Why indirect syscalls slip past some EDR hooks
A conceptual look at why user-mode hooking is a leaky abstraction — and what that means for defenders who rely on it.
Tag
1 post · all tags
A conceptual look at why user-mode hooking is a leaky abstraction — and what that means for defenders who rely on it.