logo

SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection

ID: 8b4a2318-bfa9-5f27-9c1a-528a334a7762

STIX ID: report--8b4a2318-bfa9-5f27-9c1a-528a334a7762

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-21

Author: Divya

...
...

SindriKit 1.3.0 introduces a native call-stack spoofing engine that parses .pdata and unwind structures to locate large stack frames (“Fat Frames”) and construct trampolines that conceal real return addresses, enabling syscalls and payload cleanup to execute while RtlVirtualUnwind reconstructs a legitimate-looking call chain; this enhances previous SindriKit evasion techniques and targets modern EDRs that combine ETW and thread suspension.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.