MEMORYRIFT: AN OFFENSIVE SECURITY FRAMEWORK FOR WINDOWS BUFFER OVERFLOW AND POST-EXPLOITATION ANALYSIS
Keywords:
Buffer Overflow, Windows Exploitation, Post Exploitation, Command and Control, XOR Obfuscation, Malware AnalysisAbstract
Cybersecurity research and advanced threat emulation require practical environments capable of demonstrating real-world offensive security concepts in controlled laboratory settings. Traditional approaches often focus on theoretical vulnerability analysis while lacking hands-on exposure to modern exploitation workflows, command-and-control (C2) operations, persistence mechanisms, and post-exploitation behaviors. Existing commercial frameworks frequently abstract critical implementation details into black-box operations, limiting transparency and academic research. This research presents MEMORYRIFT, a lightweight, modular, and fully transparent offensive security framework designed for Windows buffer overflow exploitation and comprehensive post-exploitation analysis. The framework integrates reliable stack-based buffer overflow triggering for arbitrary code execution, XOR-obfuscated encrypted C2 communication (key 0x5A), registry-based persistence, multi-threaded keylogging, remote shell execution, bidirectional file transfer, screenshot capture, anti-debugging techniques, and real-time observability. The Windows payload is implemented in C using WinAPI and Winsock2, while the centralized C2 server is built with Python Flask, providing a clean web-based dashboard. MEMORYRIFT emulates realistic advanced persistent threat (APT) behavior through multi-threaded execution and a transparent architecture. Evaluation in isolated VirtualBox environments (Windows 11 target and Kali Linux attacker) demonstrated 100% buffer overflow reliability, 99% keystroke capture accuracy, 185 ms average command latency, 100% persistence success across reboots, effective anti-debugging, and stable auto-reconnect. The framework bridges theoretical knowledge and practical offensive security workflows under strict ethical and isolated conditions.


