<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Lockjaw on CyberVeille</title>
    <link>https://cyberveille.ch/tags/lockjaw/</link>
    <description>Recent content in Lockjaw on CyberVeille</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>fr-fr</language>
    <copyright>Cyberveille CC BY-NC-SA 4.0</copyright>
    <lastBuildDate>Fri, 10 Apr 2026 00:00:00 +0200</lastBuildDate>
    <atom:link href="https://cyberveille.ch/tags/lockjaw/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Lockjaw v0.2.15 : nouveau framework C2 offensif modulaire en Rust/Zig pour red team</title>
      <link>https://cyberveille.ch/posts/2026-04-10-lockjaw-v0-2-15-nouveau-framework-c2-offensif-modulaire-en-rust-zig-pour-red-team/</link>
      <pubDate>Fri, 10 Apr 2026 00:00:00 +0200</pubDate>
      <guid>https://cyberveille.ch/posts/2026-04-10-lockjaw-v0-2-15-nouveau-framework-c2-offensif-modulaire-en-rust-zig-pour-red-team/</guid>
      <description>&lt;h2 id=&#34;-contexte&#34;&gt;🧩 Contexte&lt;/h2&gt;
&lt;p&gt;Publié sur GitHub (&lt;a href=&#34;https://github.com/g13net/lockjaw)&#34;&gt;https://github.com/g13net/lockjaw)&lt;/a&gt;, cet article est la documentation officielle de &lt;strong&gt;Lockjaw v0.2.15&lt;/strong&gt;, un framework de &lt;strong&gt;command-and-control (C2)&lt;/strong&gt; open source à destination des équipes red team et des simulations adversariales. Le projet est en &lt;strong&gt;phase alpha&lt;/strong&gt; et n&amp;rsquo;a pas encore fait l&amp;rsquo;objet d&amp;rsquo;une revue de code complète.&lt;/p&gt;
&lt;h2 id=&#34;-architecture&#34;&gt;🏗️ Architecture&lt;/h2&gt;
&lt;p&gt;Lockjaw repose sur une architecture multi-composants :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Teamserver&lt;/strong&gt; : écrit en &lt;strong&gt;Rust&lt;/strong&gt; (Tokio/Axum/Rustls), gère les checkins agents, la distribution de tâches, les listeners et la persistance via &lt;strong&gt;SQLite&lt;/strong&gt;. Intègre un pipeline de cross-compilation à la demande via &lt;strong&gt;Zig&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implant&lt;/strong&gt; : écrit en &lt;strong&gt;Zig&lt;/strong&gt;, ciblant &lt;code&gt;x86_64-windows&lt;/code&gt;, sans dépendance externe au C-runtime.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stagers&lt;/strong&gt; : assembleur x64 position-independent (PIC) et cradles PowerShell.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Operator CLI&lt;/strong&gt; : interface TUI asynchrone en &lt;strong&gt;Python 3&lt;/strong&gt; (prompt_toolkit).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-techniques-dévasion&#34;&gt;🛡️ Techniques d&amp;rsquo;évasion&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Indirect Syscalls (Hell&amp;rsquo;s Gate + Halo&amp;rsquo;s Gate)&lt;/strong&gt; : extraction des SSNs depuis &lt;code&gt;ntdll.dll&lt;/code&gt; en mémoire via hachage DJB2, avec scanning des voisins pour récupérer les syscalls hookés.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ghost AMSI Bypass&lt;/strong&gt; : neutralisation d&amp;rsquo;AMSI via &lt;strong&gt;Hardware Breakpoints (DR0/DR7)&lt;/strong&gt; et &lt;strong&gt;Vectored Exception Handling&lt;/strong&gt;, sans modification de la mémoire &lt;code&gt;.text&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IAT-Clean &amp;amp; Dynamic API Resolution&lt;/strong&gt; : zéro import statique pour les APIs sensibles, résolution dynamique via parcours du PEB et hachage DJB2.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Communications chiffrées RC4&lt;/strong&gt; : chiffrement symétrique de toutes les communications agent-teamserver.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-Destruct&lt;/strong&gt; : suppression du binaire via commande détachée asynchrone.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-injection-de-processus&#34;&gt;💉 Injection de processus&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Reflective Manual Mapping&lt;/strong&gt; (&lt;code&gt;migrate &amp;lt;pid&amp;gt; reflective&lt;/code&gt;) : mapping PE dans un processus distant via sections mémoire partagées (&lt;code&gt;NtCreateSection&lt;/code&gt; + &lt;code&gt;NtMapViewOfSection&lt;/code&gt;), sans &lt;code&gt;NtAllocateVirtualMemory&lt;/code&gt;/&lt;code&gt;NtWriteVirtualMemory&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PoolParty Injection&lt;/strong&gt; (&lt;code&gt;migrate &amp;lt;pid&amp;gt; reflective_poolstomp&lt;/code&gt;) : exploitation des worker factories de thread pool (&lt;code&gt;TpWorkerFactory&lt;/code&gt;) via &lt;code&gt;NtSetInformationWorkerFactory&lt;/code&gt;, sans création de thread distant (contourne Sysmon Event ID 8).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-transports&#34;&gt;📡 Transports&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HTTP/HTTPS&lt;/strong&gt; : listener Axum/Rustls avec support du &lt;strong&gt;domain fronting&lt;/strong&gt; via header &lt;code&gt;Host&lt;/code&gt; personnalisé.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DNS Tunneling&lt;/strong&gt; : tunneling DNS covert via requêtes TXT autoritatives, payload encodé en &lt;strong&gt;Base32 + RC4&lt;/strong&gt; dans les sous-domaines.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-post-exploitation&#34;&gt;🔧 Post-exploitation&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Exécution de &lt;strong&gt;Beacon Object Files (BOF)&lt;/strong&gt; AMD64 en mémoire avec loader COFF intégré.&lt;/li&gt;
&lt;li&gt;Commandes de reconnaissance : &lt;code&gt;ps&lt;/code&gt;, &lt;code&gt;whoami&lt;/code&gt;, &lt;code&gt;ipconfig&lt;/code&gt;, &lt;code&gt;sc_enum&lt;/code&gt;, &lt;code&gt;sc_query&lt;/code&gt;, &lt;code&gt;pid&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Gestion de fichiers : &lt;code&gt;ls&lt;/code&gt;, &lt;code&gt;cat&lt;/code&gt;, &lt;code&gt;rm&lt;/code&gt;, &lt;code&gt;upload&lt;/code&gt;, &lt;code&gt;download&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Exécution shell via &lt;code&gt;cmd.exe /c&lt;/code&gt; sans fenêtre.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-type-darticle&#34;&gt;📌 Type d&amp;rsquo;article&lt;/h2&gt;
&lt;p&gt;Il s&amp;rsquo;agit d&amp;rsquo;une &lt;strong&gt;publication de nouveaux outils&lt;/strong&gt; offensifs open source, dont le but principal est de documenter les capacités et l&amp;rsquo;utilisation du framework C2 Lockjaw pour des opérations red team.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
