EarlyBird is an educational implementation of the Early Bird APC (Asynchronous Procedure Call) Injection technique written in Zig for Windows systems. This project demonstrates a code injection method that leverages Windows' APC mechanism to execute shellcode in a target process.
APC (Asynchronous Procedure Call) injection is a code injection technique that takes advantage of Windows' APC mechanism. The Early Bird variant works by:
- Creating a target process in a suspended state
- Allocating memory within the target process
- Writing shellcode to the allocated memory region
- Modifying memory permissions to make the region executable
- Queuing an APC that points to the shellcode
- Resuming the main thread, which triggers APC execution
- Process Creation: Uses
CreateProcessWwithCREATE_SUSPENDEDorDEBUG_PROCESSflags - Memory Allocation: Leverages
VirtualAllocExfor remote memory allocation - Memory Writing: Utilizes
WriteProcessMemoryto inject shellcode - Permission Changes: Employs
VirtualProtectExto make memory executable - APC Queuing: Uses
QueueUserAPCto schedule shellcode execution - Thread Management: Controls thread execution with
ResumeThread
┌─────────────────┐ ┌──────────────────┐ ┌─────────────────┐
│ EarlyBird │───▶│ Target Process │───▶│ Shellcode │
│ (Injector) │ │ (Suspended) │ │ Execution │
└─────────────────┘ └──────────────────┘ └─────────────────┘
│ │ │
▼ ▼ ▼
Create Process ──▶ Allocate Memory ──▶ Queue APC
│ │ │
▼ ▼ ▼
Write Shellcode ──▶ Change Permissions ──▶ Resume Thread
Combined options:
zig build run -Dprocessname=calc.exe -Dcreateprocess=suspended| Option | Description | Default | Values |
|---|---|---|---|
processname |
Target process executable name | notepad.exe |
Any valid executable name |
createprocess |
Process creation method | debug |
suspended, debug |
# Inject into notepad.exe using debug mode
zig build run# Inject into calc.exe using suspended mode
zig build run -Dprocessname=calc.exe -Dcreateprocess=suspended