellcode, int shellcode_len)` | +| `ExceptionFilter` | function | `beacon.c:253` | `static LONG WINAPI ExceptionFilter(EXCEPTION_POINTERS *ExceptionInfo)` | +| `ExecuteModule` | function | `beacon.c:706` | `BOOL ExecuteModule(PVOID moduleBase)` | +| `ExecuteTLSCallbacks` | function | `beacon.c:600` | `void ExecuteTLSCallbacks(PVOID moduleBase)` | +| `ExitStatus` | type_alias | `beacon.c:127` | `typedef struct _PROCESS_BASIC_INFORMATION { LONG ExitStatus;` | +| `FileExistsA` | function | `beacon.c:2301` | `BOOL FileExistsA(const char* filePath)` | +| `GetC2Command` | function | `beacon.c:4200` | `char* GetC2Command(const char* host, const char* path)` | +| `GetHostname` | function | `beacon.c:3041` | `char* GetHostname()` | +| `GetIPs` | function | `beacon.c:3007` | `char* GetIPs()` | +| `GetJitteredSleep` | function | `beacon.c:1587` | `DWORD GetJitteredSleep(DWORD base_ms)` | +| `GetNtdllBase` | function | `beacon.c:1184` | `HMODULE GetNtdllBase()` | +| `GetProcessIdByName` | function | `beacon.c:582` | `DWORD GetProcessIdByName(const char* processName)` | +| `GetSyscallNumber` | function | `beacon.c:549` | `DWORD GetSyscallNumber(PVOID func_addr)` | +| `GetUsefulSoftware` | function | `beacon.c:1592` | `char* GetUsefulSoftware()` | +| `GetUsername` | function | `beacon.c:3057` | `char* GetUsername()` | +| `HellsGate` | function | `beacon.c:561` | `DWORD HellsGate(DWORD ssn)` | +| `IMAGE_DOS_SIGNATURE` | macro | `beacon.c:101` | `#define IMAGE_DOS_SIGNATURE` | +| `IMAGE_NT_OPTIONAL_HDR32_MAGIC` | macro | `beacon.c:103` | `#define IMAGE_NT_OPTIONAL_HDR32_MAGIC` | +| `IMAGE_NT_OPTIONAL_HDR64_MAGIC` | macro | `beacon.c:104` | `#define IMAGE_NT_OPTIONAL_HDR64_MAGIC` | +| `IMAGE_NT_SIGNATURE` | macro | `beacon.c:102` | `#define IMAGE_NT_SIGNATURE` | +| `INVALID_SOCKET` | macro | `beacon.c:97` | `#define INVALID_SOCKET` | +| `InMemoryOrderLinks` | type_alias | `beacon.c:267` | `typedef struct _LDR_DATA_TABLE_ENTRY { LIST_ENTRY InMemoryOrderLinks;` | +| `LC2_HOST` | macro | `beacon.c:83` | `#define LC2_HOST` | +| `LC2_PATH` | macro | `beacon.c:89` | `#define LC2_PATH` | +| `LazyDataType` | struct | `beacon.c:168` | `` | +| `Length` | type_alias | `beacon.c:262` | `typedef struct _UNICODE_STRING { USHORT Length;` | +| `Length` | type_alias | `beacon.c:277` | `typedef struct _PEB_LDR_DATA { DWORD Length;` | +| `LoadModuleFromURL` | function | `beacon.c:751` | `BOOL LoadModuleFromURL(const char* url)` | +| `MALEABLE` | macro | `beacon.c:76` | `#define MALEABLE` | +| `MAX_JITTER` | macro | `beacon.c:80` | `#define MAX_JITTER` | +| `MAX_RESPONSE_SIZE` | macro | `beacon.c:74` | `#define MAX_RESPONSE_SIZE` | +| `MAX_RETRIES` | macro | `beacon.c:81` | `#define MAX_RETRIES` | +| `MIN_JITTER` | macro | `beacon.c:79` | `#define MIN_JITTER` | +| `MapDllNameToModule` | function | `beacon.c:521` | `HMODULE MapDllNameToModule(char* dllName)` | +| `MapModuleToMemory` | function | `beacon.c:617` | `PVOID MapModuleToMemory(unsigned char* fileBuffer, DWORD fileSize)` | +| `MapPEToMemory` | function | `beacon.c:2838` | `unsigned char* MapPEToMemory(unsigned char* rawPE, DWORD rawSize, DWORD* mappedSize)` | +| `NTSTATUS` | type_alias | `beacon.c:296` | `typedef LONG NTSTATUS;` | +| `NTSTATUS` | type_alias | `beacon.c:304` | `typedef LONG NTSTATUS;` | +| `NT_SUCCESS` | macro | `beacon.c:300` | `#define NT_SUCCESS(Status)` | +| `NUM_UAS` | macro | `beacon.c:247` | `#define NUM_UAS` | +| `NUM_URLS` | macro | `beacon.c:240` | `#define NUM_URLS` | +| `NUM_USER_AGENTS` | macro | `beacon.c:231` | `#define NUM_USER_AGENTS` | +| `PSAPI_VERSION` | macro | `beacon.c:20` | `#define PSAPI_VERSION` | +| `PacketEncryptionContext` | struct | `beacon.c:329` | `` | +| `PortResult` | struct | `beacon.c:343` | `` | +| `PortScanner` | function | `beacon.c:3661` | `void PortScanner(char* targetIP, int* ports, int numPorts)` | +| `PortScannerArgs` | struct | `beacon.c:161` | `` | +| `PortScannerWrapper` | function | `beacon.c:3706` | `void PortScannerWrapper(void* arg)` | +| `ProcessBasicInformation` | macro | `beacon.c:123` | `#define ProcessBasicInformation` | +| `ProxyListener` | struct | `beacon.c:176` | `` | +| `ProxySession` | struct | `beacon.c:139` | `` | +| `ProxyThreadData` | struct | `beacon.c:147` | `` | +| `ReadFromProcess` | function | `beacon.c:1513` | `DWORD WINAPI ReadFromProcess(LPVOID lpParam)` | +| `Reserved1` | type_alias | `beacon.c:286` | `typedef struct _PEB { BYTE Reserved1[2];` | +| `ReverseArgs` | struct | `beacon.c:156` | `` | +| `ReverseShell` | function | `beacon.c:1404` | `void __cdecl ReverseShell(void* arg)` | +| `SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` | macro | `beacon.c:106` | `#define SECURITY_FLAG_IGNORE_CERT_WRONG_USAGE` | +| `SECURITY_FLAG_IGNORE_INVALID_POLICY` | macro | `beacon.c:109` | `#define SECURITY_FLAG_IGNORE_INVALID_POLICY` | +| `SECURITY_FLAG_IGNORE_REVOCATION` | macro | `beacon.c:94` | `#define SECURITY_FLAG_IGNORE_REVOCATION` | +| `SLEEP_BASE` | macro | `beacon.c:78` | `#define SLEEP_BASE` | +| `SerializeBeaconString` | function | `beacon.c:4703` | `void SerializeBeaconString(char* buffer, int* offset, const char* str)` | +| `TIMEOUT` | macro | `beacon.c:73` | `#define TIMEOUT` | +| `USER_AGENT` | macro | `beacon.c:99` | `#define USER_AGENT` | +| `USER_AGENT_A` | macro | `beacon.c:100` | `#define USER_AGENT_A` | +| `UTF8ToWide` | function | `beacon.c:2551` | `WCHAR* UTF8ToWide(const char* utf8)` | +| `UploadFileToC2` | function | `beacon.c:2108` | `BOOL UploadFileToC2(const char* url, const char* filePath)` | +| `WIN32_LEAN_AND_MEAN` | macro | `beacon.c:21` | `#define WIN32_LEAN_AND_MEAN` | +| `XOR_KEY` | macro | `beacon.c:71` | `#define XOR_KEY` | +| `_LDR_DATA_TABLE_ENTRY` | struct | `beacon.c:268` | `` | +| `_PEB` | struct | `beacon.c:287` | `` | +| `_PEB_LDR_DATA` | struct | `beacon.c:278` | `` | +| `_PROCESS_BASIC_INFORMATION` | struct | `beacon.c:129` | `` | +| `_PROCESS_BASIC_INFORMATION_` | macro | `beacon.c:115` | `#define _PROCESS_BASIC_INFORMATION_` | +| `_SECURITY_PACKAGE_DEFINITION_` | macro | `beacon.c:112` | `#define _SECURITY_PACKAGE_DEFINITION_` | +| `_SP_LSA_MODE_INITIALIZE_DEFINED_` | macro | `beacon.c:117` | `#define _SP_LSA_MODE_INITIALIZE_DEFINED_` | +| `_UNICODE_STRING` | struct | `beacon.c:262` | `` | +| `__attribute__` | function | `beacon.c:566` | `__attribute__((naked)) +NTSTATUS HellDescent( + DWORD64 arg1, DWORD64 arg2, DWORD64 arg3, + DW...` | +| `__declspec` | function | `beacon.c:417` | `__declspec(dllexport) void BeaconDataParse(datap * parser, char * buffer, int size)` | +| `__declspec` | function | `beacon.c:423` | `__declspec(dllexport) char * BeaconDataPtr(datap * parser, int size)` | +| `__declspec` | function | `beacon.c:431` | `__declspec(dllexport) int BeaconDataInt(datap * parser)` | +| `__declspec` | function | `beacon.c:436` | `__declspec(dllexport) short BeaconDataShort(datap * parser)` | +| `__declspec` | function | `beacon.c:441` | `__declspec(dllexport) int BeaconDataLength(datap * parser)` | +| `__declspec` | function | `beacon.c:446` | `__declspec(dllexport) char * BeaconDataExtract(datap * parser, int * size)` | +| `__declspec` | function | `beacon.c:456` | `__declspec(dllexport) void BeaconPrintf(int type, const char * fmt, ...)` | +| `__declspec` | function | `beacon.c:504` | `__declspec(dllexport) void BeaconOutput(int type, const char * data, int len)` | +| `anti_analysis` | function | `beacon.c:922` | `BOOL anti_analysis()` | +| `base64_decode` | function | `beacon.c:1663` | `char* base64_decode(const char* input, size_t* out_len)` | +| `base64_encode` | function | `beacon.c:1627` | `char* base64_encode(const unsigned char* data, size_t inputLen)` | +| `checkDebuggers` | function | `beacon.c:2776` | `BOOL checkDebuggers()` | +| `cleanSystemLogs` | function | `beacon.c:3384` | `void cleanSystemLogs()` | +| `cleanupProxy` | function | `beacon.c:2062` | `void cleanupProxy()` | +| `compressDirectory` | function | `beacon.c:2094` | `BOOL compressDirectory(const char* dirPath)` | +| `create_suspended_process` | function | `beacon.c:3149` | `BOOL create_suspended_process(char* path, PROCESS_INFORMATION* pi)` | +| `deleteFilesDelay` | function | `beacon.c:4537` | `void deleteFilesDelay(void* arg)` | +| `discoverLocalHosts` | function | `beacon.c:1696` | `void discoverLocalHosts()` | +| `downloadAndExecute` | function | `beacon.c:2861` | `BOOL downloadAndExecute(const char* url, const char* targetProcess)` | +| `encrypt_data` | function | `beacon.c:4454` | `char* encrypt_data(const char* data)` | +| `ensurePersistence` | function | `beacon.c:3421` | `BOOL ensurePersistence()` | +| `exec_cmd` | function | `beacon.c:4172` | `char* exec_cmd(const char* cmd)` | +| `executeCommand` | function | `beacon.c:4551` | `void executeCommand(void* cmdPtr)` | +| `executeLoader` | function | `beacon.c:1348` | `void executeLoader(void *arg)` | +| `executeUACBypass` | function | `beacon.c:3557` | `BOOL executeUACBypass(const char* payloadPath)` | +| `extract_shellcode` | function | `beacon.c:1303` | `int extract_shellcode(const char* input, size_t len, unsigned char** out)` | +| `getNetworkConfig` | function | `beacon.c:2104` | `char* getNetworkConfig()` | +| `get_entry_point_rva` | function | `beacon.c:3113` | `DWORD get_entry_point_rva(BYTE* buffer)` | +| `get_image_size` | function | `beacon.c:3107` | `DWORD get_image_size(BYTE* buffer)` | +| `get_nt_headers` | function | `beacon.c:3092` | `PIMAGE_NT_HEADERS get_nt_headers(BYTE* buffer)` | +| `get_remote_image_base` | function | `beacon.c:3156` | `ULONGLONG get_remote_image_base(PROCESS_INFORMATION* pi, BOOL is_32bit_target)` | +| `get_shell_cmd` | function | `beacon.c:335` | `const char* get_shell_cmd()` | +| `go` | function | `beacon.c:4720` | `void go(unsigned char * bof_data, int bof_size, char * args, int args_len)` | +| `handleAdversary` | function | `beacon.c:4738` | `void handleAdversary(char* command)` | +| `handleAtomic` | function | `beacon.c:4560` | `void handleAtomic(char* command)` | +| `handleDownload` | function | `beacon.c:4683` | `BOOL handleDownload(const char* command)` | +| `handleUpload` | function | `beacon.c:2280` | `BOOL handleUpload(const char* command)` | +| `hex_char_to_byte` | function | `beacon.c:1334` | `BYTE hex_char_to_byte(char c)` | +| `hex_to_bytes` | function | `beacon.c:1341` | `void hex_to_bytes(const char* hex, BYTE* output, size_t len)` | +| `initProxy` | function | `beacon.c:1753` | `void initProxy()` | +| `init_aes_context` | function | `beacon.c:3900` | `PacketEncryptionContext* init_aes_context(const char* key_hex)` | +| `isSandboxEnvironment` | function | `beacon.c:3482` | `BOOL isSandboxEnvironment()` | +| `isSensitiveFile` | function | `beacon.c:2378` | `int isSensitiveFile(const char* filename)` | +| `isVMByMAC` | function | `beacon.c:1232` | `BOOL isVMByMAC()` | +| `isValidUUID` | function | `beacon.c:4512` | `BOOL isValidUUID(const char* uuid)` | +| `is_64bit` | function | `beacon.c:3101` | `BOOL is_64bit(BYTE* buffer)` | +| `load_lazyconf` | function | `beacon.c:946` | `BOOL load_lazyconf()` | +| `main` | function | `beacon.c:5233` | `int main()` | +| `min` | macro | `beacon.c:91` | `#define min(a,b)` | +| `obfuscateFileTimestamp` | function | `beacon.c:2562` | `BOOL obfuscateFileTimestamp(const char* filepath)` | +| `obfuscateFileTimestamps` | function | `beacon.c:2592` | `void obfuscateFileTimestamps(const char* basePath, int depth)` | +| `overWrite` | function | `beacon.c:3277` | `void overWrite(const char* targetPath, const char* payloadPath)` | +| `patchAMSI` | function | `beacon.c:3074` | `BOOL patchAMSI(void)` | +| `pe_buffer_to_virtual_image` | function | `beacon.c:3119` | `BYTE* pe_buffer_to_virtual_image(BYTE* raw_buffer, DWORD* out_size)` | +| `proxy_accept_thread` | function | `beacon.c:1855` | `void WINAPI proxy_accept_thread(void* param)` | +| `proxy_thread` | function | `beacon.c:1784` | `void WINAPI proxy_thread(void* param)` | +| `relay_thread` | function | `beacon.c:1763` | `void WINAPI relay_thread(void* param)` | +| `restartClient` | function | `beacon.c:2735` | `void restartClient()` | +| `retry_http_request` | function | `beacon.c:3918` | `char* retry_http_request(const char* url, const char* method, const char* data, int max_retries)` | +| `scanPort` | function | `beacon.c:3610` | `void scanPort(void* arg)` | +| `searchCredentials` | function | `beacon.c:2425` | `char* searchCredentials(const char* basePath)` | +| `selfDestruct` | function | `beacon.c:2306` | `void selfDestruct()` | +| `simulateLegitimateTraffic` | function | `beacon.c:2656` | `void simulateLegitimateTraffic(void* param)` | +| `startProxy` | function | `beacon.c:1923` | `BOOL startProxy(const char* listenAddr, const char* targetAddr)` | +| `stopProxy` | function | `beacon.c:2010` | `BOOL stopProxy(const char* listenAddr)` | +| `stristr` | function | `beacon.c:2362` | `char* stristr(const char* str, const char* pattern)` | +| `tryPrivilegeEscalation` | function | `beacon.c:3552` | `void tryPrivilegeEscalation()` | +| `update_remote_entry_point` | function | `beacon.c:3250` | `BOOL update_remote_entry_point(PROCESS_INFORMATION* pi, ULONGLONG entry_point_va, BOOL is_32bit)` | +| `xor_string` | function | `beacon.c:915` | `void xor_string(char* data, size_t len, char key)` | +| `BEACON_H` | macro | `beacon.h:21` | `#define BEACON_H` | +| `CALLBACK_ERROR` | macro | `beacon.h:42` | `#define CALLBACK_ERROR` | +| `CALLBACK_OUTPUT` | macro | `beacon.h:41` | `#define CALLBACK_OUTPUT` | +| `datap` | struct | `beacon.h:25` | `` | +| `BEACON_H` | macro | `bof/calc/beacon.h:21` | `#define BEACON_H` | +| `CALLBACK_ERROR` | macro | `bof/calc/beacon.h:42` | `#define CALLBACK_ERROR` | +| `CALLBACK_OUTPUT` | macro | `bof/calc/beacon.h:41` | `#define CALLBACK_OUTPUT` | +| `datap` | struct | `bof/calc/beacon.h:25` | `` | +| `__imp_CloseHandle` | variable | `bof/calc/calc.c:30` | `extern FARPROC __imp_CloseHandle;` | +| `__imp_GetComputerNameA` | variable | `bof/calc/calc.c:29` | `extern FARPROC __imp_GetComputerNameA;` | +| `__imp_GetModuleHandleA` | variable | `bof/calc/calc.c:26` | `extern FARPROC __imp_GetModuleHandleA;` | +| `__imp_GetProcAddress` | variable | `bof/calc/calc.c:27` | `extern FARPROC __imp_GetProcAddress;` | +| `__imp_LoadLibraryA` | variable | `bof/calc/calc.c:28` | `extern FARPROC __imp_LoadLibraryA;` | +| `go` | function | `bof/calc/calc.c:34` | `void go(char *args, int alen)` | +| `BEACON_H` | macro | `bof/etw/beacon.h:21` | `#define BEACON_H` | +| `CALLBACK_ERROR` | macro | `bof/etw/beacon.h:42` | `#define CALLBACK_ERROR` | +| `CALLBACK_OUTPUT` | macro | `bof/etw/beacon.h:41` | `#define CALLBACK_OUTPUT` | +| `datap` | struct | `bof/etw/beacon.h:25` | `` | +| `__imp_GetModuleHandleA` | variable | `bof/etw/etw.c:22` | `extern PVOID __imp_GetModuleHandleA;` | +| `__imp_GetProcAddress` | variable | `bof/etw/etw.c:23` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_RtlCopyMemory` | variable | `bof/etw/etw.c:25` | `extern PVOID __imp_RtlCopyMemory;` | +| `__imp_VirtualProtect` | variable | `bof/etw/etw.c:24` | `extern PVOID __imp_VirtualProtect;` | +| `go` | function | `bof/etw/etw.c:26` | `void go(char *a,int l)` | +| `go` | function | `bof/test/Test.c:3` | `void go(char *args, int alen)` | +| `__imp_GetProcAddress` | variable | `bof/test/amsibypass.c:27` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_LoadLibraryA` | variable | `bof/test/amsibypass.c:26` | `extern PVOID __imp_LoadLibraryA;` | +| `__imp_RtlCopyMemory` | variable | `bof/test/amsibypass.c:29` | `extern PVOID __imp_RtlCopyMemory;` | +| `__imp_VirtualProtect` | variable | `bof/test/amsibypass.c:28` | `extern PVOID __imp_VirtualProtect;` | +| `go` | function | `bof/test/amsibypass.c:34` | `void go(char *args, int alen)` | +| `BEACON_H` | macro | `bof/test/beacon.h:21` | `#define BEACON_H` | +| `CALLBACK_ERROR` | macro | `bof/test/beacon.h:42` | `#define CALLBACK_ERROR` | +| `CALLBACK_OUTPUT` | macro | `bof/test/beacon.h:41` | `#define CALLBACK_OUTPUT` | +| `datap` | struct | `bof/test/beacon.h:25` | `` | +| `__imp_CloseHandle` | variable | `bof/test/cmdwhoami.c:28` | `extern PVOID __imp_CloseHandle;` | +| `__imp_GetProcAddress` | variable | `bof/test/cmdwhoami.c:27` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_LoadLibraryA` | variable | `bof/test/cmdwhoami.c:26` | `extern PVOID __imp_LoadLibraryA;` | +| `go` | function | `bof/test/cmdwhoami.c:43` | `void go(char *args, int alen)` | +| `NT_SUCCESS` | macro | `bof/test/disablelog.c:34` | `#define NT_SUCCESS(x)` | +| `WIN32_LEAN_AND_MEAN` | macro | `bof/test/disablelog.c:20` | `#define WIN32_LEAN_AND_MEAN` | +| `__imp_CloseHandle` | variable | `bof/test/disablelog.c:30` | `extern PVOID __imp_CloseHandle;` | +| `__imp_GetModuleHandleA` | variable | `bof/test/disablelog.c:29` | `extern PVOID __imp_GetModuleHandleA;` | +| `__imp_GetProcAddress` | variable | `bof/test/disablelog.c:28` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_LoadLibraryA` | variable | `bof/test/disablelog.c:27` | `extern PVOID __imp_LoadLibraryA;` | +| `__imp_OpenProcess` | variable | `bof/test/disablelog.c:31` | `extern PVOID __imp_OpenProcess;` | +| `go` | function | `bof/test/disablelog.c:69` | `void go(char *args, int alen)` | +| `my_wcscmp` | function | `bof/test/disablelog.c:37` | `static int my_wcscmp(const wchar_t *s1, const wchar_t *s2)` | +| `__imp_GetEnvironmentVariableA` | variable | `bof/test/getenv.c:23` | `extern PVOID __imp_GetEnvironmentVariableA;` | +| `go` | function | `bof/test/getenv.c:25` | `void go(char *args, int alen)` | +| `TH32CS_SNAPPROCESS` | macro | `bof/test/loadvnc.c:33` | `#define TH32CS_SNAPPROCESS` | +| `_PROCESSENTRY32` | struct | `bof/test/loadvnc.c:35` | `` | +| `__imp_CloseHandle` | variable | `bof/test/loadvnc.c:28` | `extern PVOID __imp_CloseHandle;` | +| `__imp_GetProcAddress` | variable | `bof/test/loadvnc.c:27` | `extern PVOID __imp_GetProcAddress;` | +| `__imp_LoadLibraryA` | variable | `bof/test/loadvnc.c:26` | `extern PVOID __imp_LoadLibraryA;` | +| `dwSize` | type_alias | `bof/test/loadvnc.c:34` | `typedef struct _PROCESSENTRY32 { DWORD dwSize;` | +| `execute_cmd_hidden` | function | `bof/test/loadvnc.c:51` | `void execute_cmd_hidden(char* cmd)` | +| `go` | function | `bof/test/loadvnc.c:81` | `void go(char *args, int alen)` | +| `Copyright` | function | `bof/test/make_table.c:17` | `Copyright (c) LazyOwn RedTeam 2025. All rights reserved. +*/ + +#include +#include .md` +3. Check dependencies: `grep -n '' readmenator-agent/ARCHITECTURE.md` +4. Edit the file +5. Regenerate: `readmenator .` + diff --git a/readmenator-agent/recipes/fix-cycle.md b/readmenator-agent/recipes/fix-cycle.md new file mode 100644 index 0000000..c93eb9d --- /dev/null +++ b/readmenator-agent/recipes/fix-cycle.md @@ -0,0 +1,6 @@ +# Recipe: Fix a Dependency Cycle + +1. Read cycles: `grep -A5 'Dependency Cycles' readmenator-agent/GOTCHAS.md` +2. Pick the cycle to break +3. Introduce an interface/abstraction to decouple +4. Verify: `readmenator . && grep -c 'cycle' readmenator-agent/GOTCHAS.md` diff --git a/readmenator-agent/recipes/fix-security.md b/readmenator-agent/recipes/fix-security.md new file mode 100644 index 0000000..47c3887 --- /dev/null +++ b/readmenator-agent/recipes/fix-security.md @@ -0,0 +1,6 @@ +# Recipe: Fix a Security Finding + +1. Read findings: `grep -n '' readmenator-agent/SECURITY.md` +2. Check API contract: `grep -A10 '' readmenator-agent/API.md` +3. Apply fix +4. Verify: `readmenator . --audit && grep -c 'CRITICAL\|HIGH' readmenator-agent/SECURITY.md` diff --git a/readmenator-agent/recipes/reduce-complexity.md b/readmenator-agent/recipes/reduce-complexity.md new file mode 100644 index 0000000..45f5dbd --- /dev/null +++ b/readmenator-agent/recipes/reduce-complexity.md @@ -0,0 +1,9 @@ +# Recipe: Reduce File Complexity + +Target hotspot: `beacon.c` +(complexity 0.6, centrality 1.0) + +1. Read dependents: `grep -n 'beacon.c' readmenator-agent/ARCHITECTURE.md` +2. Extract functions/classes into new files in the same subsystem +3. Update imports +4. Regenerate: `readmenator .` diff --git a/readmenator-rules/readmenator_all.yml b/readmenator-rules/readmenator_all.yml new file mode 100644 index 0000000..3745ed8 --- /dev/null +++ b/readmenator-rules/readmenator_all.yml @@ -0,0 +1,21 @@ +# ReadMenator suggested rules (combined) +# Generated by readmenator rule generator + +rules: + - id: rm-hardcoded-password + pattern-either: + - pattern: "password = "..."" + - pattern: "passwd = "..."" + - pattern: "pwd = "..."" + message: "Do not hardcode credentials" + severity: ERROR + languages: [python, javascript, typescript, java, go] + + +rules: + - id: rm-print-statement + pattern: "print(...)" + message: "Use logging module instead of print()" + severity: INFO + languages: [python] + diff --git a/readmenator-rules/readmenator_multi.yml b/readmenator-rules/readmenator_multi.yml new file mode 100644 index 0000000..38a7724 --- /dev/null +++ b/readmenator-rules/readmenator_multi.yml @@ -0,0 +1,13 @@ +# ReadMenator suggested rules for multi +# Generated by readmenator rule generator + +rules: + - id: rm-hardcoded-password + pattern-either: + - pattern: "password = "..."" + - pattern: "passwd = "..."" + - pattern: "pwd = "..."" + message: "Do not hardcode credentials" + severity: ERROR + languages: [python, javascript, typescript, java, go] + diff --git a/readmenator-rules/readmenator_python.yml b/readmenator-rules/readmenator_python.yml new file mode 100644 index 0000000..7c5a737 --- /dev/null +++ b/readmenator-rules/readmenator_python.yml @@ -0,0 +1,10 @@ +# ReadMenator suggested rules for python +# Generated by readmenator rule generator + +rules: + - id: rm-print-statement + pattern: "print(...)" + message: "Use logging module instead of print()" + severity: INFO + languages: [python] +