Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
lockjaw — Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF execution, and HTTP/DNS transports. | Kitploit
Tools/GitHubGitHub/g13net/lockjaw
Penetration Testing FrameworksExploit FrameworksPersistence MechanismsIDS/IPS EvasionLateral MovementPost-ExploitationCommand and ControlRed TeamingShellcode GenerationPayload DevelopmentRemote Access Trojan
263164 days agoNot yet reviewed
DNS Analysis
GitHubg13net/lockjaw

lockjaw

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF execution, and HTTP/DNS transports.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Lockjaw - Advanced Windows C2 Framework (v0.2.15)

Lockjaw is an advanced, modular command-and-control (C2) framework engineered for red team engagements, adversarial simulations, and stealth operations. It utilizes a modern split-language architecture: a high-concurrency Rust Teamserver coupled with an evasive, dependency-free Zig implant and pure-assembly position-independent code (PIC) stagers.

THIS IS ALPHA SOFTWARE Use at your own risk. Not all features have been tested, the code has not been reviewed. There are bugs and certain commands may not work.

The following have been tested:

  • Teamserver and client communications
  • EXE implant
  • Agent commands for recon
  • Process injection

BOF support has not been tested.


Architecture Overview

                      +------------------------------------+
                      |       Operator CLI (Python)        |
                      |   Async TUI / Prompt-Toolkit       |
                      +-----------------+------------------+
                                        | HTTPS / REST API (Port 50051)
                                        v
                      +------------------------------------+
                      |       Lockjaw Teamserver           |
                      |          (Rust / Tokio)            |
                      |  - SQLite Storage (SQLx)           |
                      |  - Dynamic Zig Cross-Compiler      |
                      |  - Multi-Transport Listener Manager|
                      +--------+------------------+--------+
                               |                  |
                    HTTPS / HTTP                  DNS (UDP 53)
                    (WinHTTP)                     (Hickory DNS / Base32)
                               |                  |
                               v                  v
                      +------------------------------------+
                      |       Lockjaw Implant (Zig)        |
                      |  - Indirect Syscalls (Halo's Gate) |
                      |  - Reflective & PoolParty Injection|
                      |  - In-Memory BOF Execution Engine  |
                      |  - Ghost AMSI Bypass (HWBP + VEH)  |
                      |  - IAT-Clean Dynamic API Resolv.   |
                      |  - RC4-Encrypted Communications    |
                      +------------------------------------+
  • Teamserver (Rust): Built on Tokio and Axum with Rustls. Manages agent checkins, task dispatching, listener lifecycles, and SQLite persistence. Integrates an on-demand payload cross-compilation pipeline leveraging Zig and GNU objcopy.
  • Implant (Zig & Assembly): Cross-compiled natively targeting x86_64-windows. Standalone, zero external C-runtime dependencies, running in the .Windows subsystem (headless, no console window).
  • Stagers (PIC Assembly & PowerShell): Hardened x64 position-independent assembly stager (pic_stager.s) with safe-stack architecture, shadow space preservation, and dynamic PEB traversal, alongside lightweight PowerShell download cradles.
  • Operator CLI (Python 3): Asynchronous TUI built on prompt_toolkit featuring real-time checkin alerts, numeric indexing, prefix matching, context management, and automatic file upload/download synchronization.

Core Capabilities & Features

1. Evasion & Anti-Analysis

  • Indirect Syscalls (Hell's Gate + Halo's Gate):
    • Dynamically extracts System Service Numbers (SSNs) directly from in-memory ntdll.dll using DJB2 hashing.
    • Recovers hooked syscalls via Halo's Gate neighbor scanning (up to 32 slots above and below).
    • Jumps directly to legitimate syscall; ret gadgets residing within the .text section of ntdll.dll, evading user-mode API hooks, call stack inspection, and return-address origin checks.
  • "Ghost" AMSI Bypass (HWBP + VEH):
    • In-memory AMSI neutralizer using Hardware Breakpoints (DR0/DR7) and Vectored Exception Handling (AddVectoredExceptionHandler).
    • Triggers an internal exception (0xDEADBEEF) to configure debug registers on AmsiScanBuffer.
    • Catches EXCEPTION_SINGLE_STEP, zeroes RAX (AMSI_RESULT_CLEAN = 0), and cleanly returns execution to caller.
    • Modifies zero .text memory bytes and avoids SetThreadContext detection vectors.
  • 100% IAT-Clean & Dynamic API Resolution:
    • Zero static imports for sensitive Win32/NT APIs.
    • Resolves modules by walking the PEB (InLoadOrderModuleList) and resolves function addresses dynamically via compile-time case-sensitive (djb2) and case-insensitive (djb2_i) hashing.
  • Encrypted Communications:
    • Symmetric RC4 stream encryption across all agent-teamserver communications (checkins, tasking, results).
    • Unique agent identification derived from PID, TID, and machine name via linear congruential generator (LCG).
  • Stealth Footprint:
    • Operates as a .Windows subsystem GUI application.
    • Suppresses console windows via ShowWindow(hWnd, SW_HIDE).
    • Configurable beacon sleep with randomized jitter algorithms.
    • Automatic SSL certificate error bypass (SECURITY_IGNORE_ALL_CERT_ERRORS) enabling operational use with self-signed TLS certificates and domain fronting.
  • Self-Destruct:
    • Shuts down the agent process and spawns a detached, asynchronous cleanup command (ping 127.0.0.1 -n 3 > nul & del /f /q ...) to securely wipe the binary from disk.

2. Process Migration & Injection

  • Direct Reflective Manual Mapping (migrate <pid> reflective):
    • Manually maps the agent's executable image into a remote target process using dual-mapped shared memory sections (NtCreateSection + NtMapViewOfSection mapped RW locally and RWX remotely).
    • Avoids suspicious remote virtual memory allocations (NtAllocateVirtualMemory / NtWriteVirtualMemory).
    • Performs local PE header copying, section mapping, base relocation delta fixes, and import table resolution directly within shared memory before initiating remote thread execution via NtCreateThreadEx indirect syscalls.
    • Built-in architecture validation to protect against 32-bit (WOW64) injection mismatches.
  • Reflective PoolParty Injection (migrate <pid> reflective_poolstomp):
    • Combines reflective section mapping with advanced PoolParty process injection.
    • Enumerates remote process handles via NtQuerySystemInformation to discover existing thread pool worker factories (TpWorkerFactory).
    • Queries WorkerFactoryBasicInformation, overwrites the factory's StartRoutine with an execution trampoline, and triggers agent execution by incrementing WorkerFactoryThreadMinimum via NtSetInformationWorkerFactory.
    • Zero new thread creation: Completely evades telemetry and alerts anchored on CreateRemoteThread / NtCreateThreadEx (e.g., Sysmon Event ID 8, ETW threat intelligence providers).

3. In-Memory Execution: Beacon Object Files (BOF)

  • Built-in COFF loader supporting AMD64 object files.
  • Full internal handling of relocations (IMAGE_REL_AMD64_ADDR64, IMAGE_REL_AMD64_ADDR32, IMAGE_REL_AMD64_ADDR32NB, IMAGE_REL_AMD64_REL32).
  • Resolves external dynamic dependencies using the standard __imp__<DLL>$<Function> convention.
  • Implements Beacon API compatibility functions:
    • Argument parsing: BeaconDataParse, BeaconDataInt, BeaconDataShort, BeaconDataLength, BeaconDataExtract.
    • Output formatting: BeaconFormatAlloc, BeaconFormatReset, BeaconFormatFree, BeaconFormatAppend, BeaconFormatPrintf, BeaconFormatToString, BeaconFormatInt.
    • Execution output & diagnostics: BeaconOutput, BeaconPrintf, BeaconIsAdmin.
Download Tool