Zum Hauptinhalt springen
AI & KI NachrichtenVirginia Takes Aim at Data Center Development, Energy Use(19.09.2026 um 00:18 Uhr)
Unix & Linux ServerSecurity: Ausführen beliebiger Kommandos in Rclone (Ubuntu)(18.09.2026 um 19:57 Uhr)
Unix & Linux ServerSecurity: Pufferüberlauf in gstreamer1-plugins-bad-free (Red Hat)(19.09.2026 um 00:54 Uhr)
Sichere ProgrammierungCopilot code review: An improved review experience(18.09.2026 um 22:17 Uhr)
Sichere ProgrammierungExpose Crypto KAT Runners as MCP Tools Instead of Pasting Hex(18.09.2026 um 23:27 Uhr)
AI & KI NachrichtenVirginia Takes Aim at Data Center Development, Energy Use(19.09.2026 um 00:18 Uhr)
Unix & Linux ServerSecurity: Ausführen beliebiger Kommandos in Rclone (Ubuntu)(18.09.2026 um 19:57 Uhr)
Unix & Linux ServerSecurity: Pufferüberlauf in gstreamer1-plugins-bad-free (Red Hat)(19.09.2026 um 00:54 Uhr)
Sichere ProgrammierungCopilot code review: An improved review experience(18.09.2026 um 22:17 Uhr)
Sichere ProgrammierungExpose Crypto KAT Runners as MCP Tools Instead of Pasting Hex(18.09.2026 um 23:27 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

HallWatch: Usermode indirect syscall detection

Hello everyone! I built a C++ usermode detector for indirect syscalls called HallWatch.

GitHub: https://github.com/Zypherion-Technologies/HallWatch

Most usermode detections hook the start of Nt* stubs in ntdll. Modern techniques like Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls can bypass those hooks by jumping directly to the syscall instruction.

HallWatch takes a different approach: instead of patching the stub prologue, it patches the syscall instruction itself:

0F 05 -> CC 05

Any execution path that reaches the syscall byte triggers an INT3 breakpoint, allowing the detector to inspect the caller, validate the SSN, unwind the stack, and redirect execution through a private trampoline.

It also includes detection for Hell's Gate and shadow ntdll mappings by scanning executable memory for syscall stubs.

Still a research project / PoC. it is impossible to fully detect syscalls in user-mode without some kind of debugger or tracer stepping over the code to monitor everything, but this is still a good light-weight technique to do so for system libraries.

But I'd still love feedback from people interested in Windows internals, EDRs and malware analysis to see how we could improve it.

submitted by /u/AhmedMinegames
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten HallWatch: Usermode indirect syscall detection

Thematisch verwandte Begriffe: HallWatch, Usermode, indirect, syscall · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick