
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>0xf4de Blog</title>
      <link>https://blog.0xf4de.com/blog</link>
      <description>Offensive security, C2 infrastructure, shellcode, and lab builds from 0xf4de.</description>
      <language>en-us</language>
      <managingEditor> (Chad Wilson)</managingEditor>
      <webMaster> (Chad Wilson)</webMaster>
      <lastBuildDate>Fri, 06 Mar 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://blog.0xf4de.com/tags/shellcode/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://blog.0xf4de.com/blog/writing-a-stager</guid>
    <title>Writing a Stager</title>
    <link>https://blog.0xf4de.com/blog/writing-a-stager</link>
    <description>We build a shellcode stager in C that fetches Apollo over the network in chunks, loads it with NT-layer calls, and executes it. Along the way we get into SSNs, indirect syscalls, what your call stack looks like to a defender, and why your stager and C2 redirectors should never be the same box.</description>
    <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
    <author> (Chad Wilson)</author>
    <category>c2</category><category>mythic</category><category>stagers</category><category>shellcode</category><category>indirect-syscalls</category><category>red-team</category><category>offensive</category><category>edr</category>
  </item>

    </channel>
  </rss>
