SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
ID: 8b4a2318-bfa9-5f27-9c1a-528a334a7762
STIX ID: report--8b4a2318-bfa9-5f27-9c1a-528a334a7762
Feed Name: GBHackers
Threat Score
SindriKit 1.3.0 introduces a native call-stack spoofing engine that parses .pdata and unwind structures to locate large stack frames (“Fat Frames”) and construct trampolines that conceal real return addresses, enabling syscalls and payload cleanup to execute while RtlVirtualUnwind reconstructs a legitimate-looking call chain; this enhances previous SindriKit evasion techniques and targets modern EDRs that combine ETW and thread suspension.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
