* cargo lock and version bumps
* reduce number of loadlibrary calls to reduce error 126 crashes
* version bump
* forgot to update the tcp rev shell antistring
* bump minor version and win crate version
* bump minor version and win crate version
* update lib to use new windows syntax and a few small changes i neglected to make here before
* update tcp_rev_shell to work on new windows crate
* update process_hollowing to work on new windows crate
* update process_migration to work on new windows crate
* lock things
* as expected, i completely botched the merge conflict
* lock change?
* fixed a mistake i introduced
* gitignore update for mac
* cargo things
* documentation update, finally have multiple os builds figured out
* avoid feature injection on dependencies as it has caused problems in the past
* bump version now
* this shouldnt have changed anything, just reorded so its not a random mess ordered by 'well i made it now'
* missed a required import for the move away from feature injection
* wasnt as lazy this time, actually build for two main oses
* looks nicer this way
* its been a good run, custom shields
* relying on crates now for versioning, so dont need this anymore
* kleenscan to virustotal. i probably messed something up, gotta double check in a better renderer
* new pics who dis
* order consistently
* this is gonna be a while
* here we go again
* lock
* version bumps
* updated code to support windows v0.40.0
* unused import
* wsadata re-cap
* missed a version bump
* Update process hollowing badge data via Github Action
* Update process migration badge data via Github Action
* Update reverse shell badge data via Github Action
* lock
* previously unseen compile issue / clippy flag. will have to revisit how that slipped through
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* ran cargo update
* clippy checks for all combinations of features required to pass
* hadnt saved the file, this is the desired version
* small nitpick on my gitignore lol
* new workflow was in the wrong dir and i didnt notice
* need windows dependencies in windows builds
* name consistency
* alphabetizing so i can find things when im adding/changing/removing/etc
* ran cargo fmt and accepted whatever it gave me
* not sure why it did that but i dont like those ones
* aside from that one format which i keep undoing i like them
* missed a few before
* prototype, moving to test machine for more
* dont forget this link! its useful
* its macro or nothin
* macros are weird...still playing around
* this feels close, gotta expand array in macro
* i think this does it! will sub in and test thoroughly later
* macro working in tcp_reverse_shell
* macro worked into process migrations
* macro worked into process hollowing
* small code rearranging
* returned functions are unsafe
* antistring functions are split into their own files for ease of maintenance
* post import-cleanup comment update
* extra newline
* that wasnt extra
* spacing and sorting
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* cargo things
* no more mem::zeroed, using default / null traits
* more removal of lib calls where not needed
* need to test a few payloads to make sure i didnt break anything
* remove non-needed cast
* lots of reorg so things are easier to read. still have some work to go + gotta redo for all the antistrings
* clean up some more junk and try not to create things as null when youre just gonna assign to them anyway
* lock things
* discovered a (probably) long standing bug. dirty workaround in place but gonna want to revisit that eventually
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* Update xor params badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* no substantive changes, just small updates
* shouldn't be any real change, just some code style best practices
* dunno how this didn't get added to the last commit
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* fix dependency compat again
* missed a comma
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* cleaning up some of the magic casting
* removing reliance on the stack overflow way of reading data from an buffer/array
* Update Cargo.toml
* Update Cargo.toml
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* updates to rco_utils to support api hashing
* version bumps, feature adjustments
* fix tcp cargo
* make the functions public
* hash params done
* add antisand as an optional feature of tcp_reverse shell
* fix links in comments
* lots of cleanup on tcp_reverse_shell
* clippy recommendation
* fully de-stringed version is complete, but gotta figure out how i want to toggle them
* all changes to support antisand and antistring complete!
* antisand and antistring were incompatible because of imports; fixed that. also there is a new implementation of antisand with antistring applied
* antistring support for process hollowing
* antistring updates for process migration
* lock updatrer
* i think this covers the builds needed
* new tool
* readme updates
* more readme updates
* Update README.md
* Update README.md
* Update reverse shell badge data via Github Action
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
* trying a new workflow trigger
* undoing, didnt work the way i wanted it to
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* randomize the anti-sandbox website check
* Update process migration badge data via Github Action
* Update process hollowing badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>
* clippy suggestion
* bug that prevented xor_params from doing anything at all
* Update xor params badge data via Github Action
Co-authored-by: kmanc <kmanc@users.noreply.github.com>