Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
SysWhispers2 — AV/EDR से बचाव प्रत्यक्ष सिस्टम कॉल के माध्यम से। | Kitploit
उपकरण/GitHubGitHub/jthuraisamy/syswhispers2
रक्षात्मक उपकरणपेलोड जनरेशनआईडीएस/आईपीएस से बचनाशेलकोडरेड टीमिंगशेलकोड जनरेशनपेलोड डेवलपमेंटबाइनरी शोषणआईडीएस/आईपीएस से बचना में शीर्ष #18पेलोड डेवलपमेंट में शीर्ष #6
1.8k265704 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
पेलोड जनरेशन में शीर्ष #8
शेलकोड में शीर्ष #6
शेलकोड जनरेशन में शीर्ष #8
GitHubjthuraisamy/syswhispers2

SysWhispers2

AV/EDR से बचाव प्रत्यक्ष सिस्टम कॉल के माध्यम से।

रिपॉजिटरी देखें
साझा करें

SysWhispers2

SysWhispers प्रत्यक्ष सिस्टम कॉल करने के लिए implants द्वारा उपयोग किए जाने वाले header/ASM फ़ाइलें उत्पन्न करके एविज़न में मदद करता है।

सभी कोर syscalls समर्थित हैं और उदाहरण उत्पन्न फ़ाइलें example-output/ फ़ोल्डर में उपलब्ध हैं।

SysWhispers 1 और 2 के बीच अंतर

उपयोग SysWhispers1 के लगभग समान है लेकिन आपको Windows के किस संस्करण का समर्थन करना है यह निर्दिष्ट करने की आवश्यकता नहीं है। अधिकांश परिवर्तन पर्दे के पीछे हैं। यह अब @j00ru की syscall tables पर निर्भर नहीं करता है, और इसके बजाय @modexpblog द्वारा लोकप्रिय की गई "sorting by system call address" तकनीक का उपयोग करता है। यह syscall stubs के आकार को काफी कम कर देता है।

SysWhispers2 में विशिष्ट कार्यान्वयन @modexpblog के कोड का एक रूपांतर है। एक अंतर यह है कि फ़ंक्शन नाम हैश प्रत्येक पीढ़ी पर यादृच्छिक किए जाते हैं। @ElephantSe4l, जिन्होंने पहले इस तकनीक को published किया था, का C++17 पर आधारित एक और implementation है, जो देखने लायक भी है।

मूल SysWhispers रिपॉजिटरी अभी भी उपलब्ध है लेकिन भविष्य में अप्रचलित हो सकती है।

परिचय

विभिन्न सुरक्षा उत्पाद उपयोगकर्ता-मोड API फ़ंक्शनों में हुक लगाते हैं जो उन्हें निष्पादन प्रवाह को अपने इंजनों पर पुनर्निर्देशित करने और संदिग्ध व्यवहार का पता लगाने की अनुमति देते हैं। ntdll.dll में syscalls बनाने वाले फ़ंक्शन केवल कुछ असेंबली निर्देशों से मिलकर बने होते हैं, इसलिए उन्हें अपने implant में पुनः लागू करना उन सुरक्षा उत्पाद हुक के ट्रिगरिंग को बायपास कर सकता है। इस तकनीक को @Cn33liz द्वारा लोकप्रिय बनाया गया था और उनके blog post में अधिक तकनीकी विवरण हैं जो पढ़ने योग्य हैं।

SysWhispers लाल टीम को कोर कर्नेल इमेज (ntoskrnl.exe) में किसी भी सिस्टम कॉल के लिए header/ASM जोड़े उत्पन्न करने की क्षमता प्रदान करता है। हेडर में आवश्यक प्रकार परिभाषाएँ भी शामिल होंगी।

स्थापना

> git clone https://github.com/jthuraisamy/SysWhispers2.git
> cd SysWhispers2
> py .\syswhispers.py --help

उपयोग और उदाहरण

कमांड लाइन्स

# Export all functions with compatibility for all supported Windows versions (see example-output/).
py .\syswhispers.py --preset all -o syscalls_all

# Export just the common functions (see below for list).
py .\syswhispers.py --preset common -o syscalls_common

# Export NtProtectVirtualMemory and NtWriteVirtualMemory with compatibility for all versions.
py .\syswhispers.py --functions NtProtectVirtualMemory,NtWriteVirtualMemory -o syscalls_mem

स्क्रिप्ट आउटपुट

PS C:\Projects\SysWhispers2> py .\syswhispers.py --preset common --out-file syscalls_common

python syswhispers.py -p all -a all -l all -o example-output/Syscalls

                  .                         ,--.
,-. . . ,-. . , , |-. o ,-. ,-. ,-. ,-. ,-.    /
`-. | | `-. |/|/  | | | `-. | | |-' |   `-. ,-'
`-' `-| `-' ' '   ' ' ' `-' |-' `-' '   `-' `---
     /|                     |  @Jackson_T
    `-'                     '  @modexpblog, 2021

SysWhispers2: Why call the kernel when you can whisper?

All functions selected.

Complete! Files written to:
        example-output/Syscalls.h
        example-output/Syscalls.c
        example-output/SyscallsStubs.std.x86.asm
        example-output/SyscallsStubs.rnd.x86.asm
        example-output/SyscallsStubs.std.x86.nasm
        example-output/SyscallsStubs.rnd.x86.nasm
        example-output/SyscallsStubs.std.x86.s
        example-output/SyscallsStubs.rnd.x86.s
        example-output/SyscallsInline.std.x86.h
        example-output/SyscallsInline.rnd.x86.h
        example-output/SyscallsStubs.std.x64.asm
        example-output/SyscallsStubs.rnd.x64.asm
        example-output/SyscallsStubs.std.x64.nasm
        example-output/SyscallsStubs.rnd.x64.nasm
        example-output/SyscallsStubs.std.x64.s
        example-output/SyscallsStubs.rnd.x64.s
        example-output/SyscallsInline.std.x64.h
        example-output/SyscallsInline.rnd.x64.h

क्लासिक CreateRemoteThread DLL इंजेक्शन का पहले और बाद का उदाहरण

py .\syswhispers.py -f NtAllocateVirtualMemory,NtWriteVirtualMemory,NtCreateThreadEx -o syscalls
#include <Windows.h>

void InjectDll(const HANDLE hProcess, const char* dllPath)
{
    LPVOID lpBaseAddress = VirtualAllocEx(hProcess, NULL, strlen(dllPath), MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
    LPVOID lpStartAddress = GetProcAddress(GetModuleHandle(L"kernel32.dll"), "LoadLibraryA");
	
    WriteProcessMemory(hProcess, lpBaseAddress, dllPath, strlen(dllPath), nullptr);
    CreateRemoteThread(hProcess, nullptr, 0, (LPTHREAD_START_ROUTINE)lpStartAddress, lpBaseAddress, 0, nullptr);
}
#include <Windows.h>
#include "syscalls.h" // Import the generated header.

void InjectDll(const HANDLE hProcess, const char* dllPath)
{
    HANDLE hThread = NULL;
    LPVOID lpAllocationStart = nullptr;
    SIZE_T szAllocationSize = strlen(dllPath);
    LPVOID lpStartAddress = GetProcAddress(GetModuleHandle(L"kernel32.dll"), "LoadLibraryA");
	
    NtAllocateVirtualMemory(hProcess, &lpAllocationStart, 0, (PULONG)&szAllocationSize, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
    NtWriteVirtualMemory(hProcess, lpAllocationStart, (PVOID)dllPath, strlen(dllPath), nullptr);
    NtCreateThreadEx(&hThread, GENERIC_EXECUTE, NULL, hProcess, lpStartAddress, lpAllocationStart, FALSE, 0, 0, 0, nullptr);
}

सामान्य फ़ंक्शन

--preset common स्विच का उपयोग करने पर निम्नलिखित फ़ंक्शनों के साथ एक header/ASM जोड़ी बनाई जाएगी:

फ़ंक्शन सूची विस्तार करने के लिए क्लिक करें।
  • NtCreateProcess (CreateProcess)
  • NtCreateThreadEx (CreateRemoteThread)
  • NtOpenProcess (OpenProcess)
  • NtOpenThread (OpenThread)
  • NtSuspendProcess
  • NtSuspendThread (SuspendThread)
  • NtResumeProcess
  • NtResumeThread (ResumeThread)
  • NtGetContextThread (GetThreadContext)
  • NtSetContextThread (SetThreadContext)
  • NtClose (CloseHandle)
  • NtReadVirtualMemory (ReadProcessMemory)
  • NtWriteVirtualMemory (WriteProcessMemory)
  • NtAllocateVirtualMemory (VirtualAllocEx)
  • NtProtectVirtualMemory (VirtualProtectEx)
  • NtFreeVirtualMemory (VirtualFreeEx)
  • NtQuerySystemInformation (GetSystemInfo)
  • NtQueryDirectoryFile
  • NtQueryInformationFile
  • NtQueryInformationProcess
  • NtQueryInformationThread
  • NtCreateSection (CreateFileMapping)
  • NtOpenSection
  • NtMapViewOfSection
  • NtUnmapViewOfSection
  • NtAdjustPrivilegesToken (AdjustTokenPrivileges)
  • NtDeviceIoControlFile (DeviceIoControl)
  • NtQueueApcThread (QueueUserAPC)
  • NtWaitForMultipleObjects (WaitForMultipleObjectsEx)

Visual Studio में आयात करना

टूल डाउनलोड करें