API unhooking via Perun's Fart

This TTP will create a new process in a suspended state, create a clean version of `ntdll.dll`, and overwrite the `ntdll.dll` from the current process to unhook it. After `ntdll.dll` is unhooked, the shellcode is executed to spawn calc.exe.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
API unhooking via Perun's Fart


API unhooking by overwriting the current process version of the DLL.