
PE to shellcode

🛠️ Una potente herramienta para convertir archivos PE (EXE/DLL) en shellcode independiente de la posición.
pip install pefile lznt1
python clematis.py -f <PE_file> -o <output_file> [-g <true/false>] [-c <true/false>] [-p <parameters>]
# Show help information
python clematis.py -h
# Basic usage
python clematis.py -f target.exe -o output.bin
# Disable obfuscation and compression
python clematis.py -f target.exe -o output.bin -g false -c false
# Pass arguments to target program
python clematis.py -f target.exe -o output.bin -p arg1 arg2
python clematis.py -f target.exe -o output.bin -p "arg1 arg2"
- 🛡️ Unable to perform process injection (AV/EDR/XDR blocking)
- 🔄 Executing golang programs in current process may cause blocking
- 💾 Memory leaks may occur after golang program execution
- ⚠️ Threads created by golang cannot be released!
- ✨ Convert golang programs to shellcode
- 🎯 Direct execution in current process
- ♻️ Automatic memory release after execution
- 🚀 Completely avoid golang-related memory issues
- 🔄 Reclaim all threads created by golang
2024-12-27
2024-12-28
Corregidos posibles fallos de programas DOT NET (Puede que no ocurran)
Añadido manejo para IMAGE_DIRECTORY_ENTRY_EXCEPTION ( x64 )
APIs actualizadas para usar NTAPI

Clematis convierte archivos PE a shellcode mediante los siguientes pasos:
flowchart TD
A[START] --> B[Read PE file]
B --> C[Parse PE structure]
C --> D{Is there a command line argument?}
D -- TRUE --> E[Process command line arguments]
D -- FALSE --> F{Enable compression?}
E --> F
F -- TRUE --> G[LZNT1 compression]
F -- FALSE --> H{Enable obfuscation?}
G --> H
H -- TRUE --> I[Execute obfuscation processing]
H -- FALSE --> J[Generate shellcode]
I --> J
J --> K[Output result]
K --> L[END]
¡Las Issues y las Pull Requests son bienvenidas!
| descripción | por defecto | requerido |
|---|
| -f | --file | Ruta al archivo PE a convertir | true | |
| -o | --output | Nombre del archivo de salida | true | |
| -g | --garble | Habilitar ofuscación | true | false |
| -c | --compress | Habilitar compresión | true | false |
| -p | --parameter | Parámetros de ejecución a pasar al archivo PE | false |
| antes | ahora |
|---|
VirtualAlloc | NtAllocateVirtualMemory |
VirtualProtect | NtProtectVirtualMemory |
VirtualFree | NtFreeVirtualMemory |
LoadLibrary | LdrLoadDll |
GetProcAddress | LdrGetProcedureAddress |
WaitForMultipleObjects | NtWaitForMultipleObjects |
CreateEvent | NtCreateEvent |
CloseHandle | NtClose |
SignalObjectAndWait | NtSignalAndWaitForSingleObject |
TerminateThread | NtTerminateThread |
SuspendThread | NtSuspendThread |
OpenThread | NtOpenThread |
ResumeThread | NtResumeThread |
GetContextThread | NtGetContextThread |
SetContextThread | NtSetContextThread |
| ... |
2025-1-1