sibouzitoun
1f87b142ba
Release v1.3.1: OpSec Patch (Dynamic Fat Frame Entropy)
...
- Implemented entropy-based pseudo-randomizer in snd_syscall_find_spoof_scan to prevent deterministic telemetry.
- Randomized Fat Frame selection using the SSN hash, a static counter, and ASLR-dependent module/stack addresses.
- Hardened spoof scanner to reject frames using Frame Registers (UWOP_SET_FPREG) to prevent RtlVirtualUnwind crashes.
- Added strict bounds checking to cap Fat Frame sizes at 240 bytes, preventing MASM local stack corruption.Release v1.3.0: Stack Spoofing & Dynamic Fat Frame.
v1.3.1
2026-07-07 11:27:13 +01:00
sibouzitoun
da52e28ca5
Release v1.3.0: Stack Spoofing & Dynamic Fat Frames
...
- Implemented native Call Stack Spoofing with a coordinated JMP-Trampoline
- Added dynamic .pdata Exception Directory parsing to discover Fat Frames (>= 120 bytes)
- Added x86 & x64 spoofed MASM stubs with synchronized EDR unwinder offset logic
v1.3.0
2026-07-06 16:59:33 +01:00
sibouzitoun
b7d3cf717c
Release v1.2.0: Indirect Syscalls & Pipeline Decoupling
...
- Implemented fully decoupled direct and indirect syscall invocation
- Added dynamic PEB-based gadget scanning (syscall; ret / sysenter)
- Added x86 & x64 inline MASM stubs with proper stack frame alignment
- Introduced SND_USE_DEFAULTS compile-time OpSec macro for lean payload compilation
- Extensive documentation across all primitives and examples
v1.2.0
2026-06-29 19:31:15 +01:00
sibouzitoun
f7d17fde33
Fix: loader nowinapi poc wasn't parsing the ntdll before setting it for syscall resolution.
2026-06-29 16:42:33 +01:00
sibouzitoun
aea2eb6cfb
Release v1.1.0: Process Injection & Architecture Hardening
...
- Implement complete cross-process injection engine via snd_inj_ctx_t
- Track explicit remote_entry_point for safe thread hijacking and PE execution
- Refactor standalone syscall resolvers into a unified pipeline (scan/sort)
- Perfect status code system by purging generic fallbacks in favor of highly-specific, domain-aware error codes
- Fix minor pointer validation and parsing bugs in the reflective loader
v1.1.0
2026-06-28 14:14:54 +01:00
charfeddine youssef
afffc17dfe
docs: rewrite README intro for clarity and fix minor issues with phrasing
2026-06-23 11:05:38 +01:00
sibouzitoun
fc65395be6
Refactor: Encapsulate NTDLL state within syscall subsystem
2026-06-22 20:51:58 +01:00
sibouzitoun
04be820979
Fix: Stop trying to execute LdrLoadDll from unmapped NTDLLs
...
Decouples native_load_library from the global NTDLL state. Calling LdrLoadDll on a raw disk image obviously segfaults because the loader locks aren't initialized. Always walking the PEB for this fixes it.
v1.0.1
2026-06-22 20:17:44 +01:00
sibouzitoun
5e26626615
You're Gonna Carry That Weight
v1.0.0
2026-06-22 12:38:04 +01:00