Changes to docs and install instructions

This commit is contained in:
wetw0rk
2026-01-13 17:40:07 -06:00
parent c560e972fb
commit 96bfa76297
4 changed files with 95 additions and 117 deletions
+7 -7
View File
@@ -16,7 +16,7 @@ Ultimately, the fact that you’re here means you’re already a contributor, an
# Table of Contents
- [Framework Layout](#framework-layout)
- [Kit Layout](#kit-layout)
- [Your Workspace](#your-workspace)
- [Examples](#examples)
- [Adding a Format](#adding-a-format)
@@ -27,7 +27,7 @@ Ultimately, the fact that you’re here means you’re already a contributor, an
- [New Modules](#new-modules)
- [New Formats](#new-formats)
# Framework Layout
# Kit Layout
The project is continuously evolving, but its overall layout should remain consistent. Depending on your goal, you’ll typically need to focus on just one specific area.
@@ -46,7 +46,7 @@ drwxrwxr-x 4 wetw0rk wetw0rk 4096 Mar 28 09:54 payloads
Let's break this down:
- **common**: This directory contains "handlers" for Sickle's default operations and "standard libraries" used by payload and development modules. Very rarely will you be modifying content within this directory since majority of updates to these files will be new features that affect the whole framework or simply bug fixes.
- **common**: This directory contains "handlers" for Sickle's default operations and "standard libraries" used by payload and development modules. Very rarely will you be modifying content within this directory since majority of updates to these files will be new features that affect the whole kit or simply bug fixes.
- **formats**: This is where all formats supported by Sickle are stored (e.g *c, java, python*). Should you be using a custom wrapper in a new language not supported by Sickle this is where you would add it.
@@ -58,7 +58,7 @@ Often the best way to begin module development, is by copying an existing file a
## Your Workspace
When running Sickle for the first time, a workspace for custom modules, formats, and payloads is automatically created for your user. This is done so you can safely add new features to Sickle without messing with the framework until you're ready to submit a pull request. Of course, this is also designed for those of you working as Red Team Operators who may not want to open source a custom stager.
When running Sickle for the first time, a workspace for custom modules, formats, and payloads is automatically created for your user. This is done so you can safely add new features to Sickle without messing with the kit until you're ready to submit a pull request. Of course, this is also designed for those of you working as Red Team Operators who may not want to open source a custom stager.
Within Linux this can be found under ***~/.local/share/sickle*** as shown below:
@@ -414,9 +414,9 @@ C:\Users\admin\Desktop>
Depending on what the reason is for your pull request I ask you follow the guidelines below:
- If you are extending the core framework (say a header file) ensure that you match the structure layout to that of C code. I will be manually checking this so be patient when you submit a PR.
- If you are extending the core kit (say a header file) ensure that you match the structure layout to that of C code. I will be manually checking this so be patient when you submit a PR.
- Make sure that any module submitted is documented appropriately. No need for a comment on each line but it needs to be verbose enough for me to ensure no backdoors are added to the framework. Regardless, I will be testing your code!
- Make sure that any module submitted is documented appropriately. No need for a comment on each line but it needs to be verbose enough for me to ensure no backdoors are added to the kit. Regardless, I will be testing your code!
- Try your best to stick to [PEP8](https://peps.python.org/pep-0008/), however I will not be super strict on this.
@@ -428,7 +428,7 @@ Depending on what the reason is for your pull request I ask you follow the guide
If you want to add a new payload it needs to fit the following criteria:
- The payload must be useful during exploitation and have a decently large attack surface / broad application. For example, an egghunter is a solid addition since it is a technique that can be inserted into many exploits, whereas a payload that connects to a TFTP server and downloads and executes a file may not be the best fit for the framework simply due to its size and application. However, if you want to add a new loader, say DLL injection, this is welcomed since users can then create a DLL that will perform the aforementioned TFTP technique or anything else they program (broad application).
- The payload must be useful during exploitation and have a decently large attack surface / broad application. For example, an egghunter is a solid addition since it is a technique that can be inserted into many exploits, whereas a payload that connects to a TFTP server and downloads and executes a file may not be the best fit for the kit simply due to its size and application. However, if you want to add a new loader, say DLL injection, this is welcomed since users can then create a DLL that will perform the aforementioned TFTP technique or anything else they program (broad application).
- Ensure you are using proper API, strings for example should use the function `from_str_to_xwords()`
+36 -58
View File
@@ -2,8 +2,6 @@
Currently the API used by modules is not documented. The source code is the official source of truth in terms of documentation. Since I'm actively working on new modules, the API is subject to change. Ultimately, the goal is to create official documentation for core API functions and make API as easy to use as possible.
This should be complete in version 2.0.3.
# Table of Contents
- [Linux Installation](#linux-installation)
@@ -15,40 +13,40 @@ This should be complete in version 2.0.3.
After Python has been installed, simply clone the Sickle repository.
```
wetw0rk@remachine:/opt$ git clone https://github.com/wetw0rk/Sickle
$ git clone https://github.com/wetw0rk/sickle-pdk.git
```
Once cloned, enter the `Sickle/src` directory and install the requirements using `pip3`.
Once cloned, enter the `sickle-pdk/src` directory and install the requirements using `pip3`.
```
wetw0rk@remachine:/opt/Sickle/src$ sudo pip3 install -r requirements.txt
$ sudo pip3 install -r requirements.txt
```
If you encounter any issues installing from requirements.txt you may need to install cmake as it is used by the Keystone Engine (`sudo apt install cmake -y`). Once dependencies have been installed simply run `setup.py` as shown below.
```
wetw0rk@remachine:/opt/Sickle/src$ sudo python3 setup.py install
running install
$ sudo python3 setup.py install
```
And you should be good to go!
```
wetw0rk@remachine:/opt/Sickle/src$ sickle -h
usage: sickle [-h] [-r READ] [-f FORMAT] [-m MODULE] [-a ARCH] [-b BADCHARS] [-v VARNAME] [-i] [-l]
$ sickle-pdk -h
usage: sickle-pdk [-h] [-r READ] [-p PAYLOAD] [-f FORMAT] [-m MODULE] [-a ARCH] [-b BADCHARS] [-v VARNAME] [-i] [-l [LIST]]
Sickle - Payload development framework
Sickle - Payload Development Kit
options:
-h, --help Show this help message and exit
-r READ, --read READ Read bytes from binary file (use - for stdin)
-f FORMAT, --format FORMAT Output format (--list for more info)
-m MODULE, --module MODULE Development module
-a ARCH, --arch ARCH Select architecture for disassembly
-b BADCHARS, --badchars BADCHARS Bad characters to avoid in shellcode
-v VARNAME, --varname VARNAME Alternative variable name
-i, --info Print detailed info for module or payload
-l, --list List available formats, payloads, or modules
-h, --help Show this help message and exit
-r, --read READ Read bytes from binary file (use - for stdin)
-p, --payload PAYLOAD Shellcode to use
-f, --format FORMAT Output format (--list for more info)
-m, --module MODULE Development module
-a, --arch ARCH Select architecture for disassembly
-b, --badchars BADCHARS Bad characters to avoid in shellcode
-v, --varname VARNAME Alternative variable name
-i, --info Print detailed info for module or payload
-l, --list [LIST] List available formats, payloads, or modules
```
# Windows Installation
@@ -56,63 +54,43 @@ options:
After Python has been installed, Windows installation is just as easy as installion on Linux. First clone the repository.
```
C:\>git clone https://github.com/wetw0rk/Sickle.git
Cloning into 'Sickle'...
remote: Enumerating objects: 531, done.
remote: Counting objects: 100% (91/91), done.
remote: Compressing objects: 100% (67/67), done.
remote: Total 531 (delta 22), reused 84 (delta 20), pack-reused 440
Receiving objects: 100% (531/531), 161.92 MiB | 1.32 MiB/s, done.
Resolving deltas: 100% (249/249), done.
Updating files: 100% (65/65), done.
C:\>git clone https://github.com/wetw0rk/sickle-pdk.git
```
Once cloned, enter the `Sickle/src` directory and install the requirements using `pip3`.
Once cloned, enter the `sickle-pdk/src` directory and install the requirements using `pip3`.
```
C:\Sickle\src>pip3 install -r requirements.txt
DEPRECATION: Loading egg at c:\users\developer\appdata\local\programs\python\python312\lib\site-packages\sickle-2.0.2-py3.12.egg is deprecated. pip 24.3 will enforce this behaviour change. A possible replacement is to use pip for package installation.. Discussion can be found at https://github.com/pypa/pip/issues/12330
Collecting capstone>=3.0.5 (from -r requirements.txt (line 1))
Using cached capstone-5.0.1-py3-none-win_amd64.whl.metadata (3.5 kB)
Collecting setuptools (from -r requirements.txt (line 2))
Downloading setuptools-71.0.4-py3-none-any.whl.metadata (6.5 kB)
Using cached capstone-5.0.1-py3-none-win_amd64.whl (1.3 MB)
Downloading setuptools-71.0.4-py3-none-any.whl (2.3 MB)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 2.3/2.3 MB 9.3 MB/s eta 0:00:00
Installing collected packages: setuptools, capstone
Successfully installed capstone-5.0.1 setuptools-71.0.4
[notice] A new release of pip is available: 24.0 -> 24.1.2
[notice] To update, run: python.exe -m pip install --upgrade pip
C:\sickle-pdk\src>pip3 install -r requirements.txt
```
Once dependencies have been installed simply run `setup.py` as shown below.
```
C:\Sickle\src>python setup.py install
running install
C:\sickle-pdk\src>python setup.py install
```
The last step is to enable ANSI colors. To do this simply double click the enable-ansi.reg located in the documentation folder within the repository. Upon completion, if everything went well, you should be able to run sickle from anywhere.
```
C:\>sickle -h
usage: sickle [-h] [-r READ] [-f FORMAT] [-m MODULE] [-a ARCH] [-b BADCHARS] [-v VARNAME] [-i] [-l]
C:\sickle-pdk\src>sickle-pdk -h
usage: sickle-pdk [-h] [-r READ] [-p PAYLOAD] [-f FORMAT] [-m MODULE] [-a ARCH] [-b BADCHARS] [-v VARNAME] [-i]
[-l [LIST]]
Sickle - Payload development framework
Sickle - Payload Development Kit
options:
-h, --help Show this help message and exit
-r READ, --read READ Read bytes from binary file (use - for stdin)
-f FORMAT, --format FORMAT Output format (--list for more info)
-m MODULE, --module MODULE Development module
-a ARCH, --arch ARCH Select architecture for disassembly
-b BADCHARS, --badchars BADCHARS Bad characters to avoid in shellcode
-v VARNAME, --varname VARNAME Alternative variable name
-i, --info Print detailed info for module or payload
-l, --list List available formats, payloads, or modules
-h, --help Show this help message and exit
-r, --read READ Read bytes from binary file (use - for stdin)
-p, --payload PAYLOAD Shellcode to use
-f, --format FORMAT Output format (--list for more info)
-m, --module MODULE Development module
-a, --arch ARCH Select architecture for disassembly
-b, --badchars BADCHARS Bad characters to avoid in shellcode
-v, --varname VARNAME Alternative variable name
-i, --info Print detailed info for module or payload
-l, --list [LIST] List available formats, payloads, or modules
```
# Supported Distributions
Sickle is also currently supported by `Kali Linux` and `Black Arch Linux` and can be installed via `apt`.
Sickle is also currently supported by `Kali Linux` and `Black Arch Linux` and can be installed via `apt`.
+1 -1
View File
@@ -10,7 +10,7 @@ from sickle.common.handlers.module_handler import ModuleHandler
from sickle.common.handlers.shellcode_handler import ShellcodeHandler
class Handle():
"""This class should be looked at as the coordinator of the framework.
"""This class should be looked at as the coordinator of the kit.
Execution flow is generally directed from here.
param arg_parser: The arguments passed to sickle via the command line
+51 -51
View File
@@ -23,62 +23,62 @@ SLEEP_TIME = 2
MODULE_TESTS = \
{
"diff": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -m diff",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=hexdump",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=hexdump",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=byte",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=byte",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=raw",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=raw",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=asm",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=asm"],
"diff": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -m diff",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=hexdump",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=hexdump",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=byte",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=byte",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=raw",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=raw",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r generic_sc BINFILE=modified_sc MODE=asm",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m diff -r modified_sc BINFILE=generic_sc MODE=asm"],
"badchar": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -m badchar",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -m badchar -f c"],
"badchar": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -m badchar",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -m badchar -f c"],
"disassemble": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -m disassemble",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -m disassemble -r generic_sc"],
"disassemble": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -m disassemble",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -m disassemble -r generic_sc"],
"pinpoint": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -m pinpoint",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f cs",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f bash",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f java",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f nasm",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f perl",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f ruby",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f python",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f python3",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f powershell"]
"pinpoint": [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -m pinpoint",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f cs",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f bash",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f java",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f nasm",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f perl",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f ruby",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f python",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f python3",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x64 -r generic_sc -b \"\\x00\\x0a\\x0d\" -m pinpoint -f powershell"]
}
PAYLOAD_TESTS = \
{
"linux": [ f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p linux/x86/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p linux/x86/shell_reverse_tcp LHOST=127.0.0.1 LPORT=42 -f c",
"linux": [ f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p linux/x86/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p linux/x86/shell_reverse_tcp LHOST=127.0.0.1 LPORT=42 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p linux/x64/memfd_reflective_elf_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p linux/x64/memfd_reflective_elf_tcp LHOST=127.0.0.1 LPORT=42 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p linux/x64/memfd_reflective_elf_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p linux/x64/memfd_reflective_elf_tcp LHOST=127.0.0.1 LPORT=42 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p linux/aarch64/memfd_reflective_elf_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p linux/aarch64/memfd_reflective_elf_tcp LHOST=127.0.0.1 LPORT=42 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p linux/aarch64/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p linux/aarch64/shell_reverse_tcp LHOST=127.0.0.1 LPORT=1337 -f c", ],
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p linux/aarch64/memfd_reflective_elf_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p linux/aarch64/memfd_reflective_elf_tcp LHOST=127.0.0.1 LPORT=42 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p linux/aarch64/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p linux/aarch64/shell_reverse_tcp LHOST=127.0.0.1 LPORT=1337 -f c", ],
"windows": [ f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p windows/x64/kernel_token_stealer",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p windows/x64/kernel_token_stealer -f c",
"windows": [ f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p windows/x64/kernel_token_stealer",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p windows/x64/kernel_token_stealer -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p windows/x64/kernel_ace_edit",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p windows/x64/kernel_ace_edit PROCESS=AggregatorHost.exe -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p windows/x64/kernel_ace_edit",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p windows/x64/kernel_ace_edit PROCESS=AggregatorHost.exe -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p windows/x64/kernel_sysret",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p windows/x64/kernel_sysret -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p windows/x64/kernel_sysret",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p windows/x64/kernel_sysret -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p windows/x64/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p windows/x64/shell_reverse_tcp LHOST=192.168.81.144 LPORT=1337 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p windows/x64/shell_reverse_tcp",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p windows/x64/shell_reverse_tcp LHOST=192.168.81.144 LPORT=1337 -f c",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -i -p windows/x86/kernel_token_stealer",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -p windows/x86/kernel_token_stealer -f c", ]
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -i -p windows/x86/kernel_token_stealer",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -p windows/x86/kernel_token_stealer -f c", ]
}
def get_clean_module_list(path):
@@ -107,16 +107,16 @@ def execute_test(test):
def test_all_help_pages():
modules = get_clean_module_list(f"{SICKLE_PATH}/sickle/modules")
help_pages = [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -l",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -h",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py"]
help_pages = [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -l",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -h",
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py"]
for i in range(len(help_pages)):
execute_test(help_pages[i])
time.sleep(SLEEP_TIME)
for i in range(len(modules)):
test = f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -m {modules[i]} -i"
test = f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -m {modules[i]} -i"
execute_test(test)
time.sleep(SLEEP_TIME)
@@ -126,7 +126,7 @@ def test_all_formats():
formats = get_clean_module_list(f"{SICKLE_PATH}/sickle/formats")
for i in range(len(formats)):
test = f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -r generic_sc -f {formats[i]} -b \"\\x00\\x0a\\x0d\""
test = f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -r generic_sc -f {formats[i]} -b \"\\x00\\x0a\\x0d\""
execute_test(test)
return
@@ -146,10 +146,10 @@ def test_payloads():
return
def test_flag_errors():
test_cases = [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -r poop -f c", # Read from non-existing file
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -r generic_sc -f poop", # Use invalid format
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -a x80-6 -m disassemble -r generic_sc -f c", # Invalid arch
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle.py -m doeverything4me", # Invalid module
test_cases = [f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -r poop -f c", # Read from non-existing file
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -r generic_sc -f poop", # Use invalid format
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -a x80-6 -m disassemble -r generic_sc -f c", # Invalid arch
f"{PYTHON_NAME} -B {SICKLE_PATH}/sickle-pdk.py -m doeverything4me", # Invalid module
]
for i in range(len(test_cases)):