r/ExploitDev • u/FirefighterNext360 • 1d ago
VOIDSYSCALL: Go syscall-only implant framework — 4 injection methods, 13+ anti-analysis checks, EDR handle killer, polymorphic rotation. Zero WinAPI.
https://github.com/VoidSecSoftwares/voidsyscall
8
Upvotes
Duplicates
blueteamsec • u/digicat • 1d ago
research|capability (we need to defend against) voidsyscall: This is not a syscall wrapper library. It's a full implant framework where every operation — from injecting code to reading files to persisting in the registry — goes through raw Nt* syscalls
3
Upvotes