Index / Techniques / Direct Syscalls
Technique Record · T1106

Direct Syscalls

Publicly-reported instances of Direct Syscalls bypassing endpoint security products. Maintained on the same basis for every technique in the Index.

4
recorded bypasses
3
products affected

Products recorded as bypassed by Direct Syscalls

ProductEntriesHigh-confidenceMost recent
Microsoft 212026-05-04
Bitdefender 102024-05-08
Sophos 112024-07-24

All entries

ProductConfidenceDisclosedSource
Microsoft high 2026-05-04hackers-arise.com record →
Sophos high 2024-07-24github.com record →
Bitdefender medium 2024-05-08github.com record →
Microsoft medium 2024-05-08github.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.