├── .github ├── images │ ├── frida-poc.gif │ ├── hades-banner.png │ └── syscall-detect-poc.gif └── workflows │ └── release.yml ├── .gitignore ├── .golangci.yml ├── CHANGELOG.md ├── LICENSE ├── Makefile ├── README.md ├── cmd ├── hades │ └── main.go └── hasher │ └── main.go ├── go.mod ├── go.sum ├── internal └── loader │ ├── loader.go │ ├── ptr.go │ ├── runner.go │ ├── wrappers.go │ ├── wrappers_common.go │ └── wrappers_direct.go ├── pkg ├── hashing │ └── xorhash.go └── syscalls │ ├── direct_syscalls_amd64.s │ └── stubs.go └── scripts ├── NtQueueApcThread.js └── NtWriteVirtualMemory.js /.github/images/frida-poc.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.github/images/frida-poc.gif -------------------------------------------------------------------------------- /.github/images/hades-banner.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.github/images/hades-banner.png -------------------------------------------------------------------------------- /.github/images/syscall-detect-poc.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.github/images/syscall-detect-poc.gif -------------------------------------------------------------------------------- /.github/workflows/release.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.github/workflows/release.yml -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.gitignore -------------------------------------------------------------------------------- /.golangci.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/.golangci.yml -------------------------------------------------------------------------------- /CHANGELOG.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/CHANGELOG.md -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/LICENSE -------------------------------------------------------------------------------- /Makefile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/Makefile -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/README.md -------------------------------------------------------------------------------- /cmd/hades/main.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/cmd/hades/main.go -------------------------------------------------------------------------------- /cmd/hasher/main.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/cmd/hasher/main.go -------------------------------------------------------------------------------- /go.mod: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/go.mod -------------------------------------------------------------------------------- /go.sum: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/go.sum -------------------------------------------------------------------------------- /internal/loader/loader.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/loader.go -------------------------------------------------------------------------------- /internal/loader/ptr.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/ptr.go -------------------------------------------------------------------------------- /internal/loader/runner.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/runner.go -------------------------------------------------------------------------------- /internal/loader/wrappers.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/wrappers.go -------------------------------------------------------------------------------- /internal/loader/wrappers_common.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/wrappers_common.go -------------------------------------------------------------------------------- /internal/loader/wrappers_direct.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/internal/loader/wrappers_direct.go -------------------------------------------------------------------------------- /pkg/hashing/xorhash.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/pkg/hashing/xorhash.go -------------------------------------------------------------------------------- /pkg/syscalls/direct_syscalls_amd64.s: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/pkg/syscalls/direct_syscalls_amd64.s -------------------------------------------------------------------------------- /pkg/syscalls/stubs.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/pkg/syscalls/stubs.go -------------------------------------------------------------------------------- /scripts/NtQueueApcThread.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/scripts/NtQueueApcThread.js -------------------------------------------------------------------------------- /scripts/NtWriteVirtualMemory.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/f1zm0/hades/HEAD/scripts/NtWriteVirtualMemory.js --------------------------------------------------------------------------------