LLM Skills
~/catalog/automated workflows//SKILL
Automated workflowsGitHub source

Offensive shellcode

/SKILL

Shellcode development reference for offensive security engagements. Use when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode loaders, evading AV/EDR

SnailSploitSnailSploit
2.8k
May 8, 2026
MIT License
// skill content

--- name: offensive-shellcode description: "A shellcode development reference for offensive security engagements. Use this when writing custom x86/x64 shellcode, implementing position-independent code (PIC), building shellcode loaders, evading AV/EDR detection, or converting PE files to shellcode. Covers null byte avoidance,API hashing, encoder/decoder patterns, staged vs. stageless payloads, Windows PEB traversal, and cross-platform shellcode techniques." --- ## Shellcode Development Workflow 1. Define the concept and target platform (x86/x64, Windows/Linux/macOS .) 2. Write assembly code using position-independent techniques 3. Extract the binary and test it in a controlled environment 4. Apply null byte avoidance and optimizations 5. Encode/encrypt to evade static detection 6. Package with a loader and choose a delivery method --- ## Basic Concepts ### Execution Pattern (Allocate-Write-Execute) Avoid direct “PAGE_EXECUTE_READWRITE ”:prefer: 1. Allocate using “PAGE_READWRITE ” 2. Write shellcode to the allocated region 3. Call `VirtualProtect to switch toPAGEEXECUTEREAD `c char *dest = VirtualAlloc(NULL, 0x1234, MEM_COMMIT|MEM_RESERVE, PAGE_READWRITE); memcpy(dest, shellcode, 0x1234); VirtualProtect(dest, 0x1234, PAGE_EXECUTE_READ, &old); ((void(*)())dest)(); ` ### Position-Independent Code (PIC) Techniques | Method | Platform | Notes | |--------|----------|-------| | Call/Pop | Windows | Push next addr, pop into register | | FPU state | Windows | fstenv saves instruction pointer | | SEH | Windows | Exception handler stores EIP | | GOT | Linux | Global Offset Table | | VDSO | Linux | Kernel-provided shared object | --- ## Windows API Resolution (PEB Walk) Identifying kernel32.dll without imports: 1. Get PEB via gs:[0x60] (x64) or fs:[0x30] (x86) 2. Walk PEB->Ldr.InMemoryOrderModuleList : order: exe → ntdll → kernel32 3. Hash-compare module names to locate kernel32 4. Parse the Export Address Table (EAT) 5. Find GetProcAddress by name hash, then resolve LoadLibraryA 6. Use LoadLibraryA to load WS2_32 .dll, resolve Winsock functions **WinDbg helpers for debugging PEB walk:** `bash dt nt!_TEB -y ProcessEnvironmentBlock @$teb dt nt!_PEB -y Ldr <peb_addr> dt -r _PEB_LDR_DATA <ldr_addr> dt _LDR_DATA_TABLE_ENTRY (<init_flink_addr> - 0x10) lm m kernel32 # verify base address r @r8 # check register ` --- ## Shellcode Loaders ### Loader Responsibilities - Environment verification / keying (sandbox detection) - Shellcode decryption - Safe memory allocation and injection - Ends its duties after injecting **Recommended languages:** Zig (small, no runtime), Rust (secure), Nim, Go (watch for runtime signatures) ### Allocation Phase Avoid RWX allocations : use two-step: - VirtualAllocEx / NtAllocateVirtualMemory : allocate RW - ZwCreateSection + NtMapViewOfSection : alternative approach - After writing: VirtualProtectEx to switch to RX **Other options:** code caves, stack/heap (with DEP disabled) ### Write Phase - WriteProcessMemory / NtWriteVirtualMemory - memcpy to mapped section **Evasion tips:** - Prepend shellcode with dummy opcodes - Split into chunks, write in randomized order - Add delays between writes ### Execute Phase Most scrutinized step : EDR checks thread start address against image-backed memory: | Technique | Notes | |-----------|-------| | CreateRemoteThread / ZwCreateThreadEx | Loud, heavily monitored | | NtSetContextThread | Hijack suspended thread | | NtQueueApcThreadEx` | APC injection | |API trampolines | Overwrite function prologue | | ThreadlessInject | No new threads created | Indirect execution resources: - FlavorTown - AlternativeShellcodeExec - ThreadlessInject --- ## PE-to-Shellcode Conversion | Tool | Purpose | |------|---------| | Donut | EXE/DLL → shellcode | | sRDI | DLL → position-independent shellcode | | Pe2shc | PE → shellcode | | [Amber](https://github.com/EgeBal

// original public source
SnailSploit/Claude-Red
/Skills/infrastructure/offensive-shellcode/SKILL.md
License: MIT License
Independent project, not affiliated with Anthropic. This skill remains the property of its original author.
// install this skill
Paste this command in your terminal at the root of your project:
mkdir -p .claude/commands && curl -o ".claude/commands/SKILL.md" "https://raw.githubusercontent.com/SnailSploit/Claude-Red/main/Skills/infrastructure/offensive-shellcode/SKILL.md"
Then in Claude Code, type /SKILL to activate it.
open_in_newOpen original source
// save
Save available after sign in.
loginSign in to save
// information
Stars 2.8k
LicenseMIT License
UpdatedMay 8, 2026
Format.md
AccessFree
// similar

Skills Automated workflows

View allarrow_forward