Siber Alem / Detail / 120 / Kirmizi-takim-red-team-operasyonlari-ve-edr-bypassing-process-injection-unhooking
vuln_report_viewer.sh
VULN REPORT / gövde gösterisi / ID: 120

Kırmızı Takım (Red Team) Operasyonları ve EDR Bypassing (Process Injection, Unhooking)

2026-07-21
35 views
Verified
EXPERT-REDTEAM-2026
Red teaming / edr bypass

Summary

This entry details a vulnerability found in the target system. The exploit was published on 2026-07-21 and has garnered 35 views from the community. It is classified under the gövde gösterisi category. Users are advised to review the source code in the Detail tab for technical specifics.

exploit_120.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
# Kırmızı Takım (Red Team) Operasyonları ve EDR Bypassing (Process Injection, Unhooking)

> **İleri Seviye Uzmanlık Rehberi**: Kurumsal EDR çözümlerinin (CrowdStrike, Defender for Endpoint) tespit mekanizmalarını aşma teknikleri.

---

## 1. EDR Nasıl Çalışır? (API Hooking)

EDR sistemleri, zararlı davranışları tespit etmek için kullanıcı modundaki `ntdll.dll` içerisindeki kritik WinAPI fonksiyonlarına (örneğin `NtOpenProcess`) JMP kancaları (hooks) koyar.

---

## 2. Direct Syscalls (Doğrudan Sistem Çağrıları)

Saldırgan `ntdll.dll` kancalarını atlamak için Kernel seviyesine doğrudan `syscall` komutu ile geçiş yapar:

```asm
mov r10, rcx
mov eax, 55h ; NtOpenProcess Syscall Number
syscall
ret
```

Author Profile

Admin
Admin Elite Member
View All Submissions

Entry Stats

Views 35
Downloads 8
Comments 1