BOFs
BOFs copied to clipboard
Allow APC spawn to use alternate credentials
Added BOFs/StaticSyscallsAPCUserSpawn/
Modified the .cna and entry.c slightly to accommodate CreateProcessWithLogonW. Thought it would be cool to emulate the native spawnas functionality, but use the direct syscalls for the injection.
Rather than add onto existing apc_spawn, I created separate static_syscalls_apc_user_spawn/shspawn, so the syntax doesn't become too cumbersome with the original. Let me know what you think.
No changes to Syscalls.h/beacon.h from the original.