← ./resources / blog

Stardust Shellcode Framework: A Defender's Field Guide

Stardust-style frameworks help developers organize position-independent native code. For defenders, the important lesson is not a repository fingerprint: self-contained code still has to discover APIs, manage data, obtain executable memory, and interact with the operating system.

Defensive scope

No build instructions, loaders, payload code, or deployment guidance are included. Analyze only benign fixtures or evidence collected under authorization.

What the framework concept means

Position-independent code (PIC) avoids assuming a fixed image base. A framework commonly separates a compact entry component, configuration or instance data, API discovery, and task-specific logic. That improves portability, but it also creates recognizable behavioral requirements. Windows still mediates object access, virtual memory, threads, files, registry keys, and network connections.

PIC framework and observation layersEntry + dataself-locationAPI andmodule discoveryMemory +executionKernel, EDR,network evidenceStable signals: private executable pages · non-image thread starts · runtime resolution · unusual call stacks
Implementation changes can remove static fingerprints, but they cannot remove every operating-system effect.

Static and memory clues

Static triage may reveal compact code, embedded configuration, hashed constants, few imports, or routines that walk loaded modules. None is conclusive. In memory, ask whether a region is private or image-backed, how its protections changed, whether its bytes correspond to a known file, and whether thread instruction pointers or return addresses land there. Just-in-time runtimes and security products create legitimate exceptions, so signer, parent process, prevalence, and workload role must travel with the alert.

Detection strategy

  • Correlate executable private memory with the process that created or modified it.
  • Identify thread starts and sampled stacks outside trusted image mappings.
  • Baseline applications that legitimately resolve many APIs at runtime.
  • Join memory anomalies to file origin, identity, child processes, and destinations.
  • Alert on behavior sequences, not the framework name or a single byte pattern.

Safe lab and GitHub tools

Use a snapshot-backed VM and a harmless PIC demonstration that only returns a constant or writes a local test marker. Compare compiler output and memory maps without adding injection or networking. capa and FLOSS support static triage; PE-sieve, Volatility 3, Sysmon, and WinDbg support memory and timeline validation. Record expected benign events before testing detections.

ATT&CK, CVEs, and mitigation

Observed use may map to T1055 Process Injection, T1027 Obfuscated Files or Information, or T1106 Native API. Stardust is a development pattern and framework, not a vulnerability; no CVE should be assigned merely because PIC is present. Mitigate with application control, least privilege, ASR rules, protected administrative workstations, memory telemetry, and rapid containment of anomalous processes while preserving volatile evidence.

← Previous: Msfvenom vs. DonutNext: CrystalPalace PIC →