
Import the downloaded vm into VirtualBox, configure a shared folder with auto-mount to the Z drive, log in with the provided credentials, and start the preconfigured Windows 10 environment.
Inspect a real Windows PE file with PE-bear, focusing on headers and sections (.text, .rdata, .data, .pdata, .rsrc, .reloc) and the optional header. Compare with dumpbin to visualize PE metadata.
Compare exe creation and dll creation by examining main and dllmain and their memory loading. Learn to compile, run, and analyze simple exes and dlls using templates.
Learn to create PE files, including a 64-bit implant.exe and a companion implant.dll with DllMain and RunMe exported. Inspect memory layout, module loading, and exported functions to understand PE components.
Examine how droppers deliver payloads to target machines, from simple powershell scripts to executables, and learn how to store payloads in the PE file sections .text, .data, or .rsrc.
Store the payload in the .rsrc section using a resource file, locate and load it via FindResource and LoadResource, and execute the shellcode as calc.exe in a Windows dropper.
Explore payload encoding and encryption, compare their purposes and methods to evade detection, and define plaintext, ciphertext, cipher, key, Base64, AES, and XOR.
HINT:
During code development you might encounter issues with string encryption/encoding. To troubleshoot these problems, check how they are constructed (i.e. how their length is calculated or comparison performed). This should lead you into solving the encountered problems.
Encrypt and decrypt a calc payload using AES, generating a random 16-byte key, producing AES key and ciphertext for a Windows payload, and verify decryption with AESDecrypt in crypto API.
Explore practical function call obfuscation in Windows malware, including removing VirtualProtect from the import table, using GetProcAddress, and XOR-encoded strings to conceal shellcode.
Explore backdooring PE files with trojans that mimic legitimate software to enable initial breach, persistence, privilege escalation, or lateral movement, using code caves, new sections, or extending sections.
Backdooring 32-bit putty.exe using a code cave, pushad/pushfd, and a jump back with shellcode. It demonstrates debugging, patching, and restoring original context.
Define code injection as transferring a payload between processes to preserve sessions and change context, using classic methods such as shellcode injection via debugging API and DLL injection.
Injects a 64-bit messagebox shellcode into notepad.exe by FindTarget(), allocating a remote buffer with VirtualAllocEx, writing the payload, and creating a remote thread.
Discover how dll injection loads a dll into a remote process, such as Outlook.exe, via remote memory and LoadLibrary. Compare classic dll injection with reflective dll injection as an alternative.
Demonstrates how to inject a dll into a remote process by building an injector and a payload dll, using LoadLibrary and CreateRemoteThread to run a shellcode payload.
Learn how to hide a console window in Windows malware using FreeConsole and by compiling as a GUI program with WinMain, avoiding visible prompts during payload execution.
Concludes by reviewing the PE structure, EXE and DLL compilation, and payload storage in .data, .text, and .rsrc. Explores function call obfuscation and previews future topics like hooking and injection.
Are you a pen tester having some experience with Metasploit or Empire frameworks? Or maybe you take your first steps as an ethical hacker and you want to know more about how all these offensive tools work? Or you are a blue teamer or threat hunter who needs to better understand the internal workings of malware?
This course will provide you the answers you're looking for. It will teach you how to develop your own custom malware for latest Microsoft Windows 10. And by custom malware we mean building a dropper for any payload you want (Metasploit meterpreter, Empire or Cobalt Strike beacons, etc.), injecting your shellcodes into remote processes, creating trojan horses (backdooring existing software) and bypassing Windows Defender AV.
You will receive a virtual machine with complete environment for developing and testing your software, and a set of source code templates which will allow you to focus on understanding the essential mechanisms instead of less important technical aspects of implementation.