{"repo":"x42en/sysplant","free":true,"listed":false,"github":"https://github.com/x42en/sysplant","clone":"git clone https://github.com/x42en/sysplant.git","description":"Your Windows syscall hooking factory - feat Canterlot's Gate - All accessible over MCP","language":"Nim","stars":132,"topics":["syscalls","windows","c","edr-bypass","framework","hacking","hooking","nim","offensive-tools","python"],"license":"GPL-3.0","category":"mcp-servers","readme_excerpt":"..:: SysPlant ::.. Your Syscall Factory (feat. Canterlot's Gate) SysPlant is a python generation tool of the currently known syscall hooking methods. It currently supports following gates (aka: iterators): - Hell's Gate : Lookup syscall by first opcodes - Halos's Gate : Lookup syscall by first opcodes and search nearby if first instruction is a JMP - Tartarus' Gate : Lookup syscall by first opcodes and search nearby if first or third instruction is a JMP - FreshyCalls : Lookup syscall by name (start with Nt and not Ntdll), sort addresses to retrieve syscall number - SysWhispers2 : Lookup syscall by name (start with Zw), sort addresses to retrieve syscall number - SysWhispers3 : SysWhispers2 style but introduce direct/indirect/random jump with static offset - Canterlot's Gate ! :unicorn: :rainbow: (from an initial idea of MDSEC article) but who was missing a pony name : Lookup syscall using Runtime Exception Table (sorted by syscall number) and detect offset to syscall instruction for random jumps. - Custom Allows you to choose an iterator and a syscall stub method (direct / indirect / random / egg hunter) which describe the way your NtFunctions will be effectively called. :warning: DISCLAIMER Please only use this tool on systems you have permission to access. Usage is restricted to Pentesting or Education only. All credits are based on my own research, please feel free to claim any method if I made mistakes... --- Introduction This personal project aims to be a simple tool to","default_branch":null,"files":null,"tree":[],"storefront":"/r/x42en","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/x42en/sysplant/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}