Indirect Syscalls
our assembly ntdll.dll
+-----------------------+ +-----------------------+
| | | |
| mov exa, <ssn> | | mov exa, <ssn> |
| jmp <addr of syscall> | ----------->| syscall |
| | | ret |
+-----------------------+ +-----------------------+

Last updated