17 Commits

Author SHA1 Message Date
koins baa2dc2176 main merge 2022-09-10 05:55:56 -07:00
kmanc cea2e51ba0 Code style (#54)
* no substantive changes, just small updates

* shouldn't be any real change, just some code style best practices

* dunno how this didn't get added to the last commit

* Update reverse shell badge data via Github Action

* Update process migration badge data via Github Action

* Update process hollowing badge data via Github Action

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-08-18 04:54:13 -07:00
koins 2ec25f7a77 master merge 2022-04-22 13:22:58 -07:00
kmanc 038fa0ebc6 Antistring (#44)
* updates to rco_utils to support api hashing

* version bumps, feature adjustments

* fix tcp cargo

* make the functions public

* hash params done

* add antisand as an optional feature of tcp_reverse shell

* fix links in comments

* lots of cleanup on tcp_reverse_shell

* clippy recommendation

* fully de-stringed version is complete, but gotta figure out how i want to toggle them

* all changes to support antisand and antistring complete!

* antisand and antistring were incompatible because of imports; fixed that. also there is a new implementation of antisand with antistring applied

* antistring support for process hollowing

* antistring updates for process migration

* lock updatrer

* i think this covers the builds needed

* new tool

* readme updates

* more readme updates

* Update README.md

* Update README.md

* Update reverse shell badge data via Github Action

* Update process migration badge data via Github Action

* Update process hollowing badge data via Github Action

* trying a new workflow trigger

* undoing, didnt work the way i wanted it to

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-04-22 11:18:26 -07:00
koins ea777bf499 master merge 2022-03-05 21:30:10 -08:00
kmanc ba41e0a746 dependency_fix (#36)
* the windows crate recently made another breaking change that they didnt acknowledge as breaking

* need to repin the windows crate to 0.33.0 so that old versions dont mess up compilation

* compile profiles drastically reduce binary size across the board

* small version bumps to reflect bugfix

* reordered for alphabtizing

* lock update

* Update reverse shell badge data via Github Action

* Update process hollowing badge data via Github Action

* missed a feature change for the fix

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-03-05 21:19:07 -08:00
koins 5dd5592701 this is much cleaner IMO 2022-02-16 21:03:08 -08:00
koins c390fb92f2 project layout for a rat consisting of three components. operator uses client to interact with c2. c2 interacts with implant on victim machine 2022-02-15 20:40:21 -08:00
kmanc 62455ab55e Encryption (#31)
* reworked a lot of the way encrypting shellcodes work. allowed xor_shellcode to xor more than just the shellcode. renamed xor_shellcode accordingly. changed the feature name from encrypted to xor. bumped versions

* gh actions and shields

* lock and toml

* these functions are only needed here

* these functions not needed in a lib (at least not now)

* lock

* Update process migration badge data via Github Action

* Update process hollowing badge data via Github Action

* Update xor params badge data via Github Action

* missed one thing, damn

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-02-02 22:30:54 -08:00
kmanc ada97f0b16 Shellcode encrypter (#25)
* GH actions update

* new badge to track

* lock and toml

* new tool

* key and encrypted shellcode placeholders

* i missed the lock i guess

* slice xor function which will be needed for later tools

* shellcode XORer and printer

* slice length to generic function as a util

* extend shorter slice to be the same length as longer slice by repeating

* return both of the inputs for equalize to make it harder to misuse. return result (possible error) for xor to make it more clear what went wrong

* default key length ++ and version bump

* version bump

* better validation of input data
2022-01-30 09:48:32 -08:00
kmanc 45d72c96f0 Process hollowing (#23)
* missed commit

* build new tool

* mostly boilerplate for process hollowing

* prepping new tool

* fixing up boilerplate

* whoops, didnt change name

* whoops, didnt change name in another place

* update lock

* scoping out the windows implementation

* CreateProcessW compiles, on to ZwQueryInformation

* new dep for process hollowing

* end to end but something is wrong, gotta debug

* failing at createprocessw....... bleh

* update docs to include process hollowing as the new tool

* update builds in github actions for process_hollowing

* toml and lock updates for process_hollowing

* process_hollowing as the new hotness. windows implementation is 'done' in that it compiles, but it panics immediately so gonna have to look into that

* moved to 'A' win32 calls from 'W'. still not working, but getting further along

* Merge utils into process hollowing (#14)

* update to lock and toml

* adding a utils library for some shared useful functions. starting with u8 array --> u32

* moved to 'A' win32 calls from 'W'. still not working, but getting further along

* needed 64 bit too

* use utils lib instead of byteorder crate. things seem to be working better as a result

* at a bit of a loss...why doesnt this work?

* this was gonna bug me. utils first, then tools

* prep readme for when windows actually works

* moving lone bracket to line above for workflow compat

* badge in workflow, shields, and readme

* still not working, but also not crashing

* spacing error i think

* second validation check. still doesnt work though

* debugging continues

* am i closer? im on the last line so i kinda hope so

* lock update

* update to the new shared config

* update readme a little, more to come

* pretty sure i had a mistake there. also the 'needs' thing will save headache later

* still dunno what the deal is, trying to narrow down the problem

* trying new payloads to no avail

* readme update, still some placeholders

* back to OG shellcode

* it works now. my brain is mush, but it works now

* take THAT comment

* Update README.md

* Update README.md

* Update README.md

* got this working much faster than expected

* readme updated

* Update process hollowing badge data via Github Action

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-01-28 19:46:01 -08:00
kmanc 14bf59fa01 Refactor (#21)
* shared config library! this will make setting up the payloads much easier

* update lock and toml for new shared config

* migrate rev shell to the new shared config

* lock update again

* shellcodes to config lib

* migrating...process migration to the new shared config

* update readme's links

* minor version bumps

* Update process migration badge data via Github Action

* Update reverse shell badge data via Github Action

Co-authored-by: kmanc <kmanc@users.noreply.github.com>
2022-01-25 22:00:52 -08:00
kmanc 776934d2ea Refactor (#6)
* more readable cargo files

* no more branch specifier

* documentation overhaul

* ok final rename i think

* change order and add cleans
2021-12-27 12:37:24 -08:00
kmanc e487ca18b8 Refactor (#4)
* versioning change; H.M.L where H=breaking change, M=non-breaking change, L=bugfix

* updating gitignore

* project structure to workspaces
2021-12-27 05:29:04 -08:00
kmanc d4a3ea0f1a Small refactor (#3)
* move target checks out of main

* Cargo update
2021-12-20 05:30:45 -08:00
kmanc 22c0530946 Windows process migration (#2)
* broken link

* update toml for next tool: process injection

* boilerplating for shellcode injector

* some stubs, need internet to go futher

* link time optimization drastically reduces the size of windows executables - will have to investigate drawbacks when i have internet

* readme update prep

* small typing optimization

* New Windows dependencies for process injection

* msfvenom reverse tcp shell to localhost 4444 as example shellcode

* Windows shellcode injection to the explorer.exe process

* placeholder

* small bump for the half-feature completion
2021-12-20 04:52:58 -08:00
Kevin 8cd431f9f1 Cargo lock and toml 2021-12-13 19:28:04 -08:00