Loader features
A loader feature is stub-level configuration, not a runtime: step. It
changes how the generated stub is built, how it talks to the kernel, or how it
resolves the payload’s imports, so it carries no payload and is not ordered in
the pipeline. The ordered preparations/executions/controls are
techniques.
The registry (src/features/mod.rs) is metadata-only: picaro techniques list
prints the features in their own table, picaro techniques show <name> renders a
feature’s README, and picaro techniques validate checks the registry.
Registered features
Section titled “Registered features”| Feature | Scope | ATT&CK | Stability | Summary |
|---|---|---|---|---|
| syscalls | loader | T1106 | stable | Resolves NT SSNs at runtime and calls the kernel through an ntdll syscall; ret gadget, so the suspicious Win32 imports leave the IAT. |
| api_resolution | loader | T1106 | experimental | Serves selected payload imports from proxies built on the syscall layer, so the shadowed names never enter the loader’s IAT. |
| strings | loader | T1027 | stable | Obfuscates every sensitive string literal in the generated stub and rebuilds it at runtime. |
| args | payload | T1036, T1055 | stable | Fixes the payload’s command line at build time and merges it with the runtime arguments. |