shc just wraps scripts in C, so tools like auditd or bpftrace can still see them.
I solved this by bundling an interpreter (like BusyBox) and the script into a single static binary. Bypassing system shells like /bin/sh keeps the script hidden from kernel-level monitoring.
I also added LLVM obfuscation and anti-debugging to make reverse engineering harder.
I just meant that by embedding cat or ls, we don't need to pass arguments externally. This skips the execution events (like execve) that monitors look for.
21
u/masiroo 5d ago
shc just wraps scripts in C, so tools like auditd or bpftrace can still see them.
I solved this by bundling an interpreter (like BusyBox) and the script into a single static binary. Bypassing system shells like /bin/sh keeps the script hidden from kernel-level monitoring.
I also added LLVM obfuscation and anti-debugging to make reverse engineering harder.