|
|
2 rokov pred | |
|---|---|---|
| .. | ||
| README.md | 2 rokov pred | |
| beacon.h | 2 rokov pred | |
| blindeventlog.c | 2 rokov pred | |
| blindeventlog.cna | 2 rokov pred | |
| blindeventlog.h | 2 rokov pred | |
| blindeventlog.o | 2 rokov pred | |
| bofcompile.bat | 2 rokov pred | |
Blind Eventlog by suspending its threads. This technique requires elevated privileges.
Be aware that all events, from the period the threads were suspended, will be pushed to Eventlog the moment the threads are resumed.
suspend: find and suspend all Eventlog threads and disrupt its functionality.resume: find and resume all Eventlog threads and restore its functionality.blindeventlog <suspend | resume>x64 Native Tools Command Prompt for VS <2019/2022> terminal.bofcompile.bat script to compile the object file.