indirect-syscall-dev
Indirect Syscall Dispatch — Windows x64
Invoke an NT API by executing the syscall instruction from inside an unmodified module (ntdll), without calling the hooked Nt* / Zw* stub prologue. The result: a call stack that ends in ntdll!<some Nt function>+0x12 instead of yourloader!your_trampoline, and no inline-hook byte-pattern detection on your dispatch path.
This skill is the dispatch companion to stack-spoofing. It assumes you understand ntdll stub layout and the syscall ABI at the level of windows-internals/references/syscalls.md. It focuses on implementing the dispatcher correctly.
When to activate
- Implementing or reviewing indirect syscall dispatchers in C / C++ / Rust / Go
- Selecting between Hell's / Halo's / Tartarus' / FreshyCalls / RecycledGate on a specific EDR hook pattern
- Debugging SSN drift after a Patch Tuesday (
STATUS_INVALID_PARAMETERfrom an NT API that used to work) - Diagnosing
syscall;retgadget discovery failures on stripped ntdll builds - Composing an indirect dispatcher with a stack spoof trampoline (Draugr / SilentMoonwalk)
- Writing a multi-arg wrapper (
NtCreateThreadExhas 11,NtQuerySystemInformationExhas 6) - Porting a dispatcher between languages — preserving the SSN-table and gadget-cache contracts
If the question is "what does mov r10, rcx mean" → wrong skill, read windows-internals/references/syscalls.md. If the question is "how do I build a dispatcher that still works when ntdll is inline-hooked at offset 0" → right skill.