mirror of
https://github.com/youssefnoob003/SindriKit
synced 2026-07-07 21:57:09 +00:00
aea2eb6cfb
- Implement complete cross-process injection engine via snd_inj_ctx_t - Track explicit remote_entry_point for safe thread hijacking and PE execution - Refactor standalone syscall resolvers into a unified pipeline (scan/sort) - Perfect status code system by purging generic fallbacks in favor of highly-specific, domain-aware error codes - Fix minor pointer validation and parsing bugs in the reflective loader
2.5 KiB
2.5 KiB
PoC: loader_noCRT_nowinapi
Location: pocs/loader_noCRT_nowinapi/
Minimal reflective loader with the Microsoft CRT stripped (/NODEFAULTLIB). Demonstrates SindriKit's CRT manifest fallbacks and the smallest viable integration surface for implant-style binaries.
What it demonstrates
- Release build with
/NODEFAULTLIBand/ENTRY:main - PEB hash walk for
ntdll(snd_peb_get_module_base_hash) — no disk read - Syscall scan strategy (single resolver, no sort fallback)
- Mixed profile:
snd_mem_win+snd_mod_nt - Hardcoded payload path (edit source before building)
Walkthrough
No CLI — edit file_path in main.c before building.
1. Bootstrap ntdll from PEB
PVOID ntdll = NULL;
status = snd_peb_get_module_base_hash(SND_HASH_NTDLL_DLL, &ntdll);
snd_syscall_set_ntdll(ntdll);
snd_syscall_strategy_set(snd_syscall_resolve_ssn_scan);
2. Configure loader context
const char *file_path = "payload.exe";
snd_ldr_pe_ctx_t ctx = {0};
ctx.mem_api = &snd_mem_win;
ctx.mod_api = &snd_mod_nt;
3. Load, prepare, execute
status = snd_disk_buffer_load(file_path, &file_buf);
ctx.raw_source = &file_buf;
status = snd_ldr_pe_prepare_image(&ctx);
status = snd_ldr_pe_execute_image(&ctx);
No DLL export FFI (-e/-a).
4. Cleanup
snd_ldr_pe_detach_image(&ctx); // no-op unless stage == EXECUTED
snd_ldr_pe_free_mapped_image(&ctx);
snd_buffer_free(&file_buf);
Building
CRT-less mode replaces the full PoC set with this target. Debug must be off:
cmake -B build -DSND_CRTLESS=ON -DSND_ENABLE_DEBUG=OFF -DSND_BUILD_PAYLOADS=ON
cmake --build build --config Release
When SND_CRTLESS=ON, the engine compiles src/common/crt_manifest.c for intrinsic memcpy/memset fallbacks. PoC CMake adds:
target_link_options(loader_noCRT_nowinapi PRIVATE /NODEFAULTLIB /ENTRY:main)
Warning
SND_BUILD_TESTS=ONforcesSND_CRTLESS=OFF. Use a clean build directory when switching modes.
Output: build/pocs/loader_noCRT_nowinapi/Release/loader_noCRT_nowinapi.exe
OpSec impact
- No implicit CRT telemetry or default library imports
- PEB-only
ntdllresolution (no KnownDlls, no disk read) - Memory still uses Win32
VirtualAllocviasnd_mem_win— swap tosnd_mem_sysfor full stealth
See also
- Building: CRT-less tier
- Common infrastructure
- loader_nowinapi.md — full CLI loader with NT backends