Commit Graph

  • 1f87b142ba Release v1.3.1: OpSec Patch (Dynamic Fat Frame Entropy) - Implemented entropy-based pseudo-randomizer in snd_syscall_find_spoof_scan to prevent deterministic telemetry. - Randomized Fat Frame selection using the SSN hash, a static counter, and ASLR-dependent module/stack addresses. - Hardened spoof scanner to reject frames using Frame Registers (UWOP_SET_FPREG) to prevent RtlVirtualUnwind crashes. - Added strict bounds checking to cap Fat Frame sizes at 240 bytes, preventing MASM local stack corruption.Release v1.3.0: Stack Spoofing & Dynamic Fat Frame. main v1.3.1 sibouzitoun 2026-07-07 11:27:13 +01:00
  • da52e28ca5 Release v1.3.0: Stack Spoofing & Dynamic Fat Frames - Implemented native Call Stack Spoofing with a coordinated JMP-Trampoline - Added dynamic .pdata Exception Directory parsing to discover Fat Frames (>= 120 bytes) - Added x86 & x64 spoofed MASM stubs with synchronized EDR unwinder offset logic v1.3.0 sibouzitoun 2026-07-06 16:59:33 +01:00
  • b7d3cf717c Release v1.2.0: Indirect Syscalls & Pipeline Decoupling v1.2.0 sibouzitoun 2026-06-29 19:31:15 +01:00
  • f7d17fde33 Fix: loader nowinapi poc wasn't parsing the ntdll before setting it for syscall resolution. sibouzitoun 2026-06-29 16:42:33 +01:00
  • aea2eb6cfb Release v1.1.0: Process Injection & Architecture Hardening v1.1.0 sibouzitoun 2026-06-28 14:14:54 +01:00
  • afffc17dfe docs: rewrite README intro for clarity and fix minor issues with phrasing charfeddine youssef 2026-06-23 11:05:38 +01:00
  • fc65395be6 Refactor: Encapsulate NTDLL state within syscall subsystem sibouzitoun 2026-06-22 20:51:58 +01:00
  • 04be820979 Fix: Stop trying to execute LdrLoadDll from unmapped NTDLLs v1.0.1 sibouzitoun 2026-06-22 20:17:44 +01:00
  • 5e26626615 You're Gonna Carry That Weight v1.0.0 sibouzitoun 2026-06-22 12:38:04 +01:00