_RastaMouse
rastamouse.me
_RastaMouse
@rastamouse.me
Wannabe security guy. Director @ Zero-Point Security.
Works!
January 2, 2026 at 1:01 AM
Sure, makes sense. You can't just leave the APIs in this scenario though, because Crystal Palace throws the error "Function xxx is not in MODULE$Function format". Maybe we need a new command to skip relocating specified functions? Or maybe some other way to deal with it that fits with your plans.
January 2, 2026 at 12:10 AM
The idea was to merge hooks into a BOF, 'make coff', then run via beacon_inline_execute. I don't think we want to attach the Beacon BOF APIs to funcs within the merged COFF though. What would you attach them to? Can't we just leave/ignore them so Beacon can link them to the proper internal funcs?
January 1, 2026 at 11:35 PM
How are we handling BeaconOutput, BeaconPrintf, etc with a COFF object?
January 1, 2026 at 2:52 PM
lol nevermind, there were a few mins of 2025 left :D
December 31, 2025 at 11:36 PM
Yeah, I see what you're cookin' there. Definitely worth exploring. I guess that's my first project of 2026 sorted :)
December 31, 2025 at 11:09 PM
Yeah, exactly this. You get to choose, but you can't have both :)
December 31, 2025 at 7:24 PM
I really like the experimentation though
December 6, 2025 at 8:58 AM