
Remove API hooks from a Beacon process.

Primary LanguageCBSD 3-Clause "New" or "Revised" LicenseBSD-3-Clause

This is a Beacon Object File to refresh DLLs and remove their hooks. The code is from Cylance's Universal Unhooking research:


To use:

Load unhook.cna into Cobalt Strike via Cobalt Strike -> Script Manager

Run 'unhook' from Beacon

To build:

x86: Open Visual Studio x86 Native Tools Command Prompt and type 'make'
x64: Open Visual Studio x64 Croos Tools Command Prompt and type 'make'

This project derived from:

Reflective DLL Injection
BSD 3-Clause License
Copyright (c) 2011, Stephen Fewer of Harmony Security (www.harmonysecurity.com)

BSD 3-Clause License
Copyright (c) 2017, Cylance Inc.

Unhook Meterpreter Extension
BSD-3-Clause License
2006-2018, Rapid7, Inc.