Post #2109 5.82K Aug 20, 2024, 10:48 UTC LayeredSyscall – Abusing VEH to Bypass EDRshttps://whiteknightlabs.com/2024/07/31/layeredsyscall-abusing-veh-to-bypass-edrs#redteam #edr #hook #bypass White Knight Labs LayeredSyscall - Abusing VEH to Bypass EDRs | White Knight Labs Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows. 🔥 6 😴 3 ❤ 2 👍 2