Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
voidsyscall — Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer. | Kitploit
उपकरण/GitHubGitHub/voidsecsoftwares/voidsyscall
Privilege EscalationEncryption/Decryption ToolsPersistence MechanismsIDS/IPS EvasionLateral MovementPost-ExploitationMalware AnalysisPenetration TestingCommand and ControlRed TeamingPayload Development
6277020 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
Remote Access Trojan
GitHubvoidsecsoftwares/voidsyscall

voidsyscall

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

voidsyscall

go license platform c2 syscalls

English | 简体中文 | 조선어 | Русский

Zero WinAPI. Every NT primitive resolved at runtime from ntdll in memory — SYSCALL instructions issued directly via Plan9 assembly stubs, no import table, no ntdll usermode hooks touched. C2 over HTTPS / DNS / ICMP, AES-256-GCM per message. Windows native. Linux builds. macOS builds.

This is not a syscall wrapper library. It's a full implant framework where every operation — from injecting code to reading files to persisting in the registry — goes through raw Nt* syscalls resolved at boot from the current ntdll export table. No WinAPI calls exist in the binary. Nothing for an EDR to hook at usermode.


What's inside

Syscall engine

  • Runtime SSN resolution: PEB → LDR → ntdll base → PE export table → djb2 hash match → prologue scan for B8 xx xx 00 00 0F 05 (direct) or 4C 8B D1 B8 xx xx 00 00 0F 05 (Hells Gate). Every function name is hashed at compile time — no plaintext strings in the binary.
  • Direct syscall: Plan9 asm (asm_amd64.s) loads the SSN into EAX, sets 7 args by hand, executes SYSCALL. Return via RAX/RDX.
  • Indirect syscall: Locates a 0F 05 C3 gadget (syscall;ret) inside ntdll, calls through it. The CPU trap lands inside ntdll — call stack shows ntdll frames, not implant frames. No usermode hook survives.
  • SSN fingerprint: Dumps all resolved SSNs from the current ntdll build, generates a fingerprint hash. Export as hex, import on another machine. Detects build mismatches before they burn you.
  • Unhook: Locks .text to RWX, copies original bytes from the disk- mapped ntdll, restores protection, flushes icache, nukes SSN cache. Every usermode hook placed by any EDR is gone.

Injection — 4 methods, polymorphic rotation

The agent rotates through injection techniques automatically. Each call uses a different method — no two injections look the same in forensics.

MethodHow it worksWhy it's stealthy
Section mappingNtCreateSection → NtMapViewOfSection (remote) → NtCreateThreadExNo RWX allocation in VAD. Section is file-backed. Memory scanners see PAGE_EXECUTE_READ, not PAGE_EXECUTE_READWRITE.
Process hollowNtCreateUserProcess (suspended) → NtSuspendProcess → zero image base → alloc + write shellcode → NtSetContextThread (RIP = shellcode) → NtResumeProcessProcess appears as legitimate svchost.exe in taskmgr. Only memory contents differ.
APC queuingEnumerate threads via NtQuerySystemInformation → NtOpenThread → NtQueueApcThreadNo new thread created. No new TEB. No new stack allocation. Fires when thread enters alertable wait.
Module stompingAlloc in target → write minimal PE header + shellcode → NtCreateThreadEx at entry pointModule list shows a plausible DLL name. PE header is valid enough to fool module enumeration.

Anti-analysis — 13+ detection methods

Runs all checks, returns a scored threat report. Auto-destruct on Critical.

CheckMethod
VM detectionCPUID leaf 0x40000000 hypervisor signature scan (VMware, VirtualBox, Hyper-V, KVM, Xen, QEMU, Parallels) + leaf 0x40000001 fallback
Sandbox detectionCPU count, registry artifacts (VMware Tools, VBox Guest Additions, VMware/VBox services), sandbox process scan (30+ known names: wireshark, procmon, x64dbg, ida, etc.)
Debugger detectionPEB.BeingDebugged, PEB.NtGlobalFlag, heap debug flags, ProcessDebugPort, ProcessDebugObjectHandle, ProcessDebugFlags, hardware breakpoint DR0-7, timing single-step check
Timing anomalyRDTSC-based: 50 samples of NtQuerySystemInformation latency, mean/stddev, flag if >10% of samples exceed 3σ variance. Catches instrumentation overhead.
PEB evasionPatches BeingDebugged, NtGlobalFlag, ProcessHeap flags, DebugPort, ThreadHideFromDebugger — all via GS segment reads + NtWriteVirtualMemory. No API calls.

Token operations

All via Nt* syscalls, no WinAPI.

  • EnablePrivilege(index) — set any privilege by LUID
  • EnableAllTokenPrivileges() — 20 privileges at once (Debug, Impersonate, TCB, Backup, Restore, etc.)
  • GetProcessTokenIntegrityLevel() — query mandatory integrity
  • StealProcessToken(pid) — open + duplicate another process token
  • ImpersonateThread() / RevertToSelf()

VAD operations

  • EnumVirtualMemory() — walk all virtual regions via NtQueryVirtualMemory
  • FindWritableExecRegions() — find PAGE_EXECUTE_READWRITE committed regions
  • HideRegion() — set PAGE_NOACCESS to hide memory from scanners
  • UnhideRegion() — restore original protection

File I/O — all Nt* syscalls

NtCreateFile → NtReadFile / NtWriteFile → NtClose. Zero CreateFileA, ReadFile, WriteFile, or DeleteFileW calls. ReadFileContents(), WriteFileContents(), DeleteFileNt(), FileExists().

Registry persistence — all Nt* syscalls

NtCreateKey → NtSetValueKey. AddRunKeyPersistence(), RemoveRunKeyPersistence(). No RegCreateKeyEx, RegSetValueEx, or any Advapi32 calls.

Handle operations

  • EnumerateSystemHandles() — all open handles in the system via NtQuerySystemInformation(SystemHandleInformation)
  • FindEDRHandles() — matches owner PIDs against 30+ known EDR process names (MsSense, CrowdStrike, Sentinel, Cylance, Carbon Black, etc.)
  • CloseEDRHandles() — closes monitoring handles the EDR placed in your process
  • IsProcessMonitored() — boolean check: are we being watched?

Memory encryption

  • Vault: In-memory XOR cipher with auto re-keying on a timer. Plaintext never stored raw. Re-key decrypts → generates new key → re-encrypts. Forensic heap dumps between re-key intervals get garbage.
  • SecureDelete: 3-pass wipe (random → zeros → ones → zeros) before NtFreeVirtualMemory.
  • StackEncrypt: Encrypt stack-allocated buffers before return. Stack frame reuse makes forensics unreliable.

AMSI / ETW / evasion patches

  • PatchAMSI() — AmsiScanBuffer → MOV EAX, 0; RET
  • PatchETW() — EtwEventWrite → RET
  • PatchNtTraceEvent() — NtTraceEvent → RET
  • PatchDbgUiRemoteBreakin() — thread breakin → RET
  • PatchInstrumentationCallbacks() — ThreadHideFromDebugger

C2 channels

ChannelWire formatPrereqs
HTTPSbinary POST, custom framing, randomized UA/pathTLS cert
DNS<idx>-<total>-<base32> subdomain, TXT responseDNS resolution
ICMPv4payload in echo request/reply ID+seqraw socket (root/Admin)

All channels implement the Channel interface. Adding NTP, DoH, or TURN means implementing the interface — zero agent changes.

Crypto

AES-256-GCM per-message AEAD. Unique 12-byte nonce per message. Per-implant keyring. Passphrase-based key derivation available. 3 tests, all passing.


Layout

टूल डाउनलोड करें