mirror of
https://github.com/youssefnoob003/SindriKit
synced 2026-07-07 21:57:09 +00:00
aea2eb6cfb
- Implement complete cross-process injection engine via snd_inj_ctx_t - Track explicit remote_entry_point for safe thread hijacking and PE execution - Refactor standalone syscall resolvers into a unified pipeline (scan/sort) - Perfect status code system by purging generic fallbacks in favor of highly-specific, domain-aware error codes - Fix minor pointer validation and parsing bugs in the reflective loader
3.3 KiB
3.3 KiB
Changelog
All notable technique additions, strategy improvements, and core architecture updates to SindriKit will be documented in this file.
The format is based on Keep a Changelog, and this project attempts to adhere to Semantic Versioning.
[1.1.0] - 2026-06-26
Second major release. The framework grows from a reflective-loader-centric engine into a multi-domain toolkit with expanded primitives, reorganized headers, and comprehensive documentation.
Major Additions
- Injection Domain: Introduced classic remote injection (
snd_inj_classic_pe,snd_inj_classic_shell) driven by a sharedsnd_inj_ctx_tstate machine. - Expanded Primitives: Added Process and Mapping APIs (
snd_proc_*,snd_map_*) and Object Manager support for\KnownDlls\bootstrapping. - Syscall Pipeline: Introduced pluggable syscall strategies (
snd_syscall_resolve_ssn_scan,snd_syscall_resolve_ssn_sort). - New PoCs: Added
inject_shellandinject_peto demonstrate stealth remote injection profiles.
Architecture & Refactoring
- Parsers Restructuring: Split parsing into
pe/andenv/(PEB walking) subdomains with a unified export resolver. - Syscall Subsystem: Encapsulated NTDLL state; bootstrap now requires explicit
snd_syscall_set_ntdllbefore direct syscall backends operate. - Common Infrastructure: Split monolithic
helpers.handnt_defs.hinto granular headers (memory.h,string.h,debug.h,nt/types.h, etc.) and added robust bounds checking. - Loader Enhancements: Updated reflective loader to use
snd_ldr_pe_ctx_twith explicit state tracking (snd_pe_target_t) and introduced new runtime FFI macros (SND_CALL_EXPORT).
Removals & Deprecations
- Removed legacy named gate resolvers (Hell's Gate, Halo's Gate, Tartarus, VelesReek) in favor of generic SSN strategies.
- Removed monolithic flat headers (
helpers.h,nt_defs.h) and legacy parsing code. - Removed implicit backend symbols (
snd_mem_native,snd_mod_native) to enforce explicit_ntand_sysprofiles.
[1.0.1] - 2026-06-22
Fixed
- Loaders: Fixed an access violation in
native_load_librarycaused by resolvingLdrLoadDllfrom an unmapped/disk NTDLL image. The loader now strictly resolves via the active PEB to maintain loader lock integrity.
[1.0.0] - 2026-06-22
SindriKit is a Windows evasion toolkit written in C. This first release provides the core engine, focusing on a Dependency Injection architecture that separates offensive techniques from underlying OS execution mechanics.
Major Additions
- Syscall Resolution: Dynamic SSN resolution with a cascading fallback pipeline supporting Hell's Gate, Halo's Gate, Tartarus' Gate, and VelesReek.
- Kernel-State Bootstrapping: Maps unhooked system modules directly from the
\KnownDllsObject Manager directory. - Reflective Loader: A fully functional 8-stage in-memory PE loader built on the framework, capable of executing entirely via direct syscalls.
- Algorithm Agility: Compile-time API hashing (DJB2 or FNV1A) via CMake.
- PE Parser: Custom, bounds-checked PE32/PE32+ parser with explicit state tracking (
is_mapped). - Dynamic FFI: Custom MASM assembly bridges for executing arbitrary functions safely.