TOOL: DarkWidow | Soumyanil Biswas @WildWestHackinFest
TOOL: DarkWidow | Soumyanil Biswas  @WildWestHackinFest
Uploaded February 2025 | Updated September 2026, 2 weeks ago
πŸ”— Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences β€” wildwesthackinfest.com

πŸ”— Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com

Links to the demos used in this presentation:

DarkWidow V1 : Evade ( NonAdmin process) Sophos XDR : "Call For Tools" Demo
youtube.com/watch?v=YEe3HccdvBk

DarkWidow V1: Evade (Admin privilege process) Sophos XDR: "Call For Tools" Demo
youtube.com/watch?v=IL-FpKS_LzY

DarkWidow V2 - Synthetic Frame Thread Stack Spoofing Enabled
youtube.com/watch?v=HqtXD3CJg9k

This is a Dropper/Post-Exploitation Tool targeting Windows machines.
Its capabilities include:
1. Indirect Dynamic Syscall
2. SSN + Syscall address sorting via Modified TartarusGate approach
3. Remote Process Injection via APC Early Bird (MITRE ATT&CK TTP: T1055.004)
4. Spawning a sacrificial Process as the target process
5. ACG(Arbitrary Code Guard)/BlockDll mitigation policy on spawned process
6. PPID spoofing (MITRE ATT&CK TTP: T1134.004)
7. Api resolving from TIB (Directly via offset (from TIB) - TEB - PEB - resolve Nt Api) (MITRE ATT&CK TTP: T1106)
8. Cursed Nt API hashing
9. With Admin privileges:
Disables Event Log via killing all threads of svchost.exe, i.e. killing the whole process (responsible svchost.exe)

Finally, I will showcase my tool demo video which would perform a successful Execution of payload and provide
crystal clear Event Log against Sophos XDR enabled Environment.

Version 2 has Synthetic Frame Thread Stack Spoofing version enabled.
It will be released at BlackHat Asia 2024 on April 18th, 2024,

///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) β€” Wild West Hackin' Fest: wildwesthackinfest.com
TOOL: DarkWidow | Soumyanil BiswasThe Terminator Effect: AIs Role in Fighting Cyber Threats | James McQuiggan | WWHF 2023Building a Winning Team Culture | Heath Adams | WWHF 2023Offensive Lab Environments (Without the Suck) | Travis KaunGiving Swords to Our Future AI Overlords | Matt Lee and Eric StevensWere All Scared, Too: 10 Years of Lessons from Cybersecurity Mentorship | Lesley Carhart | WWHF2023The Secrets of USAF Debriefing Methodology Will Make You a Better Hacker | Josh Mason | WWHF 2023From Sore to SOAR: Reinventing Sentinel Automation Without Logic Apps | Henri HambartsumyanBuild your Sh*tty Add-On With KiCad For Your Electronic Badges! | Adrien Lasalle
Wild West Hackin Fest |

TOOL: DarkWidow | Soumyanil Biswas

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER