RBT Security

RBT Security RBT Security is built to help companies protect their networks and systems against cyber threats.

We believe we can make a difference through our pe*******on testing, security awareness, Red Team, Adversary Emulation, and Purple Team assessments.

If security tools only monitor standard API calls, what happens when attackers skip them entirely? Our new demo covers d...
07/14/2026

If security tools only monitor standard API calls, what happens when attackers skip them entirely?

Our new demo covers direct syscalls, a technique that bypasses traditional antivirus hooks by communicating directly with the Windows kernel. We walk through manually extracting syscall numbers, automatically building the code with SysWhispers3, and executing a Havoc C2 beacon.

πŸ”— Blog: https://www.rbtsec.com/blog/direct-syscalls-in-practice-bypassing-userland-edr-hooks-with-windbg-syswhispers3-havoc-c2/
πŸ”— Demo: https://www.youtube.com/watch?v=LA5ls9mDCzQ

Direct syscalls let malware bypass userland EDR hooks by calling the Windows kernel directly. Instead of going through the heavily hooked ntdll.dll stubs, the implant builds its own clean syscall stub (mov r10, rcx; mov eax, SSN; syscall; ret).

API hooking can be weaponized.We built GhostHook a.k.a (Pekenux) to demonstrate how attackers use Microsoft Detours and ...
06/28/2026

API hooking can be weaponized.

We built GhostHook a.k.a (Pekenux) to demonstrate how attackers use Microsoft Detours and sRDI to steal credentials directly from password managers in memory without leaving a file on disk. Check out the technical breakdown.

πŸ”— Blog: https://www.rbtsec.com/blog/api-hooking-techniques-trampoline-hooks-iat-hooking-and-inline-patching-copy/

πŸ”— Demo: https://youtu.be/gnZpBbXUmxc

New to Maldev? Start with our Maldev 101 - foundational series befo...

Check out our latest demo on how advanced implants evade Windows Defender protections using memory encryption, API obfus...
04/28/2026

Check out our latest demo on how advanced implants evade Windows Defender protections using memory encryption, API obfuscation, and hybrid C2 redirectors.

https://www.youtube.com/watch?v=8y7L1gCtk-M

3 likes. "Windows Defender Evasion: Implant Analysis & Full Bypass | Havoc C2"

Address

18 King Street East, Suite 1400
Toronto, ON
M5C1C4

Alerts

Be the first to know and let us send you an email when RBT Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share