Получи случайную криптовалюту за регистрацию!

​​Ekko_CFG_Bypass A PoC for adding NtContinue to the CFG allo | HackGit


A PoC for adding NtContinue to the CFG allowed list in order to make callback-based sleep obfuscation techniques work in a CFG protected process.

Use the markCFGValid_std function to call SetProcessValidCallTargets and the markCFGValid_nt function to call NtSetInformationVirtualMemory.

