* Setup script and other small changes
* Changes to make the setup.ps1 script work properly
* Update README.md
* Update README.md
* Update README.md
* Some code improvements
* Update README.md
* C&C features removed; ETW patch and DInvoke added.
In the C&C Python console the options execute, downexec and copy have been removed.
In the C# agent, ETW is now patched before setting up the reverse connection and the DInvoke technique (check out SharpSploit!) is being used to replace some PInvoke calls.
DInvoke removes IAT Win32 API entries and also avoids EDR API hooking by manually loading and mapping the required modules.
* Some minor changes
* PInvoke removed.
* DInvoke implemented and some other minor changes
* Processess listing improved
* Strings encoded using base64
* AMSI patching added.
* LdrLoadDll hooking added to deny undesired DLLs (like EDR's) in our process.
This will protect our malware from some EDR dll injections. Since the hooking is using DInvoke and manual module mapping its a bit slow, which may give enough time to the EDRs to load their Dlls in our process in some cases.
* Update Controller.cs
* LdrLoadDll hooking removed temporally. Great fixes on GetSystem and EnablePrivileges.
* Basic sandbox detection added.
* RWX memory protection removed from direct syscalls shellcode allocating. and others
* Update README.md
* Update README.md
* update images
* Update README.md
* Setup script and other small changes
* Changes to make the setup.ps1 script work properly
* Update README.md
* Update README.md
* Update README.md
* Some code improvements
* Update README.md
* C&C features removed; ETW patch and DInvoke added.
In the C&C Python console the options execute, downexec and copy have been removed.
In the C# agent, ETW is now patched before setting up the reverse connection and the DInvoke technique (check out SharpSploit!) is being used to replace some PInvoke calls.
DInvoke removes IAT Win32 API entries and also avoids EDR API hooking by manually loading and mapping the required modules.
* Some minor changes
* PInvoke removed.
* DInvoke implemented and some other minor changes
* Processess listing improved
* Strings encoded using base64
* AMSI patching added.
* Setup script and other small changes
* Changes to make the setup.ps1 script work properly
* Update README.md
* Update README.md
* Update README.md
* Some code improvements
* Update README.md
Since named pipes impersonation is one of the Meterpreter's default getsystem methods, a lot of AV systems are aware of this technique and they tag it as malicious as soon as you try to use it. In order to avoid AV detection, the GetSystem functionality will try to impersonate a System process's access token and only if that fails it will use the old named pipes impersonation method.
Now the inject functionaly also allows to reflectively inject .NET assemblies in exe format.
The .NET assemblies injection functionality has been improved to support different scenarios.
Now the inject functionaly also allows to reflectively inject .NET assemblies in exe format.
The .NET assemblies injection functionality has been improved to support different scenarios.
With this changes, the injection of shellcode can be executed both in the own shell process or in another process as well.
The shellcode injection is executed using directly syscalls, avoiding user mode API calls to evade EDR API hooking.
In the future, more Win32 API calls will be replaced with their corresponding syscalls.