itsMe Posted June 3, 2023 Share Posted June 3, 2023 This is the hidden content, please Sign In or Sign Up LightsOut LightsOut will generate an obfuscated DLL that will disable AMSI & ETW while trying to evade AV. This is done by randomizing all WinAPI functions used, xor encoding strings, and utilizing basic sandbox checks. Mingw-w64 is used to compile the obfuscated C code into a DLL that can be loaded into any process where AMSI or ETW are present (i.e. PowerShell). LightsOut is designed to work on Linux systems with python3 and mingw-w64 installed. No other dependencies are required. Features currently include: XOR encoding for strings WinAPI function name randomization Multiple sandbox check options Hardware breakpoint bypass option This is the hidden content, please Sign In or Sign Up Link to comment Share on other sites More sharing options...
Recommended Posts