Detecting Manual Syscalls from User Mode
Conversation
this is my favourite method - unless an AV product has been chewing on ntdll.text section.
1
Exactly. IIRC that's how one of the syswhispers implementations handles it. You can also just remove the entry from the PEB to begin with.



