indirect-syscall-dev

Installation
SKILL.md

Indirect Syscall Dispatch — Windows x64

Invoke an NT API by executing the syscall instruction from inside an unmodified module (ntdll), without calling the hooked Nt* / Zw* stub prologue. The result: a call stack that ends in ntdll!<some Nt function>+0x12 instead of yourloader!your_trampoline, and no inline-hook byte-pattern detection on your dispatch path.

This skill is the dispatch companion to stack-spoofing. It assumes you understand ntdll stub layout and the syscall ABI at the level of windows-internals/references/syscalls.md. It focuses on implementing the dispatcher correctly.

When to activate

  • Implementing or reviewing indirect syscall dispatchers in C / C++ / Rust / Go
  • Selecting between Hell's / Halo's / Tartarus' / FreshyCalls / RecycledGate on a specific EDR hook pattern
  • Debugging SSN drift after a Patch Tuesday (STATUS_INVALID_PARAMETER from an NT API that used to work)
  • Diagnosing syscall;ret gadget discovery failures on stripped ntdll builds
  • Composing an indirect dispatcher with a stack spoof trampoline (Draugr / SilentMoonwalk)
  • Writing a multi-arg wrapper (NtCreateThreadEx has 11, NtQuerySystemInformationEx has 6)
  • Porting a dispatcher between languages — preserving the SSN-table and gadget-cache contracts

If the question is "what does mov r10, rcx mean" → wrong skill, read windows-internals/references/syscalls.md. If the question is "how do I build a dispatcher that still works when ntdll is inline-hooked at offset 0" → right skill.


Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
indirect-syscall-dev — aeondave/malskill