{"id":19456712,"url":"https://github.com/x0reaxeax/syscook64","last_synced_at":"2025-10-18T05:02:18.247Z","repository":{"id":162274181,"uuid":"636850537","full_name":"x0reaxeax/SysCook64","owner":"x0reaxeax","description":"Indirect Syscall invocation via thread hijacking","archived":false,"fork":false,"pushed_at":"2023-05-05T20:09:33.000Z","size":13,"stargazers_count":14,"open_issues_count":0,"forks_count":3,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-04-05T11:39:53.207Z","etag":null,"topics":["detection-evasion","edr-bypass","edr-evasion","hook-bypass","indirect-syscall","redteam","thread-context"],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/x0reaxeax.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-05-05T19:50:59.000Z","updated_at":"2024-12-23T06:07:40.000Z","dependencies_parsed_at":null,"dependency_job_id":"514520cb-5086-49f3-a98c-09cdb80f4e5e","html_url":"https://github.com/x0reaxeax/SysCook64","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x0reaxeax%2FSysCook64","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x0reaxeax%2FSysCook64/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x0reaxeax%2FSysCook64/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x0reaxeax%2FSysCook64/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/x0reaxeax","download_url":"https://codeload.github.com/x0reaxeax/SysCook64/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248985186,"owners_count":21193900,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["detection-evasion","edr-bypass","edr-evasion","hook-bypass","indirect-syscall","redteam","thread-context"],"created_at":"2024-11-10T17:18:14.812Z","updated_at":"2025-10-18T05:02:18.184Z","avatar_url":"https://github.com/x0reaxeax.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# SysCook64 - Cooking thread contexts for fun and profit\n\n## What is this?\nThis is a PoC technique for indirect syscall execution, by suspending, altering and resuming a thread.  \nThe target thread's context is modified in order to land on a `syscall` instruction in `NTDLL` (we're doing `NtAllocateVirtualMemory`), with registers and stack prepared for syscall execution.  \nThere's no need for syscall stubs, since all the arguments are written directly to the target's thread context, while it's suspended.  \n\n## Demo\n[YouTube](https://youtu.be/HU47BmJJw98)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fx0reaxeax%2Fsyscook64","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fx0reaxeax%2Fsyscook64","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fx0reaxeax%2Fsyscook64/lists"}