
Sickle - Payload-Entwicklungskit

Sickle ist ein Werkzeug, das ich ursprünglich entwickelt habe, um sowohl bei der Entwicklung als auch beim Verständnis von Shellcode effektiver zu sein. Im Laufe der Entwicklung und Nutzung hat es sich jedoch zu einem Payload-Entwicklungskit entwickelt. Auch wenn sich die aktuellen Module hauptsächlich an Assembler richten, ist dieses Werkzeug nicht auf Shellcode beschränkt.
Derzeit kann Sickle bei Folgendem helfen:
Sickle unterstützt die Shellcode-Generierung über die Keystone Engine. Da es sich um eine neu hinzugefügte Funktion handelt, ist die Payload-Unterstützung begrenzt. Ziel ist es jedoch, für jede Architektur und Plattform eine einfache Reverse Shell hinzuzufügen.

Sickle enthält ein „Diffing“-Modul, das ursprünglich für die Analyse von Shellcode-Stubs entwickelt wurde. Der ursprüngliche „asm“-Modus führt lineare Disassemblierungs-Diffs sowohl auf Assembler-Ebene als auch auf Opcode-Ebene getrennt durch.

Darüber hinaus bietet Sickle verschiedene Modi für Diff-Vergleiche, wodurch es über die Shellcode-Entwicklung hinaus nützlich ist.

Eine häufige Aufgabe ist das Testen des eigenen Shellcodes. Dieser Prozess umfasst typischerweise die folgenden Schritte:
Auch wenn diese Schritte unbedeutend erscheinen mögen, können sie bei wiederholter Ausführung viel Zeit in Anspruch nehmen. Sickle vereinfacht den Prozess, indem es Shellcode automatisch für schnelle Tests kapselt; das „run“-Modul unterstützt derzeit sowohl Windows- als auch Unix-Systeme.

Sickle kann außerdem eine Binärdatei in extrahierte Opcodes (Shellcode) umwandeln und diese anschließend in Maschinenbefehle (Assembler) übersetzen. Beachten Sie, dass dieser Prozess nur mit rohen Binärdateien funktioniert und die Disassemblierung derzeit linear über Capstone erfolgt.

Im obigen Beispiel disassembliert das Modul „disassemble“ eine von Stephen Fewer entworfene Reverse Shell zu Assembler.
Die Shellcode-Extraktion war das erste Modul beziehungsweise die Kernfunktion von Sickle, da Opcodes je nach verwendetem Wrapper unterschiedlich interpretiert werden. JavaScript zum Beispiel speichert und interpretiert Shellcode nicht auf dieselbe Weise wie ein C-Programm.

Die wohl größte Inspiration hierfür war msfvenom.
Obwohl dies bei 64-Bit-Exploits weniger üblich ist, gibt es Fälle, in denen ein Exploit die Verwendung bestimmter Zeichen einschränkt. Hier glänzt das Modul „pinpoint“, da es direkt die Assembler-Anweisungen identifiziert und hervorhebt, die für die erkannten Bad Characters verantwortlich sind.

Ursprünglich war dieses Werkzeug ein einziges großes Skript. Im Laufe der Weiterentwicklung musste ich den Code jedoch bei jedem Update neu erlernen. Um dem entgegenzuwirken, folgt Sickle nun einem modularen Ansatz, der es erlaubt, neue Funktionen hinzuzufügen, ohne viel Zeit damit zu verbringen, das Design des Werkzeugs neu zu erlernen.
$ sickle-pdk -l
Shellcode Ring Description
--------- ---- -----------
windows/x64/virtualalloc_exec_tcp 3 A lightweight stager that connects to a handler via TCP over IPv4 to receive and execute shellcode
windows/x64/egghunter 3 Egghunter based on Hell's Gate and NtProtectVirtualMemory
windows/x64/virtualalloc_exec_https 3 A lightweight stager that connects to a handler over HTTPS to receive and execute shellcode
windows/x64/exec 3 Executes a command on the target host
windows/x64/reflective_pe_loader 3 Stageless Reflective PE Loader that takes an x64 binary and executes it in memory
windows/x64/shell_reverse_tcp 3 Reverse Shell via TCP over IPv4 that provides an interactive cmd.exe session
windows/aarch64/shell_reverse_tcp 3 Reverse Shell via TCP over IPv4 that provides an interactive cmd.exe session
windows/x86/shell_reverse_tcp 3 Reverse shell via TCP over IPv4 that provides an interactive cmd.exe session
windows/x64/kernel_token_stealer 0 Token stealing shellcode for privilege escalation
windows/x64/kernel_sysret 0 Generic method of returning from kernel space to user space
windows/x64/kernel_ace_edit 0 SID entry modifier for process injection
windows/x86/kernel_token_stealer 0 Token stealing shellcode for privilege escalation
linux/x64/memfd_reflective_elf_tcp 3 Staged Reflective ELF Loader via TCP over IPV4 which executes an ELF from a remote server
linux/aarch64/memfd_reflective_elf_tcp 3 Staged Reflective ELF Loader via TCP over IPv4 which executes an ELF from a remote server handler
linux/aarch64/shell_reverse_tcp 3 Reverse Shell via TCP over IPv4 that provides an interactive /bin/sh session
linux/x86/execve 3 Executes a shell session such as /bin/sh
linux/x86/shell_reverse_tcp 3 Reverse shell via TCP over IPV4 that provides an interactive /bin/sh session
Architectures
-------------
aarch64
x64
x86
Modules Description
------- -----------
disassemble Simple linear disassembler for multiple architectures
handler Module for handling payload distribution and session management
asm_shell Interactive assembler and disassembler
diff Bytecode diffing module for comparing two binaries (or shellcode)
pinpoint Highlights opcodes within a disassembly to identify instructions responsible for bad characters
run Wrapper used for executing bytecode (shellcode)
format Converts bytecode into a respective format (activated anytime '-f' is used)
badchar Produces a set of all potential invalid characters for validation purposes
Format Description
------ -----------
perl Format bytecode for Perl
python Format bytecode for Python
hex_space Format bytecode in hex, seperated by a space
nasm Format bytecode for NASM
java Format bytecode for Java
javascript Format bytecode for Javascript (Blob to send via XHR)
escaped Format bytecode for one-liner hex escape paste
rust Format bytecode for a Rust application
uint8array Format bytecode for Javascript as a Uint8Array directly
bash Format bytecode for bash script (UNIX)
powershell Format bytecode for Powershell
cs Format bytecode for C#
dword Format bytecode in dword
c Format bytecode for a C application
raw Format bytecode to be written to stdout in raw form
ruby Format bytecode for Ruby
num Format bytecode in num format
hex Format bytecode in hex
python3 Format bytecode for Python3
Dieser Ansatz ermöglicht es jedem Modul, eine ausführliche Dokumentation seiner Funktionalität zu erstellen.
$ sickle-pdk -m run -i
Usage information for run
Name: Shellcode Runner
Module: run
Architecture: Multi
Platform: Multi
Ring: 3
Author(s):
wetw0rk
Tested against:
Linux
Windows
Module Description:
Executes bytecode from a binary file (-r) or a payload module (-p) under the context
of the currently running operating system and architecture. Meaning if you are
running on AARCH64 bytecode will be interpreted as such and if you're on x64 it will
interpret it as x64 respectively.
Example:
/usr/local/bin/sickle-pdk -m run -r shellcode
Dieser Ansatz umfasst auch die Dokumentation für Shellcode-Stubs.
$ sickle-pdk -p windows/x64/egghunter -i
Usage information for windows/x64/egghunter
Name: Windows (x64) Hell's Gate based Egghunter
Module: windows/x64/egghunter
Architecture: x64
Platform: windows
Ring: 3
Author(s):
hvictor
Tested against:
Windows 11 (10.0.26100 N/A Build 26100)
Argument Information:
Name Description Optional
---- ----------- --------
TAG Egg (provide 4 bytes) yes
Module Description:
This egghunter iterates virtual memory addresses and before searching for the egg, it
performs a NtProtectVirtualMemory system call. This system call is similar to
VirtualProtect, and is parameterized to set the memory to be scanned to READ, WRITE,
EXECUTE. This way, when the egg is found, the shellcode after it is guaranteed to be
executable.
Example:
/usr/local/bin/sickle-pdk -p windows/x64/egghunter TAG=w00t