stack-spoofing-dev
Installation
SKILL.md
Stack Spoofing — Windows x64
Produce a spoofed call stack that survives unwinder-based inspection (ETW-TI, EDR stack walkers, StackWalk64). Each frame must have a legitimate .pdata entry, an unwind description that matches the planted frame size, and a return address that points inside a known module's .text.
This skill assumes you already understand .pdata / UNWIND_INFO at the level described in windows-internals/references/exception-unwind.md. It focuses on implementing the spoofer, not on teaching the format.
When to activate
- Implementing or reviewing Draugr / SilentMoonwalk / NtContinue / YouMayPasser / VulcanRaven / Unwinder spoofers in C, C++, Rust, Go, or Plan9 ASM
- Choosing between spoof strategies for a specific Windows build or thread context (main, TP worker, alertable, console-attached)
- Debugging
spoof_init: FAIL jmp_rbxor unwinder-reported frame-size mismatches - Adjusting
MinJmpRbxFrameSize/MinAddRspXthresholds after.pdatainventory changes across Windows builds - Integrating a spoofer with an indirect syscall dispatcher (RecycleGate / Hell's / FreshyCalls)
- Hardening a pre-existing spoofer against modern EDR correlation (Eclipse, SAVE_NONVOL safety, backed-vs-unbacked caller)
- Porting a spoofer between languages without breaking the ASM/context-struct contract
If the question is "what does UNWIND_INFO look like" → wrong skill, read windows-internals/references/exception-unwind.md. If the question is "how do I make NtWriteVirtualMemory appear to come from RtlUserThreadStart" → right skill.