https://winternl.com/detecting-manual-syscalls-from-user-mode/
https://fool.ish.wtf/2022/11/detecting-indirect-syscalls.html
https://www.crow.rip/crows-nest/mal/dev/inject/syscalls/indirect-syscalls
https://jsecurity101.medium.com/understanding-telemetry-kernel-callbacks-1a97cfcb8fb3
https://www.countercraftsec.com/blog/detecting-malicious-artifacts-using-an-etw-consumer-in-kernel-mode/
https://www.youtube.com/watch?v=Le5GHLthnlc
https://github.com/thefLink/Hunt-Weird-Syscalls/tree/main
https://s3cur3th1ssh1t.github.io/A-tale-of-EDR-bypass-methods/
https://github.com/microsoft/krabsetw/tree/master
https://0xdarkvortex.dev/hiding-in-plainsight
https://discord.gg/U23CTVJnuS
By 0xkylm