SkillAgentSearch skills...

WowGrail

PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)

Install / Use

/learn @aaaddress1/WowGrail
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

wowGrail

Rebuild a new to Abuse the conversion layer embedded in WOW64(Windows 32 on Windows 64), that makes malware able to launch 32-bit NTAPI interrupts, and bypass Antivirus agents in no time.

It's a proof-of-concept of the talk of HITB 2021. There are more details about reversing the whole WOW64 layer by Microsoft and abuse, see Rebuild The Heaven's Gate: from 32 bit Hell back to Heaven Wonderland.

HIGHLY RECOMMEND

Compile It in Release mode, if you're using MSVC toolchain. Due to MSVC's performance instrumentation in Debug mode, there'll be an unexpected memory layout.

Demo

Related Skills

View on GitHub
GitHub Stars109
CategoryDevelopment
Updated8mo ago
Forks25

Languages

C++

Security Score

92/100

Audited on Jul 24, 2025

No findings