This repository is provided strictly for educational purposes, academic research, and authorized defensive testing. The code has been completely defanged—the shellcode byte array is empty, and target destinations point to unroutable example.com placeholders. The author does not support or condone unauthorized use of this material.
This repository contains a structural Go-based automation script designed to demonstrate payload encoding, encapsulation, and HTTP request delivery mechanics.
Rather than executing an exploit directly, this script models the delivery layer: it reads a structural payload layout from an external JSON file, injects a placeholder shellcode variable, and packages the data into an outbound HTTP POST request.
The logic is fully contained and safe for open-source analysis:
- Defanged Shellcode: The
rawShellcodebyte slice is explicitly left empty to prevent arbitrary code execution. - Placeholder Targeting: The destination endpoint is hardcoded to a benign
http://example.comdestination. - JSON Marshalling: Demonstrates how automation scripts dynamically pack
EncodedShellcodeinto JSON structures before transport. - TLS Transport Settings: Utilizes custom
tls.ConfigwithInsecureSkipVerify: trueto emulate how security tools bypass self-signed certificate constraints in local lab environments.
When analyzing scripts that use this transport logic (such as Metasploit stagers or custom runners), defenders should look for the following artifacts:
- Network Logs: High-frequency or automated HTTP POST requests targeting specific APIs containing large base64 or string-encoded payload blocks (
EncodedShellcode). - TLS Certificates: Outbound TLS connections to unfamiliar servers that utilize self-signed or unverified certificates, correlating with the
InsecureSkipVerifylogic. - Process Analysis: If paired with memory injection payloads (like VNC injectors), monitor processes for anomalous
WinINetAPI interactions or unusual remote thread allocations.
-
Create a dummy JSON file named
payload.jsonwith a basic structure (e.g.,{"Target": "Test"}). -
Update the
payloadFilepath string in the script constants to point to your test file. -
Run the Go builder:
go build WeapingAngel.go