Cortex Bypass
by s4ltyt04st - Friday November 10, 2023 at 02:52 PM
#1
Hey there,

I've been developing some malware trying to bypass Cortex's XDR. I have a malware that creates a process and injects a payload into it, I do all this whith syscalls (without the command syscall in my asm code, I do a jump in a memory space where I know that is an instruction syscall and a ret), but Cortex still catching my malware by "Behaviour".
Does anyone now how can Cortex catch this if I ain't using the ntdll.dll so Cortex shouldn't been able to see my actions?

Thanks.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Bypass Cookies Encryption | Working FrancisMDouble 8 1,055 1 hour ago
Last Post: 0x0xGunger998
  Malware On Steroids 0neSh0t 348 24,205 1 hour ago
Last Post: 0x0xGunger998
  [ LIST ] 5 FREE STEALERS WITH PROS/CONS elix 391 15,326 1 hour ago
Last Post: 0x0xGunger998
  Malware Development MD MZ E Book Mandala 51 2,003 1 hour ago
Last Post: 0x0xGunger998
  3 sektor7 free courses NEO123 50 3,410 1 hour ago
Last Post: 0x0xGunger998

Forum Jump:


 Users browsing this forum: 1 Guest(s)