← LibraryTechnique entry
EDR-INDIRECT-SYSCALLDefense Evasion
Indirect Syscall (Tartarus' Gate)
Jump to a clean syscall stub inside ntdll's own memory after hook check — preserves call-stack origin, defeats stack-walk EDR.
§ Where this technique fits
EDR-INDIRECT-SYSCALL is catalogued under the Defense Evasion tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.