Call Stack Spoofing via Thread Pool and Enum Callback Trampolining

The research explores a Windows EDR evasion technique that forges a legitimate-looking call stack. The author demonstrates how to combine the Thread Pool, Windows API callback functions, and indirect system calls to create a
Vendors
Intel
Products
Control-Flow Enforcement Technology
Edr
Intel Cet
Thread Pool
Windows
Windows Api