
PE to shellcode

🛠️ A powerful tool for converting PE files (EXE/DLL) into position-independent shellcode.
pip install pefile lznt1
python clematis.py -f <PE_file> -o <output_file> [-g <true/false>] [-c <true/false>] [-p <parameters>]
# Show help information
python clematis.py -h
# Basic usage
python clematis.py -f target.exe -o output.bin
# Disable obfuscation and compression
python clematis.py -f target.exe -o output.bin -g false -c false
# Pass arguments to target program
python clematis.py -f target.exe -o output.bin -p arg1 arg2
python clematis.py -f target.exe -o output.bin -p "arg1 arg2"
- 🛡️ Unable to perform process injection (AV/EDR/XDR blocking)
- 🔄 Executing golang programs in current process may cause blocking
- 💾 Memory leaks may occur after golang program execution
- ⚠️ Threads created by golang cannot be released!
- ✨ Convert golang programs to shellcode
- 🎯 Direct execution in current process
- ♻️ Automatic memory release after execution
- 🚀 Completely avoid golang-related memory issues
- 🔄 Reclaim all threads created by golang
2024-12-27
2024-12-28
Fixed potential DOT NET program crashes (May not occur)
Added handling for IMAGE_DIRECTORY_ENTRY_EXCEPTION ( x64 )
Updated APIs to use NTAPI

Clematis converts PE files to shellcode through the following steps:
flowchart TD
A[START] --> B[Read PE file]
B --> C[Parse PE structure]
C --> D{Is there a command line argument?}
D -- TRUE --> E[Process command line arguments]
D -- FALSE --> F{Enable compression?}
E --> F
F -- TRUE --> G[LZNT1 compression]
F -- FALSE --> H{Enable obfuscation?}
G --> H
H -- TRUE --> I[Execute obfuscation processing]
H -- FALSE --> J[Generate shellcode]
I --> J
J --> K[Output result]
K --> L[END]
Issues and Pull Requests are welcome!
| desc | default | required |
|---|
| -f | --file | Path to the PE file to convert | true | |
| -o | --output | Output filename | true | |
| -g | --garble | Enable obfuscation | true | false |
| -c | --compress | Enable compression | true | false |
| -p | --parameter | Execution parameters to pass to the PE file | false |
| before | now |
|---|
VirtualAlloc | NtAllocateVirtualMemory |
VirtualProtect | NtProtectVirtualMemory |
VirtualFree | NtFreeVirtualMemory |
LoadLibrary | LdrLoadDll |
GetProcAddress | LdrGetProcedureAddress |
WaitForMultipleObjects | NtWaitForMultipleObjects |
CreateEvent | NtCreateEvent |
CloseHandle | NtClose |
SignalObjectAndWait | NtSignalAndWaitForSingleObject |
TerminateThread | NtTerminateThread |
SuspendThread | NtSuspendThread |
OpenThread | NtOpenThread |
ResumeThread | NtResumeThread |
GetContextThread | NtGetContextThread |
SetContextThread | NtSetContextThread |
| ... |
2025-1-1