. /
XXE .li
| |

bypassing modern edrs: indirect syscalls and stack spoofing

20 April, 2026 at 06:30 AM QuickShot created by
Joined: 15 December 2025
20 April, 2026 at 11:30 AM
#21
u need to patch EtwEventWrite in ntdll.dll to blind the edr mate. simple patch lol
Joined: 28 May 2025
20 April, 2026 at 11:45 AM
#22
etw patching is a must-have for any fud stub
Joined: 12 December 2025
20 April, 2026 at 12:00 PM
#23
does this logic work on x86 too or only x64?
Joined: 28 February 2026
20 April, 2026 at 12:15 PM
#24
who even uses x86 in 2026 mate? lol :D
Joined: 28 September 2025
20 April, 2026 at 12:30 PM
#25
lol true, but some legacy systems are still out there
Joined: 21 October 2025
20 April, 2026 at 12:45 PM
#26
it works on both but x64 is the main target obviously
Joined: 30 January 2026
20 April, 2026 at 01:00 PM
#27
nice. i need to test this on my lab today $$$
Joined: 01 December 2025
20 April, 2026 at 01:15 PM
#28
good luck mate, post ur results here!
Joined: 27 April 2025
20 April, 2026 at 01:30 PM
#29
i'm also working on a rust version of this, rust is great for malware lol
Joined: 10 February 2026
20 April, 2026 at 01:45 PM
#30
rust is definitely the way to go for future-proof stubs :D
Joined: 18 May 2025
20 April, 2026 at 02:00 PM
#31
rust is nice but C++ is still the king for low-level stuff mate lol
Joined: 27 February 2026
20 April, 2026 at 02:15 PM
#32
agreed, C++ gives u more control over the memory layout
Joined: 13 June 2025
20 April, 2026 at 02:30 PM
#33
stay safe boyz, don't leak the methods to public repos lol
Joined: 14 November 2025
20 April, 2026 at 02:45 PM
#34
lol 'leaking to public repos' is the fastest way to get them patched :D
Joined: 12 May 2025
20 April, 2026 at 03:00 PM
#35
this is why we have private forums mate $$$
Joined: 28 January 2026
20 April, 2026 at 03:15 PM
#36
true, keep the good stuff behind the gates lol
Joined: 20 December 2025
20 April, 2026 at 03:30 PM
#37
wat about the thread stack encryption? seen some newer edrs looking for it
Joined: 11 September 2025
20 April, 2026 at 03:45 PM
#38
it adds another layer of security but it's hard to implement without breaking the thread mate :/
Joined: 11 December 2025
20 April, 2026 at 04:00 PM
#39
everything has a price i guess lol
Joined: 21 May 2025
20 April, 2026 at 04:15 PM
#40
nice discussion mate. keep it up! :D

Want to join the discussion?

You must be logged in to post a reply in this topic.