{"version":1,"pages":[{"id":"ICwJ765nojSV4fRDGRsu","title":"Golang Malware Development","pathname":"/","siteSpaceId":"sitesp_EWHYE","description":""},{"id":"UVzHWEdZWARulO7ABuZb","title":"Golang Programming Intro","pathname":"/malware-development-in-golang-introduction/golang-programming-intro","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Malware Development In Golang - Introduction"}]},{"id":"gPBpbvy5c8MyJ1RRD40L","title":"1. Preparing the Go Environment","pathname":"/malware-development-in-golang-introduction/golang-programming-intro/1.-preparing-the-go-environment","siteSpaceId":"sitesp_EWHYE","description":"#golang","breadcrumbs":[{"label":"Malware Development In Golang - Introduction"},{"label":"Golang Programming Intro"}]},{"id":"FusBHLEfquRWNwEmgxBj","title":"2. Hello World","pathname":"/malware-development-in-golang-introduction/golang-programming-intro/2.-hello-world","siteSpaceId":"sitesp_EWHYE","description":"#golang #helloworld","breadcrumbs":[{"label":"Malware Development In Golang - Introduction"},{"label":"Golang Programming Intro"}]},{"id":"ya3W79Nb1ihRf0VeUcVa","title":"3. Calling MessageBox winAPI from GO","pathname":"/malware-development-in-golang-introduction/golang-programming-intro/3.-calling-messagebox-winapi-from-go","siteSpaceId":"sitesp_EWHYE","description":"#systemprogramming #golang #messagebox","breadcrumbs":[{"label":"Malware Development In Golang - Introduction"},{"label":"Golang Programming Intro"}]},{"id":"lhrpsC85zKiPZ9Vf8QMb","title":"4. Shellcode Runner","pathname":"/malware-development-in-golang-introduction/golang-programming-intro/4.-shellcode-runner","siteSpaceId":"sitesp_EWHYE","description":"#shellcoderunner #golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Malware Development In Golang - Introduction"},{"label":"Golang Programming Intro"}]},{"id":"iMIjo0gwoCyQdDA1CgJc","title":"Shellcode Injection","pathname":"/code-injection-techniques/shellcode-injection","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Code Injection Techniques"}]},{"id":"vK9GagP21CVH6VUra45D","title":"1. Classic Shellcode Injection","pathname":"/code-injection-techniques/shellcode-injection/1.-classic-shellcode-injection","siteSpaceId":"sitesp_EWHYE","description":"#shellcodeinjection #golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Code Injection Techniques"},{"label":"Shellcode Injection"}]},{"id":"ikcTDPf7xXSm7akds9D4","title":"2. Process Hollowing","pathname":"/code-injection-techniques/shellcode-injection/2.-process-hollowing","siteSpaceId":"sitesp_EWHYE","description":"#processhollowing#golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Code Injection Techniques"},{"label":"Shellcode Injection"}]},{"id":"tsX6pot0NjPyHRqfc5hJ","title":"3. QueueUserAPC","pathname":"/code-injection-techniques/shellcode-injection/3.-queueuserapc","siteSpaceId":"sitesp_EWHYE","description":"#processinjection #queueUserAPC #golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Code Injection Techniques"},{"label":"Shellcode Injection"}]},{"id":"rxD3bC3MZyFlqw6w9DQp","title":"DLL Injection","pathname":"/code-injection-techniques/dll-injection","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Code Injection Techniques"}]},{"id":"d53O2xOgdCwKvqCWW2nQ","title":"1. Dll Injection","pathname":"/code-injection-techniques/dll-injection/1.-dll-injection","siteSpaceId":"sitesp_EWHYE","description":"#processinjection #dllinjection #golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Code Injection Techniques"},{"label":"DLL Injection"}]},{"id":"pIMDHR3mWQ7IkgRwtr4V","title":"2. Reflective DLL Injection","pathname":"/code-injection-techniques/dll-injection/2.-reflective-dll-injection","siteSpaceId":"sitesp_EWHYE","description":"#malware #development #golang #dllinjection #reflective #redteam","breadcrumbs":[{"label":"Code Injection Techniques"},{"label":"DLL Injection"}]},{"id":"kssbZYRyWEfs0CGpqGOY","title":"Payloads","pathname":"/payloads/payloads","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Payloads"}]},{"id":"XdyJ253ULEyljoXiSIHH","title":"1. Basic DLL using Golang","pathname":"/payloads/payloads/1.-basic-dll-using-golang","siteSpaceId":"sitesp_EWHYE","description":"#golang #maldev #malwaredevelopment #persistence","breadcrumbs":[{"label":"Payloads"},{"label":"Payloads"}]},{"id":"CdptZR5RzwJtyoc6Dgc2","title":"2. Malicious DLL using Golang","pathname":"/payloads/payloads/2.-malicious-dll-using-golang","siteSpaceId":"sitesp_EWHYE","description":"#golang #maldev #malwaredevelopment #persistence #shellcoderunner","breadcrumbs":[{"label":"Payloads"},{"label":"Payloads"}]},{"id":"oEaHWZ1lN7VZaQw8GQvj","title":"3. Malicious XLL using Golang","pathname":"/payloads/payloads/3.-malicious-xll-using-golang","siteSpaceId":"sitesp_EWHYE","description":"#golang #maldev #malwaredevelopment #persistence #shellcoderunner #excelplugin #xll","breadcrumbs":[{"label":"Payloads"},{"label":"Payloads"}]},{"id":"3tLMBoFtTE4B1cIuSfda","title":"Shellcode development","pathname":"/payloads/shellcode-development","siteSpaceId":"sitesp_EWHYE","description":"#golang #shellcode #x64 #windows #srdi","breadcrumbs":[{"label":"Payloads"}]},{"id":"F2VbK6hoqGmJ4mhmGqlj","title":"1. Keystone Engine","pathname":"/payloads/shellcode-development/1.-keystone-engine","siteSpaceId":"sitesp_EWHYE","description":"#keystone-engine #assembler #golang-bindings","breadcrumbs":[{"label":"Payloads"},{"label":"Shellcode development"}]},{"id":"jUN8cHamsKVGUMv7mlaN","title":"2.  Windows x64 Shellcode Development intro","pathname":"/payloads/shellcode-development/2.-windows-x64-shellcode-development-intro","siteSpaceId":"sitesp_EWHYE","description":"#x64 #shellcode #golang #asm","breadcrumbs":[{"label":"Payloads"},{"label":"Shellcode development"}]},{"id":"SEVssRxkxCBzu14oQeWi","title":"3. Transforming DLLs into Shellcode","pathname":"/payloads/shellcode-development/3.-transforming-dlls-into-shellcode","siteSpaceId":"sitesp_EWHYE","description":"#srdi #golang #assembly #x64 #shellcode #shellcodedevelopment","breadcrumbs":[{"label":"Payloads"},{"label":"Shellcode development"}]},{"id":"vnorjbelLb37XBCYsUXC","title":"AV Bypass","pathname":"/evasion/av-bypass","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Evasion"}]},{"id":"EqF9g7Ci1i5c7jaFc1FN","title":"1. Introduction","pathname":"/evasion/av-bypass/1.-introduction","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"}]},{"id":"sjCwVLR7wlPrJmg6L3Zc","title":"2. Remove the shellcode from the payload","pathname":"/evasion/av-bypass/2.-remove-the-shellcode-from-the-payload","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"}]},{"id":"MF7fyV689dkUKXTKoTOB","title":"3. Delay Execution","pathname":"/evasion/av-bypass/3.-delay-execution","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"}]},{"id":"Y6dzKS8kKYZg3dWZxa6k","title":"1. time.Sleep() 1/2","pathname":"/evasion/av-bypass/3.-delay-execution/1.-time.sleep-1-2","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment #sleep","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"},{"label":"3. Delay Execution"}]},{"id":"8d3XokL4mto50OYeLuHg","title":"2. time.Sleep() 2/2","pathname":"/evasion/av-bypass/3.-delay-execution/2.-time.sleep-2-2","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment #sleep","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"},{"label":"3. Delay Execution"}]},{"id":"WMSUeGtI9hiwFgOuw0y5","title":"3. Custom Sleep function","pathname":"/evasion/av-bypass/3.-delay-execution/3.-custom-sleep-function","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment #sleep","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"},{"label":"3. Delay Execution"}]},{"id":"WN1RmGLKqCHk94vLNaFf","title":"4. XOR Encryption","pathname":"/evasion/av-bypass/4.-xor-encryption","siteSpaceId":"sitesp_EWHYE","description":"#AVEvasion #Golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"}]},{"id":"apEzlTLRWXPniYQtidjm","title":"5. AMSI Bypass","pathname":"/evasion/av-bypass/5.-amsi-bypass","siteSpaceId":"sitesp_EWHYE","description":"#amsi #amsibypass #golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Evasion"},{"label":"AV Bypass"}]},{"id":"kuFKjblPTRGN74nZwrmm","title":"EDR Bypass","pathname":"/evasion/edr-bypass","siteSpaceId":"sitesp_EWHYE","description":"#EDREvasion #Golang #maldev #malwaredevelopment","breadcrumbs":[{"label":"Evasion"}]},{"id":"8gHDM6ACnoVVf4LRmoNX","title":"1. Setting up a testing environment","pathname":"/evasion/edr-bypass/1.-setting-up-a-testing-environment","siteSpaceId":"sitesp_EWHYE","description":"#OpenEDR #xcitium #elastic","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"}]},{"id":"aZBDKk4VpZhM7sJayioD","title":"2. Userland Hooks","pathname":"/evasion/edr-bypass/2.-userland-hooks","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"}]},{"id":"Z51xjunPgJB0bkspsuKl","title":"1. What are userland hooks?","pathname":"/evasion/edr-bypass/2.-userland-hooks/1.-what-are-userland-hooks","siteSpaceId":"sitesp_EWHYE","description":"#EDREvasion #UserlandHooks","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"2. Userland Hooks"}]},{"id":"r2XrvT6a9zU4u5JmB7kS","title":"2. Load a fresh copy of the dll from disk","pathname":"/evasion/edr-bypass/2.-userland-hooks/2.-load-a-fresh-copy-of-the-dll-from-disk","siteSpaceId":"sitesp_EWHYE","description":"#EDREvasion #UserlandHooks #unhook","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"2. Userland Hooks"}]},{"id":"MnVNX3XTdmQeai7qeWSH","title":"3. Programmatically detect ntdll hooks","pathname":"/evasion/edr-bypass/2.-userland-hooks/3.-programmatically-detect-ntdll-hooks","siteSpaceId":"sitesp_EWHYE","description":"#EDREvasion #UserlandHooks #unhook","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"2. Userland Hooks"}]},{"id":"IGaIQPCsMPbMKO7w6pt4","title":"4. Direct and Indirect Syscalls (shellcode runner)","pathname":"/evasion/edr-bypass/2.-userland-hooks/4.-direct-and-indirect-syscalls-shellcode-runner","siteSpaceId":"sitesp_EWHYE","description":"#syscalls #directsyscalls #indirectsyscalls #Golang #EDREvasion","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"2. Userland Hooks"}]},{"id":"kev1xlnN44XVAZBEidET","title":"3. VPN abuse for Endpoint Protection Evasion","pathname":"/evasion/edr-bypass/3.-vpn-abuse-for-endpoint-protection-evasion","siteSpaceId":"sitesp_EWHYE","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"}]},{"id":"mpIWOu5TNlyPJQZIRNw7","title":"1. Global Protect Abuse 1/2","pathname":"/evasion/edr-bypass/3.-vpn-abuse-for-endpoint-protection-evasion/1.-global-protect-abuse-1-2","siteSpaceId":"sitesp_EWHYE","description":"#globalprotect #redteaming #globalprotect #VPNabuse","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"3. VPN abuse for Endpoint Protection Evasion"}]},{"id":"EVn6vXRIroPutCJAiha4","title":"2. Global Protect Abuse 2/2","pathname":"/evasion/edr-bypass/3.-vpn-abuse-for-endpoint-protection-evasion/2.-global-protect-abuse-2-2","siteSpaceId":"sitesp_EWHYE","description":"#globalprotect #redteaming #globalprotect #VPNabuse","breadcrumbs":[{"label":"Evasion"},{"label":"EDR Bypass"},{"label":"3. VPN abuse for Endpoint Protection Evasion"}]}]}