Significant changes have been made to the core framework; however, the functionality and syntax remain the same as version 3.1.0. Additionally, a change has been made to Windows staged payloads.
When using staged payloads, the use of Netcat is no longer encouraged. Instead, a handler module has been integrated for quick deployment of second stage stubs.
Sickle v4 offers newly added shellcode stubs including:
- windows/aarch64/shell_reverse_tcp
- windows/x64/egghunter
- windows/x64/virtualalloc_exec_tcp
- windows/x64/virtualalloc_exec_https
- windows/x64/reflective_pe_loader
Sickle v4 has also added EXITFUNC features to select payloads.