* cargo lock and version bumps
* reduce number of loadlibrary calls to reduce error 126 crashes
* version bump
* forgot to update the tcp rev shell antistring
* bump minor version and win crate version
* bump minor version and win crate version
* update lib to use new windows syntax and a few small changes i neglected to make here before
* update tcp_rev_shell to work on new windows crate
* update process_hollowing to work on new windows crate
* update process_migration to work on new windows crate
* lock things
* as expected, i completely botched the merge conflict
* lock change?
* fixed a mistake i introduced
* gitignore update for mac
* cargo things
* documentation update, finally have multiple os builds figured out
* avoid feature injection on dependencies as it has caused problems in the past
* bump version now
* this shouldnt have changed anything, just reorded so its not a random mess ordered by 'well i made it now'
* missed a required import for the move away from feature injection
* wasnt as lazy this time, actually build for two main oses
* looks nicer this way
* its been a good run, custom shields
* relying on crates now for versioning, so dont need this anymore
* kleenscan to virustotal. i probably messed something up, gotta double check in a better renderer
* new pics who dis
* order consistently
* this is gonna be a while
* here we go again
* lock
* version bumps
* updated code to support windows v0.40.0
* unused import
* wsadata re-cap
* missed a version bump
* Update process hollowing badge data via Github Action
* Update process migration badge data via Github Action
* Update reverse shell badge data via Github Action
* lock
* previously unseen compile issue / clippy flag. will have to revisit how that slipped through
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* ran cargo fmt and accepted whatever it gave me
* not sure why it did that but i dont like those ones
* aside from that one format which i keep undoing i like them
* missed a few before
* prototype, moving to test machine for more
* dont forget this link! its useful
* its macro or nothin
* macros are weird...still playing around
* this feels close, gotta expand array in macro
* i think this does it! will sub in and test thoroughly later
* macro working in tcp_reverse_shell
* macro worked into process migrations
* macro worked into process hollowing
* small code rearranging
* returned functions are unsafe
* antistring functions are split into their own files for ease of maintenance
* post import-cleanup comment update
* extra newline
* that wasnt extra
* spacing and sorting
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* cargo things
* no more mem::zeroed, using default / null traits
* more removal of lib calls where not needed
* need to test a few payloads to make sure i didnt break anything
* remove non-needed cast
* lots of reorg so things are easier to read. still have some work to go + gotta redo for all the antistrings
* clean up some more junk and try not to create things as null when youre just gonna assign to them anyway
* lock things
* discovered a (probably) long standing bug. dirty workaround in place but gonna want to revisit that eventually
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* Update xor params badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* no substantive changes, just small updates
* shouldn't be any real change, just some code style best practices
* dunno how this didn't get added to the last commit
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* fix dependency compat again
* missed a comma
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* updates to rco_utils to support api hashing
* version bumps, feature adjustments
* fix tcp cargo
* make the functions public
* hash params done
* add antisand as an optional feature of tcp_reverse shell
* fix links in comments
* lots of cleanup on tcp_reverse_shell
* clippy recommendation
* fully de-stringed version is complete, but gotta figure out how i want to toggle them
* all changes to support antisand and antistring complete!
* antisand and antistring were incompatible because of imports; fixed that. also there is a new implementation of antisand with antistring applied
* antistring support for process hollowing
* antistring updates for process migration
* lock updatrer
* i think this covers the builds needed
* new tool
* readme updates
* more readme updates
* Update README.md
* Update README.md
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* trying a new workflow trigger
* undoing, didnt work the way i wanted it to
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* randomize the anti-sandbox website check
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* should be everything required to keep up with the windows crate breaking changes
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* the windows crate recently made another breaking change that they didnt acknowledge as breaking
* need to repin the windows crate to 0.33.0 so that old versions dont mess up compilation
* compile profiles drastically reduce binary size across the board
* small version bumps to reflect bugfix
* reordered for alphabtizing
* lock update
* Update reverse shell badge data via Github Action
* Update process hollowing badge data via Github Action
* missed a feature change for the fix
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* whoops
* newlines to end files
* better code comments
* better code comments
* only compile necessary features. ones not asked for get dummy stub functions
* newline at end of file
* small version bump. better conditional compilation logic. better code comments
* build updates to try to cover feature combinations
* typo
* lock
* glaring readme issues...will address more on separate branch
* newline
* typo
* typo
* this was more than just a patch bump for utils
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* Update xor params badge data via Github Action
* lock
* compat change on windows crate
* require newer win version to support change
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* this is gonna get messy
* getting closer, need to check something
* i was editing the wrong file, lol
* ok now we've made some progress, lets use it
* this needs some cleanup. but tldr is the library has three new functions. one is a legit implementation for windows to try to tell if its AV testing. the other two are bs placeholders
* basic comments and reverse the logic for the wrong one
* lock
* antisand works and now properly passes feature to rco_utils. version bump!
* antisand works and now properly passes feature to rco_utils. version bump!
* Update lib.rs
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* reworked a lot of the way encrypting shellcodes work. allowed xor_shellcode to xor more than just the shellcode. renamed xor_shellcode accordingly. changed the feature name from encrypted to xor. bumped versions
* gh actions and shields
* lock and toml
* these functions are only needed here
* these functions not needed in a lib (at least not now)
* lock
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* Update xor params badge data via Github Action
* missed one thing, damn
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* GH actions update
* new badge to track
* lock and toml
* new tool
* key and encrypted shellcode placeholders
* i missed the lock i guess
* slice xor function which will be needed for later tools
* shellcode XORer and printer
* slice length to generic function as a util
* extend shorter slice to be the same length as longer slice by repeating
* return both of the inputs for equalize to make it harder to misuse. return result (possible error) for xor to make it more clear what went wrong
* default key length ++ and version bump
* version bump
* better validation of input data
* missed commit
* build new tool
* mostly boilerplate for process hollowing
* prepping new tool
* fixing up boilerplate
* whoops, didnt change name
* whoops, didnt change name in another place
* update lock
* scoping out the windows implementation
* CreateProcessW compiles, on to ZwQueryInformation
* new dep for process hollowing
* end to end but something is wrong, gotta debug
* failing at createprocessw....... bleh
* update docs to include process hollowing as the new tool
* update builds in github actions for process_hollowing
* toml and lock updates for process_hollowing
* process_hollowing as the new hotness. windows implementation is 'done' in that it compiles, but it panics immediately so gonna have to look into that
* moved to 'A' win32 calls from 'W'. still not working, but getting further along
* Merge utils into process hollowing (#14)
* update to lock and toml
* adding a utils library for some shared useful functions. starting with u8 array --> u32
* moved to 'A' win32 calls from 'W'. still not working, but getting further along
* needed 64 bit too
* use utils lib instead of byteorder crate. things seem to be working better as a result
* at a bit of a loss...why doesnt this work?
* this was gonna bug me. utils first, then tools
* prep readme for when windows actually works
* moving lone bracket to line above for workflow compat
* badge in workflow, shields, and readme
* still not working, but also not crashing
* spacing error i think
* second validation check. still doesnt work though
* debugging continues
* am i closer? im on the last line so i kinda hope so
* lock update
* update to the new shared config
* update readme a little, more to come
* pretty sure i had a mistake there. also the 'needs' thing will save headache later
* still dunno what the deal is, trying to narrow down the problem
* trying new payloads to no avail
* readme update, still some placeholders
* back to OG shellcode
* it works now. my brain is mush, but it works now
* take THAT comment
* Update README.md
* Update README.md
* Update README.md
* got this working much faster than expected
* readme updated
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>