Overview
Havoc implements indirect syscalls to evade user-mode hooks placed by EDRs and security products. Instead of callingsyscall instructions directly from hooked NTDLL functions, Havoc extracts the syscall instruction address from a clean function and invokes it indirectly.
Indirect syscalls bypass user-mode hooks by avoiding hooked function prologues while still using legitimate syscall instructions from NTDLL.
How It Works
Syscall Extraction
During initialization, Havoc extracts two critical pieces of information from NTDLL:- System Service Number (SSN): The syscall number for each NT function
- Syscall Instruction Address: Location of a clean
syscallinstruction
payloads/Demon/src/core/Syscalls.c:12
SSN Extraction Process
TheSysExtract function parses NTDLL function stubs to extract SSNs:
Source: payloads/Demon/src/core/Syscalls.c:90
Hook Detection & Evasion
If a function is hooked, Havoc uses neighboring syscalls to calculate the correct SSN: Source:payloads/Demon/src/core/Syscalls.c:201
Assembly Implementation
The actual syscall invocation is performed in assembly: Source:payloads/Demon/src/asm/Syscall.x64.asm
Execution Flow
- Configuration:
SysSetConfigstores the syscall configuration (SSN + instruction address) - Invocation:
SysInvokeloads the SSN and jumps to the cleansyscallinstruction - Execution: The CPU executes the syscall using the correct SSN
- Return: Execution returns to Havoc code
Supported Syscalls
Havoc extracts SSNs for the following NT functions during initialization: Source:payloads/Demon/src/core/Syscalls.c:43
Full Syscall List
Full Syscall List
EDR Evasion Benefits
Bypasses User-Mode Hooks
EDRs typically hook NTDLL functions by modifying the first few bytes:Kernel Callback Visibility
OPSEC Considerations
- Memory Scanning: The syscall configuration stored in memory may be detected
- Call Stack Analysis: Stack traces will show unusual call patterns
- Telemetry: Kernel callbacks still fire for all operations
- Thread Context: Some EDRs inspect thread start addresses and call stacks
Related Techniques
- Token Management - Uses indirect syscalls for token operations
- .NET Execution - Combines with AMSI bypass
- Stack spoofing for return address manipulation
References
- Syscall extraction:
payloads/Demon/src/core/Syscalls.c - Assembly stubs:
payloads/Demon/src/asm/Syscall.x64.asm - Configuration:
payloads/Demon/include/core/Syscalls.h
