SkillAgentSearch skills...

Sigma

Execute shellcode with ZwCreateSection, ZwMapViewOfSection, ZwOpenProcess, ZwMapViewOfSection and ZwCreateThreadEx

Install / Use

/learn @mobdk/Sigma
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

Sigma

Execute shellcode with ZwCreateSection, ZwMapViewOfSection, ZwOpenProcess, ZwMapViewOfSection and ZwCreateThreadEx

This PoC show how to use the above syscall and use hex editor to embed Mimikatz "inside" a C# string, breaking the syntax of C# string, Mimikatz is read from memory.

Sigma.cs is source code Sigma.dll compiled version with Mimikatz embedded

PoC vid showing compiling and execution on Windows 10 64bit with Defender active, the 15 sec. wait break Defender timing.

https://youtu.be/YTy3cdPoL_o

View on GitHub
GitHub Stars15
CategoryDevelopment
Updated9mo ago
Forks4

Languages

C#

Security Score

67/100

Audited on Jun 10, 2025

No findings