Projects in Awesome Lists tagged with direct-syscalls
A curated list of projects in awesome lists tagged with direct-syscalls .
https://github.com/virtualalllocex/defcon-31-syscalls-workshop
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
antivirus-bypass antivirus-evasion direct-syscalls edr-bypass edr-evasion indirect-syscalls malware-analysis malware-development malware-development-guide shellcode shellcode-loader syscalls windows-internals workshop
Last synced: 04 Apr 2025
https://github.com/VirtualAlllocEx/Direct-Syscalls-vs-Indirect-Syscalls
The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls
av-bypass av-evasion direct-syscalls edr-bypass edr-evasion indirect-syscalls shellcode-loader windows-int
Last synced: 04 Apr 2025
https://github.com/annihilatorq/shadow_syscall
windows syscalls with a single line and a high level of abstraction. has modern cpp20 wrappers and utilities, range-based DLL and export enumeration, wrapper around KUSER_SHARED_DATA. supported compilers: clang, gcc and msvc
analysis cpp direct-syscalls export getmodulehandle getprocaddress hashing header-only masm obfuscation reverse-engineering shadow-syscalls shellcode syscall syscalls win-internals
Last synced: 04 Apr 2025
https://github.com/virtualalllocex/direct-syscalls-vs-indirect-syscalls
The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls
av-bypass av-evasion direct-syscalls edr-bypass edr-evasion indirect-syscalls shellcode-loader windows-int
Last synced: 11 Jul 2025
https://github.com/voidvxvi/HellBunny
Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks
api-hashing direct-syscalls dll dll-sideloading edr-bypass edr-evasion iat-camouflage indirect-syscalls maldev malware-development msvc native-api ntapi payload-encryption process-injection shellcode-injection shellcode-loader windows
Last synced: 30 Dec 2025
https://github.com/fadouse/bypassetwdirectsyscallshellcodeloader
BypassETWDirectSyscallShellcodeLoader is a robust C++14 application designed for secure and stealthy shellcode execution. It incorporates advanced anti-debugging and anti-sandboxing techniques to evade detection and analysis, making it suitable for penetration testing and security research.
bypass-antivirus direct-syscalls dynamic-api-resolution ettw-bypass injector redteam-tool shellcode-injection shellcode-loader
Last synced: 09 Mar 2026