Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Win32_Offensive_Cheatsheet — Win32 and Kernel abusing techniques for pentesters | Kitploit
Tools/GitHubGitHub/matthieu-hackwitharts/win32_offensive_cheatsheet
Persistence MechanismsExploitationIDS/IPS EvasionReverse EngineeringPost-ExploitationPenetration TestingBinary AnalysisLearning & EducationRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Curated Resources
Payload Development
GitHubmatthieu-hackwitharts/win32_offensive_cheatsheet

Win32_Offensive_Cheatsheet

Win32 and Kernel abusing techniques for pentesters

View Repository
981136173 years agoReviewed by Kitploit
Share

Win32 Offensive Cheatsheet

Win32 and Kernel abusing techniques for pentesters & red-teamers made by @UVision and @RistBS

Dev mode enabled, open to any help :)

  • Windows Binary Documentation
    • PE structure
    • PE Headers
    • Parsing PE
    • Export Address Table (EAT)
    • Resolve function address
    • Import Address Table (IAT)
      • Parsing IAT
    • Import Lookup Table (ILT)
    • Enable SeDebug privilege
  • Execute some binary
    • Classic shellcode execution
    • DLL execute
    • RAW file to PE
  • Code injection techniques
    • CreateRemoteThread injection
    • Process Hollowing
    • APC Queue technique
    • Early Bird
    • Reflective DLL Injection
    • Dll injection
    • Process Doppelganging
    • Fibers
    • CreateThreadPoolWait
    • Thread Hijacking
    • MapView code injection
    • Module Stomping
    • Function Stomping
  • Hooking techniques
    • Inline hooking
    • IAT hooking
  • RE Bypass techniques
    • Call and Strings obfuscation
    • Manual function resolve
    • Win32 API Hashing
  • EDR/Endpoint bypass
    • Direct syscall
    • High level languages
    • Patch inline hooking
    • Detect hooks
    • Patch ETW
    • Sandbox bypass
    • Debugging Bypass
    • VirtualProtect technique
    • Fresh copy unhook
    • Hell's Gate
    • Heaven's Gate
    • PPID spoofing
    • Process Instrumentation Callback
    • Heap Encryption
    • Sleep Obfuscation
  • Driver Programming basics
    • General concepts
    • System Service Dispatch Table (SSDT)
    • Driver entry
    • Input Output)
    • Communicate with driver
    • Driver signing (Microsoft)
    • Custom callbacks (ObRegisterCallbacks)
  • Offensive Driver Programming
    • Patch kernel callback
    • Patch protected process
  • Using Win32 API to increase OPSEC
    • Persistence
      • Scheduled Tasks
    • Command line spoofing
  • Misc Stuff
    • x64 Calling Convention
    • Indirect Execution
      • CFG Bypass with SetProcessValidCallTargets

  • Malware/Sophisticated techniques
    • Case of Emotet : PPID Spoofing using WMI
    • Zeus malware hidden files technique
    • SpyEye keyloger hooking technique
    • Most ridiculous malware stop (WannaCry)

Windows Binary Documentation

Useful tools and Websites/Books/Cheatsheet

  • 🔹 https://github.com/RistBS/Awesome-RedTeam-Cheatsheet/ (Very Good Cheatsheet)
  • 🔹 https://www.ired.team/ (Awesome red team cheatsheet with great code injection notes)
  • 🔹 https://undocumented.ntinternals.net/ (Undocumented NT functions)
  • 🔹 https://docs.microsoft.com/en-us/windows/win32/api/ (Microsoft Official Doc)
  • 🔹 Windows Kernel Programming - Pavel Yosifovich
  • 🔹 https://research.checkpoint.com/ (Very interesting docs about evasion, anti-debug and so more)
  • 🔹 https://www.vx-underground.org/ (Awesome content about malware dev and reverse)

PE Structure

PE Headers

  • DOS_HEADER : First Header of PE, contains MS DOS message ("This programm cannot be run in DOS mode...."), MZ Header (Magic bytes to identify PE) and some stub content.
  • IMAGE_NT_HEADER : Contains PE file signature, File Header and Optionnal Header
  • SECTION_TABLE : Contains sections headers
  • SECTIONS : Not a header but useful to know : these are sections of the PE

Details : https://www.researchgate.net/figure/PE-structure-of-normal-executable_fig1_259647266

Parsing PE

Simple PE parsing to retrieve IAT and ILT absolute address:

  • Obtain base address : GetModuleHandleA(NULL);
  • PIMAGE_DOS_HEADER = base address, dos header
  • PIMAGE_NT_HEADER = BaseAddress+PIMAGE_DOS_HEADER.e_lfnanew (RVA NT_HEADER)
  • IMAGE_DATA_DIRECTORY = OptionnalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT] of PIMAGE_NT_HEADER
  • IMAGE_IMPORT_DIRECTORY = IMAGE_DATA_DIRECTORY.VirtualAddress (RVA of IMAGE_IMPORT_DIRECTORY)
  • IMAGE_IMPORT_DESCRIPTOR = BaseAddress + IMAGE_IMPORT_DIRECTORY.VirtualAddress (RVA of IMAGE_IMPORT_DESCRIPTOR)
  • IAT absolute address : IMAGE_IMPORT_DESCRIPTOR.FirstThunk (RVA IAT) + BaseAddress
  • ILT absolute address : IMAGE_IMPORT_DESCRIPTOR.OriginalFirstThunk (RVA ILT) + BaseAddress

Export Address Table (EAT)

The EAT Resolves all functions that are exported by the PE & resolves also DLLs. It Defined in IMAGE_EXPORT_DIRECTORY structure:

typedef struct _IMAGE_EXPORT_DIRECTORY {
		DWORD Characteristics;
		DWORD TimeDateStamp;
		WORD  MajorVersion;
		WORD  MinorVersion;
		DWORD Name;   // name of DLL
		DWORD Base;   // first ordinal number
		DWORD NumberOfFunctions; // number of entries in EAT
		DWORD NumberOfNames; // number of entries in (1) (2)
		DWORD AddressOfFunctions; // RVA EAT and contains also RVA of exported functions
		DWORD AddressOfNames;   // Pointer array contains address of function names
		DWORD AddressOfNameOrdinals; // Pointer array contains address of ordinal number of functions (index in AddressOfFunctions)
} IMAGE_EXPORT_DIRECTORY, *PIMAGE_EXPORT_DIRECTORY;   

Please note that the EAT is defined in a DLL, not in a "real" PE (a PE will use the EAT of a loaded dll to resolve pointers to functions it want to use).

Resolve function address

Using function address

What do you wait ? Find this function !

Using ordinal number

An ordinal number is an index position to the corresponding function address in AddressOfFunctions array. It can be used to retrieve the correct address of function, like below :

Let's try to find the corresponding address (Addr4) with given ordinal number 3.

  • AddressOfFunctions : Addr1 Addr2 Addr3 Addr4 .... AddrN
  • AdressOfNameOrdinals : 2 5 7 3 ... N

The address we are looking for is on 3th position (from 0), and our ordinal number corresponds to the index of this address.

Using function name

The Nth element in AddressOfNames array corresponding to the Nth element in AddressOfNameOrdinals array : using a given name, you can retrieve the corresponding ordinal number, and proceed to find the function address using this number.

Import Address Table (IAT)

Download Tool