Indirect Syscalls: Detection Beyond One Sensor
Indirect syscall research explores alternate routes through internal Windows service boundaries. Defenders should focus on the observable action and require independent endpoint evidence, rather than building an alert around a particular calling convention.
Behavior survives routing changes
A process that creates a suspicious child, accesses a protected process, modifies persistence, or connects to a rare destination leaves evidence beyond one API layer. Build analytics around sequence, signer, user, target object, and result. Keep kernel, identity, and network data available for corroboration.
Safe testing and controls
Use approved purple-team simulations and a disposable VM to test event coverage; never turn bypass research into production code. Use Sigma to capture behavior hypotheses, then validate them with EDR and Sysmon. Enable tamper protection, application control, least privilege, and prompt security updates.
CVE context
CVE-2023-21768 was a Windows error reporting service elevation-of-privilege vulnerability exploited in the wild. It demonstrates why the impact of a user-mode foothold depends on patch level and privilege boundaries, not merely on a process's API use.
Key takeaways
- Detect the action, target, and sequence rather than a single call path.
- Test coverage with authorized simulations and independent telemetry.
- Patch privilege-escalation flaws and reduce local admin exposure.