Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

WeapingAngel

Structural Proof of Concept (PoC) Runner in Go

⚠️ Disclaimer

This repository is provided strictly for educational purposes, academic research, and authorized defensive testing. The code has been completely defanged—the shellcode byte array is empty, and target destinations point to unroutable example.com placeholders. The author does not support or condone unauthorized use of this material.

📌 Overview

This repository contains a structural Go-based automation script designed to demonstrate payload encoding, encapsulation, and HTTP request delivery mechanics.

Rather than executing an exploit directly, this script models the delivery layer: it reads a structural payload layout from an external JSON file, injects a placeholder shellcode variable, and packages the data into an outbound HTTP POST request.

🛠️ Code Functionality & Defanging

The logic is fully contained and safe for open-source analysis:

  • Defanged Shellcode: The rawShellcode byte slice is explicitly left empty to prevent arbitrary code execution.
  • Placeholder Targeting: The destination endpoint is hardcoded to a benign http://example.com destination.
  • JSON Marshalling: Demonstrates how automation scripts dynamically pack EncodedShellcode into JSON structures before transport.
  • TLS Transport Settings: Utilizes custom tls.Config with InsecureSkipVerify: true to emulate how security tools bypass self-signed certificate constraints in local lab environments.

🔍 Behavioral Indicators for Defenders

When analyzing scripts that use this transport logic (such as Metasploit stagers or custom runners), defenders should look for the following artifacts:

  • Network Logs: High-frequency or automated HTTP POST requests targeting specific APIs containing large base64 or string-encoded payload blocks (EncodedShellcode).
  • TLS Certificates: Outbound TLS connections to unfamiliar servers that utilize self-signed or unverified certificates, correlating with the InsecureSkipVerify logic.
  • Process Analysis: If paired with memory injection payloads (like VNC injectors), monitor processes for anomalous WinINet API interactions or unusual remote thread allocations.

🚀 Local Lab Setup

  1. Create a dummy JSON file named payload.json with a basic structure (e.g., {"Target": "Test"}).

  2. Update the payloadFile path string in the script constants to point to your test file.

  3. Run the Go builder:

    go build WeapingAngel.go

    We present "WeapingAngel" We defanged this because others might use it for illegal intent, which we do not support nor encourage. dont be a skid haha

About

A defanged Go script modeling payload encoding and JSON/HTTP delivery mechanics for educational research.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages