mirror of
https://github.com/youssefnoob003/SindriKit
synced 2026-07-07 21:57:09 +00:00
da52e28ca5
- Implemented native Call Stack Spoofing with a coordinated JMP-Trampoline - Added dynamic .pdata Exception Directory parsing to discover Fat Frames (>= 120 bytes) - Added x86 & x64 spoofed MASM stubs with synchronized EDR unwinder offset logic
Core Architecture
Design patterns, execution models, and telemetry constraints governing SindriKit.
Caution
No direct OS calls in domain logic. Host interaction goes through injected API tables or explicitly bootstrapped execution layers (syscall pipeline, FFI bridges).
Framework layers
┌─────────────────────────────────────────────────────────────┐
│ Application / implant / PoC │
└───────────────────────────┬─────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ Domains: loaders · injection · (future) evasion │
└───────────────────────────┬─────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ Primitives + execution (DI tables, syscalls, FFI) │
└───────────────────────────┬─────────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ Parsers · Common │
└─────────────────────────────────────────────────────────────┘
Table of Contents
- dependency_injection.md —
os_api.hcontracts and backend matrix - state_machines.md — loader and injection stage graphs
- status_system.md —
snd_status_t, DEBUG vs SILENT tiers - redteam_integration.md — CMake embed, hash rotation, BYOM