Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
sickle-pdk — Sickle - Kit di sviluppo payload | Kitploit
Strumenti/GitHubGitHub/wetw0rk/sickle-pdk
Framework di ExploitGenerazione di PayloadExploitReverse EngineeringAnalisi di BinariSviluppo Payload
GitHubwetw0rk/sickle-pdk

sickle-pdk

Sickle - Kit di sviluppo payload

Vedi Repository
8721241 mese faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Sickle - Kit di sviluppo di payload

alt text

Sickle è uno strumento che ho sviluppato inizialmente per aiutarmi a essere più efficace, sia nello sviluppo che nella comprensione dello shellcode. Tuttavia, nel corso del suo sviluppo e del suo utilizzo, si è evoluto in un kit di sviluppo di payload. Sebbene i moduli attuali siano principalmente orientati all'assembly, questo strumento non si limita allo shellcode.

Attualmente Sickle può aiutare nelle seguenti attività:

  • Conversione di istruzioni assembly in codice macchina (opcode)
  • Esecuzione di bytecode, inclusi i payload generati
  • Formattazione degli opcode per un linguaggio di destinazione
  • Identificazione dei caratteri non validi
  • Disassemblaggio lineare
  • Diffing

Generazione di shellcode

Sickle supporta la generazione di shellcode tramite il Keystone Engine. Trattandosi di una funzionalità aggiunta di recente, il supporto per i payload è limitato. Tuttavia, l'obiettivo è aggiungere una reverse shell di base per ogni architettura e piattaforma.

alt text

Diffing

Sickle include un modulo di "diffing" progettato inizialmente per analizzare gli stub di shellcode. La modalità "asm" originale esegue diff di disassemblaggio lineare sia a livello di linguaggio assembly che di opcode, separatamente.

alt text

Inoltre, Sickle offre varie modalità per eseguire diff, rendendolo utile anche al di là dello sviluppo di shellcode.

alt text

Esecuzione di shellcode

Un'attività comune che potresti svolgere spesso è testare il tuo shellcode. Questo processo in genere prevede i seguenti passaggi:

  1. Compilare il codice assembly.
  2. Estrarre lo shellcode e formattarlo in modo appropriato per il wrapper scelto.
  3. Compilare il wrapper.
  4. Eseguire il wrapper.

Sebbene questi passaggi possano sembrare banali, possono richiedere molto tempo se ripetuti. Sickle semplifica il processo incapsulando automaticamente lo shellcode per test rapidi, e il modulo "run" attualmente supporta sia sistemi Windows che Unix.

alt text

Disassemblaggio

Sickle può anche convertire un file binario in opcode estratti (shellcode) e poi tradurli in istruzioni macchina (assembly). Nota che questo processo funziona solo con file binari grezzi e attualmente esegue il disassemblaggio in modo lineare tramite Capstone.

alt text

Nell'esempio mostrato sopra, il modulo "disassemble" disassembla in assembly una reverse shell progettata da Stephen Fewer.

Estrazione di shellcode

L'estrazione dello shellcode è stato il primo modulo, o meglio, la funzionalità principale di Sickle, poiché gli opcode vengono interpretati in modo diverso a seconda del wrapper utilizzato. JavaScript, ad esempio, non memorizza e interpreta lo shellcode nello stesso modo in cui farebbe un programma C.

alt text

Forse la più grande fonte di ispirazione per tutto ciò è stato msfvenom.

Identificazione dei caratteri non validi

Sebbene meno comuni negli exploit a 64 bit, possono esserci casi in cui un exploit limita l'uso di determinati caratteri. È qui che il modulo "pinpoint" eccelle, poiché identifica ed evidenzia direttamente le istruzioni assembly responsabili dei caratteri non validi individuati.

Progettazione basata sui moduli

Inizialmente, questo strumento è nato come un unico grande script. Tuttavia, man mano che si evolveva, mi sono ritrovato a dover reimparare il codice a ogni aggiornamento. Per risolvere questo problema, Sickle ora segue un approccio modulare, che consente di aggiungere nuove funzionalità dedicando il minimo tempo a reimparare la progettazione dello strumento.

root@kitploit:~
$ sickle-pdk -l

  Shellcode                              Ring Description
  ---------                              ---- -----------
  windows/x64/virtualalloc_exec_tcp       3   A lightweight stager that connects to a handler via TCP over IPv4 to receive and execute shellcode
  windows/x64/egghunter                   3   Egghunter based on Hell's Gate and NtProtectVirtualMemory
  windows/x64/virtualalloc_exec_https     3   A lightweight stager that connects to a handler over HTTPS to receive and execute shellcode
  windows/x64/exec                        3   Executes a command on the target host
  windows/x64/reflective_pe_loader        3   Stageless Reflective PE Loader that takes an x64 binary and executes it in memory
  windows/x64/shell_reverse_tcp           3   Reverse Shell via TCP over IPv4 that provides an interactive cmd.exe session
  windows/aarch64/shell_reverse_tcp       3   Reverse Shell via TCP over IPv4 that provides an interactive cmd.exe session
  windows/x86/shell_reverse_tcp           3   Reverse shell via TCP over IPv4 that provides an interactive cmd.exe session
  windows/x64/kernel_token_stealer        0   Token stealing shellcode for privilege escalation
  windows/x64/kernel_sysret               0   Generic method of returning from kernel space to user space
  windows/x64/kernel_ace_edit             0   SID entry modifier for process injection
  windows/x86/kernel_token_stealer        0   Token stealing shellcode for privilege escalation
  linux/x64/memfd_reflective_elf_tcp      3   Staged Reflective ELF Loader via TCP over IPV4 which executes an ELF from a remote server
  linux/aarch64/memfd_reflective_elf_tcp  3   Staged Reflective ELF Loader via TCP over IPv4 which executes an ELF from a remote server handler
  linux/aarch64/shell_reverse_tcp         3   Reverse Shell via TCP over IPv4 that provides an interactive /bin/sh session
  linux/x86/execve                        3   Executes a shell session such as /bin/sh
  linux/x86/shell_reverse_tcp             3   Reverse shell via TCP over IPV4 that provides an interactive /bin/sh session

  Architectures
  -------------
  aarch64
  x64
  x86

  Modules       Description
  -------       -----------
  disassemble   Simple linear disassembler for multiple architectures
  handler       Module for handling payload distribution and session management
  asm_shell     Interactive assembler and disassembler
  diff          Bytecode diffing module for comparing two binaries (or shellcode)
  pinpoint      Highlights opcodes within a disassembly to identify instructions responsible for bad characters
  run           Wrapper used for executing bytecode (shellcode)
  format        Converts bytecode into a respective format (activated anytime '-f' is used)
  badchar       Produces a set of all potential invalid characters for validation purposes

  Format        Description
  ------        -----------
  perl          Format bytecode for Perl
  python        Format bytecode for Python
  hex_space     Format bytecode in hex, seperated by a space
  nasm          Format bytecode for NASM
  java          Format bytecode for Java
  javascript    Format bytecode for Javascript (Blob to send via XHR)
  escaped       Format bytecode for one-liner hex escape paste
  rust          Format bytecode for a Rust application
  uint8array    Format bytecode for Javascript as a Uint8Array directly
  bash          Format bytecode for bash script (UNIX)
  powershell    Format bytecode for Powershell
  cs            Format bytecode for C#
  dword         Format bytecode in dword
  c             Format bytecode for a C application
  raw           Format bytecode to be written to stdout in raw form
  ruby          Format bytecode for Ruby
  num           Format bytecode in num format
  hex           Format bytecode in hex
  python3       Format bytecode for Python3

Questo approccio consente a ogni modulo di generare una documentazione dettagliata per le proprie funzionalità.

root@kitploit:~
$ sickle-pdk -m run -i

Usage information for run

              Name: Shellcode Runner
            Module: run
      Architecture: Multi
          Platform: Multi
              Ring: 3

Author(s):
    wetw0rk

Tested against:
    Linux
    Windows

Module Description:

  Executes bytecode from a binary file (-r) or a payload module (-p) under the context
  of the currently running operating system and architecture. Meaning if you are
  running on AARCH64 bytecode will be interpreted as such and if you're on x64 it will
  interpret it as x64 respectively.

Example:

  /usr/local/bin/sickle-pdk -m run -r shellcode

Questo approccio include anche la documentazione per gli stub di shellcode.

root@kitploit:~
$ sickle-pdk -p windows/x64/egghunter -i

Usage information for windows/x64/egghunter

              Name: Windows (x64) Hell's Gate based Egghunter
            Module: windows/x64/egghunter
      Architecture: x64
          Platform: windows
              Ring: 3

Author(s):
    hvictor

Tested against:
    Windows 11 (10.0.26100 N/A Build 26100)

Argument Information:

  Name          Description           Optional
  ----          -----------           --------
  TAG           Egg (provide 4 bytes)      yes

Module Description:

  This egghunter iterates virtual memory addresses and before searching for the egg, it
  performs a NtProtectVirtualMemory system call. This system call is similar to
  VirtualProtect, and is parameterized to set the memory to be scanned to READ, WRITE,
  EXECUTE. This way, when the egg is found, the shellcode after it is guaranteed to be
  executable.

Example:

  /usr/local/bin/sickle-pdk -p windows/x64/egghunter TAG=w00t
Scarica lo strumento