
Rust Weaponization for Red Team Engagements.
My experiments in weaponizing Rust for implant development and general offensive operations.
mingw toolchain, although certain libraries cannot be compiled successfully in other OSes.| File | Description |
|---|---|
| Allocate_With_Syscalls | It uses NTDLL functions directly with the ntapi Library |
| Create_DLL | Creates DLL and pops up a msgbox, Rust does not fully support this so things might get weird since Rust DLL do not have a main function |
| DeviceIoControl | Opens driver handle and executing DeviceIoControl |
| EnableDebugPrivileges | Enable SeDebugPrivilege in the current process |
| Shellcode_Local_inject | Executes shellcode directly in local process by casting pointer |
| Execute_With_CMD | Executes cmd by passing a command via Rust |
| ImportedFunctionCall | It imports minidump from dbghelp and executes it |
| Kernel_Driver_Exploit | Kernel Driver exploit for a simple buffer overflow |
| Named_Pipe_Client | Named Pipe Client |
| Named_Pipe_Server | Named Pipe Server |
| PEB_Walk | Dynamically resolve and invoke Windows APIs |
| Process_Injection_CreateThread | Process Injection in running process with CreateThread |
| Process_Injection_CreateRemoteThread | Process Injection in remote process with CreateRemoteThread |
| Process_Injection_Self_EnumSystemGeoID | Self injector that uses the EnumSystemsGeoID API call to run shellcode. |
| Unhooking | Unhooking calls |
| asm_syscall | Obtaining PEB address via asm |
| base64_system_enum | Base64 encoding/decoding strings |
| http-https-requests | HTTP/S requests by ignoring cert check for GET/POST |
| patch_etw | Patch ETW |
| ppid_spoof | Spoof parent process for created process |