S β€” Layered Evasion Framework

A multi-layered evasion framework combining Hell’s Hall indirect syscalls, PEB-based API hashing, IAT camouflage, custom CRT removal, ntdll unhooking via KnownDlls, sandbox detection, self-deletion, and Fiber-based shellcode execution β€” built to understand and demonstrate how modern offensive tooling evades EDR/AV at every layer.

May 13, 2026 Β· 18 min Β· MrAzoth

Direct Syscall Injection with Custom API Resolution

A shellcode injector that bypasses userland hooks by resolving and calling NT syscalls directly β€” no Win32 API strings, no GetProcAddress, no GetModuleHandle. Custom PEB walk, export table parsing, and compile-time Djb2 hashing.

April 19, 2026 Β· 10 min Β· MrAzoth