stack-spoofing-dev

Installation
SKILL.md

Stack Spoofing — Windows x64

Produce a spoofed call stack that survives unwinder-based inspection (ETW-TI, EDR stack walkers, StackWalk64). Each frame must have a legitimate .pdata entry, an unwind description that matches the planted frame size, and a return address that points inside a known module's .text.

This skill assumes you already understand .pdata / UNWIND_INFO at the level described in windows-internals/references/exception-unwind.md. It focuses on implementing the spoofer, not on teaching the format.

When to activate

  • Implementing or reviewing Draugr / SilentMoonwalk / NtContinue / YouMayPasser / VulcanRaven / Unwinder spoofers in C, C++, Rust, Go, or Plan9 ASM
  • Choosing between spoof strategies for a specific Windows build or thread context (main, TP worker, alertable, console-attached)
  • Debugging spoof_init: FAIL jmp_rbx or unwinder-reported frame-size mismatches
  • Adjusting MinJmpRbxFrameSize / MinAddRspX thresholds after .pdata inventory changes across Windows builds
  • Integrating a spoofer with an indirect syscall dispatcher (RecycleGate / Hell's / FreshyCalls)
  • Hardening a pre-existing spoofer against modern EDR correlation (Eclipse, SAVE_NONVOL safety, backed-vs-unbacked caller)
  • Porting a spoofer between languages without breaking the ASM/context-struct contract

If the question is "what does UNWIND_INFO look like" → wrong skill, read windows-internals/references/exception-unwind.md. If the question is "how do I make NtWriteVirtualMemory appear to come from RtlUserThreadStart" → right skill.


Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
stack-spoofing-dev — aeondave/malskill