Skip to content

πŸ”§ NullSec Stealth - Advanced evasion & anti-forensics toolkit | Crystal, Lua, D, Haskell, V | Steganography, process masking, timestamp manipulation, covert channels, fileless execution

License

Notifications You must be signed in to change notification settings

bad-antics/nullsec-stealth

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ‘» NullSec Stealth

Advanced Evasion & Anti-Forensics Toolkit

Discord GitHub License

Crystal Lua D Haskell V

    β–ˆβ–ˆβ–ˆβ–„    β–ˆ  β–ˆ    β–ˆβ–ˆ  β–ˆβ–ˆβ–“     β–ˆβ–ˆβ–“      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  β–„β–ˆβ–ˆβ–ˆβ–ˆβ–„  
    β–ˆβ–ˆ β–€β–ˆ   β–ˆ  β–ˆβ–ˆ  β–“β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–’    β–“β–ˆβ–ˆβ–’    β–’β–ˆβ–ˆ    β–’ β–“β–ˆ   β–€ β–’β–ˆβ–ˆβ–€ β–€β–ˆ  
   β–“β–ˆβ–ˆ  β–€β–ˆ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ  β–’β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘    β–’β–ˆβ–ˆβ–‘    β–‘ β–“β–ˆβ–ˆβ–„   β–’β–ˆβ–ˆβ–ˆ   β–’β–“β–ˆ    β–„ 
   β–“β–ˆβ–ˆβ–’  β–β–Œβ–ˆβ–ˆβ–’β–“β–“β–ˆ  β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘    β–’β–ˆβ–ˆβ–‘      β–’   β–ˆβ–ˆβ–’β–’β–“β–ˆ  β–„ β–’β–“β–“β–„ β–„β–ˆβ–ˆβ–’
   β–’β–ˆβ–ˆβ–‘   β–“β–ˆβ–ˆβ–‘β–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–’β–’ β–“β–ˆβ–ˆβ–ˆβ–€ β–‘
   β–‘ β–’β–‘   β–’ β–’ β–‘β–’β–“β–’ β–’ β–’ β–‘ β–’β–‘β–“  β–‘β–‘ β–’β–‘β–“  β–‘β–’ β–’β–“β–’ β–’ β–‘β–‘β–‘ β–’β–‘ β–‘β–‘ β–‘β–’ β–’  β–‘
     β–‘    β–‘    β–‘   β–‘   β–‘         β–‘            β–‘   β–‘   β–‘        
   β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„
   β–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘ S T E A L T H β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–ˆ
   β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€
                       bad-antics

πŸ”“ Join discord.gg/killers for premium features!


🎯 Features

Tool Language Description Free Premium
stegohide Crystal Advanced steganography encoder βœ… πŸ”₯
procmask Lua Process name/memory masking βœ… πŸ”₯
timewarp D Timestamp manipulation βœ… πŸ”₯
cryptchan Haskell Encrypted covert channels ❌ πŸ”₯
ghostmem V Fileless memory execution ❌ πŸ”₯
avbypass Crystal AV signature evasion ❌ πŸ”₯

πŸ“ Structure

nullsec-stealth/
β”œβ”€β”€ crystal/
β”‚   └── stegohide.cr      # Steganography encoder/decoder
β”œβ”€β”€ lua/
β”‚   └── procmask.lua      # Process masking utility
β”œβ”€β”€ dlang/
β”‚   └── timewarp.d        # Timestamp manipulation
β”œβ”€β”€ haskell/
β”‚   └── cryptchan.hs      # Encrypted covert channels
└── vlang/
    └── ghostmem.v        # Fileless memory execution

πŸ”§ Installation

Crystal - StegoHide

cd crystal
crystal build stegohide.cr --release -o stegohide
./stegohide encode -i secret.txt -c cover.png -o output.png

Lua - ProcMask

cd lua
lua procmask.lua --pid 1234 --name "systemd"

D - TimeWarp

cd dlang
dmd -release -O timewarp.d -of=timewarp
./timewarp --file target.exe --time "2020-01-01 00:00:00"

Haskell - CryptChan

cd haskell
ghc -O2 cryptchan.hs -o cryptchan
./cryptchan --mode server --port 443 --key mykey

V - GhostMem

cd vlang
v -prod ghostmem.v -o ghostmem
./ghostmem --payload shellcode.bin --target pid

πŸ’€ Tool Details

StegoHide (Crystal)

Advanced steganography tool supporting multiple carrier formats:

  • PNG/BMP - LSB encoding with encryption
  • JPEG - DCT coefficient manipulation
  • WAV/MP3 - Audio spectrum hiding
  • PDF - Whitespace encoding
  • AES-256 encryption for payloads

ProcMask (Lua)

Process evasion and masking utility:

  • Rename running process in memory
  • Mask command line arguments
  • Hollow process injection setup
  • Parent PID spoofing preparation
  • Module list manipulation

TimeWarp (D)

Timestamp manipulation for anti-forensics:

  • Modify MACB timestamps (Modified, Accessed, Changed, Birth)
  • Recursive directory timestamp matching
  • Random timestamp within range
  • Clone timestamps from reference file
  • NTFS $STANDARD_INFO and $FILE_NAME manipulation

CryptChan (Haskell)

Encrypted covert communication channels:

  • DNS tunneling with encryption
  • ICMP covert channel
  • HTTP header smuggling
  • TLS certificate field hiding
  • Timing-based channels

GhostMem (V)

Fileless payload execution:

  • Direct syscall execution
  • Memory-only payload loading
  • Process hollowing
  • Module stomping
  • Thread execution hijacking

⚠️ Legal Disclaimer

FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY

These tools are designed for:

  • Red team engagements
  • Penetration testing
  • Security research
  • Educational purposes

Unauthorized use against systems you don't own or have permission to test is illegal.


πŸ“œ License

NullSec Proprietary License - See LICENSE for details.

Premium features require a valid key from discord.gg/killers


Discord β€’ GitHub β€’ Tools

Made with πŸ’€ by bad-antics

About

πŸ”§ NullSec Stealth - Advanced evasion & anti-forensics toolkit | Crystal, Lua, D, Haskell, V | Steganography, process masking, timestamp manipulation, covert channels, fileless execution

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published