discovered 03 Aug 2026
SyscallInjector
→ View on GitHubSyscallInjector is a stealthy DLL injector designed to execute direct syscalls on Windows, effectively bypassing endpoint detection and antivirus hooks. Its notable features include dynamic resolution of System Service Numbers, manual PE mapping, and the use of RWX memory allocation to circumvent commonly hooked functions. Additionally, it incorporates a mechanism to wipe shellcode after execution to further evade detection.