WS5 - Creating Shellcode for Hackers
Description
Instructed by: Bramwell “Bw3ll” Brizendine
Level of Difficulty: Intermediate, Advanced
Abstract:
Creating shellcode is for the brave! This workshop takes a modern approach to the time-honored tradition of Windows shellcode creation. Intended for those with intermediate to advanced knowledge, we will refresh x86 assembly and cover Windows internals.
You will create Win32/WoW64 shellcode with NASM before moving onto intermediate, multi-API shellcode. Along the way, we will cover GetPC, position independence, bad characters, calling conventions, stack discipline, manual API resolution through the PEB/TEB, export walking, name/hash-based resolution, strings, and passing handles or pointers between calls.
For evasion, we will explore manual/automated encoding techniques, making our shellcode self-modifying. We will also cover advanced techniques, including direct Windows syscalls with ShellWasp. You will learn Windows structures, native API parameter handling, and creating persistence with syscalls. Expect to be made privy to many shellcoding tips and tricks to bring out the best in your shellcode.
By the end, you'll be able to: Create Windows shellcode using NASM; launch and debug it; resolve and chain WinAPIs by name or hash; obfuscate and encode shellcode; integrate direct syscalls with ShellWasp.
Prep: Study x86 assembly and basic Windows debugging. A VM will be provided. Required: modern PC (Intel) / VM
Pre-Requisites:
Students should have basic comfort reading and writing beginner's x86 assembly. We will review some concepts. Basic Windows debugging experience is helpful but not needed. Prior shellcode writing experience is not expected. A Windows VM and lab materials will be provided. VM should be on a modern Intel machine (avoid M2 Macs due to incompatibility with Intel Assembly). Student may use own machine with VM if they set up the software (instructions will be provided).
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


