/EDR_Evasion_101

Ways to evade EDR hooking using ntdll unhooking and direct syscall.

Primary LanguageC

EDR Hooking Evasion

The repository is based on EDR hook evasion, and we cover topics such as Ntdll Unhooking, Direct and Indirect Syscall.

In my blog, I delve deeper into the explanation, for more information: https://oblivions-research.gitbook.io/