Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
AtomicSyscall — Tools and PoCs for Windows syscall investigation. | Kitploit
도구/GitHubGitHub/daem0nc0re/atomicsyscall
IDS/IPS EvasionReverse EngineeringBinary AnalysisLearning & EducationPayload DevelopmentAdversarial Attack
GitHubdaem0nc0re/atomicsyscall

AtomicSyscall

Tools and PoCs for Windows syscall investigation.

저장소 보기
364462010개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

AtomicSyscall

Windows syscall 조사를 위한 도구 및 PoC.

목차

  • AtomicSyscall
    • HeavensGate
    • SyscallDumper
    • SyscallPoCs
    • SyscallResolvers
    • Get-SyscallNumber.ps1
    • Reference
    • Acknowledgments

HeavensGate

이 디렉터리는 Heaven's Gate 기법을 위한 것입니다. README.md를 참조하세요.

SyscallDumper

맨 위로

프로젝트

이 도구는 ntdll.dll 또는 win32u.dll에서 Windows syscall을 덤프하기 위한 것입니다:``` C:\Tools>SyscallDumper.exe -h

SyscallDumper - Tool to dump syscall.

Usage: SyscallDumper.exe [Options] [INPUT_DLL_1] [INPUT_DLL_2]

    -h, --help   : Displays this help message.
    -d, --dump   : Flag to dump syscall from ntdll.dll or win32u.dll.
    -D, --diff   : Flag to take diff between 2 dlls.
    -f, --format : Specifies output format. "c" for C/C++, "cs" for CSharp, "py" for Python.
    -n, --number : Specifies syscall number to lookup in decimal or hex format.
    -o, --output : Specifies output file (e.g. "-o result.txt").
    -s, --search : Specifies search filter (e.g. "-s createfile").
    INPUT_DLL_1  : Specifies path of ntdll.dll or win32u.dll. Older one in diffing.
    INPUT_DLL_2  : Specifies path of ntdll.dll or win32u.dll. Newer one in diffing.
ntdll.dll 또는 win32u.dll에서 syscall 번호를 덤프하려면 `-d`(`--dump`) 옵션을 사용하세요. 소스 DLL을 지정하지 않으면 이 도구는 `C:\Windows\System32\ntdll.dll` 및 `C:\Windows\System32\win32u.dll`에서 syscall 번호를 덤프합니다:```
C:\Tools>SyscallDumper.exe -d

[*] No target is specified.
[>] Dumping from system default ntdll.dll and win32u.dll.
[>] Loading C:\Windows\System32\ntdll.dll.
[+] C:\Windows\System32\ntdll.dll is loaded successfully.
    [*] Architecture : AMD64
    [*] Image Name   : ntdll.dll
[+] Got 463 syscall(s).
[>] Loading C:\Windows\System32\win32u.dll.
[+] C:\Windows\System32\win32u.dll is loaded successfully.
    [*] Architecture : AMD64
    [*] Image Name   : win32u.dll
[+] Got 1258 syscall(s).

[Syscall Table from C:\Windows\System32\ntdll.dll]

---------------------------------------------------------------------------------
| Syscall Name                                          | Number | Number (hex) |
---------------------------------------------------------------------------------
| NtAcceptConnectPort                                   | 2      | 0x0002       |
| NtAccessCheck                                         | 0      | 0x0000       |

--snip--

| NtWriteVirtualMemory                                  | 58     | 0x003A       |
| NtYieldExecution                                      | 70     | 0x0046       |
---------------------------------------------------------------------------------

[*] Found 463 syscall(s).


[Syscall Table from C:\Windows\System32\win32u.dll]

-----------------------------------------------------------------------------------
| Syscall Name                                            | Number | Number (hex) |
-----------------------------------------------------------------------------------
| NtBindCompositionSurface                                | 4373   | 0x1115       |
| NtCloseCompositionInputSink                             | 4374   | 0x1116       |

--snip--

| NtValidateCompositionSurfaceHandle                      | 5350   | 0x14E6       |
| NtVisualCaptureBits                                     | 5351   | 0x14E7       |
-----------------------------------------------------------------------------------

[*] Found 1258 syscall(s).

덤프 결과에서 syscall 이름을 필터링하려면 -s (--search) 옵션을 사용하세요. 그리고 -o (--output) 옵션을 사용하여 결과를 파일로 저장할 수 있습니다:``` C:\Tools>SyscallDumper.exe -d C:\SyscallSamples\1809x64\ntdll.dll -s token -o result.txt

[>] Loading C:\SyscallSamples\1809x64\ntdll.dll. [+] C:\SyscallSamples\1809x64\ntdll.dll is loaded successfully. [] Architecture : AMD64 [] Image Name : ntdll.dll [+] Got 462 syscall(s). [>] Trying to save results. [*] Output File Path : c:\Tools\result.txt [+] Results are saved successfully.

c:\Tools>type result.txt [Syscall Table from C:\SyscallSamples\1809x64\ntdll.dll]


| Syscall Name | Number | Number (hex) |

| NtAdjustGroupsToken | 107 | 0x006B | | NtAdjustPrivilegesToken | 65 | 0x0041 | | NtAdjustTokenClaimsAndDeviceGroups | 108 | 0x006C | | NtCompareTokens | 155 | 0x009B | | NtCreateLowBoxToken | 172 | 0x00AC | | NtCreateToken | 191 | 0x00BF | | NtCreateTokenEx | 192 | 0x00C0 | | NtDuplicateToken | 66 | 0x0042 | | NtFilterToken | 222 | 0x00DE | | NtFilterTokenEx | 223 | 0x00DF | | NtImpersonateAnonymousToken | 246 | 0x00F6 | | NtOpenProcessToken | 290 | 0x0122 | | NtOpenProcessTokenEx | 48 | 0x0030 | | NtOpenThreadToken | 36 | 0x0024 | | NtOpenThreadTokenEx | 47 | 0x002F | | NtQueryInformationToken | 33 | 0x0021 | | NtQuerySecurityAttributesToken | 339 | 0x0153 | | NtSetInformationToken | 404 | 0x0194 |

[] Found 18 syscall(s). [] Filter String : "token"

`-n`(`--number`) 옵션을 사용하면 syscall 번호로 syscall 이름을 다음과 같이 조회할 수 있습니다.
syscall 번호를 16진수 형식으로 지정하려면 "0x"로 시작해야 합니다.```
C:\Tools>SyscallDumper.exe -d C:\dev\SyscallSamples\21H1x64\ntdll.dll -n 85

[>] Loading C:\dev\SyscallSamples\21H1x64\ntdll.dll.
[+] C:\dev\SyscallSamples\21H1x64\ntdll.dll is loaded successfully.
    [*] Architecture : AMD64
    [*] Image Name   : ntdll.dll
[+] Got 470 syscall(s).

[Syscall Table from C:\dev\SyscallSamples\21H1x64\ntdll.dll]

----------------------------------------
| Syscall Name | Number | Number (hex) |
----------------------------------------
| NtCreateFile | 85     | 0x0055       |
----------------------------------------

[*] Found 1 syscall(s).


C:\Tools>SyscallDumper.exe -d C:\dev\SyscallSamples\21H1x64\ntdll.dll -n 0x55

[>] Loading C:\dev\SyscallSamples\21H1x64\ntdll.dll.
[+] C:\dev\SyscallSamples\21H1x64\ntdll.dll is loaded successfully.
    [*] Architecture : AMD64
    [*] Image Name   : ntdll.dll
[+] Got 470 syscall(s).

[Syscall Table from C:\dev\SyscallSamples\21H1x64\ntdll.dll]

----------------------------------------
| Syscall Name | Number | Number (hex) |
----------------------------------------
| NtCreateFile | 85     | 0x0055       |
----------------------------------------

[*] Found 1 syscall(s).

출력 형식을 변경하려면 -f(--format) 옵션을 사용하세요. 현재 C/C++(c), CSharp(cs) 및 Python(py)이 지원됩니다:``` C:\Tools>SyscallDumper.exe -d C:\dev\SyscallSamples\Win11Arm64\ntdll-arm64.dll -f c

[>] Loading C:\dev\SyscallSamples\Win11Arm64\ntdll-arm64.dll. [+] C:\dev\SyscallSamples\Win11Arm64\ntdll-arm64.dll is loaded successfully. [] Architecture : ARM64 [] Image Name : ntdll.dll [+] Got 486 syscall(s).

[Syscall Table from C:\dev\SyscallSamples\Win11Arm64\ntdll-arm64.dll]

enum NT_SYSCALLS { NtAcceptConnectPort = 2, NtAccessCheck = 0, NtAccessCheckAndAuditAlarm = 41,

--snip--

NtWriteVirtualMemory = 58,
NtYieldExecution = 70

}

[*] Found 486 syscall(s).

C:\Tools>SyscallDumper.exe -d C:\dev\SyscallSamples\Win11Arm64\ntdll-arm64.dll -f cs

도구 다운로드