Skip to main content

SysPlant - Your syscall factory

Project description

..:: SysPlant ::..

Your Syscall Factory (feat. Canterlot's Gate)

Canterlot's Gate

PyPI version Supported Python versions Build Status Project Licence PyPI downloads Code Quality Code Coverage Code style: Black Documentation Status

SysPlant is a python generation tool of the currently known syscall hooking methods. It currently supports following gates (aka: iterators):

  • Hell's Gate : Lookup syscall by first opcodes
  • Halos's Gate : Lookup syscall by first opcodes and search nearby if first instruction is a JMP
  • Tartarus' Gate : Lookup syscall by first opcodes and search nearby if first or third instruction is a JMP
  • FreshyCalls : Lookup syscall by name (start with Nt and not Ntdll), sort addresses to retrieve syscall number
  • SysWhispers2 : Lookup syscall by name (start with Zw), sort addresses to retrieve syscall number
  • SysWhispers3 : SysWhispers2 style but introduce direct/indirect/random jump with static offset
  • Canterlot's Gate ! :unicorn: :rainbow: (from an initial idea of MDSEC article) but who was missing a pony name : Lookup syscall using Runtime Exception Table (sorted by syscall number) and detect offset to syscall instruction for random jumps.
  • Custom Allows you to choose an iterator and a syscall stub method (direct / indirect / random) which describe the way your NtFunctions will be effectively called.

:warning: DISCLAIMER
Please only use this tool on systems you have permission to access.
Usage is restricted to Pentesting or Education only.
All credits are based on my own research, please feel free to claim any method if I made mistakes...


Introduction

This personal project aims to be a simple tool to better understand & generate different syscall retrieval methods, and being able to play with direct / indirect syscall stub. The first goal was to get my hands into NIM and then it overflow to C and Rust :wink: ...
SysPlant has been developped for Linux users, some stuff might be broken within Windows or Mac. PR are welcome if you found anything that does not work as expected.

Supported Languages

Language Status Cross-compile from Linux
NIM :white_check_mark: Stable nim c -d=mingw --cpu=amd64
C :white_check_mark: Stable x86_64-w64-mingw32-gcc
Rust :white_check_mark: Stable cargo build --target x86_64-pc-windows-gnu

What is iterator option ?

Sysplant is based on existing mechanisms for syscall number and addresses retrieval. I do not claim any of their discovery, I just harmonize all this methods in a single tool to be able to generate them easily using templates. These mechanisms are called iterator, if you look at the code you'll probably understand why :wink:
If you want to go further in the explanations of what is a syscall ? you should check @Alice Climent blogpost about syscalls techniques

What is method option ?

One your iterator has been choosen you can then specify a method option based on the existing way to call syscalls. All the iterator are supported which let you select whatever you want as a final syscall stub.

  1. Direct: the syscall is made directly in the Sysplant ASM call. You only need the syscall number but AV/EDR might see you...
  2. Indirect: the Sysplant ASM call jump to the begining of Ntdll stub. You only need syscall address and no longer call syscall in your code but AV/EDR might hook these functions
  3. Random: the Sysplant ASM call jump to a random syscall instruction of Ntdll stubs. You need the syscall number and 1 syscall instruction address. You then no longer call syscall in your code and can avoid hooked functions.

Sysplant Stubs

Documentation

I've tried to keep an up to date documentation, so please READ THE DOC. You will find there many information about the tool's usages and a complete description of the classes and methods.

Some specifics usages are described:

Credits

Massive shout-out to these useful projects that helps me during this journey, or individuals for their reviews

:construction: TODO

This project is in WIP state...
Some PR & reviews are more than welcome :tada: !

  • Add internal names randomization
  • Setup documentation
  • Setup tests
  • Add x86 support
  • Add WoW64 support
  • Setup NIM templates
  • Setup C templates
  • Setup Rust templates
  • Setup Go / CPP / C# / Whatever templates

License

This project is licensed under the GPLv3 License, for individuals only. If you want to integrate this work in your commercial project please contact me through 0x42en[at]gmail.com

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sysplant-0.4.0.tar.gz (159.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sysplant-0.4.0-py3-none-any.whl (198.6 kB view details)

Uploaded Python 3

File details

Details for the file sysplant-0.4.0.tar.gz.

File metadata

  • Download URL: sysplant-0.4.0.tar.gz
  • Upload date:
  • Size: 159.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for sysplant-0.4.0.tar.gz
Algorithm Hash digest
SHA256 6896df1393f016d5f19e84eb1d6875ace54494154a8d80550170f3a85df86217
MD5 b5e3520dbc50689eaf8d51c320b76969
BLAKE2b-256 bf664c40acbb97a193c141c2ef8c284c0b290f76bff752f475e7bdf1384b59c6

See more details on using hashes here.

File details

Details for the file sysplant-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: sysplant-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 198.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for sysplant-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c2ec699a2d4d4dcc8805400f48b97ab7f302e63d9e3f8d574a65509678566296
MD5 430fc8585c1481911d3023a6dc764fa4
BLAKE2b-256 282e7028f3008335d686799f84b9c438c0e428aad4f9a84518019e6bdeeda7b3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page