GhostSys is an academic research toolkit that showcases five CET-compliant syscall evasion methods designed to bypass leading EDRs on Windows 11. This project provides open-source resources, including gadget discovery and eBPF JIT abuse techniques, serving as a valuable asset for educational and research purposes in cybersecurity.
GhostSys is an academic research project that presents a proof-of-concept toolkit showcasing five syscall evasion techniques compliant with CET (Control-Flow Enforcement Technology). This toolkit is designed to effectively bypass advanced endpoint detection and response systems (EDRs) on Windows 11, including leading solutions like SentinelOne Singularity XDR, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
The research paper is currently in the publication process and will remain accessible within this repository until published.
This project is intended strictly for educational, academic, and red team research use. The techniques may help enhance system defenses rather than facilitate unauthorized access or exploit vulnerabilities. Users must employ these methods responsibly, ethically, and only in controlled environments or with explicit consent. Users are fully responsible for any implementation of the provided code.
# To use the provided tools, ensure a safe lab environment before execution.
GhostSys serves as a vital resource for researchers and practitioners looking to explore and improve cybersecurity measures against emerging threats.
No comments yet.
Sign in to be the first to comment.