Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SynthAPT — Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating advanced detections and AI-based investigation agents. | Kitploit
Tools/GitHubGitHub/acedef/synthapt
Penetration Testing FrameworksPrivilege EscalationExploit FrameworksPayload GenerationLateral MovementShellcodePost-ExploitationCommand and ControlRed TeamingAI SecurityAdversarial Attack
23147155 months agoReviewed by Kitploit
GitHub
acedef/synthapt

SynthAPT

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating advanced detections and AI-based investigation agents.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SynthAPT

Overview

SynthAPT is a playbook-based adversary simulation framework for replicating complex attack paths. It is designed for validating advanced detections and AI-based investigation agents. The core idea is that malware behavior can be expressed in JSON and compiled into functional malware, enabling rapid development of realistic scenarios using LLMs.

The core implant is a shellcode payload driven by a playbook interpreter. A playbook predefines the full attack path and the implant follows it, moving throughout the environment via process injection, lateral movement, etc. Each implant spawns as an independent thread with its own instruction set, so multi-stage attacks (e.g. initial access → privesc → lateral movement → exfiltration) are expressed as a graph of cooperating implants, all defined upfront in the playbook. This has three major advantages:

  1. Payloads can mimic real malware without C2 infrastructure - the full attack path is embedded in the payload and C2 interactions can be mocked
  2. Payloads are repeatable - they execute the entire attack path identically every time, making them suitable for regression testing detections
  3. LLMs can translate threat intelligence reports and blogs directly into working payloads, without requiring offensive expertise or building malware from scratch

Features

  • Position-independent shellcode - the implant is fully PIC and can be rolled into any loader or injector
  • Rich opcode library - execution, token manipulation, process injection, process hollowing, lateral movement, AD enumeration and modification, registry, services, and more
  • Self-replicating payloads - the implant can drop itself as an EXE or DLL with a different task set, enabling multi-stage delivery without a C2
  • Flexible output formats - compile a playbook to raw shellcode, a PE EXE, or a PE DLL
  • In-memory Python - a Python interpreter may be reflectively loaded at runtime, exposing all implant capabilities as a Python module for flexible scripting
  • NPC simulation - 'explorer' opcodes allow unzipping and launching payloads automatically in a way that automatically reproduces user-interaction artifacts (when injected into Explorer.exe)
  • TUI editor with LLM agent - a terminal-based playbook editor with an integrated Claude agent that can generate and edit playbooks from natural language or threat intelligence
  • BOF Loader - functionality may be extended with standard Beacon Object Files

Building from Source

If you don't want to use the release you can compile it like so:

  1. cargo
  2. rustup
  3. binutils-mingw-w64-x86-64
cargo install cargo-make
rustup toolchain install nightly
rustup target add x86_64-pc-windows-gnu --toolchain nightly                                                                                                                                                         
sudo apt install gcc-mingw-w64-x86-64

Build with cargo make:

cargo make build
./target/release/synthapt

This will compile the shellcode and the editor.

Use

Running SynthAPT without any commands will drop you into the editor. You can provide a Claude API key and view the changes as you prompt.

SynthAPT playbook editor and compiler

Usage: synthapt [COMMAND]

Commands:
  edit          Open the TUI editor with a playbook loaded from PATH
  validate      Validate a playbook JSON file and print any errors
  export-skill  Export the agent system prompt as a Claude Code slash command skill
  compile       Compile a playbook to a payload

If you want to use another LLM or a subscription, you can run synthapt export-skill and use that with whatever coding setup you have.

It should spit out a JSON playbook. Compile it into a payload with the compile command:

Compile a playbook to a payload

Usage: synthapt compile [OPTIONS] <PLAYBOOK> [OUTPUT]

Arguments:
  <PLAYBOOK>  Path to the playbook JSON file
  [OUTPUT]    Output file path (default: payload.bin / payload.exe / payload.dll)

Options:
  -e, --exe          Compile to PE EXE
  -d, --dll          Compile to PE DLL
  -b, --base <BASE>  Override the embedded base shellcode with a custom binary
  -h, --help         Print help

Opcodes Reference

Constants can be defined as strings, hex objects, or base64 objects:

"constants": [
  "c:\\windows\\temp\\file.txt",
  { "hex": "deadbeef" },
  { "base64": "SGVsbG8=" }
]

end (0x00)

End of task set. Automatically appended by the compiler - you do not need to add it.


store_result (0x01)

Store the last operation result into a variable.

FieldType
varu16required
{ "op": "store_result", "var": 0 }

get_shellcode (0x02)

Return the current shellcode bytes with an optional task ID and/or magic value patched in.

FieldType
tasku8optional
magicu32 hex string or numberoptional
{ "op": "get_shellcode" }
{ "op": "get_shellcode", "task": 5, "magic": "0x18181818" }

sleep (0x03)

Sleep for the given number of milliseconds.

FieldType
msu32required
{ "op": "sleep", "ms": 5000 }

run_command (0x04)

Execute a command via cmd.exe.

FieldType
commandstringrequired
{ "op": "run_command", "command": "whoami /all" }

get_cwd (0x05)

Get the current working directory. No arguments.

{ "op": "get_cwd" }

read_file (0x06)

Read a file and return its contents.

FieldType
pathstringrequired
{ "op": "read_file", "path": "c:\\users\\public\\data.txt" }
{ "op": "read_file", "path": "%0" }

write_file (0x07)

Write bytes to a file.

FieldType
pathstringrequired
contentbytesoptional (empty file if omitted)
{ "op": "write_file", "path": "c:\\temp\\out.txt", "content": "hello" }
{ "op": "write_file", "path": "%0", "content": "$1" }

check_error (0x08)

Print the status code of a variable (0 = success, non-zero = error).

FieldType
varu16required
{ "op": "check_error", "var": 0 }

conditional (0x09)

Branch to different task indices based on variable state.

FieldType
mode"data" or "error"required
var1u16required
var2u16optional (compare two vars instead of single check)
trueu16required (task index if condition is true)
falseu16required (task index if condition is false)

true_target and false_target are accepted as aliases for true and false.

Single-variable modes:

  • "data" — true if var1 has non-empty data
  • "error" — true if var1 status is 0 (success)

Two-variable modes (var2 present):

  • "data" — true if var1 data equals var2 data
  • "error" — true if var1 error code equals var2 error code
{ "op": "conditional", "mode": "error", "var1": 0, "true": 3, "false": 5 }
{ "op": "conditional", "mode": "data", "var1": 0, "var2": 1, "true": 3, "false": 5 }

set_var (0x0A)

Set a variable to a literal value.

FieldType
varu16required
databytesoptional (empty if omitted)

Literal string and hex/base64 values are stored with a 5-byte result prefix so they look like normal operation results when read back. Variable ($n) and constant (%n) references are passed through as-is.

Download Tool