Skip to content
← LibraryTechnique entry
EDR-INDIRECT-SYSCALLDefense Evasion

Indirect Syscall (Tartarus' Gate)

Jump to a clean syscall stub inside ntdll's own memory after hook check — preserves call-stack origin, defeats stack-walk EDR.

§ Where this technique fits

EDR-INDIRECT-SYSCALL is catalogued under the Defense Evasion tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.