LACUNA Chain: Ghost Frames — defeats all EDR layers of call-stack-based detection
This is Part II. If you haven’t read Part I — HookChain, go do that first. Part I showed how to defeat userland NTDLL hooks with IAT manipulation, dynamic SSN resolution, and indirect syscalls. Tha...