This UDRL and Sleepmask Development course, created by Alex Reid and Zero-Point Security, teaches students how to apply low-level Windows knowledge and offensive tradecraft in the writing and development of Cobalt Strike’s User-Defined Reflective Loader and Sleepmask components. 

2026 Updates 

The course has been updated to stay current with the latest version of Cobalt Strike. It also has been expanded to include new modules covering more advanced BeaconGate configuration and evasion tradecraft:

  • Lightweight BeaconGate and Runtime Configuration BOF: Build an abbreviated, more efficient BeaconGate obfuscation process, plus a BOF to toggle between it and the full version at runtime 
  • Loading Sensitive Libraries via Proxy: Use call stack spoofing to defeat a common detection rule targeting suspicious library loads during the reflective loading process. 
  • BeaconGate Support for BOFs: Extend BeaconGate’s obfuscation to arbitrary Windows APIs called from BOFs, with no modification to the BOFs themselves required. 
  • Alpharius: A CET Compliant Stack Spoofing and Sleep Obfuscation Technique Utilizing Fibers: Learn a novel, fiber-based call stack spoofing and sleep obfuscation technique that chains multiple spoofed calls without ever leaving user code exposed in memory. 

Training Content 

1. Welcome

  • Introduction 
  • Author’s Note 
  • Software Requirements 

2. Introduction to UDRL and Sleepmask 
Development

  • Defining the Problem 
  • Component Requirements 
  • Project setup 
  • Build Automation 
  • Testing Payloads 

3. UDRL: Extending Stardust

  • Introduction to Stardust 
  • API Resolution Via Macros 
  • Debug Output 
  • Supporting Forwarded APIs 
  • Pointer Arithmetic 
  • Custom User Data 
  • Global Variables Without NtProtectVirtualMemory 
  • Removing Padding 

4. UDRL: Basic Reflective Loading

  • Parsing PE Headers 
  • Mapping Sections 
  • Populating the Import Address Table 
  • Processing Relocations 
  • Transferring Execution 

5. Sleepmask: Basic Ekko Implementation

  • Integrating Common Assets 
  • Preparing sleep_mask 
  • Masking Heap Memory 
  • Understanding Ekko 
  • Implementing Ekko 

6.  Sleepmask: Through the BeaconGate With Ekko

  • Understanding the Problem 
  • Passing Stack Parameters 
  • Storing Return Values 
  • Integrating BeaconGate 

7. Lightweight BeaconGate and Runtime Configuration BOF 

  • Introduction to Abbreviated Obfuscation 
  • Implementing Obfuscation with a BOF 
  • Toggling Between Processes 

8. BeaconGate Support for BOFs 

  • Understanding Beacon APIs 
  • Routing Windows APIs 
  • Adding BeaconGate Functionality 

9. UDRL: Module Stomping

  • Introduction to Module Stomping 
  • Identifying Sacrifical DLLs 
  • Basic Implementation 

10.  UDRL: Advanced Module Stomping

  • Background Research 
  • Manipulating Section Handles 
  • Replacing LoadLibraryEx 
  • Mapping Beacon’s Unwind Info 
  • Finding and Fixing Sleepmask and BOF Unwind Info 

11.  Common: Control Flow Guard

  • Understanding Control Flow Guard 
  • Enumerating CFG and Modifying the Bitmap 

12.  Evasion: Call Stack Spoofing

  • Introduction to Hunt Sleeping Beacons and Call Stack Detection 
  • Exposing Timer Functionality to the UDRL 
  • Beacon Entry via NtContinue 
  • Concealing the Main Thread’s Call Stack During Timer Execution 
  • Disguising Timer Stacks with ROP and JOP 
  • Suspicious Timers and Where to Hide Them 

13. Evasion: Loading Sensitive Libraries Via Proxy 

  • Detecting Suspicious Library Loads 
  • Leveraging Call-Stack Stack Spoofing 
  • Implementing Proxied Library Loading  

14.  Evasion: Cleaning the LitterBox

  • Introduction to LitterBox and Underlying Tools 
  • Patriot: Hiding Suspicious CONTEXTs 
  • Moneta: Freeing the Initial Allocation 
  • YARA: Addressing Static Signatures 
  • PE-sieve: Avoiding Entropy Checks 

15.  Alpharius: A CET-Compliant Stack Spoofing and Sleep Obfuscation Technique  

  • Explaining Intel Control-Flow Enforcement Technology 
  • CETs Impact on Tooling 
  • Introduction to Fibers as Spoofing Technique 
  • Designing the Alpharius Technique 

16.  Evasion: Assorted Tradecraft and Code Cleanup

  • Extending BeaconGate for Unsupported APIs 
  • Exception Handling via Wow64PrepareForException 
  • Exiting Beacon Gracefully 
  • Ekko via Threadpool Timers 
  • Code Cleanup and Bug Fixes 

17.  Course Completion

  • Areas for Future Exploration 
  • Closing 
  • Course Evaluation 
  • Certificate of Completion 

Ready to Get Started?