Skip to main content

Overview

The shellcode command provides capabilities for injecting raw shellcode into processes using either process injection (into existing processes) or fork & run (spawning new processes). Multiple injection techniques are supported with varying OPSEC profiles.

Syntax

Injection Methods

inject

Inject shellcode into an existing process.
string
required
Architecture of the shellcode:
  • x86 - 32-bit shellcode
  • x64 - 64-bit shellcode
integer
required
Process ID of the target process to inject into
string
required
Local path to the raw shellcode file (will be uploaded to agent)
string
Optional arguments to pass to the shellcode (base64 encoded)

spawn

Spawn a new process and inject shellcode (fork & run).
string
required
Architecture:
  • x86 - Spawns 32-bit process
  • x64 - Spawns 64-bit process
string
required
Local path to the raw shellcode file
string
Optional arguments to pass to the shellcode

execute

Execute shellcode directly in the current process.
Executing shellcode in-process is risky and may crash the agent if the shellcode is incompatible or malformed.

Injection Techniques

The injection technique can be configured using the config command:
Uses the default injection method configured in the profile.Process Flow:
  1. Open target process
  2. Allocate memory (respects config memory.alloc)
  3. Write shellcode
  4. Protect memory (respects config memory.execute)
  5. Create thread (respects config inject.technique)

Memory Allocation Techniques

Configure memory allocation method:
  • 0 - VirtualAllocEx (Win32 API)
  • 1 - NtAllocateVirtualMemory (Indirect syscall)

Memory Protection Techniques

Configure memory protection method:
  • 0 - VirtualProtectEx (Win32 API)
  • 1 - NtProtectVirtualMemory (Indirect syscall)

Return Values

string
Injection result:
  • INJECT_ERROR_SUCCESS (0) - Injection succeeded
  • INJECT_ERROR_FAILED (1) - General failure
  • INJECT_ERROR_INVALID_PARAM (2) - Invalid parameters
  • INJECT_ERROR_PROCESS_ARCH_MISMATCH (3) - Architecture mismatch
integer
Thread ID of the created thread (if successful)

Examples

Basic Process Injection

Fork & Run with Configured Spawn Process

Advanced Injection with Custom Technique

Shellcode with Arguments

32-bit Injection

OPSEC Considerations

Shellcode injection is heavily monitored by EDR solutions. Use indirect syscalls and legitimate spawn processes.

Process Selection

Good Injection Targets:
  • Long-running system processes
  • Processes with legitimate network activity
  • Processes matching your shellcode architecture
Avoid:
  • Protected processes (PPL)
  • Antivirus/EDR processes
  • System critical processes (csrss.exe, lsass.exe)

Spawn Process Selection

Configure legitimate-looking spawn processes:

API Call Flow

Depending on configuration, the following API sequence is used: INJECTION_TECHNIQUE_SYSCALL with all syscall options:
  1. CreateProcessA (spawning only)
  2. NtAllocateVirtualMemory* (indirect syscall)
  3. NtWriteVirtualMemory* (indirect syscall)
  4. NtProtectVirtualMemory* (indirect syscall)
  5. NtCreateThreadEx* or NtQueueApcThread* (indirect syscall)
  6. NtResumeThread* (indirect syscall)
Note: * indicates indirect syscall usage

Memory Permissions

  • Avoid RWX memory if possible (highly suspicious)
  • Use RW allocation, write shellcode, then change to RX
  • Configure with memory.alloc and memory.execute

Detection Vectors

  1. Process Open: Opening handles to inject into processes
  2. Memory Allocation: Allocating executable memory in remote processes
  3. Thread Creation: Creating threads in remote processes
  4. Memory Permissions: RWX memory regions
  5. Shellcode Signatures: Known beacon/payload signatures

Use Cases

Cobalt Strike Beacon Injection

Metasploit Payload Injection

Custom Shellcode Runner

Architecture Mismatch

Injecting shellcode into a process with mismatched architecture will fail:
  • Cannot inject x64 shellcode into x86 process
  • Cannot inject x86 shellcode into x64 process (WoW64 exception may apply)
Always verify target process architecture:

Configuration Summary

Notes

  • Shellcode files are automatically chunked for upload (max 30MB per chunk)
  • Injection respects the configured injection technique
  • Failed injections return error codes for troubleshooting
  • Always test shellcode in a lab environment first
  • Some shellcode (like Cobalt Strike beacons) may require specific arguments
  • Suspended processes created with proc create suspended are good injection targets