LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection
ID: cb7e02fb-dc31-5f3a-b264-e50a1369202e
STIX ID: report--cb7e02fb-dc31-5f3a-b264-e50a1369202e
Feed Name: GBHackers
## Executive Summary This report documents the LACUNA Chain "Ghost Frames" technique, which exploits gaps in Windows unwind metadata to construct benign-looking call stacks from trusted DLL addresses (ntdll, kernelbase, win32u, wow64). By chaining these "ghost" frames and exploiting a timing window in ETW-Ti's asynchronous stack collection (the ETW-Ti APC Window), the technique can hide malicious execution from kernel-level stack telemetry and shadow stacks; the study demonstrates successful evasion against multiple enterprise EDRs and recommends detection improvements focused on anomalous gap addresses and multi-telemetry correlation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
