
Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.
English | 简体中文 | 조선어 | Русский
Zero WinAPI. Every NT primitive resolved at runtime from ntdll in memory —
SYSCALL instructions issued directly via Plan9 assembly stubs, no import table,
no ntdll usermode hooks touched. C2 over HTTPS / DNS / ICMP, AES-256-GCM per
message. Windows native. Linux builds. macOS builds.
This is not a syscall wrapper library. It's a full implant framework where
every operation — from injecting code to reading files to persisting in the
registry — goes through raw Nt* syscalls resolved at boot from the current
ntdll export table. No WinAPI calls exist in the binary. Nothing for an EDR
to hook at usermode.
B8 xx xx 00 00 0F 05 (direct) or
4C 8B D1 B8 xx xx 00 00 0F 05 (Hells Gate). Every function name is
hashed at compile time — no plaintext strings in the binary.asm_amd64.s) loads the SSN into EAX,
sets 7 args by hand, executes SYSCALL. Return via RAX/RDX.0F 05 C3 gadget (syscall;ret) inside
ntdll, calls through it. The CPU trap lands inside ntdll — call stack
shows ntdll frames, not implant frames. No usermode hook survives..text to RWX, copies original bytes from the disk-
mapped ntdll, restores protection, flushes icache, nukes SSN cache.
Every usermode hook placed by any EDR is gone.The agent rotates through injection techniques automatically. Each call uses a different method — no two injections look the same in forensics.
| Method | How it works | Why it's stealthy |
|---|---|---|
| Section mapping | NtCreateSection → NtMapViewOfSection (remote) → NtCreateThreadEx | No RWX allocation in VAD. Section is file-backed. Memory scanners see PAGE_EXECUTE_READ, not PAGE_EXECUTE_READWRITE. |
| Process hollow | NtCreateUserProcess (suspended) → NtSuspendProcess → zero image base → alloc + write shellcode → NtSetContextThread (RIP = shellcode) → NtResumeProcess | Process appears as legitimate svchost.exe in taskmgr. Only memory contents differ. |
| APC queuing | Enumerate threads via NtQuerySystemInformation → NtOpenThread → NtQueueApcThread | No new thread created. No new TEB. No new stack allocation. Fires when thread enters alertable wait. |
| Module stomping | Alloc in target → write minimal PE header + shellcode → NtCreateThreadEx at entry point | Module list shows a plausible DLL name. PE header is valid enough to fool module enumeration. |
Runs all checks, returns a scored threat report. Auto-destruct on Critical.
| Check | Method |
|---|---|
| VM detection | CPUID leaf 0x40000000 hypervisor signature scan (VMware, VirtualBox, Hyper-V, KVM, Xen, QEMU, Parallels) + leaf 0x40000001 fallback |
| Sandbox detection | CPU count, registry artifacts (VMware Tools, VBox Guest Additions, VMware/VBox services), sandbox process scan (30+ known names: wireshark, procmon, x64dbg, ida, etc.) |
| Debugger detection | PEB.BeingDebugged, PEB.NtGlobalFlag, heap debug flags, ProcessDebugPort, ProcessDebugObjectHandle, ProcessDebugFlags, hardware breakpoint DR0-7, timing single-step check |
| Timing anomaly | RDTSC-based: 50 samples of NtQuerySystemInformation latency, mean/stddev, flag if >10% of samples exceed 3σ variance. Catches instrumentation overhead. |
| PEB evasion | Patches BeingDebugged, NtGlobalFlag, ProcessHeap flags, DebugPort, ThreadHideFromDebugger — all via GS segment reads + NtWriteVirtualMemory. No API calls. |
All via Nt* syscalls, no WinAPI.
EnablePrivilege(index) — set any privilege by LUIDEnableAllTokenPrivileges() — 20 privileges at once (Debug, Impersonate, TCB, Backup, Restore, etc.)GetProcessTokenIntegrityLevel() — query mandatory integrityStealProcessToken(pid) — open + duplicate another process tokenImpersonateThread() / RevertToSelf()EnumVirtualMemory() — walk all virtual regions via NtQueryVirtualMemoryFindWritableExecRegions() — find PAGE_EXECUTE_READWRITE committed regionsHideRegion() — set PAGE_NOACCESS to hide memory from scannersUnhideRegion() — restore original protectionNtCreateFile → NtReadFile / NtWriteFile → NtClose. Zero CreateFileA,
ReadFile, WriteFile, or DeleteFileW calls. ReadFileContents(),
WriteFileContents(), DeleteFileNt(), FileExists().
NtCreateKey → NtSetValueKey. AddRunKeyPersistence(), RemoveRunKeyPersistence().
No RegCreateKeyEx, RegSetValueEx, or any Advapi32 calls.
EnumerateSystemHandles() — all open handles in the system via
NtQuerySystemInformation(SystemHandleInformation)FindEDRHandles() — matches owner PIDs against 30+ known EDR process
names (MsSense, CrowdStrike, Sentinel, Cylance, Carbon Black, etc.)CloseEDRHandles() — closes monitoring handles the EDR placed in your
processIsProcessMonitored() — boolean check: are we being watched?NtFreeVirtualMemory.PatchAMSI() — AmsiScanBuffer → MOV EAX, 0; RETPatchETW() — EtwEventWrite → RETPatchNtTraceEvent() — NtTraceEvent → RETPatchDbgUiRemoteBreakin() — thread breakin → RETPatchInstrumentationCallbacks() — ThreadHideFromDebugger| Channel | Wire format | Prereqs |
|---|---|---|
| HTTPS | binary POST, custom framing, randomized UA/path | TLS cert |
| DNS | <idx>-<total>-<base32> subdomain, TXT response | DNS resolution |
| ICMPv4 | payload in echo request/reply ID+seq | raw socket (root/Admin) |
All channels implement the Channel interface. Adding NTP, DoH, or TURN
means implementing the interface — zero agent changes.
AES-256-GCM per-message AEAD. Unique 12-byte nonce per message. Per-implant keyring. Passphrase-based key derivation available. 3 tests, all passing.