
lockjaw is a modular command-and-control framework pairing a Rust teamserver with an evasive Zig implant, built for authorized red team engagements and adversary simulation against Windows targets.
| Tool | g13net/lockjaw — modular Windows C2 framework with a Rust teamserver, Zig implant, and pure-assembly PIC stagers (v0.2.15, alpha) |
| Category | Command-and-control / red team operations tooling |
| Primary Use | Adversary emulation and authorized red team engagements, generating and controlling evasive Windows implants over HTTP/HTTPS/DNS transports |
| Safe Use | Deployed only in authorized penetration tests, red team engagements, and isolated lab environments with written permission from system owners |
| Telemetry Note | Implant behaviors map to observable tradecraft: AMSI bypass via hardware breakpoints, thread-pool injection evading CreateRemoteThread-based detections but discoverable via NtQuerySystemInformation handle audits, DNS tunneling visible as high-volume Base32 subdomain TXT queries, and a self-destruct sequence that shells out to cmd.exe for file deletion |
lockjaw is a command-and-control framework hosted at g13net/lockjaw, currently at version 0.2.15 and explicitly labeled alpha software by its author. The project is interesting less for its feature checklist than for its architecture: rather than the usual single-language C codebase, it splits responsibilities across three distinct toolchains. A Rust teamserver handles concurrency and listener management, a Zig implant runs on the target with zero external C-runtime dependencies, and pure x64 position-independent assembly stagers bridge the two. The repository metadata confirms the split, listing Zig as the primary language alongside Rust and Zig topics and red-team-oriented tags like c2-framework, adversary-emulation, and command-and-control.
The teamserver is built on Tokio and Axum with Rustls for TLS, persisting state in SQLite via SQLx. What stands out architecturally is the integrated cross-compilation pipeline: when an operator requests a payload, the teamserver invokes the Zig compiler and GNU objcopy on demand to produce the implant binary or raw .bin shellcode. This is a design borrowed from frameworks like Sliver, where payload generation is a first-class server function rather than a separate build step. The teamserver also manages multiple listeners — HTTP, HTTPS, and DNS — that can be started, stopped, and inspected dynamically at runtime without a restart, which is useful for long authorized engagements where transport flexibility matters.
On the target side, the implant is cross-compiled natively for x86_64-windows, runs headless in the .Windows subsystem, and suppresses console windows via ShowWindow(hWnd, SW_HIDE). Its evasion posture is aggressive and well-documented in the README. Indirect syscalls are implemented through the Hell's Gate and Halo's Gate techniques: the implant dynamically extracts System Service Numbers from in-memory ntdll.dll using DJB2 hashing, recovers hooked syscalls by scanning neighboring slots, and jumps directly to legitimate syscall; ret gadgets. This sidesteps user-mode API hooks, call stack inspection, and return-address origin checks — the classic detection surface of direct syscall stubs.
The AMSI bypass, branded "Ghost," is one of the more technically interesting components described. Instead of patching amsi.dll bytes in memory, the implant registers a Vectored Exception Handler via AddVectoredExceptionHandler, triggers an internal exception (0xDEADBEEF) to configure hardware breakpoint registers DR0/DR7 on AmsiScanBuffer, and then catches the resulting EXCEPTION_SINGLE_STEP to zero out RAX — forcing AMSI_RESULT_CLEAN = 0 — before returning execution cleanly. Because it modifies zero .text bytes and never calls SetThreadContext, it evades several classes of tamper detection. The implant is also fully IAT-clean: sensitive Win32/NT APIs are resolved at runtime by walking the PEB's InLoadOrderModuleList and matching function addresses via case-sensitive (djb2) and case-insensitive (djb2_i) hashes, leaving no static imports to fingerprint.
Process migration comes in two flavors, both documented in depth. The reflective path (migrate <pid> reflective) manually maps the agent image into a remote process using dual-mapped shared memory sections — NtCreateSection plus NtMapViewOfSection, mapped RW locally and RWX remotely — deliberately avoiding NtAllocateVirtualMemory and NtWriteVirtualMemory allocations that EDR products flag. The variant the author calls reflective_poolstomp combines reflective mapping with the publicly documented PoolParty technique: it enumerates remote handles via NtQuerySystemInformation to find existing thread pool worker factories (TpWorkerFactory), overwrites the factory's StartRoutine, and triggers execution by adjusting WorkerFactoryThreadMinimum through NtSetInformationWorkerFactory. The explicit design goal is zero new thread creation, defeating detections anchored on CreateRemoteThread and NtCreateThreadEx such as Sysmon Event ID 8. Architecture validation guards against WOW64 mismatches, a common operational failure mode.
The in-memory BOF execution engine implements a COFF loader for AMD64 object files with full relocation handling (IMAGE_REL_AMD64_ADDR64, ADDR32, ADDR32NB, REL32) and resolves imports through the standard __imp__<DLL>$<Function> convention. Notably, it ships a broad Beacon API compatibility layer — BeaconDataParse, BeaconFormatPrintf, BeaconOutput, BeaconIsAdmin, and friends — meaning existing Beacon Object Files from the wider ecosystem should theoretically load without modification. The README is candid that BOF support has not been tested, which is a meaningful caveat for any team evaluating this for real engagements: only teamserver/client comms, the EXE implant, recon commands, and process injection are listed as tested.
Transport diversity is a strength. Beyond the Axum/Rustls HTTPS listener with self-signed certificate auto-generation, the implant speaks WinHTTP with proxy auto-detection, custom Host header support for domain fronting, and a blanket certificate error bypass for operational flexibility. The covert channel is DNS tunneling: the implant encodes checkins and results as Base32-wrapped, RC4-encrypted subdomains (<base32>.<domain>), with tasking delivered back inside TXT records. The DNS listener is implemented natively on the teamserver side using Hickory. All agent-teamserver traffic, regardless of transport, is symmetric RC4-encrypted, and agent identity is derived deterministically from PID, TID, and machine name via a linear congruential generator. Defenders should note that RC4 and Base32 subdomain chatter are both patterned, observable signals.
Post-exploitation capabilities are orthodox: ps enumerates processes with architecture detection via IsWow64Process and — unusually thorough — evaluates Arbitrary Code Guard (ACG) and Control Flow Guard (CFG) mitigations plus token ownership via LookupAccountSidA, which directly informs injection target selection. Service auditing (sc_enum, sc_query), identity checks (whoami, pid), network profiling (ipconfig via GetAdaptersInfo), file management (pwd, ls, cat, upload, download), and shell execution through anonymous pipes round out the set. A self-destruct command shuts the agent down and spawns a detached cleanup process to wipe the binary from disk.
The operator experience is a Python 3 asynchronous TUI built on prompt_toolkit, communicating with the teamserver over an HTTPS REST API on port 50051. It offers real-time checkin alerts, numeric agent indexing, prefix matching, and automatic file transfer synchronization. The teamserver exposes sensible operational controls: configurable operator and listener ports, a static --api-key for the REST API, SQLite persistence at lockjaw.db by default, and separate auto-generated certificates for operator and agent TLS endpoints.
For defenders and detection engineers, lockjaw is a useful case study in modern evasion stacking even if never run operationally: hardware-breakpoint AMSI bypass, thread-pool injection without thread creation, shared-section manual mapping, IAT-clean hashing, and DNS tunneling in one package. For red teams, the honest alpha status, untested BOF loader, absent license file, and small community (26 stars) mean this belongs in a lab, evaluated against your own detection stack, before it touches any authorized engagement. Its value today is educational — a readable, actively engineered reference for how contemporary implant tradecraft is assembled.
g13net/lockjaw.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.