TGViewer
Proxy Bar Proxy Bar @proxy_bar · 21.5K subscribers
Post #3235 5K
NT AFD.SYS HTTP Downloader: From First Syscall to bypass the majority of usermode EDR hooks

Text and code by Eleven Red Pandas https://github.com/oxfemale · https://x.com/bytecodevm

The article explores a low-level networking technique on Windows that bypasses the traditional Winsock API layer by communicating directly with the kernel networking driver AFD (Ancillary Function Driver) through Native API calls such as NtCreateFile and NtDeviceIoControlFile. Instead of using standard functions from ws2_32.dll, the…

https://core-jmp.org/2026/03/nt-afd-sys-http-downloader-from-first-syscall-to-bypass-the-majority-of-usermode-edr-hooks/
  • 😱 8
  • 👍 4
  • 🔥 1
More from @proxy_bar
  1. Sep 30, 2026После обеда доклады продолжаются !!!
  2. Sep 30, 2026Достать мерч в этом году стало проще, но быстро разбирают
  3. Sep 30, 2026Стартовал zeroNights 2026 #zeronights2026
  4. Sep 30, 2026Пора выдвигаться ! Увидимся внутри $USERNAME #zeronights2026
  5. Sep 28, 2026CVE-2026-19444: kubectl 😆😆😆
  6. Sep 28, 2026Prompt Injection in the Wild
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →