Repository for API Hashing script detailed in the Huntress Blog
This repository hosts the hashing replacement script and yara rule detailed in the huntress blog.https://www.huntress.com/blog/hackers-no-hashing-randomizing-api-hashes-to-evade-cobalt-strike-shellcode-detection To use the script simply runpython apihashreplace.py <32 or 64> Egpython apihashreplace.py 32 shellcode.bin GitHub View Github
Read more